PRIVACY POLICY

1.Introduction

Empower Physio Sligo Ltd ("we", "our", "us") is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect your personal information when you visit our website, contact us, or book an appointment with us.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Protection Act 2018 and applicable Irish data protection laws.

2.Data Controller

The data controller responsible for your personal information is:

Empower Physio Sligo Ltd

Address:
Unit B2A, The Back Avenue,
Cleveragh Industrial Estate,
Co. Sligo,
Ireland
F91 X3EW

Email:
info@empowerphysiosligo.ie

3.Information We Collect

We may collect and process the following information:

Website Enquiries

If you contact us through our website, email or telephone, we may collect:

  • Name

  • Email address

  • Telephone number

  • Any information included in your enquiry

Appointment Bookings

When booking an appointment online through our booking system, we may collect:

  • Name

  • Contact details

  • Appointment preferences

  • A brief description of your injury, symptoms or reason for seeking treatment

Health Information

Information relating to your symptoms, injury or reason for seeking treatment may constitute special category personal data under GDPR.

Where such information is voluntarily provided, it will be processed only for the purposes of appointment management, determining suitability for physiotherapy services, and directing individuals to appropriate healthcare services where necessary.

Technical Information

When you visit our website, we may automatically collect:

  • IP address

  • Browser type and version

  • Device information

  • Operating system

  • Website usage information

Cookie and analytics information

4.How we use your information

We may use your information to:

  • Respond to enquiries

  • Manage appointments

  • Contact you regarding your booking

  • Provide physiotherapy services

  • Process payments

  • Improve our website and services

  • Maintain security and prevent misuse of our website

  • Comply with legal and regulatory obligations

5. Legal Basis for Processing

We process personal data under the following legal bases:

Contract

Where processing is necessary to manage appointments or provide services requested by you.

Legitimate Interests

Where processing is necessary to operate and improve our business, respond to enquiries and manage our website.

Consent

Where required for cookies, analytics or marketing communications.

Legal Obligation

Where processing is required by law or regulatory requirements.

Special Category Health Data

Health information is processed only where necessary for the provision of healthcare services and in accordance with Article 9 GDPR.

6. Online Booking and Third-Party Providers

Appointments may be booked through Cliniko.

Cliniko acts as a data processor on our behalf and processes information in accordance with its own privacy and security standards.

Payments may be processed through Stripe or other secure payment providers. We do not store or have access to full payment card details.

7.Marketing Communications

If we introduce newsletters or marketing communications in the future, we will only send these where you have provided consent or where otherwise permitted by law.

You may unsubscribe at any time.

8.Data Retention

We retain personal information only for as long as necessary for the purposes for which it was collected, including legal, regulatory, taxation and business requirements.

Enquiry information may be retained for a reasonable period following contact.

Clinical records are retained in accordance with professional, legal and regulatory requirements applicable to physiotherapy practice in Ireland.

9.Data Sharing

We do not sell personal information.

We may share information with trusted service providers where necessary for:

  • Website hosting

  • Online booking services

  • Payment processing

  • IT and security services

  • Legal or regulatory compliance

All such providers are required to maintain appropriate confidentiality and security measures.

10.International Transfers

Where personal information is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place as required by GDPR.

11.Cookies and Analytics

Our website may use cookies and analytics tools to improve website performance and user experience.

Where required by law, non-essential cookies will only be used with your consent.

Further information is available in our Cookie Policy.

12.Children's Privacy

Our services are available to adults and children aged 6 years and older.

Where personal information relates to a child, a parent or legal guardian may be involved in the booking and treatment process as appropriate.

13.Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure.

However, no method of internet transmission can be guaranteed to be completely secure.

14.Your Rights

Under GDPR you may have the right to:

  • Access your personal data

  • Correct inaccurate data

  • Request deletion of data

  • Restrict processing

  • Object to processing

  • Request data portability

  • Withdraw consent where processing relies on consent

Requests may be submitted to:

info@empowerphysiosligo.ie

15.Complaints

If you are unhappy with how we process your personal information, you have the right to lodge a complaint with the Data Protection Commission.

16.Changes to this Policy

We may update this Privacy Policy from time to time.

Any updates will be published on this page together with the revised version date.