At Polisthenics, we are committed to protecting your privacy and handling your personal data responsibly and transparently. This Privacy policy explains how we collect, use, store and protect your personal data when you use our website, book services or engage with our virtual or in-person offerings.
This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our website or services, you acknowledge this Privacy policy.
1. Information we collect
We collect and process different types of personal data depending on your interaction with us:
- Personal information – name, email address, phone number, date of birth and address.
- Health information – injury history, symptoms, medical or health-related information provided through intake forms or consultations, training background and physical limitations. This information is only collected where necessary to provide safe and appropriate services.
- Technical data – IP address, browser type, device information and website usage data (via cookies and analytics tools).
- Payment information – payment details required to process transactions. We do not store full credit or debit card details. Payments are handled securely by third-party payment providers.
- Additional information – any other data you provide during communication with us, such as through emails or phone calls.
2. Lawful basis for processing your data
We process your personal data under the following lawful bases:
- Contract – processing is necessary to provide services you have requested, including consultations, assessments and personalised programs.
- Legal obligation – we may process data to comply with legal and regulatory requirements, including record-keeping.
- Legitimate interests – to operate our business effectively, improve services, manage bookings and communicate with clients in a reasonable and expected way.
- Consent – where required, such as for marketing communications or non-essential cookies. You can withdraw consent at any time via our contact form, by emailing us or using the “unsubscribe” link in marketing emails.
3. Processing health data
Health information is classified as special category data under UK GDPR.
We process health data because it is necessary for:
- Providing physiotherapy, rehabilitation, and strength and conditioning services
- Assessing suitability for training or treatment
- Monitoring progress and outcomes
This data is processed under the UK GDPR and handled with strict confidentiality.
4. How we use your information
We use your personal data to:
- Deliver physiotherapy, rehabilitation and training services
- Assess your needs and create personalised plans
- Manage bookings and appointments
- Communicate about your services or enquiries
- Process payments securely
- Improve our services and user experience
- Comply with legal and professional obligations
5. How we share your information
We may share your data only where necessary and appropriate:
- Service providers such as payment processors, booking systems and IT support
- Legal or regulatory bodies where required by law
- With your consent, where applicable
All third-party providers are required to handle your data in line with data protection laws.
We do not sell or rent your personal data.
6. Data retention
We will retain your personal data for as long as necessary to provide our services and comply with legal obligations. Health information will be kept for at least eight years following your last treatment or as required by law.
7. Data security
We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse,or disclosure.
While we take data security seriously, no system can guarantee absolute security.
8. Your rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request deletion of your data (subject to legal obligations)
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Request data portability
To exercise your rights, please contact us via our contact form.
9. Cookies and tracking technologies
We use cookies to ensure our website functions properly and to understand how visitors use the site.
- Essential cookies are required for the website to work
- Non-essential cookies (such as analytics) are only used with your consent
You can manage or withdraw your cookie preferences at any time via the cookie settings on our website.
For full details, please see our Cookie policy.
10. International data transfers
If personal data is transferred outside the UK or European Economic Area (EEA), we ensure appropriate safeguards are in place, such as standard contractual clauses or equivalent protections.
11. Changes to this privacy policy
We may update this Privacy policy from time to time to reflect changes in law or our services. Any updates will be posted on this page with a revised โLast updatedโ date.
12. Contact us
If you have any questions regarding this Privacy policy or how we handle your personal data, please contact us via our contact form.
Last updated:ย 11 January 2026