Privacy Policy

This policy was last updated on the 21st May 2018.

Who we are

Osteoperformance Limited, a limited company, registered in England & Wales under company number 09892026 and with registered office address at 2 St Mark’s Place,  Wimbledon, SW19 7ND.

We are listed on the Information Commissioner’s register of data controllers under number ZA346385.

Please use our contact page to get in touch with us.

Who we are and what this privacy policy covers

This privacy policy explains how and why Osteoperformance Limited (“we”, “us” or “Osteoperformance”) may collect personal data* and special category data ** about you and the rights you have in relation to this data.  Please note that this policy relates to all our business activities, not just this website.

* personal data means any information about a living individual which allows them to be identified from that data including, for example, name, email address or address. Identification can be by the information alone or in conjunction with any other information.

** special category data means data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person’s sex life or sexual orientation.

In order for Osteoperformance to provide its services, we may need to collect special category data regarding your medical history. We will only collect this special category data with your explicit consent and, if we request such information, we will explain why we are requesting it and how we intend to use it.

Our commitment to you

We are committed to respecting your privacy and to protecting your personal data. Furthermore, we fully endorse and will adhere to all UK data protection legislation including the principles of the UK Data Protection Act 1998, any subsequent amendments thereto and all legislation implementing the General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”).

In particular we will comply with our legal obligations to keep personal data up to date, to store and destroy it securely, to not collect or retain excessive amounts of data, to use reasonable measures to protect personal data from loss, misuse, unauthorised access and disclosure and to ensure that appropriate technical measures are in place to protect personal data.

How you consent to this privacy policy

By using our website and any of our services and by providing us with any personal data, you are consenting to the use of that information as set out in this policy.

Please do not send us any information if you do not want it to be used in this way.

Please note that if you do not provide certain requested information we may be unable to provide certain of our services to you.

Personal data which you provide on behalf of someone else

If you give us information on behalf of someone else, you confirm that the other person has appointed you to act on his/her behalf and has agreed that you can (i) give consent on his/her behalf to the processing of his/her personal data and (ii) receive on his/her behalf any data protection notices.

How we obtain information about you

1. Information which you provide us
You provide us with personal data when you fill in one of the contact forms on our website, book an appointment via our website, or email us or phone us, or meet us in person.

When you attend an appointment with us, you will be asked to provide special category data about your medical history.

We may also ask for your permission to contact your GP for further information about your medical history. If this is the case, we will ask you to give your consent to this on a consent form that we will provide during your appointment.

2. Information we collect about you
We collect information about you when you engage with us online or by email e.g. when you visit our website, complete one of our contact forms, book an appointment, open or forward an email sent by us, or attend an appointment with us. Information may be collected via cookies and similar technologies, as detailed below.

3. Information we receive from other sources
We may also collect information about you from reputable third parties that operate in accordance with UK data protection legislation or other public sources, if this is permitted by law, such as analytics providers.

How we obtain information about you

1. Information which you provide us
You provide us with personal data when you fill in one of the contact forms on our website, book an appointment via our website, or email us or phone us, or meet us in person.

When you attend an appointment with us, you will be asked to provide special category data about your medical history.

We may also ask for your permission to contact your GP for further information about your medical history. If this is the case, we will ask you to give your consent to this on a consent form that we will provide during your appointment.

2. Information we collect about you
We collect information about you when you engage with us online or by email e.g. when you visit our website, complete one of our contact forms, book an appointment, open or forward an email sent by us, or attend an appointment with us. Information may be collected via cookies and similar technologies, as detailed below.

3. Information we receive from other sources
We may also collect information about you from reputable third parties that operate in accordance with UK data protection legislation or other public sources, if this is permitted by law, such as analytics providers.

Use of cookies and similar technologies

We use cookies and may use similar technologies such as pixel tags and web beacons on our website and in our some of our emails.

What is a cookie?

A cookie is a small text file (letters and/or numbers) which is sent to and stored on your computer (or other electronic device).  Cookies are used to identify you whenever you visit a website, to remember what you have done on a website to help improve your browsing experience, to remember log-ins or to provide advertising while visiting a particular site.

There are many types of cookies but broadly they can be grouped by purpose:

  • strictly necessary cookies which are used e.g. to make a website work (these cookies are limited to the working session and are deleted once the browser is closed);

  • performance cookies which collect information about how websites are used e.g. which pages are visited, providing statistics on how a website is used and measuring any errors that occur – these do not collect any information that could personally identify a user and are used to improve websites, to understand the interests of users and to measure the effectiveness of advertising;

  • functionality cookies which are used to remember settings and to personalise content when a user returns to a website; and

  • targeting cookies which are linked to services provided by third parties and which are used e.g. to link to social networks such as Facebook via “Like” or “Share” buttons (the third party may subsequently use information about a user’s visit to target advertising to them on other websites) or to provide advertising agencies with information on a user’s visit to a website so that they can present users with advertisements that they may be interested in.

