Skip to main content
Privacy Policy — PhysioLeads

PRIVACY POLICY

Policy version: [17-9/26]

Introduction

This Privacy Policy is provided by Joe Sharp Media Limited, a company registered in England and Wales under company number 17430344 with registered office at C/O Kingswood Allotts Limited, Sidings Court, Doncaster, South Yorkshire, England, DN4 5NU ('we', 'our' or 'us'). We provide PhysioLeads, a branded customer relationship management platform for physiotherapy clinics, including integrations, workflows, automations and related services (Services).

We take your privacy seriously. Please read this Privacy Policy carefully as it explains how and why we collect, store, use and share personal data when we act as a controller.

It also explains your rights in relation to your personal data and how to contact us or the Information Commissioner's Office (ICO) if you have a question or complaint. Our processing of personal data is regulated by applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We act as controller for personal data we process for our own purposes, including information about clinic customers, authorised users, enquiries, billing, support, security and our own business communications. Where we process patient, lead or other personal data on behalf of a clinic through the Services (Customer Personal Data), the clinic is the controller and we act as its processor. That processor activity is governed by our agreement and Data Processing Schedule with the clinic.

↑ Back to top

What this policy applies to

This Privacy Policy primarily explains how we process personal data when we act as controller. If you are a patient or prospective patient whose information is processed through a clinic's PhysioLeads account, the relevant clinic is responsible for deciding how and why your information is used. Please also see the section 'Patient and lead data processed on behalf of clinics' below.

The Services may link to or rely on apps, websites, APIs or services owned and operated by us or trusted third parties. Those third parties may process personal data in accordance with their own privacy information where they act as independent controllers. For more information about service providers we use, see 'Who we share your personal data with' below.

↑ Back to top

Personal data we collect about you

The personal data we collect about you when we act as controller depends on how you interact with us and the Services. We may collect and use the following categories of personal data:

Category of dataIn more detail
Identity, contact and account data Your name, business email address, telephone number, clinic or business name, job title or role, username or account identifier, authentication details, business and billing address, and account preferences.
Service, support and relationship data Information about the Services supplied to your clinic, onboarding and configuration information, support requests, correspondence, feedback, account administration records and, where attributable to you, content or prompts you submit through Service features.
Billing and transaction data Subscription and billing history, invoice details, payment status, transaction references and limited payment information provided to us by our payment provider. We do not ordinarily receive or store full payment card details.
Technical, usage and security data IP address, device and browser information, login and session data, access and audit logs, timestamps, security events, pages or features used, and cookie or similar identifier data where applicable.
Enquiry and marketing data Your name, business contact details, clinic or business details, enquiry or demo request, correspondence, marketing preferences, unsubscribe requests and opt-out records.

If you do not provide personal data we reasonably require, we may be unable to create or administer your account, respond to your enquiry, provide support or otherwise provide the Services to your clinic.

We use this personal data for the purposes described in the section 'How and why we use your personal data' below.

↑ Back to top

Patient and lead data processed on behalf of clinics

When a clinic uses the Services, we may process Customer Personal Data on the clinic's behalf. Depending on how the clinic configures its account and integrations, this may include names, dates of birth, contact details, appointment details and appointment types, treating clinician, attendance or session history, lead or patient status, communications, campaign activity and other relevant fields. Some of this information may constitute special category health data because it reveals or allows information about an individual's health or treatment to be inferred.

We process Customer Personal Data only to provide, operate, secure, maintain and support the Services in accordance with the clinic's documented instructions and the applicable Data Processing Schedule. We do not use identifiable Customer Personal Data for our own independent direct marketing or to train general-purpose machine-learning or generative AI models for our own purposes. The Services are not intended to store full clinical notes, diagnoses or complete medical records unless expressly agreed with the clinic.

