Data Privacy Policies

Data Privacy and GDPR - The Foot Clinic Policy

1.Purpose of this Policy

This Data Privacy & GDPR Policy explains how Sole Therapy Ltd (“the Clinic”, “we”, “our”) collects, uses, stores, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable healthcare confidentiality standards.

We are committed to maintaining the highest level of data protection, clinical confidentiality, and transparency for all patients, staff, contractors, and website users.

2.Data Controller

Sole Therapy Ltd t/a The Foot Clinic Registered in the United Kingdom Contact: cb.footclinic@gmail.com Telephone: 01492 533836 Address:36 Sea View Road, Colwyn Bay, Conwy, LL29 8DG

3.Categories of Personal Data that we Collect

We collect and process the following categories of data:

  • Identity Data — name, date of birth, sex.

  • Contact Data — address, email, telephone number / next of kin contact telephone number.

  • Medical & Clinical Data — medical history, treatment notes, diagnostic information, imaging, prescriptions / medication, referrals.

  • Financial Data — payment information, invoices, transaction records.

  • Technical Data — IP address, browser type, device information.

  • Usage Data — website interactions, appointment booking behaviour.

  • Marketing & Communication Preferences — consent for newsletters, offers, or updates.

4.Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Provision of Healthcare (Article 6(1)(b) & Article 9(2)(h)) Necessary for the performance of a contract and for the provision of medical diagnosis and treatment.

  • Legal Obligation (Article 6(1)(c)) Compliance with HCPC, HMRC, insurance, safeguarding, and clinical record‑keeping requirements.

  • Consent (Article 6(1)(a)) For marketing communications, optional services, or non‑essential data processing.

  • Legitimate Interests (Article 6(1)(f)) For service improvement, fraud prevention, and website analytics.

5.How We Use Your Data

Your data is used for:

  • Delivering podiatric assessment, diagnosis, and treatment.

  • Managing appointments, reminders, and follow‑up care.

  • Maintaining accurate clinical records.

  • Processing payments and invoices.

  • Communicating with you regarding your care.

  • Ensuring regulatory compliance.

  • Improving our website, services, and patient experience.

  • Managing complaints, incidents, or insurance claims.

6.Third Party Services We Use

We use trusted third‑party platforms to deliver safe, efficient clinical and administrative services. Each provider has its own GDPR‑compliant privacy policy and data protection safeguards.

6.1 Cliniko (Practice Management System)

Used for appointment scheduling, clinical notes, invoicing, and secure patient record storage. Data stored: identity, contact, medical, financial. Location: Cliniko is hosted in Australia and is GDPR compliant with Standard Contractual Clauses.

6.2 Squarespace (Website Hosting & Forms)

Used for website hosting, contact forms, and analytics. Data stored: contact details, technical data, usage data. Squarespace uses global servers and maintains GDPR compliance.

6.3 Google Maps (Embedded Location Services)

Used to display clinic location and assist with navigation. Data processed: IP address, device information, location‑related technical data. Google acts as an independent data controller.

6.4 Facebook / Meta Platforms (Social Media & Advertising)

Used for marketing, communication, and optional advertising campaigns. Data processed: engagement metrics, technical data, marketing preferences. Meta acts as an independent data controller.

6.5 Payment Providers (Stripe & Dojo)

Used for secure card payment processing. Data stored: financial data, transaction details.

6.6 Email & Communication Services (Gmail - see google services below for further privacy information)

Used for appointment confirmations, clinical communication, and administrative correspondence.

We ensure all third‑party processors meet UK GDPR requirements and provide appropriate technical and organisational safeguards.

7.Data Sharing

We only share personal data when necessary and lawful:

  • With other healthcare professionals (with your consent or when clinically necessary).

  • With insurers or legal representatives (when required).

  • With regulatory bodies (HCPC, HMRC, safeguarding authorities).

  • With IT providers strictly for maintenance and security purposes.

We never sell personal data.

8.Data Retention

Clinical records are retained for the minimum statutory period:

  • Adults: 8 years from the date of last treatment.

  • Children: Until age 25 (or 26 if treated at age 17).

  • Financial records: 6 years for HMRC compliance.

  • Marketing data: Until consent is withdrawn.

