top of page
CorPhysio logo

• Movement • Mobility • Strength • Recovery • Balance

• Flexibility • Rehabilitation • Performance • Prevention • Wellbeing

Privacy Policy

Last Updated: August 2026

CorPhysio is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal and health data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

About Us (The Data Controller)


CorPhysio is a private physiotherapy practice operated by Frances Rafiq.

Data Controller: Frances Rafiq
ICO Registration Number: ZB251216
Contact Email: fran@corphysio.co.uk
Contact Number: 07815 569191

The Types of Personal Data We Collect
 
Personal Identifiers: Name, date of birth, home address, email address and phone number.
Emergency Contact Details: Name and phone number of a next of kin.
Special Category (Health) Data: Medical history, clinical symptoms, assessment notes, treatment plans, GP details, scans and referral letters.
Financial Data: Payment details, billing history and health insurance policy numbers, where applicable.

How We Get Your Personal Data and Why We Have It

Most of the personal information we process is provided directly by you, for example when:

  • You book an appointment through our website or booking system.

  • You complete an initial intake or health questionnaire.

  • You contact us directly by email, text or WhatsApp.

We may also receive personal information from:

  • Medical specialists, GPs or insurance companies providing a referral.

  • A previous clinic where you have specifically requested that your historic clinical records are transferred to CorPhysio.

Our Lawful Basis for Processing Your Information

Under UK GDPR, CorPhysio processes personal information only where there is a lawful basis to do so. Depending on the purpose, this may include:

Contract: Where processing is necessary to arrange, provide and manage your physiotherapy services, appointments and payments.

Legal Obligation: Where we are required to process or retain information to comply with applicable legal or regulatory obligations.

Health and Medical Information: Health information is classed as special category data. Where it is necessary for the provision of physiotherapy assessment, treatment and healthcare, CorPhysio relies on the health or social care condition under Article 9(2)(h) of the UK GDPR, together with the relevant provisions of the Data Protection Act 2018.

How We Store Your Personal Data

Your digital clinical records, treatment notes and appointment history are stored securely within Rehab Guru, the clinical management system used by CorPhysio. Appropriate measures are taken to protect personal and health information against unauthorised access, loss or disclosure.

CorPhysio retains clinical records in line with applicable professional and records-management guidance. In England, adult clinical records are generally retained for a minimum of eight years from the date of the last treatment. Records relating to children are retained for longer in accordance with the relevant retention guidance.

Once the relevant retention period has expired, records will be securely deleted or destroyed where there is no continuing legal, regulatory or clinical reason to retain them.

Sharing Your Data

CorPhysio treats your personal and clinical information as confidential. We will never sell your personal information or share it with third parties for their own marketing purposes.

Where necessary and lawful, relevant information may be shared with:

  • Healthcare professionals: Such as your GP, consultant or other healthcare professional involved in your care.

  • Health insurance providers: Where information is required to administer or report on insured treatment.

  • Service providers: Organisations that process information on CorPhysio’s behalf, such as Rehab Guru, where necessary to provide and manage our services.

  • Public authorities or regulators: Where CorPhysio is legally required to disclose information, or where disclosure is otherwise permitted or required by law.

Where information is shared, CorPhysio will only share what is reasonably necessary for the relevant purpose and will do so in accordance with applicable data protection and confidentiality requirements.

Your Data Protection Rights

Under data protection law, you have rights in relation to your personal information. These may include:

  • Right of access: You can ask for a copy of the personal information CorPhysio holds about you.

  • Right to rectification: You can ask us to correct information you believe is inaccurate or incomplete.

  • Right to erasure: In some circumstances, you can ask us to delete your personal information. This right may be limited where CorPhysio is required to retain clinical records.

  • Right to restrict processing: In certain circumstances, you can ask us to restrict how your personal information is used.

  • Right to object: In some circumstances, you may have the right to object to the processing of your personal information.

You will not normally be required to pay a fee to exercise your data protection rights. We will respond to valid requests within the time limits required by data protection law.

To make a request, please contact: fran@corphysio.co.uk

How to Complain

If you have any concerns about how CorPhysio uses or protects your personal information, please contact us in the first instance so that we have an opportunity to address your concerns.

Email: fran@corphysio.co.uk

If you remain dissatisfied, you have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK regulator for data protection.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113

You can also find information about making a data protection complaint on the ICO website. The ICO says that, in most cases, people should raise their concern with the organisation first before escalating it to them.

bottom of page