The relevant clinic is responsible for determining the purposes and lawful basis for processing its patient and lead information, identifying any applicable condition for processing special category data, providing required privacy information and responding to individuals' rights requests. If you are a patient or prospective patient and wish to exercise rights in relation to information a clinic processes through PhysioLeads, you should normally contact that clinic directly. If we receive such a request, we may refer it to the clinic and assist the clinic as required by data protection law and our Data Processing Schedule.

↑ Back to top

How your personal data is collected

We collect personal data directly from you when you or your clinic creates or uses an account, contacts us, requests a demonstration, asks for support, corresponds with us or interacts with our Services. We may also receive business contact information from your clinic or employer and technical information automatically when you use the Services. Where we act as processor, Customer Personal Data may be received from the clinic or a connected practice management system, such as Cliniko, where the clinic has enabled the relevant integration.

The Website and Services may use cookies or similar technologies for functions such as authentication, session management, security, preferences and, where applicable, analytics. Where consent is required by law for a particular cookie or similar technology, we will obtain it before using that technology. Further information will be provided through the Website, Platform or relevant cookie notice where applicable.

↑ Back to top

How and why we use your personal data

When we act as controller, data protection law requires us to have a lawful basis for using your personal data. Depending on the circumstances, we may rely on:

  1. your consent, where consent is required or otherwise appropriate
  2. compliance with our legal and regulatory obligations
  3. performance of a contract with you, or steps taken at your request before entering into a contract, where you personally are party to or seeking to enter into that contract, or
  4. our legitimate interests or those of a third party, where those interests are not overridden by your rights and interests

A legitimate interest is a business or commercial reason to use personal data. Where we rely on legitimate interests, we consider the purpose of the processing, whether it is necessary and the impact on the individual. For example, we may rely on legitimate interests to administer our relationship with a clinic customer and its authorised personnel, provide support, keep the Services secure and communicate with business contacts.

The table below explains what we use your personal data for and why.

What we use your personal data forOur reasons
Create and manage accounts and authorised users Where you contract with us personally, performance of our contract or steps taken at your request before entering into it. Where the clinic or another organisation is our customer, our legitimate interests in administering the customer relationship and enabling its authorised users to access the Services.
Provide the Services, onboarding and support, and communicate with you about your use of the Services Depending on the circumstances, performance of a contract with you or our legitimate interests in providing and supporting the Services for our business customer and its authorised personnel.
Process subscription payments, invoices and other financial administration Depending on the circumstances, performance of a contract, compliance with legal obligations, and our legitimate interests in administering payments, accounts and debts.
Respond to enquiries, demonstration requests and pre-contract communications Steps taken at your request before entering into a contract where applicable, or our legitimate interests in responding to prospective business customers and developing our business.
Send non-marketing service communications, including changes to the Services, terms, policies and important notices Depending on the circumstances, performance of a contract, compliance with legal obligations, or our legitimate interests in administering the Services and customer relationship.
Protect the security and integrity of the Services, systems and data, and prevent misuse or fraud Compliance with legal obligations where applicable and our legitimate interests in securing our systems, users and business and preventing or investigating misuse, fraud and other unlawful activity.
Service analytics, quality assurance and product improvement Our legitimate interests in understanding and improving our Services and business. We use controller data and, where appropriate, aggregated or anonymised information for these purposes. We do not use Customer Personal Data for our own independent purposes contrary to the clinic's instructions or our Data Processing Schedule.
Maintain, update and improve customer and user records Depending on the circumstances, performance of a contract, compliance with legal obligations, or our legitimate interests in maintaining accurate records and managing customer relationships.
Send direct marketing about PhysioLeads and related services Consent where required. Where consent is not required, our legitimate interests in promoting our services to business contacts, subject to applicable electronic marketing rules and your right to object or opt out.
Comply with law, enforce our legal rights, defend claims and manage disputes Compliance with legal and regulatory obligations and, where applicable, our legitimate interests in protecting our business, rights and interests or those of others.
Share relevant information in connection with a merger, acquisition, financing, restructuring, asset sale, insolvency or similar corporate transaction Depending on the circumstances, compliance with legal obligations and our legitimate interests in protecting, realising or growing the value of our business and assets, with information anonymised where reasonably possible.