9.Data Security Measures

We implement robust technical and organisational measures:

  • Encrypted clinical records (Cliniko).

  • Secure website hosting (Squarespace).

  • Encrypted email communication (Gmail and Squarespace).

  • Access controls and staff confidentiality agreements (on-site).

  • Regular cybersecurity reviews (All third parties).

  • Secure disposal of paper records (on-site).

10.Your Rights Under UK GDPR

You have the right to:

  • Access your data.

  • Request correction of inaccurate data.

  • Request deletion (where legally permissible).

  • Restrict processing.

  • Object to processing.

  • Request data portability.

  • Withdraw consent for marketing at any time.

Requests can be made by emailing cb.footclinic@gmail.com.

11.Cookies and Website Tracking

Our website may use cookies for:

  • Functionality (booking forms, navigation).

  • Analytics (Squarespace, Google, Cliniko).

  • Marketing (Facebook Pixel, not currently enabled).

You can manage cookie preferences through your browser settings.

12.Complaints

If you have concerns about how your data is handled, you may contact:

Information Commissioner’s Office (ICO)‍ ‍www.ico.org.uk Telephone: 0303 123 1113

13.Updates To This Policy

We may update this policy periodically to reflect changes in legislation, clinical practice, or technology. This will always be the latest version, here, on our Website.

Data Privacy and Squarespace (website host)

Our website collects personal information to power our site analytics, including:

Information about your browser, network, and device; Web pages you visited prior to coming to this website; Your IP address.

This information may also include details about your use of this website, including:

Clicks; Internal links; Pages visited; Scrolling; Searches; Timestamps.

We provide this information to Squarespace, our website analytics provider, to learn about site traffic and activity.

Squarespace data privacy policy HERE

Data Privacy and Google Maps (embedded link on our website)‍ ‍‍ ‍

Our website has an external link to Google Maps for your convenience in locating us.

Their policy is as follows:

When accessing some sub-services of our website, additional personal services are processed.
Processed data categories: technical connection data of the server access (IP address, date, time, requested page, browser information) data for creating usage statistics.
Purpose of processing: Delivery of content provided by third parties and display interactive maps.
The legal basis for processing: Your consent according to Art. 6 (1) a GDPR. Data is transmitted: to the data processor Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, EIR-D02 R 296 Dublin, Ireland (
https://cloud.google.com).
This may also mean a transfer of personal data to a country outside the European Union. The data is transferred to the USA on the basis of Art. 45 GDPR in conjunction with the European Commission's adequacy decision C(2023) 4745, since the data recipient has committed to comply with the data processing principles of the Data Privacy Framework (DPF).

Google Maps Data Policy HERE

T

Data Privacy and Cliniko (embedded link)

Our website includes a link to Cliniko to enhance your booking experience and allow self-booking. Your contact information will be required, and is used solely for identification and for our reception team to contact you when required.

Cliniko is additionally used for booking patients in, storing their contact information, and hosting patient health records.

This information is not shared by us apart from when clinical need dictates eg Sending a letter of referral to a GP.

Your data is hosted by Cliniko cloud, and their data policy can be found HERE

Data Privacy and Dojo (Card Payment Processing)

When you pay by card at our clinic, the payment is processed securely by Dojo, our trusted card‑payment provider.

Dojo collects your card details (securely encrypted), the amount you paid, the date and time of the transaction.

Dojo does NOT collect any medical information, anything unrelated to your payment.

Dojo collects this information to process your payment safely, to prevent fraud, to meet UK financial regulations, to allow refunds or receipts if needed.

Dojo uses bank‑level security and follows strict UK GDPR and payment‑security rules. Neither we nor Dojo can see your full card number.

Your card details are only shared with your bank or fraud‑prevention services when required. It is never used for marketing.

Dojo Privacy Policy HERE

Data Privacy and Facebook (embedded link)

Our website includes a link to our official Facebook page to help us connect with our community and share updates. When you click on this link, you will be redirected to Facebook's platform. Please note that your interactions on Facebook are governed by Facebook's own Privacy Policy and Terms of Service. We encourage you to review their policies to understand how they collect, use, and share your data.

Facebook Data Policy HERE