Total Fit Therapy – Newcastle-under-Lyme

Privacy Policy for Total Fit Therapy

 

Last updated: 6 July 2025

 

1. Introduction

Welcome to Total Fit Therapy.  We respect your privacy and are committed to protecting your personal data.  This privacy policy will inform you how we collect, use, and share your personal data when you visit our website, engage our services, or otherwise interact with us, and tell you about your privacy rights under UK law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

 

2. Definitions

Personal data: Any information relating to an identified or identifiable natural person.

Processing: Any operation performed on personal data (e.g., collection, storage, use, transmission).

Data controller: The organisation that determines the purposes and means of processing personal data.

Data processor: The organisation that processes personal data on behalf of the controller.

UK GDPR: The UK’s version of the EU General Data Protection Regulation as retained in UK law.

 

3. Who We Are

Total Fit Therapy Ltd (“we”, “us” or “our”) is the data controller for your personal data.  Our registered office is at 29 Marsh Parade, Newcastle-under-Lyme, ST5 1BT.  For any enquiries about this policy or how we process your data, please contact our Data Protection Officer at info@totalfittherapy.co.uk or by post at the above address.

 

4. Data We Collect

We may collect and process the following personal data:

Identity Data: Name, date of birth, gender.

Contact Data: Postal address, email address, telephone numbers.

Health and Therapy Data: Medical history, therapy notes, fitness assessments, treatment plans.

Financial Data: Payment card details, billing address, transaction history.

Technical Data: IP address, browser type and version, time zone, cookies, usage data.

Marketing and Communications Data: Your preferences in receiving marketing materials and your communication history with us.

 

5. How We Collect Your Data

Directly from you when you register, book appointments, make inquiries, or provide information during treatment sessions.

Automatically through our website (e.g., cookies and analytics).

From third parties, such as referees, health professionals, or payment providers, where necessary and with your consent where required.

 

6. Legal Basis for Processing

We rely on the following lawful bases under UK GDPR:

Contractual necessity: Processing necessary to perform our service agreement with you.

Legal obligation: Processing to comply with applicable laws (e.g., medical record retention, accounting requirements).

Consent: Where you have given clear consent for us to process sensitive data (e.g., health information) or to send marketing communications.

Legitimate interests: Processing necessary for our legitimate interests (e.g., fraud prevention, improving our services), provided your rights do not override those interests.

 

7. How We Use Your Data

We use your personal data to:

Deliver therapy and fitness services, including assessments, treatment planning, and follow-up.

Communicate with you regarding appointments, billing, and enquiries.

Process payments and manage your account.

Comply with legal and regulatory obligations (e.g., health records, audit).

Personalise and improve our services, website, and customer experience.

Send you marketing materials (with your consent).

Protect against fraud and maintain the security of our services.

 

8. Sharing Your Data

We may share your personal data with:

Service providers (data processors), such as IT support, payment processors, and analytics providers, who act on our instructions and are bound by confidentiality.

Healthcare professionals (e.g., GPs, specialists) when you consent or when required for your care.

Regulatory authorities, law enforcement, or courts if required by law.

Acquirers or business partners in the event of a sale, merger, or transfer of assets, subject to confidentiality and data protection safeguards.

 

9. International Transfers

If we transfer your personal data outside the UK, we will ensure appropriate safeguards are in place, such as:

EU/UK approved standard contractual clauses;

Binding corporate rules;

Transfers to countries with an adequacy decision by the UK Government.

 

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption, access controls, regular security assessments, and staff training.

 

11. Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy, or as required by law.  Typical retention periods include:

Medical records: 8 years from last treatment (or 25 years for minors).

Financial records: 6 years for accounting and audit purposes.

Marketing data: Until consent is withdrawn or inactivity for 2 years.

Website data: Cookies and analytics data retained according to our Cookie Policy.

 

12. Your Rights

Under UK GDPR, you have the right to:

Request access to your personal data (Subject Access Request).

Rectify inaccurate or incomplete data.

Erase your data (right to be forgotten) in certain circumstances.

Restrict or object to processing.

Data portability (receive your data in a structured format).

Withdraw consent at any time where processing is based on consent.

Lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have breached data protection laws (www.ico.org.uk).

 

13. Cookies and Tracking

We use cookies and similar tracking technologies on our website to enhance your browsing experience, analyse site traffic, and personalise content. A cookie is a small file placed on your device when you visit a website. Cookies help us recognise your device and remember your preferences.

Types of Cookies We Use

Strictly Necessary Cookies: Essential for website functionality (e.g., login, security, session management).

Performance and Analytics Cookies: Collect anonymous information about how you use the site (e.g., pages visited, time spent) to help us improve performance.

Functional Cookies: Remember choices you make (e.g., language preference, font size) to provide enhanced features.

Marketing and Advertising Cookies: Track your browsing habits to deliver targeted advertisements relevant to your interests.

ThirdParty Cookies

We may allow trusted thirdparty service providers (e.g., Google Analytics, social media platforms) to place cookies when you interact with embedded content or share buttons.

Managing and Disabling Cookies

You can manage or disable cookies at any time through your browser settings. Below are links to popular browser instructions:

Chrome: https://support.google.com/chrome/answer/95647

Firefox: https://support.mozilla.org/kb/enable-and-disable-cookies

Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac

Edge: https://support.microsoft.com/microsoft-edge/delete-cookies-in-microsoft-edge

Please note that disabling strictly necessary cookies may affect the functionality of our website.

Consent

When you first visit our website, you will see a cookie consent banner. By continuing to browse the site without changing your settings, you consent to our use of cookies as described in this policy.

 

14. Changes to This Policy Changes to This Policy**

We may update this policy from time to time.  The “Last updated” date will reflect the most recent changes.  We encourage you to review this policy periodically for any changes.

 

15. Contact Us

If you have questions or concerns about this privacy policy or our data practices, please contact us:

Total Fit Therapy Ltd

29 Marsh Parade, Newcastle-under-Lyme, ST5 1BT

Email: info@totalfittherapy.co.uk

Phone: 07503550373

 

By using our services, you acknowledge that you have read and understood this privacy policy and agree to its terms.