See 'Who we share your personal data with' for further information on the steps we will take to protect your personal data where we need to share it with others.

↑ Back to top

Marketing

We may send business contacts marketing communications about PhysioLeads and related services where permitted by law.

The rules depend on the type of recipient. Where we send electronic marketing to a corporate subscriber, such as a limited company or LLP, the consent rule in the Privacy and Electronic Communications Regulations 2003 (PECR) generally does not apply, although UK data protection law still applies where we use an individual's personal data and we may rely on legitimate interests where appropriate. Where the recipient is an individual subscriber, such as a sole trader or certain types of partnership, or consent is otherwise required, we will obtain consent or rely on the applicable 'soft opt-in' where its conditions are met.

You can object to or opt out of direct marketing at any time by:

  • contacting us at [insert]
  • using the unsubscribe or opt-out mechanism included in the relevant marketing communication

We will identify ourselves in electronic marketing and provide a valid way to opt out. We do not sell your personal data or share it with other organisations for their own direct marketing purposes.

For more information about your right to object to direct marketing, see 'Your rights' below.

↑ Back to top

Who we share your personal data with

We share personal data with service providers where this is reasonably necessary to operate our business or provide and support the Services. Core categories include CRM and platform providers, hosting and IT providers, communications providers, payment processors, security providers and professional advisers. HighLevel, Inc. provides the underlying CRM platform used for PhysioLeads.

Where a service provider acts as our processor, we require it to process personal data only on our instructions and to implement appropriate protections. Where we use a provider as a Sub-Processor for Customer Personal Data, the additional requirements in our Data Processing Schedule apply.

Depending on the circumstances, recipients of personal data may include:

  • HighLevel, Inc. and other technology, hosting, communications, security and integration providers used to operate and support the Services
  • payment providers, accountants, auditors, insurers, lawyers and other professional advisers who support our business
  • law enforcement agencies, courts, tribunals, regulators and public authorities where disclosure is required or permitted by law
  • actual or prospective purchasers, investors, lenders, professional advisers and other relevant parties in connection with a merger, acquisition, financing, restructuring, asset sale, insolvency or similar transaction, subject to appropriate confidentiality protections

Where a clinic connects a third-party practice management system, such as Cliniko, information may pass between that system and PhysioLeads under the clinic's instructions. The clinic will typically have its own relationship with that provider. If you would like more information about the service providers we use and why, please contact us using the details below.

We do not sell personal data or disclose it to third parties for their own direct marketing purposes.

↑ Back to top

How long your personal data will be kept

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, regulatory and dispute-resolution requirements. In general, we may keep customer contract, billing and financial records for up to 6 years after the relevant customer relationship ends; account, support and business relationship records for the duration of the relationship and thereafter for so long as reasonably necessary, which may be up to 6 years; marketing information until you opt out or it is no longer reasonably required, while retaining a minimal suppression record where necessary to respect your opt-out; and technical or security logs for periods appropriate to their operational and security purpose. Customer Personal Data that we process as a processor is returned or deleted in accordance with the clinic's instructions and the Data Processing Schedule, subject to applicable legal requirements and technical backup cycles.

When personal data is no longer required, we will delete it, securely dispose of it or anonymise it so that it no longer identifies an individual.

↑ Back to top

ANONYMISED INFORMATION

We may use information that has been irreversibly anonymised so that it no longer identifies, and cannot reasonably be used to identify, an individual for purposes such as service analytics, security, performance monitoring and product improvement. We do not treat properly anonymised information as personal data and we will not seek to re-identify it.

