Female Focus Clinic

Privacy Notice (UK GDPR)

Female Focus Physiotherapy

Effective Date: May 2018

Last Updated: March 2026

At Female Focus, we are committed to protecting and respecting your privacy. This Privacy Notice explains how we collect, use, store and protect your personal data, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

  1. Who are we?

    Female Focus is a physiotherapy practice and is the Data Controller for the personal data we process.

    Clinic Address:

    Female Focus, Yew Tree Wellness, Carr Lane, Alderley Edge, Cheshire, SK9 7SL

    Email: babs@femalefocusclinic.co.uk

    Phone: 07483 146186

    Data Protection Lead: Barbara Chesworth

  2. How do we keep your data secure?

    We take the security of your data seriously and use appropriate technical and organisational measures to protect it.

    We use WriteUpp as our practice management system to securely store patient records, clinical notes and appointment information.

    • Security: WriteUpp is ISO 27001 certified and UK GDPR compliant

    • Encryption: Data is encrypted and securely stored on UK/EU servers

    • Access controls: Only authorised staff at Female Focus can access your records, using secure passwords and two-factor authentication

    • Confidentiality: All staff are bound by professional and legal duties of confidentiality

    We regularly review our data protection practices to ensure ongoing compliance.

  3. What information do we collect?

    We only collect information necessary to provide you with safe and effective physiotherapy treatment.

    This may include:

    • Personal information: Name, address, date of birth, contact details

    • Health information (special category data): Medical history, assessment notes, treatment plans, GP or consultant details

    • Administrative information: Appointment records, insurance details, payment history

  4. How and why we use your data

    Lawful basis under Article 6 (UK GDPR):

    We process your personal data because:

    • Performance of a contract: To provide physiotherapy services

    • Legal obligation: To comply with professional, regulatory and record-keeping requirements

    • Vital interests: In emergency situations

    • Consent: For certain communications, such as appointment reminders where required

    Additional condition under Article 9 (health data):

    Because we process health data, we rely on:

    • Article 9(2)(h): Provision of health care and treatment

    • Article 9(2)(a): Explicit consent, where applicable

  5. Who has access to your data?

    • Internal access: Your treating physiotherapist and authorised administrative staff

    • Third parties: We do not sell or rent your data. We only share information with third parties such as GPs, consultants or insurance providers with your consent or where required by law

    • Data processors: WriteUpp processes data on our behalf under a GDPR-compliant data processing agreement

    We do not transfer your data outside the UK unless appropriate safeguards are in place.

  6. How long we keep your data (Retention)

    In line with legal and professional guidance from the Chartered Society of Physiotherapy:

    • Adult records are kept for 8 years from the date of last treatment

    • Children’s records are kept until the patient’s 25th birthday

    After this period, records are securely destroyed.

  7. Your rights under UK GDPR

    You have the right to:

    • Access your personal data (Subject Access Request)

    • Rectification of inaccurate or incomplete data

    • Erasure of your data, where legally permitted

    • Restriction of processing in certain circumstances

    • Data portability, where applicable

    • Object to processing in specific situations

    • Withdraw consent at any time where processing is based on consent

    We do not use automated decision-making or profiling.

  8. Children’s data

    Where we treat children, personal data is processed in line with UK GDPR and professional standards. Consent will be obtained from a person with parental responsibility unless the child is deemed competent to provide consent themselves.

  9. Data breaches

    In the unlikely event of a personal data breach, we will assess the risk and, where required, report it to the Information Commissioner’s Office (ICO) within 72 hours. We will also inform affected individuals if there is a high risk to their rights and freedoms.

  10. Complaints

    If you have concerns about how we handle your personal data, please contact us in the first instance.

    You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO): Website: https://www.ico.org.uk