Cookies can also be grouped according to whether they are ‘first-party’ cookies or ‘third-party’ cookies. The difference is that first-party cookies are placed and controlled by the website you are visiting whereas third-party cookies are placed and controlled by a third-party.

What are pixel tags and web beacons?

Pixel tags and web beacons are tiny graphic images embedded in a web page or in emails to achieve similar purposes as those described above.  For example, web beacons can be used to see which email messages are opened or forwarded to enable a better understanding of which types of email messages customers are interested in and to help improve communication with customers.

How and why we use cookies and similar technologies

In addition, we use the following cookies and similar technologies (some of which are managed for us by third parties):

  • Wix.com cookies that are strictly necessary and performance cookies to help us to identify and track visitors to our website.

  • Google Analytics cookies for statistical purposes to collect data about website usage (for example page views and time spent on our website) to help us understand which of our pages are performing well and which pages require improvement. This data does not include personally identifiable information.

  • Advertising cookies – to determine whether you have performed a specific action when you engage with us via an advertising or email campaign, or visit our website, so that we can select and carefully tailor the products and services that we market to you and improve our web pages, promotions and our communications with you. It is worth noting that opting out of advertising cookies does not mean that you will not see adverts, it just means that they will no longer be tailored to you.

To learn how to manage cookies and control your privacy and how to opt out of receiving email notifications or marketing materials from us please read the relevant sections below. For a detailed cookie report, please contact us.

How to manage cookies and control your privacy

Most web browsers allow some control of most cookies through the browser settings – these settings will typically be found in the ‘options’ or ‘preferences’ menu of your internet browser. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, please visit:

For a video about cookies visit www.google.co.uk/policies/technologies/cookies.

The exact procedure to prevent new cookies from being installed and how to delete existing cookies depends on which browser you are using but the following links may be helpful:

If you do not want your website visits to be recorded by Google Analytics you can opt-out with the addition of the Google Analytics Opt-out Browser Add-on which is available for Microsoft Internet Explorer 11, Google Chrome, Mozilla Firefox, Apple Safari and Opera.

You can choose to disable cookies in your internet browser but please note that if you delete cookies or decline to accept them you may not be able to use all of the features we offer, or store your preferences; in addition, some of our web pages might not display properly. If you want to turn off the more invasive cookies but leave most other functionality in working order, then a good option is to turn off third-party cookies using your browser settings.

In addition, we recommend that you check your privacy settings on any site which requires you to register or login, and that you never save your passwords in your browser or on your device, other than in a reputable password management system.

The legal basis for processing personal data and how we use your information

Most of the personal data we hold is processed because it is necessary the performance of our contract with you or to take steps to enter into a contract with you. Some of our processing is necessary for compliance with a legal obligation. We may also process personal data for our legitimate interests or the legitimate interests of a third party or where we have your consent.

We may use your information for some or all the following purposes:

  • to enable you to book an appointment;

  • to provide health services to you;

  • to respond to your enquiries in relation to our services;

  • so that we can tell you about our services or products that may be of interest to you;

  • to notify you of changes to our services;

  • to seek your views or comments;

  • where it is necessary for the preparation or performance of a contract with you;

  • where it is necessary in connection with a professional or legal obligation;

  • to personalise and improve our services to you;

  • if you have a business or professional relationship with us to develop our business relationship with you;

  • to remember your preferences e.g. if you ask not to receive marketing material we will keep a record of this;

  • to conduct research, statistical analysis and behavioural analysis;

  • to compile anonymous statistics, for example, website usage statistics;

  • to customise our website and its content to your particular preferences;

  • to notify you of any changes to our website or to our services that may affect you;

  • to detect and prevent fraud;

  • for other everyday business purposes, such as internal record keeping, payment processing and financial account management, contract management, website administration, analytics, corporate governance, reporting and legal compliance;

  • where we otherwise consider such use of your information as not detrimental to you, within your reasonable expectations and necessary to fulfil our legitimate business interests.

Who your personal data may be shared with

We recognise that your information is valuable and will take all reasonable measures to protect your information while it is in our care (see how below).

Your personal data may be transferred to:

  • third party service providers (such as Cliniko and Mailchimp) who store/process information on our behalf, including providers of information technology, identity management, website hosting and management, data analysis, data back-up, security and storage services;

  • mailing or printing agents, contractors and advisers that provide a service to us or act as our agents; and

  • insurance companies, law enforcement, regulatory, or other government agencies for the purposes of fraud prevention and/or to comply with any legal and regulatory issues and disclosures.

We may also share certain pieces of aggregated, non-personal data about you with third parties. For example, we may provide a third party with information such as the number of users who searched for a particular term or how many users clicked on a particular advertisement. This information does not identify you individually.

We do not sell, rent, distribute or otherwise make personal data commercially available to any third party except as described in this policy or with your prior permission.

