THRIVE PHYSIOTHERAPY

Privacy Policy & Information Governance

How we collect, use, store, and protect your personal information.

Last updated: April 2026

When you use Thrive Physiotherapy (including our Sapphire Children's Therapy service), you trust us with your information. This privacy policy explains what data we collect, why we collect it, what we do with it, and how we protect it. It applies to clients, service users, parents and carers, employees, and self-employed associates.

The Director of Thrive Physiotherapy assumes the function of data controller and supervises compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Thrive Physiotherapy is registered with the Information Commissioner's Office (ICO). Registration reference: ZB928406I.

1. Information we collect

On initial enquiry

•Contact details: name, address, phone numbers, and email address
•Personal details relevant to the enquiry: date of birth, relevant diagnoses, reason for enquiry
•Referral source (e.g. self-referral, GP, solicitor, case manager, school, council)

For children and young people (0–25)

•Parent/guardian details and description of family unit
•Educational placement details
•Pre- and post-natal history
•Developmental data: milestones, feeding, communication, physical, sensory, and learning profile
•Medical details: relevant illnesses, medications, relevant family history
•Reports from other professionals (paediatricians, OTs, SLTs, psychologists, audiology, CAMHS, social care)
•EHCPs, IEPs, school reports, and progress notes from educational staff
•Safeguarding history and/or concerns

For adult clients

•Contact details, medical history relevant to physiotherapy, GP and consultant details
•Reports from other healthcare professionals
•Safeguarding concerns (where relevant)

Assessment and treatment records

•Assessment forms, standardised outcome measures, clinical notes, treatment plans, progress notes, and discharge summaries
•Reports: EHCP, expert witness, medico-legal, and tribunal reports
•Photographs and videos (only with explicit written consent)
•Correspondence: emails, text messages, and records of phone conversations

Financial records

•Name of bill payer and client name, invoices, receipts, records of payments, bank details (where provided)

Employee and associate records

When we engage staff or self-employed associates, we collect: contact details, DBS confirmation, HCPC registration, qualifications, references, right-to-work evidence, bank details, and professional indemnity insurance details.

Website and chatbot data

•Contact form: collects name, email, phone, service interest, and a brief message. Stored by Formspree and forwarded to our inbox.
•AI chatbot: conversations are processed in real time by Anthropic. Not permanently stored by Thrive Physiotherapy. If you tap 'Send my details', the conversation summary is forwarded to our inbox.
•Cookies: essential cookies only. No tracking, analytics, or advertising cookies.

2. Where we get our information

Personal data is provided by the client, or by parents/guardians for children under 16. For clients lacking capacity under the Mental Capacity Act 2005, information may be provided by carers or professionals. Information may also come from schools, medical professionals, solicitors, case managers, and allied health professionals, with prior consent.

3. Lawful basis for processing

Consent (Article 6(1)(a)): you have given clear consent. Legitimate interests (Article 6(1)(f)): processing necessary for providing physiotherapy services. Legal obligation (Article 6(1)(c)): compliance with our HCPC regulatory obligations. Contract (Article 6(1)(b)): necessary for performing the service you've engaged us for.

For health data: Explicit consent (Article 9(2)(a)) and health or social care provision (Article 9(2)(h)).

4. How we use your information

•Provide physiotherapy assessments, treatment, and ongoing care
•Produce clinical reports including EHCP, expert witness, and medico-legal reports
•Communicate about appointments and care
•Liaise with other professionals (with your consent)
•Deliver moving and handling training and organisational services
•Process payments and maintain financial records
•Comply with professional, legal, and regulatory obligations
•Respond to website enquiries
•Recruit and manage employees and associates

5. Data retention periods

Clinical records (children)Until the child's 25th birthday (or 26th if treatment ended at age 17)
Clinical records (adults)8 years from date of last contact or discharge
EHCP reports and tribunal documentationUntil the young person's 25th birthday
Expert witness and medico-legal reportsRetained indefinitely or as required by legal obligations
Financial records6 years from end of financial year (HMRC)
Contact data (enquiries that didn't proceed)12 months, then securely deleted
Employee/associate records6 years from end of employment or contract
Training records and certificates6 years from date of training
Chatbot conversationsNot stored. Form submissions retained 12 months.

If under investigation or if litigation is likely, records are held indefinitely in their original form.

6. Information we share

We do not share personal information unless:

With your consent: we may share with GPs, consultants, schools, local authorities, and social care teams with your explicit written consent. For medico-legal work, information is shared with instructing parties as agreed.

For safeguarding: we will share without consent if we believe a child, young person, or vulnerable adult is at risk of harm, in accordance with the Children Act 1989/2004 and the Care Act 2014.

For legal reasons: if required by law, regulation, or court order.

Third-party data processors

Google WorkspaceEmails, documents, calendarBusiness email and file storage
FormspreeContact form submissionsForwarding website enquiries
Anthropic (Claude AI)Chatbot conversations (not stored)AI enquiry chatbot
NetlifyNo personal data storedWebsite hosting

7. Consent

Prior to initial assessment, clients (or parents/carers) are provided with this privacy policy and asked to sign a consent form covering: consent to assessment and treatment, collection and storage of data, sharing with named third parties, and photographs/video where applicable. Consent may be withdrawn at any time in writing.

8. Photographs and video

Photographs or video will never be taken without explicit written consent. Any images retained as part of clinical records are stored securely in encrypted systems, accessible only to the therapist(s) involved, and not shared without express written consent. If consent is withdrawn, images are deleted unless required for legal or safeguarding purposes.

9. How we protect your data

•All electronic records stored in password-protected, encrypted systems
•Two-factor authentication on all systems containing personal data
•Paper records (if any) kept in locked storage
•Access restricted to therapist(s) directly involved in care
•Associates access only data necessary for their assigned clients
•Portable devices encrypted and password-protected
•Data backed up regularly in encrypted cloud storage
•Staff and associates receive data protection training at induction

10. Children's data

For children under 16, data is collected with consent of a parent or person with parental responsibility. Young people aged 16+ with capacity may provide their own consent. Children's data is used only for physiotherapy care, EHCP provision, or medico-legal reporting. It is never used for marketing.

11. Self-employed associates

Associates working under the Thrive brand are required to: sign a subcontractor agreement including data protection obligations, hold current HCPC registration and appropriate insurance, hold an Enhanced DBS, complete data protection and safeguarding training, access only necessary client data, and return or securely delete all data if the relationship ends.

12. Your rights

•Right of access: request a copy of data we hold (Subject Access Request, responded to within one month)
•Right to rectification: request correction of inaccurate data
•Right to erasure: request deletion (subject to legal retention obligations)
•Right to restrict processing
•Right to data portability
•Right to object to processing based on legitimate interests
•Right to withdraw consent at any time

To exercise any of these rights, please contact us via the contact form. We may need to verify your identity.

13. Data breaches

In the event of a breach, we will assess the risk, notify the ICO within 72 hours if the breach poses a risk to rights and freedoms, notify affected individuals without undue delay if the risk is high, and document the breach and remedial action taken.

14. Complaints

Contact us in the first instance via the contact form. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

15. Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated revision date.

A full copy of our privacy policy is available as a downloadable document on request.