Privacy Policy — Stay Well Therapies
Last updated: 25/07/2025
Data Controller: Milush Romov, Chartered Physiotherapist Trading as Stay Well Therapies
Email: [email protected]
Business Address: Suite 472 80A Ruskin Ave, Welling DA16 3QQ
ICO Registration Number: Pending
1. Who We Are
Stay Well Therapies is a mobile physiotherapy provider offering in-home services such as falls prevention, postural rehab, and physiotherapy in care or nursing homes. We are committed to protecting your personal data and privacy in accordance with the UK General Data Protection Regulation (UK GDPR).
2. What Data We Collect
We may collect and securely store:
- Full name, date of birth, and contact details
- Address and emergency contact
- GP/consultant details
- Medical and treatment history
- Assessment notes and clinical records
- Payment and appointment information
- Website analytics or cookie data (non-identifiable)
3. Why We Collect Your Data
We process your data to:
- Deliver personalised physiotherapy services
- Maintain accurate and legally compliant clinical records
- Communicate appointment updates
- Handle insurance or legal correspondence
- Fulfil professional and regulatory obligations (HCPC, CSP)
- Maintain internal admin and financial records
4. Legal Grounds for Processing
We rely on the following lawful bases under UK GDPR:
- Contract (Article 6(1)(b)) – to provide physiotherapy services
- Legal obligation (6(1)(c)) – to meet professional and clinical obligations
- Healthcare exemption (Article 9(2)(h)) – for special category health data
- Consent (6(1)(a)) – only used for marketing or optional info sharing
5. Sharing Your Data
Your personal data may be shared only where necessary and with:
- Your GP, consultant, or healthcare team (with your consent or clinical need)
- Insurers or legal representatives (if relevant)
- Regulatory bodies (HCPC, CSP)
- Third-party providers (booking systems, cloud storage) bound by confidentiality
- Accountants or legal advisers (if applicable)
We do not sell or trade your data.
6. Data Security
We take robust security measures, including:
- Encrypted digital records and password protection
- Confidentiality agreements with software providers
- Access restricted to authorised personnel only
7. Data Retention
- Adults: Records are kept for at least 8 years after final treatment
- Minors: Retained until their 25th birthday
- Financial data: Held for at least 6 years for HMRC compliance
After these periods, data will be securely deleted or anonymised.
8. Your Rights
Under UK GDPR, you may:
- Request access to your data
- Correct inaccurate information
- Request deletion or restriction (where legally permitted)
- Withdraw consent (e.g. for marketing)
- Object to processing
- Lodge a complaint with the Information Commissioner's Office (ICO)
Contact:
Email: [email protected]
Mail: Suite 472 80A Ruskin Ave, Welling DA16 3QQ
Phone: 07517231237
ICO: Pending
9. Marketing
We will only send you newsletters or offers if you have explicitly opted in. You can opt out anytime via email or by clicking 'unsubscribe' in any message.
10. Cookies & Website Data
Our website uses cookies for performance and analytics. You can adjust cookie settings via your browser.
11. Complaints
If you have concerns about how your data is handled, please contact us first. If unresolved, you may contact the Information Commissioner's Office:
Website: www.ico.org.uk
Phone: 0303 123 1113