Privacy Policy
ReThread Health is committed to protecting your personal data and maintaining confidentiality in accordance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018 (DPA 2018)
- Privacy and Electronic Communications Regulations (PECR)
- The Osteopathic Practice Standards issued by the General Osteopathic Council (GOsC)
1. Data Controller
ReThread Health is the Data Controller responsible for your personal information.
- Website: www.rethreadhealth.co.uk
- Email: enquiries@RTH.co.uk
- ICO Registration Number: ZB880295
If you have any questions regarding this policy or your data, please contact us using the details above.
2. The Information We Collect
We collect both personal data and special category data to provide safe and effective healthcare.
Personal Data: Full name, Date of birth, Address, Telephone number, Email address, GP details, Emergency contact details, Appointment history, Billing and payment information (including transaction metadata).
Special Category Data (Health Data): Medical history, Presenting complaints, Clinical findings, Treatment notes, Test results or referral letters, and Correspondence relating to your healthcare.
3. Purpose of Processing
Your information is processed for the following purposes:
- To provide safe, appropriate osteopathic and/or massage treatment.
- To maintain accurate and contemporaneous clinical records.
- To communicate regarding appointments and care.
- To comply with regulatory, professional, and insurance obligations.
- To manage and administer the business (including processing payments).
- To defend or establish legal claims.
4. Lawful Basis for Processing
Personal Data (Article 6 UK GDPR):
- Article 6(1)(b): Performance of a contract (provision of healthcare services and processing payments).
- Article 6(1)(c): Compliance with legal obligations.
- Article 6(1)(f): Legitimate interests in operating a healthcare practice.
Special Category Data (Article 9 UK GDPR):
- Article 9(2)(h): Provision of health care or treatment (supported by Schedule 1, Part 1(2) of the DPA 2018).
- Article 9(2)(f): Establishment, exercise, or defence of legal claims.
Note: Clinical data is processed by or under the responsibility of a health professional subject to the obligation of professional secrecy.
5. Confidentiality & Professional Standards
ReThread Health is bound by professional duties of confidentiality under the Osteopathic Practice Standards (GOsC)and common law. All information shared is confidential unless disclosure is:
- Required by law or court order.
- Necessary to prevent serious harm to yourself or others.
- Made with your explicit consent.
6. Data Storage & Security
Your data is stored securely using:
- Cliniko: Encrypted practice management software (ISO 27001 certified).
- Zettle (by PayPal): Secure, PCI-compliant card payment processing for in-clinic transactions.
- Stripe: Secure, PCI-compliant online payment processing.
- Hardware: Password-protected and encrypted devices.
- Physical: Locked storage for any paper-based records.
We implement technical and organisational measures to safeguard your data against unauthorised access, loss, or disclosure.
7. Retention of Records
Clinical records are retained in accordance with professional healthcare guidance:
- Adults: 8 years from the date of your last appointment.
- Minors: Until the patient’s 25th birthday (or 26th if they were 17 at the time of last treatment), or 8 years after the last treatment, whichever is longer.
Records are securely destroyed/deleted after this period. Financial records are retained for 6 years as required by HMRC.
8. Sharing Your Data
We do not sell data for marketing. Your information may be shared only where:
- Payment Processing: Transaction data is shared with Zettle or Stripe to process your payment. If you request a digital receipt via Zettle, your email or phone number is processed by them for that purpose.
- Care Coordination: Necessary for your care (e.g., sending a report to your GP) with your consent.
- Legal/Insurance: Required by our professional indemnity insurers or by legal mandate/safeguarding requirements.
9. International Transfers
Where providers store data outside the UK (e.g., Cliniko in Australia or PayPal/Zettle global servers), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or the International Data Transfer Addendum, to ensure your data receives the same level of protection as it does in the UK.
10. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your records (Subject Access Request).
- Correction: Request correction of inaccurate data.
- Erasure: Request deletion of data. Please note: This right is not absolute for clinical records. We are legally required to retain medical notes for the periods specified in Section 7.
- Restriction/Objection: Limit how we use your data in certain circumstances.
- Withdraw Consent: Where consent was the sole basis for processing.
11. Cookies & Website Tracking
Our website uses essential cookies for booking functionality. Non-essential cookies (Analytics/Marketing) will only be placed with your explicit consent via our cookie banner.
12. Complaints
If you have concerns about your data, please contact enquiries@RTH.co.uk. If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk.