Privacy Policy & Information Governance
How we collect, use, store, and protect your personal information.
Last updated: April 2026
When you use Thrive Physiotherapy (including our Sapphire Children's Therapy service), you trust us with your information. This privacy policy explains what data we collect, why we collect it, what we do with it, and how we protect it. It applies to clients, service users, parents and carers, employees, and self-employed associates.
The Director of Thrive Physiotherapy assumes the function of data controller and supervises compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Thrive Physiotherapy is registered with the Information Commissioner's Office (ICO). Registration reference: ZB928406I.
1. Information we collect
On initial enquiry
For children and young people (0–25)
For adult clients
Assessment and treatment records
Financial records
Employee and associate records
When we engage staff or self-employed associates, we collect: contact details, DBS confirmation, HCPC registration, qualifications, references, right-to-work evidence, bank details, and professional indemnity insurance details.
Website and chatbot data
2. Where we get our information
Personal data is provided by the client, or by parents/guardians for children under 16. For clients lacking capacity under the Mental Capacity Act 2005, information may be provided by carers or professionals. Information may also come from schools, medical professionals, solicitors, case managers, and allied health professionals, with prior consent.
3. Lawful basis for processing
Consent (Article 6(1)(a)): you have given clear consent. Legitimate interests (Article 6(1)(f)): processing necessary for providing physiotherapy services. Legal obligation (Article 6(1)(c)): compliance with our HCPC regulatory obligations. Contract (Article 6(1)(b)): necessary for performing the service you've engaged us for.
For health data: Explicit consent (Article 9(2)(a)) and health or social care provision (Article 9(2)(h)).
4. How we use your information
5. Data retention periods
If under investigation or if litigation is likely, records are held indefinitely in their original form.
6. Information we share
We do not share personal information unless:
With your consent: we may share with GPs, consultants, schools, local authorities, and social care teams with your explicit written consent. For medico-legal work, information is shared with instructing parties as agreed.
For safeguarding: we will share without consent if we believe a child, young person, or vulnerable adult is at risk of harm, in accordance with the Children Act 1989/2004 and the Care Act 2014.
For legal reasons: if required by law, regulation, or court order.
Third-party data processors
7. Consent
Prior to initial assessment, clients (or parents/carers) are provided with this privacy policy and asked to sign a consent form covering: consent to assessment and treatment, collection and storage of data, sharing with named third parties, and photographs/video where applicable. Consent may be withdrawn at any time in writing.
8. Photographs and video
Photographs or video will never be taken without explicit written consent. Any images retained as part of clinical records are stored securely in encrypted systems, accessible only to the therapist(s) involved, and not shared without express written consent. If consent is withdrawn, images are deleted unless required for legal or safeguarding purposes.
9. How we protect your data
10. Children's data
For children under 16, data is collected with consent of a parent or person with parental responsibility. Young people aged 16+ with capacity may provide their own consent. Children's data is used only for physiotherapy care, EHCP provision, or medico-legal reporting. It is never used for marketing.
11. Self-employed associates
Associates working under the Thrive brand are required to: sign a subcontractor agreement including data protection obligations, hold current HCPC registration and appropriate insurance, hold an Enhanced DBS, complete data protection and safeguarding training, access only necessary client data, and return or securely delete all data if the relationship ends.
12. Your rights
To exercise any of these rights, please contact us via the contact form. We may need to verify your identity.
13. Data breaches
In the event of a breach, we will assess the risk, notify the ICO within 72 hours if the breach poses a risk to rights and freedoms, notify affected individuals without undue delay if the risk is high, and document the breach and remedial action taken.
14. Complaints
Contact us in the first instance via the contact form. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
15. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date.
A full copy of our privacy policy is available as a downloadable document on request.