Security and protection of your personal data

We use reasonable technical, administrative and physical controls to safeguard your personal data from unlawful use and unauthorised disclosure. For example, we store your personal data on secure servers. In all cases we will ensure that any access or transfer of your personal data is compliant with UK data protection law.

Where we use third parties (see above) to provide elements of our service and/or to process data on our behalf they are bound by law or contract to protect your personal data and only use it in accordance with our instructions. We only allow third parties to handle your personal data on the understanding that they will keep the information confidential.

If one of our service providers (e.g. a mailing service) needs to transfer your personal data outside of the European Economic Area (“EEA”) then we will ensure a data protection level equal to the one in the EEA or we will obtain your consent to the transfer.

Please note that Osteoperformance uses Cliniko, a cloud-based practice management system, to manage patient personal data. Cliniko stores this data outside the EEA however, it is working towards GDPR compliance by putting in place a Data Protection Addendum to its Privacy Policy. You can read Cliniko’s Privacy Policy here and you can read about how Cliniko is working towards GDPR compliance here.

If you do not wish your personal data to be stored on Cliniko, please contact us so that we can make alternative arrangements.

Only staff engaged in providing your treatment will have access to your patient records, although we may use occasional support personnel to make appointments and help manage accounts. Any personnel who have access to personal and/or confidential information are subject to confidentiality obligations and may be subject to discipline including termination and criminal prosecution if they fail to meet these obligations.

If you want detailed information on how to protect your information and your computers and devices against fraud, identity theft, viruses and other online problems you can visit Get Safe Online, which is supported by HM Government and leading businesses.

Children’s information

We also offer our services to children under 16 years. If you ask us to provide treatment to your child, we will ask you to sign a form consenting to the treatment and to the processing of that child’s data.

Data retention

We are legally obliged to retain your medical record for 8 years. Records concerning children who have received treatment will be retained until the child has reached the age of 25. After these periods, you can request that your records are deleted.

Links to third party sites

This privacy policy only addresses the use and disclosure of personal data by us. Our website may contain links to other websites which may be of interest to you. In addition, we may provide social sharing and follow buttons, for example to Facebook and Twitter, on our website. If you use or follow these links or buttons to any of these third party sites, please be aware that they have their own cookies and privacy policies which we recommend you read. We do not control these other sites and we cannot be responsible for the content of these sites or for protection of any information you provide to other sites.  You should be cautious when entering personal data online.

Your rights

We want to ensure you remain in control of your personal data.  Part of this is making sure you understand your legal rights.

You have a number of legal rights under applicable data protection legislation in relation to the personal data that we hold about you, including:

  • The right to access (a copy of) particular personal data that we hold about you and certain supplementary information (e.g. the sources from which we acquired the information, the purposes for processing the information and the persons/entities with whom we are sharing the information). We may (i) refuse to provide details and/or (ii) charge a small fee, if relevant legislation allows us to do so, in which case we will provide reasons for our decision as required by law.

  • The right to ask that we erase your information in certain circumstances. Please note that there may be circumstances where you ask us to erase your information but we are legally entitled to retain it.

  • The right to withdraw your consent to the use of your information where we are relying on that consent (for example, you can opt out of receiving email notifications from us). Please note that we may still be entitled to process your information if we have another legitimate reason (other than consent) for doing so.

  • In some circumstances, you have the right to receive some of your information in a usable format and/or request we transmit that data to a third party where this is technically feasible. Please note that this right of transfer only applies to information which you have provided to us.

  • The right to ask that we update your personal data free of charge, if it is inaccurate or incomplete.

  • The right to request that we restrict the processing of your personal data in certain circumstances. Again, there may be circumstances where you ask us to restrict the processing of your information, but we are legally entitled to refuse that request.

  • The right to make a complaint with the Information Commissioner if, after raising your concern with us and making a privacy complaint, you think that any of your rights have been infringed by us.

You can exercise your rights by contacting us. Please note that we usually act on requests and provide information free of charge. We may however be entitled to refuse to act on a request and we may charge a reasonable fee in relation to our administrative costs if the request is baseless, excessive or repeated.

We will respond to you as soon as we can. This will generally be within 28 days from the date we receive your request but if your request is going to take longer to deal with we will let you know.

How to opt out of receiving marketing materials

You have the right to opt out from receiving marketing materials from us. You can do this by contacting us or by clicking on the relevant link in the email itself. You may choose to opt out of one or all lists.

Making a privacy complaint

If you want to submit a written complaint about how we handle your personal data, please contact us or email us at info@osteoperformance.co.uk.

If you make a privacy complaint, we will respond to let you know how your complaint will be handled. We may ask you for further details, consult with other parties and keep records regarding your complaint.

Contact and further information

If you have any questions or concerns about this privacy policy or the information we hold about you, please contact us or email us at info@osteoperformance.co.uk.

Changes to our privacy policy

This policy is subject to change from time to time. Changes may be made when our business practices change or when data privacy laws are updated. You should therefore check this policy regularly to ensure that you are aware of any changes.

Menu