Home - Privacy Policy

Privacy Policy (One Body LDN Ltd)

Last Reviewed: August 2026

One Body LDN Ltd (“One Body LDN”, “we”, “our”, “us”) is committed to protecting the privacy of our clients, patients, website visitors, and anyone who engages with our services. This Privacy Policy explains how we collect, use, store, share, and protect personal data in line with the UK GDPR, the Data Protection Act 2018, and PECR (privacy rules for electronic communications and marketing).
Plain English Summary
  • We collect the information we need to book appointments, deliver healthcare safely, and run the clinic (including billing and insurance).
  • When you become a patient, we keep clinical records as required for safe care and regulatory reasons.
  • We may use cookies/analytics to improve the website and measure marketing performance (you can control this via our cookie banner).
  • We do not sell your personal data.
  • You have rights over your data (access, correction, objection, etc.) and you can contact us at any time.
1. Who We Are (Data Controller)

Company: One Body LDN Ltd
Registered Office: The Retreat, 406 Roding Lane South, Woodford Green, Essex, England, IG8 8EY
Website: https://onebodyldn.com
ICO Registration: ZA789544

2. Scope of This Privacy Policy

This policy applies to:

  • Visitors to our website
  • Clients/patients using our services (including physiotherapy, sports massage, osteopathy, acupuncture)
  • People who contact us by phone, email, forms, or other channels
  • Email subscribers and marketing recipients
  • Parents/guardians where we treat a child (see Children’s Privacy)

If you are a patient, the sections on Healthcare Data and Retention are particularly relevant.

3. Our Clinical Systems and Data Security

We use medical-grade AI clinical documentation software to manage clinical records and patient administration. The software is registered as a UK Class I Medical Device. This supports robust clinical governance and secure record-keeping aligned with healthcare and data protection expectations.

(For clarity: no software “certification” replaces our own duties as a healthcare provider. We remain responsible for ensuring appropriate security, access controls, retention, and lawful processing.)

4. Definitions
  • Personal Data: Information that identifies you directly or indirectly (e.g. name, email, phone number, IP address).
  • Special Category Data: Sensitive information such as health/medical data.
  • Data Controller: One Body LDN Ltd — we decide how and why personal data is processed.
  • Processor: A third party that processes personal data on our behalf (e.g. booking, email, analytics, payment providers).
5. What Data We Collect

A) Standard personal data

  • Name, email address, phone number
  • Address (home/billing, if needed)
  • Appointment/booking details
  • Communications with us (emails, messages, call notes)
  • Feedback and Complaints Data: Written feedback, survey responses, and formal complaints, which are retained and processed for clinical governance, quality assurance, and staff training purposes.

B) Payment data
Payment status and transaction references. One Body LDN Ltd does not directly store full payment card numbers or card security codes. Where clients save a card to their online account or make a payment, card details are processed and stored securely by our accredited third-party payment service provider in connection with our online booking system. Saved card details are processed strictly to collect authorised payments, future bookings, outstanding balances, cancellation charges, and insurance shortfalls/excesses.

C) Healthcare data (special category)

  • Medical history and relevant health information
  • Clinical assessments and treatment notes
  • Relevant imaging/diagnostic information (if provided)
  • Correspondence from other healthcare professionals (where relevant)

D) Website and device data

  • IP address, device type, browser type
  • Pages visited, time spent, clicks, referral source
  • Cookie and tracking identifiers (depending on your preferences)

E) Children’s data (where applicable)

  • Child’s first name and age/date of birth
  • Parent/guardian contact details
  • Relevant clinical information needed for care
6. How We Collect Your Data

We collect information:

  • Through online forms (booking forms, contact forms, insurance forms)
  • During consultations, treatment sessions, and follow-up communications
  • Via phone, email, and written correspondence
  • From referrals (e.g. insurers, healthcare partners, or other professionals) where appropriate
  • Automatically via cookies and similar technologies on our website (subject to your cookie choices)

If you provide someone else’s personal data (e.g. your child), you confirm you have the right and authority to share it with us.

