PRIVACY POLICY
1.Introduction
Empower Physio Sligo Ltd ("we", "our", "us") is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store and protect your personal information when you visit our website, contact us, or book an appointment with us.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Protection Act 2018 and applicable Irish data protection laws.
2.Data Controller
The data controller responsible for your personal information is:
Empower Physio Sligo Ltd
Address:
Unit B2A, The Back Avenue,
Cleveragh Industrial Estate,
Co. Sligo,
Ireland
F91 X3EW
Email:
info@empowerphysiosligo.ie
3.Information We Collect
We may collect and process the following information:
Website Enquiries
If you contact us through our website, email or telephone, we may collect:
Name
Email address
Telephone number
Any information included in your enquiry
Appointment Bookings
When booking an appointment online through our booking system, we may collect:
Name
Contact details
Appointment preferences
A brief description of your injury, symptoms or reason for seeking treatment
Health Information
Information relating to your symptoms, injury or reason for seeking treatment may constitute special category personal data under GDPR.
Where such information is voluntarily provided, it will be processed only for the purposes of appointment management, determining suitability for physiotherapy services, and directing individuals to appropriate healthcare services where necessary.
Technical Information
When you visit our website, we may automatically collect:
IP address
Browser type and version
Device information
Operating system
Website usage information
Cookie and analytics information
4.How we use your information
We may use your information to:
Respond to enquiries
Manage appointments
Contact you regarding your booking
Provide physiotherapy services
Process payments
Improve our website and services
Maintain security and prevent misuse of our website
Comply with legal and regulatory obligations
5. Legal Basis for Processing
We process personal data under the following legal bases:
Contract
Where processing is necessary to manage appointments or provide services requested by you.
Legitimate Interests
Where processing is necessary to operate and improve our business, respond to enquiries and manage our website.
Consent
Where required for cookies, analytics or marketing communications.
Legal Obligation
Where processing is required by law or regulatory requirements.
Special Category Health Data
Health information is processed only where necessary for the provision of healthcare services and in accordance with Article 9 GDPR.
6. Online Booking and Third-Party Providers
Appointments may be booked through Cliniko.
Cliniko acts as a data processor on our behalf and processes information in accordance with its own privacy and security standards.
Payments may be processed through Stripe or other secure payment providers. We do not store or have access to full payment card details.
7.Marketing Communications
If we introduce newsletters or marketing communications in the future, we will only send these where you have provided consent or where otherwise permitted by law.
You may unsubscribe at any time.
8.Data Retention
We retain personal information only for as long as necessary for the purposes for which it was collected, including legal, regulatory, taxation and business requirements.
Enquiry information may be retained for a reasonable period following contact.
Clinical records are retained in accordance with professional, legal and regulatory requirements applicable to physiotherapy practice in Ireland.
9.Data Sharing
We do not sell personal information.
We may share information with trusted service providers where necessary for:
Website hosting
Online booking services
Payment processing
IT and security services
Legal or regulatory compliance
All such providers are required to maintain appropriate confidentiality and security measures.
10.International Transfers
Where personal information is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place as required by GDPR.
11.Cookies and Analytics
Our website may use cookies and analytics tools to improve website performance and user experience.
Where required by law, non-essential cookies will only be used with your consent.
Further information is available in our Cookie Policy.
12.Children's Privacy
Our services are available to adults and children aged 6 years and older.
Where personal information relates to a child, a parent or legal guardian may be involved in the booking and treatment process as appropriate.
13.Security
We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure.
However, no method of internet transmission can be guaranteed to be completely secure.
14.Your Rights
Under GDPR you may have the right to:
Access your personal data
Correct inaccurate data
Request deletion of data
Restrict processing
Object to processing
Request data portability
Withdraw consent where processing relies on consent
Requests may be submitted to:
15.Complaints
If you are unhappy with how we process your personal information, you have the right to lodge a complaint with the Data Protection Commission.
16.Changes to this Policy
We may update this Privacy Policy from time to time.
Any updates will be published on this page together with the revised version date.