PRIVACY POLICY
SteadyMotion Clinical Ltd
Last Updated: 11 June 2026
PLAIN ENGLISH SUMMARY (Key Points)
What We Collect:
- Your personal details (name, contact, next of kin)
- Health information (medical history, treatment notes, assessment results)
- Payment details (never store full card numbers)
- Website data (cookies for analytics only)
Why We Need It:
- To provide you with physiotherapy treatment
- To meet legal record-keeping requirements (HCPC)
- To improve our services securely
How We Protect It:
- Stored in secure, encrypted clinical systems
- Access limited to authorised staff only
- Never sold to third parties
- Backed up regularly
Your Rights:
- Request a copy of your data (free of charge)
- Ask us to correct or delete your data
- Object to certain processing
- Withdraw consent at any time
Contact Us:hello@steadymotionclinical.co.uk | Complaints: ICO Helpline 0303 123 1113
Read the Full Legal Policy Below ↓
========================
TABLE OF CONTENTS
========================
1. Who We Are
2. What Data We Collect
3. Why We Need Our Data (Legal Basis for Processing)
4. How We Store and Protect Your Data
5. International Data Transfers
6. Artificial Intelligence (AI) Usage
7. Who We Share Your Data With
8. How Long We Keep Our Data
9. Your Rights Under UK GDPR
10. Cookies and Tracking
11. Complaints
12. Changes to This Policy
13. Contact Us
========================
1. WHO WE ARE
SteadyMotion Clinical Ltd (Company No: 17168626) is a private physiotherapy practice specialising in geriatric and neurological care. We are registered with the Information Commissioner's Office (ICO) under registration number: C1914166.
Our registered office is: 124 City Road, London, EC1V 2NX.
Contact Email: hello@steadymotionclinical.co.uk
Data Protection Officer Contact: dataprotection@steadymotionclinical.co.uk
We are the "Data Controller" for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA). This means we are responsible for deciding how we hold and use your personal data.
2. WHAT DATA WE COLLECT
We collect and process the following categories of personal data to provide our services:
- Identity Data: Name, date of birth, address, contact details, and next of kin information.
- Health Data (Special Category Data): Medical history, diagnosis, treatment notes, assessment results, rehabilitation progress, medication lists, and relevant family history. This is classified as "Special Category Data" under Article 9 of the UK GDPR due to its sensitivity. We also collect visual data (e.g., photographs or videos of posture, gait, or exercises) where clinically relevant.
- Financial Data: Payment details (processed securely via third-party gateways; we do not store full card numbers or CVV codes on our systems).
- Technical Data: IP address, browser type, operating system, and device information (collected via website cookies for analytics only).
- Correspondence Data: Records of communications between you and us (emails, call logs).
3. WHY WE NEED OUR DATA (LEGAL BASIS FOR PROCESSING)
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
- Article 6(1)(b) – Contract: Necessary to perform the contract of care we have with you (assessment, diagnosis, and treatment).
- Article 6(1)(c) – Legal Obligation: To comply with statutory requirements, including record-keeping standards set by the Health and Care Professions Council (HCPC), tax laws, and potential legal proceedings.
- Article 6(1)(f) – Legitimate Interests: To manage our business administration, prevent fraud, improve our services, and for internal quality assurance audits.
- Article 6(1)(a) – Consent: For specific marketing communications (newsletters) or where we require explicit consent to share data with third parties not directly involved in your care.
For Special Category Data (Health Data), we rely on Article 9(2)(h) of the UK GDPR: Processing is necessary for the provision of health or social care or treatment, carried out by a health professional (Chartered Physiotherapist) subject to professional secrecy obligations, in accordance with the Data Protection Act 2018.
Note: Vital Interests are only used in genuine life-or-death emergencies where consent cannot be obtained.
4. HOW WE STORE AND PROTECT YOUR DATA
We take data security seriously. Your data is stored using the following secure methods:
- Clinical Records: All patient clinical notes, assessments, and treatment plans are stored exclusively in a secure, UK-based, GDPR-compliant Electronic Health Record (EHR) system with end-to-end encryption, role-based access controls, and audit logging.
- Communications: Administrative correspondence is handled via secure email channels. No clinical data is stored on personal email accounts.
