Version date: August 2026
We're committed to protecting the privacy of all individuals who provide personal and medical information to us, including patients who use our clinical services and individuals who contact us through our website. This Privacy Policy explains how we collect, protect, use and share personal information.
We may review and update this policy from time to time. When we do, the latest version will be published on our website, and changes will take effect immediately.
Resync Physiotherapy & Wellbeing is the data controller for the information described in this policy. We are based at 68 Balsall Street, Balsall Common, CV7 7AP. You can contact us about anything in this policy at abi@resyncphysiotherapy.co.uk or on 01676 936083.
We are registered with the Information Commissioner's Office as a data controller under Resync Wellbeing Ltd. This registration was previously held in the name of Abigail Edmunds and transferred to Resync Wellbeing Ltd in August 2026. Personal Information collected before that date continues to be held and processed under this policy.
'Resync Wellbeing Ltd' means Resync Wellbeing Ltd, a company registered in England and Wales under company number 17391320, with its registered office at 1623 Warwick Rd, Knowle, Solihull B93 9LF , trading as Resync Physiotherapy & Wellbeing at 68 Balsall Street, Balsall Common.
'Resync', 'we', 'our' and 'us' refer to Resync Wellbeing Ltd.'You' and 'your' refer to the person using this website or receiving Services from us.
'Patient' means any individual who receives clinical services from Resync, whether in the clinic, at home or online.
'Personal Information' means any information that can identify an individual, including health and medical records.'Special Category Data' means information about health, as defined in Article 9 of the UK GDPR, which we hold in the course of providing Services.
'Services' means physiotherapy, sports and deep tissue massage, acupuncture, Pilates, strength and conditioning, rehabilitation, occupational health, online coaching and programming, and related health services provided by Resync.
'Data Controller' means Resync Wellbeing Ltd, which determines how and why your Personal Information is processed.
Information you provide directly: personal details such as your name, date of birth, address, phone number and email; medical history, presenting symptoms and relevant health information provided during appointments; emergency contact details; and payment and billing information.
Information collected automatically through our website:technical data such as anonymised IP address, browser type, operating system and platform; details about your visit including pages viewed, links clicked, time on site and documents downloaded; and cookie data.
We use your information to provide safe, effective healthcare tailored to you; maintain accurate and legally required clinical records; contact you regarding appointments, treatment plans and follow-ups; process payments and manage accounts; respond to enquiries; comply with legal, regulatory and professional obligations; and improve our services and website experience.
Under UK GDPR we must have a lawful basis for handling your information. For most of what we do, that basis is contract — we need your details to provide the treatment you've booked. For health information specifically, which is special category data, we rely on Article 9: processing necessary for the provision of health treatment by a registered health professional bound by a duty of confidentiality.
We also rely on legal obligation where the law requires us to keep records, legitimate interests for running and improving the practice, and consent for marketing emails and for sharing your information with other healthcare professionals. Where we rely on consent, you can withdraw it at any time.
Our website uses cookies to distinguish you from other visitors. This helps us improve your browsing experience and optimise our website. For full details, please see our Cookie Policy.
We use Cliniko, a secure practice management system, to store your medical records and appointment details. Cliniko is fully GDPR-compliant and adheres to strict international standards of data security and encryption. Your medical records are accessible only to authorised clinical staff.
Your clinical records are held within the UK or the European Economic Area. Some of the services we use for our website, email and analytics may process limited data outside the UK. Where that happens, we only use providers who protect your information to UK standards — through adequacy decisions or standard contractual clauses.
In line with UK healthcare regulations and professional standards, we keep medical records for eight years after your last treatment. For patients under 18, records are kept until your 25th birthday, or 26 if you were 17 at the last treatment. After this period, records are permanently and securely deleted. Enquiry and marketing data is kept for no longer than we need it, and deleted if you unsubscribe.
We may share your data within our team, only with those directly involved in your care and clinic administration; with other healthcare providers such as your GP or consultant, with your consent; where required by law, regulation or court order; and with trusted third-party providers for hosting, secure record storage and email systems. All providers are GDPR-compliant. We do not sell or rent your information to third parties.
We use Heidi Health as a processor for AI-assisted clinical note taking. Heidi processes your information only on our written instructions under a data processing agreement, uses the audio from your appointment solely to generate the draft note rather than retaining it, and holds ISO 27001 and SOC 2 Type II certification. A Data Protection Impact Assessment covering this use is available on request.
We will only send you marketing emails, such as news about classes, talks or offers, if you have asked us to. Every email includes an unsubscribe link and you can opt out at any time, or by emailing us. Opting out of marketing won't affect appointment reminders or clinical communication, which we send as part of your care.
We use physical, electronic and administrative safeguards to protect your data against loss, alteration or unauthorised access. While transmission over the internet can never be entirely secure, once we receive your information we apply strict procedures and security measures to protect it.
In the unlikely event of a data breach that puts your rights or freedoms at risk, we will report it to the Information Commissioner's Office within 72 hours and tell you directly without undue delay.
Under UK GDPR you have the right to access the personal and medical data we hold about you; request corrections to inaccurate data; request erasure where appropriate; restrict or object to certain types of processing; receive your data in a portable format or have it transferred to another provider; withdraw consent where we rely on it; and make a complaint to the Information Commissioner's Office if you are unhappy with how your data has been handled.
To exercise your rights, please contact us in writing. We may ask for proof of identity before processing requests, and we'll respond within one month. There is normally no charge. Please note that some rights are limited where we have a legal duty to retain clinical records.
We treat patients under 18 with the consent of a parent or guardian, who will normally attend the appointment. Their records are handled with the same care and confidentiality as any other patient's, and retained as set out above. Our website is not directed at children.
We use Heidi, an AI clinical documentation tool, to support the quality of the care we provide. During your appointment Heidi listens and produces a draft set of clinical notes, which means we can concentrate on you rather than on writing things down. Every note is reviewed and edited by your physiotherapist before it goes anywhere near your record. The clinical judgement stays ours, and the AI makes no decisions about your care.
We will tell you before we use Heidi in your appointment, and you can decline at any time. If you would rather we didn't use it, just say so and we'll take notes the usual way. Declining will not affect your treatment or the time we spend with you.
We don't use automated decision-making or profiling to make decisions about your care. Clinical decisions are made by a registered physiotherapist.
Our website may occasionally contain links to third-party websites, including our booking system. These sites have their own privacy policies and we are not responsible for them. Please check their policies before providing personal information.
Questions, comments or requests regarding this policy should be sent to abi@resyncphysiotherapy.co.uk. If you're not satisfied with our response, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.