7. How We Use Your Data (Purposes and Lawful Bases)

UK GDPR requires a lawful basis under Article 6 for personal data and an additional condition under Article 9 for special category health data.

A) Appointment management and service delivery

Purpose: includes essential service messages such as appointment reminders, booking confirmations, and updates about your insurance entitlements or session usage.

  • Article 6(1)(b) Contract (to provide services you request)
  • Article 6(1)(f) Legitimate interests (running a safe and efficient clinic)

B) Providing healthcare and maintaining clinical records

Purpose: assessment, diagnosis, treatment, clinical documentation, safety and continuity of care

  • Article 6(1)(b) Contract and/or Article 6(1)(c) Legal obligation (where applicable)
  • Article 9(2)(h) Health or social care (medical diagnosis and treatment)

C) Insurance processing, advocacy, and clinical coordination

Purpose: Liaising directly with your health insurer, benefit provider, GP, or referring consultant to secure authorisations, submit billing, manage shortfalls, and coordinate clinical care.

  • Article 6(1)(a) Consent – where you choose to use private health insurance or a third‑party payer
  • Article 6(1)(b) Contract – to arrange, deliver, and administer your insured appointments and claims
  • Article 9(2)(h) Health or social care – processing health data for medical diagnosis and treatment

Note: By registering as a client and booking care funded by Private Health Insurance (PHI), you explicitly grant One Body LDN Ltd authorisation to liaise directly with your insurer, GP, consultant, or other medical representatives regarding treatment plans, authorisations, and claims.

D) Compliance and regulation

Purpose: meeting legal, regulatory, and professional obligations (e.g. record keeping, audits, responding to regulators)

  • Article 6(1)(c) Legal obligation
  • Article 9(2)(h) (where health data is involved)

E) Marketing (where you opt in)

Purpose: newsletters, offers, updates

  • Article 6(1)(a) Consent (and PECR rules apply)
    You can unsubscribe at any time using the link in emails or by contacting us.

F) Exceptional Circumstances & Vital Interests

Purpose: Protecting life or health in a medical emergency.

  • Article 6(1)(d) Vital Interests
  • Article 9(2)(c) where special category health data is involved).

G) Clinical governance, supervision, and quality assurance

Purpose: Conducting clinical audits, practitioner supervision, and staff training to maintain high standards of patient care.

  • Article 6(1)(f) Legitimate interests
  • Article 9(2)(i) / Article 9(2)(h) (ensuring high standards of quality and safety of healthcare).
8. Service Communications

Service communications are not marketing. If you become a client or patient of One Body LDN, we may contact you by email or other direct means where necessary to deliver the services and benefits available to you. These service communications may include:

  • Notifications about unused or remaining private health insurance sessions, where you may be entitled to further treatment under your policy
  • Administrative or eligibility updates relating to insurance-funded care
  • Occasional satisfaction surveys or feedback requests so we can monitor clinic performance and improve our services.

These communications are treated as part of our service and clinical governance designed to help you fully utilise benefits you already have, avoid missed entitlements, and support continuity of care. They are not promotional in nature and do not constitute marketing communications. 

Lawful basis: Article 6(1)(b) UK GDPR (Performance of a Contract) and Article 6(1)(f) UK GDPR (Legitimate Interests to ensure continuity of care, safety, and effective clinical administration).

9. Healthcare Data (Special Category Data)

As a healthcare provider, we process health data under Article 9(2)(h) UK GDPR for medical diagnosis and treatment. We aim to keep clinical records accurate, secure, and accessible only to authorised staff.

Where relevant, we follow professional and regulatory expectations for documentation and confidentiality (including HCPC-related standards where applicable to our clinicians and best practice guidance for clinical record-keeping).

10. Cookies, Analytics, and Advertising

We use cookies and similar technologies to:

  • Make the website work (necessary cookies)
  • Understand website use (analytics)
  • Measure and improve advertising (marketing cookies, where permitted)

You can manage your preferences at any time via our cookie banner (consent management tool) and/or your browser settings.

