Privacy Policy

This privacy policy is served by Enphysio Ltd and explains how we; collect, use,  process,  handle, protect and store your personal data when you use our specialist physiotherapy services and/or website www.enphysio.co.uk.  If you are asked to provide personal data when using our physiotherapy services or website, it will only be used in the ways described in this privacy policy.

 

I am committed to protecting and keeping your data secure. If you have any questions, concerns or requests about how I use your information, please contact me (Emily Nellist) our data protection officer,  at emily@enphysio.co.uk or call 07802276519.

 

If you do not agree to the following policy you may wish to refrain from submitting your personal information to us or refrain from using our services and/ or viewing & using our website.

 

This privacy policy will be updated from time to time. The most recent version was last updated October 2019. Please ensure you check our privacy policy when returning to our website or before engaging with our services.

Policy key definitions:

"I", "our", "us", or "we" refer to the business, Enphysio Ltd,

"you", "the user" refer to you, the person using our website or our services.

GDPR means General Data Protection Act 2018.

ICO means Information Commissioner's Office.

Cookies mean small files stored on a user’s computer or device.

About us

 Enphysio ltd is a registered limited company with the companies’ house of England and Wales, registration number 12151386. Emily Nellist is the sole physiotherapist that works under the company name Enphysio ltd.

I am registered and compliant with the following regulatory governing bodies; health care professionals council (HCPC), the chartered society of Physiotherapy (CSP) and the acupuncture association of chartered physiotherapist (AACP).

Enphysio is compliant with GDPR (https://www.gov.uk/data-protection ) and is registered with the ICO (https://ico.org.uk) under the Data Protection Register.

How I use your personal data

Booking an appointment

I will collect personal data from you when you contact me to book an appointment. To book an appointment you will have contacted me via email, phone message or phone call and you will have given your; full name, address, email address and your telephone number. This will be stored securely on a GPDR compliant cloud-based practise management system called writeupp along with your appointment date and time. Your appointment will have been confirmed by either email, phone message or phone call. For more information on writeupp please read their privacy policy at https://www.writeupp.com/privacy-policy/ .

 

I will use your personal data to

●       Register you as a new client

●       To send you documents to read and sign prior to your initial appointment

●       Manage payment

●       Collect and recover monies owed to us

●       To manage our relationship with you

●       To send you details of our services

●       To contact you in response to a specific enquiry.

All the personal data I acquire from or about you will be stored securely.

If I have received a referral for you from your Doctor, it will be uploaded to writeupp. I will have contacted you via telephone or email to organise an appointment and will have taken your contact details to register you as a new client.

You will then receive; documents via email for you to complete &return prior to your initial appointment.

At your initial appointment you will be asked to give further personal details which will include your:  gp name & address, home address, date of birth, email address, telephone number & next of kin contact details. If you have private insurance, you will be required to provide your insurance company details and authorisation code.

During your initial appointment I will take a medical history, this is a legal requirement of our profession and due to the personal data I will collect from you I have a lawful obligation to hold this data in accordance with the GDPR guidelines, article 5. 

Your Physiotherapy records will include your; contact details, assessment and treatment notes which will be held for 8 years from the date of your last treatment. After this time your records will be erased securely. This is a lawful and professional requirement set by our regulatory governing bodies and is in line with NHS industry standards of practice.

At the end of your treatment, I will write a letter back to your referring doctor if you have been referred. I may share your information with your doctor should you require investigation or further treatment by a another health professional but before I do, I will request your permission.

 

Payment

If you are self-paying you will be required to pay the full cost of your appointment by either cash or card at the time of your appointment. If you require a receipt, I will email it to you. Should you not have an email address a printed copy will be sent to you. We will keep a copy of your receipt for six years in keeping with HMRC recording keeping. After this time your receipt/s will be securely deleted.

 

Using our website

If you contact me through our website and provide your personal information you do at your own discretion and risk. Your personal information is kept private and stored securely until a time it is no longer required.

Our website is hosted by Squarespace. Squarespace collects personal data when you visit our website, including:

●       Information about your browser, network and device

●       Web pages you visited prior to coming to this website

●       Your IP address

 

For further information on how squarespace handles your personal data please read their privacy policy at https://www.squarespace.com/privacy

 

Clicking on links

Our website may contain links to other websites or third parties.

Please verify the authenticity of these links before you click on them. If you click on a link/map, cookies maybe saved onto your device from an external website. If you click on these links, you do so at your own risk, and we cannot be held liable for any damages caused by visiting any other websites linked from our website.