- Financial Data: Processed via secure third-party payment gateways compliant with PCI-DSS standards. We do not store credit card details on our systems.
- Backups: Automated, encrypted backups are maintained by our cloud provider in accordance with industry best practices.
- Physical Security: Any physical notes or equipment are kept in locked, secure locations when not in use.
- Access Control: Access to data is strictly limited on a "need-to-know" basis. All access to clinical records is role-based and logged.
5. INTERNATIONAL DATA TRANSFERS
Your data may be stored on servers located in the United Kingdom and, in limited circumstances, in countries outside the UK or European Economic Area (EEA), such as the United States (e.g., if our cloud providers or software tools utilize US-based infrastructure).
Where we transfer your data to a country that does not have the same data protection laws as the UK, we ensure appropriate safeguards are in place. These include:
- Using providers who are certified under the EU-US Data Privacy Framework.
- Implementing Standard Contractual Clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreement (IDTA).
- Ensuring the provider adheres to strict security protocols.
- Conducting Transfer Impact Assessments (TIAs) where required.
6. ARTIFICIAL INTELLIGENCE (AI) USAGE
We may utilise Artificial Intelligence tools to assist with administrative tasks (e.g., drafting emails, summarising notes) and clinical support (e.g., generating exercise plan drafts).
- Human-in-the-Loop: All AI-generated content is reviewed, edited, and approved by a qualified Chartered Physiotherapist before being used or shared. AI is never used to make clinical diagnoses or treatment decisions autonomously.
- Data Privacy: We NEVER upload Patient Identifiable Data (PII) to public AI models. All data processed by AI is anonymized or pseudonymized prior to processing.
- No Automated Decision Making: We do not use automated profiling or decision-making that significantly affects you without human intervention.
- Audit Trail: We maintain records of AI usage in line with our Data Protection Impact Assessment (DPIA) processes.
7. WHO WE SHARE YOUR DATA WITH
We do not sell your data. We only share it with:
- Your Referrers (GPs, Consultants) with your explicit consent.
- Other Healthcare Professionals (e.g., Occupational Therapists, Speech Therapists) involved in your care, with your consent.
- Legal/Regulatory Bodies (e.g., HCPC, ICO, Courts) if required by law or to protect vital interests.
- Payment Processors (to process transactions).
- IT Support Providers (who act as Data Processors under strict contractual obligations).
We may also share anonymised data for service improvement or research where permitted by law.
8. HOW LONG WE KEEP OUR DATA
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.
- Adult Patient Records: Retained for a minimum of 8 years after the last contact, in accordance with HCPC and NHS guidelines.
- Child Patient Records: Retained until the patient reaches the age of 25 (or 26 if treated at age 17-18).
- Website Analytics Data: Retained for a maximum of 12 months or until cookies are cleared by the user.
- Marketing Data: Retained until you unsubscribe or withdraw consent.
9. YOUR RIGHTS UNDER UK GDPR
You have the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you (Subject Access Request).
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may request deletion of your data, subject to legal obligations to retain records (e.g., HCPC requirements).
- Right to Restrict Processing: You may request we limit how we use your data in certain circumstances.
- Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time.
To exercise these rights, please contact us at hello@steadymotionclinical.co.uk. We aim to respond to all requests within 30 days. Please note that we may need to verify your identity before processing your request. Some rights may be limited where we have a legal duty to retain records.
10. COOKIES AND TRACKING
Our website uses cookies to improve your experience and analyse traffic.
- Essential Cookies: Necessary for the website to function (e.g., security).
- Analytical Cookies: Used to understand how visitors interact with the website. These do not collect personal identifiers.
- Marketing Cookies: Used to track visitors across websites to display relevant ads (if applicable).
You can control cookies through your browser settings or our Cookie Control System (located on the website footer). If you deny cookies, some features of the website may not function correctly. For more details, please see our Cookie Banner settings on this website.
11. COMPLAINTS
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. CHANGES TO THIS POLICY
We may update this policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be available on our website. We will notify you of significant changes via email if we hold your contact details.
This policy is reviewed annually or following significant legal/practice changes.
13. CONTACT US
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Data Protection Officer Contact: dataprotection@steadymotionclinical.co.uk