11. Third-Party Services (Processors)

We use trusted third parties to help us operate our website and services. Where a supplier acts as our processor, we put appropriate data processing agreements in place.

Examples may include:

  • Website analytics tools
  • Email marketing platforms 
  • Payment processors
  • Website optimisation/advertising tools

Payment processing is handled by third parties, and we do not store full card details on our systems.

12. When We Share Your Data

We only share personal data where necessary and appropriate, such as:

  • For your care: with your GP, consultant, or other treating professional (where relevant and appropriate)
  • For insurance and medical care: We liaise directly with your health insurer, GP, consultant, or third-party referrer. This includes sharing necessary clinical progress notes, diagnosis details, treatment summaries, and billing codes, as well as requesting authorisation for additional treatment sessions on your behalf.
  • For legal/regulatory reasons: if required by law or requested by a regulator or authority
  • With service providers: who support our operations (under contractual safeguards)
  • For debt recovery: Where an account balance or insurance shortfall remains unpaid after formal notice, we may share relevant contact details, appointment dates, and outstanding invoice data with third-party debt recovery agencies or legal representatives acting on our behalf.

We do not sell your personal data.

13. International Transfers

Some suppliers may process data outside the UK/EEA. Where international transfers occur, we use appropriate safeguards such as:

  • The UK International Data Transfer Agreement (IDTA) and/or
  • Standard Contractual Clauses, plus additional measures where required.
14. Data Retention

We keep personal data only as long as necessary for the purposes we collected it, including legal and clinical obligations.

Typical retention periods:

  • Clinical/health records: Retained for a minimum of 8 years following the last treatment date for adult patients. For children/minors, clinical records are retained until their 25th or 26th birthday (8 years after reaching adulthood at age 18), or longer where required by clinical guidelines or legal obligations. Statutory medical retention duties strictly override personal data erasure requests.
  • Marketing preferences: until you withdraw consent or unsubscribe
  • Payment data: card details are not stored by us; transaction records may be retained for accounting/audit as required
15. Security Measures

We use appropriate organisational and technical measures to protect personal data, which may include:

  • Access controls and role-based permissions
  • Staff training and confidentiality requirements
  • Encryption and secure storage where appropriate
  • Multi-factor authentication where available
  • Secure clinical systems and periodic reviews of security practices
16. Your Rights (UK GDPR)

You have rights over your personal data, including:

  • Access (request a copy of your data)
  • Rectification (correct inaccurate or incomplete data)
  • Erasure (request deletion where lawful)
  • Restriction (limit processing in certain situations)
  • Objection (especially to legitimate interests processing or marketing)
  • Portability (in limited circumstances)
  • Withdraw consent (for marketing at any time)

Important: A data erasure request cannot override our statutory legal duty under UK health data regulations to retain medical clinical records for the mandatory retention periods set out in Section 14.

17. Children’s Privacy

We do not knowingly collect data from children under 13 via the website without parental/guardian involvement. If we treat a child, a parent/guardian will usually manage communications and consent where required.

Parents/guardians can contact us to:

  • Review or update a child’s data
  • Withdraw consent (where applicable)
  • Request erasure (where lawful)
18. Automated Decision-Making & AI Transparency

We do not use automated decision-making, profiling, or Artificial Intelligence (AI) systems to make automated clinical, diagnostic, or customer decisions that produce legal or similarly significant effects on your care. Any AI tools utilised within our operational or clinical documentation software operate solely under strict human clinical oversight and verification by our qualified practitioners.

19. Data Breaches

If a personal data breach occurs, we assess it promptly and take appropriate steps to limit harm. Where required, we will:

  • Notify the ICO within applicable timeframes, and
  • Notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
20. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are significant, we may also notify you by email and/or via the website.

21. Complaints

If you wish to exercise your rights, you can complain to the UK regulator:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, SK9 5AF
https://ico.org.uk/
Helpline: 0303 123 1113