 

Cookies

Cookies are small pieces of text sent to your browser which get stored on your device when you visit a website. They serve a variety of functions; they remember preferences and understand how people use different features of the website which can improve the experience of the visitors. 

We use cookies and similar technologies on our website for the following purposes; security & functional cookies, authentication, customisation, performance and analytics.

 

We use these cookies to;

●       Monitor your engagement and how you use our website.

●       Help you navigate and use key features on our website.

●       Help us manage our website effectively and provide the best experience for you.

●       Help us improve the website content and functions.

The cookies we use will not collect, save or store personal information about you.

 

Controlling cookies -opting out

There is a cookie banner on our website which allows you to accept the use of cookies saved to your device. If you do not want our website to store cookies on your device, you could either; not click on the accept cookie banner or change the settings in your web browser to not accept cookies. However, please be aware that in doing so this may limit your ability to use our website. In your browser settings you can see which cookies are active and you can clear them from your browser or device should you wish to do so.

For more information about how squarespace uses cookies to run our website & what cookies are dropped onto your device, please read their cookie policy at www.squarespace.com/cookie-policy .

 

Email mailing list

We do not have an email mailing list that you can subscribe to on our website. If you attend a workshop or an appointment I may ask if you would like to join our email mailing list. Once I have your verbal permission, I will use your personal information and add you to our email mailing list. If you wish to unsubscribe please contact me via email and I will remove you.

Social Media

Enphysio has social media profiles on Instagram, Twitter and Facebook.  Enphysio_for women, @enphysio and enphysio_for women, respectively. For more information on these social media privacy policies please read the following;

https://instagram/privacy

https://twitter.com/privacypolicy

https://m.facebook.com/policy.php

 

Disclosure of your personal data to third parties

I may have to share your personal data with

●       Health professionals for purposes of discussing your treatment

●       Service providers who provide IT

●       HMRC and other regulatory authorities

●       Professional advisors including insurers, lawyers, auditors and bankers

 

I will require all these third parties to whom I share your personal data with, to keep it secure and use it in accordance with the law. They will only be allowed to process your data on our instruction alone.

 

Data security

I have put in place appropriate measures to prevent your personal data from being accessed or used in an unauthorised way or from being accidentally lost.

Keeping your data up to date

I will ask you to confirm your personal data from time to time, as I have a duty to keep accurate and up to date records. If there are any changes to your contact details (email, address or telephone number) please let us know as soon as possible.

 

You can exercise certain legal rights in relation to your personal data that I process. These are below.

 

The right to be informed

I have provided honest explanations in this privacy policy of how I collect and handle your personal data. If you have any questions please contact me via email at emily@enphysio.co.uk.

 

The right of access to your information

If you would like to make a subject access request, please send the request to me in writing with proof of identification. Subject access requests will be handled in accordance with article 15 of GDPR.

I will respond to you within 30 days of receiving your request. You will not be charged for this information. However, if you request more than one copy of your information or request repeated copies of your information and an admin fee will be charged.

The right to request rectification

If there is inaccurate personal data that I hold about you regarding your contact details. Please let me know and I will correct and update your details.

 

With regards to your physiotherapy notes, once I have committed your notes to our practise management system they cannot be changed.  If there is an error in your notes such as a wrong date of surgery or incorrect number of pregnancies. I will add a physiotherapy note to your records with the correct information. However, your original notes cannot be changed or deleted for legal reasons.

 

The right to request erasure of personal data

I have a legal obligation to hold your personal data that I have acquired from your Physiotherapy treatment for 8 years and until this time has passed, I am unable to erase this information.

If you have given me your permission to send you information about Enphysio services by subscribing to our email list, you have the right to request erasure. Please do so by emailing emily@enphysio.co.uk and you will be removed from our email list.

 

The right to request i restrict the processing of your personal data

If you request restriction, no further information would be added to your records and they will be stored on writeupp.

 

The right to request data portability

We are unable to transfer our physiotherapy notes to another physiotherapy service. However, a treatment summary can be written if requested to supply to another service and an admin fee may apply.

 

The right to object

If Enphysio uses your personal data to email you about the services I provide, you can object and withdraw your consent. I will then remove you from our emailing list.

 

The right not to be subject to automated decision-making including profiling

I do not perform any automated decision-making including profiling on your personal data.

 

Complaints

I am committed to protecting and keeping your data secure. However, if for some reason you are not happy with how I collect or use your data you have the right to complain to the ICO. (www.ico.org.uk). I would be grateful however, if you could contact Enphysio first if you do have a compliant, so that I can try and resolve any issues with you.