↑ Back to top

AUTOMATED DECISION-MAKING

When acting as controller, we do not currently make decisions about individuals based solely on automated processing that have legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law, including appropriate opportunities to make representations, obtain human intervention and contest the decision. Clinics may configure automated workflows and communications within PhysioLeads for their own purposes; where those activities involve Customer Personal Data, the clinic is the controller and is responsible for the relevant decisions and legal requirements.

↑ Back to top

Transferring your personal data out of the UK

To provide and support the Services, we use service providers that may process personal data outside the United Kingdom, including in the United States. This includes HighLevel, Inc., which provides the underlying CRM platform used for PhysioLeads.

Where personal data is subject to a restricted transfer under UK data protection law, we will only transfer it where the transfer is permitted by law, including where an applicable UK adequacy regulation applies or appropriate safeguards and enforceable rights are in place.

  • where a country or recipient is covered by a UK adequacy regulation, we may rely on that adequacy regulation, including the UK Extension to the EU-US Data Privacy Framework where the relevant US recipient is certified and the transfer falls within its scope
  • where adequacy does not apply, we may use safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another transfer mechanism recognised under UK data protection law

The transfer mechanism applicable to a particular provider may change over time where this is permitted by law. Please contact us if you would like further information about the safeguards used for a particular transfer.

↑ Back to top

Your rights

Depending on the circumstances and the way in which we process your personal data as controller, you may have the following rights. These rights are subject to conditions and exemptions under data protection law and can usually be exercised free of charge.

Access to a copy of your personal data The right to be provided with a copy of your personal data.
Correction (also known as rectification) The right to require us to correct any mistakes in your personal data.
Erasure (also known as the right to be forgotten) The right to require us to delete your personal data—in certain situations.
Restriction of use The right to require us to restrict use of your personal data in certain circumstances, e.g. if you contest the accuracy of the data.
Data portability The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations.
To object to use The right to object:
  • at any time to your personal data being used for direct marketing (including profiling)
  • in certain other situations to our continued use of your personal data, e.g. where we use you personal data for our legitimate interests.
Safeguards for significant solely automated decisions Where we make a significant decision based solely on automated processing, the right to receive information about the decision and, where required by law, to make representations, obtain human intervention and contest the decision.

For further information about these rights and when they apply, please contact us using the details below. If your request relates to patient or lead information processed through a clinic's PhysioLeads account, the clinic is normally the controller and you should contact that clinic directly. We may refer your request to the clinic and assist it where required.

If you would like to exercise a right in relation to personal data for which we are controller, please email or write to us using the contact details below. When contacting us, please:

  • provide enough information to identify yourself (for example, your full name, clinic or business and account details) and any additional identity information we may reasonably request, and
  • tell us which right you wish to exercise and the information to which your request relates
↑ Back to top

Keeping your personal data secure

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, unauthorised disclosure or access. Access is restricted to people and service providers who have a genuine need to access the information for the relevant purpose.

We also maintain procedures for responding to suspected personal data breaches. Where required by law, we will notify affected individuals and/or the ICO or another relevant regulator.

If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.

↑ Back to top

How to complain

You can make a data protection complaint to us using the contact details below. We will provide a clear route for complaints, acknowledge a data protection complaint within 30 days, take appropriate steps to investigate it and communicate the outcome without undue delay.

You also have the right to lodge a complaint with the Information Commissioner's Office. You do not need to wait for our complaint process to finish before contacting the ICO, although we would welcome the opportunity to address your concerns directly where appropriate.

The ICO can be contacted through its website at https://ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.

↑ Back to top

Changes to this privacy policy

We may change this privacy policy from time to time. When we make significant changes we will take steps to inform you, for example via the Services or by other means, such as email.

↑ Back to top

How to contact us

  1. For further information about this Privacy Policy or our privacy practices, to exercise a right or to make a data protection complaint about personal data for which we are controller, please contact us using the details below:

Name: Joe Sharp

Email: joe@joesharp.com

Address: C/O Kingswood Allotts Limited, Sidings Court, Doncaster, South Yorkshire, England, DN4 5NU

↑ Back to top