Privacy policy

Your information, handled clearly and responsibly

How PromoteHealth collects, uses and protects personal information when you visit the website, get in touch or book an appointment.

Last updated

Version date: 1 January 2026

PromoteHealth is the data controller responsible for personal data handled through enquiries, bookings and service delivery.

What this policy covers

This policy explains what personal data may be collected, the lawful basis for doing so, how data is stored and shared, and the rights available to you under UK data protection law.

Personal data

The main categories of information we may collect

The exact information collected will depend on how you interact with PromoteHealth.

Information you provide

This may include your name, email address, telephone number, address, appointment details and enquiry information when you contact us, book online, make a payment or use the online booking system.

Health-related information

As a physiotherapy practice, PromoteHealth may process health information that is classed as special category data under UK GDPR. This is used only for the purpose of providing healthcare services and is stored securely using appropriate systems.

Information collected automatically

When you visit the website, limited technical information may be collected such as anonymised IP data, browser type, device information, pages visited and the date or time of visits.

Why it is collected

Personal data may be used to respond to enquiries, manage bookings, provide physiotherapy services, maintain clinical records, process payments, improve the website and keep services secure.

Lawful basis

Third-party systems and data handling

Personal data is processed on the basis of providing healthcare services, fulfilling contractual obligations and complying with legal requirements.

  • Contract: to manage appointments, bookings and services you request
  • Consent: where you contact us or submit enquiries
  • Legal obligation: to meet healthcare, tax or regulatory requirements
  • Legitimate interests: to operate, maintain and improve the website and services securely
  • Special category health data: processed under Article 9(2)(h) for healthcare provision and treatment
Third-party services

Booking, payments and practice software

Online bookings are handled through Square, and health-related records may be managed through Rehab Guru. Relevant data is processed in accordance with their own security measures and legal obligations. PromoteHealth does not store full payment card details on its own systems.

Where trusted third-party suppliers are used, they are expected to process data only as necessary, keep it secure and comply with applicable data protection requirements.

Retention and rights

How long data may be kept and the rights available to you

Data is retained only as long as necessary and in line with professional and legal obligations.

Retention

Clinical records may be retained in line with healthcare guidance, including eight years from the last treatment for adults and longer where records relate to children. Administrative and enquiry data is kept only as long as needed for operational or legal purposes.

Your rights

You may have the right to access personal data, request correction, request erasure where applicable, restrict or object to processing, withdraw consent where consent is relied upon, and complain to the Information Commissioner’s Office.

Cookies and analytics

The website may use cookies and analytics tools to improve functionality and understand website use. Non-essential cookies are used only with consent. See the cookie policy for more detail.

Changes to this policy

This privacy policy may be updated from time to time. Any changes will be posted on this page with an updated version date.