Privacy policy
Last updated: 21 June 2026
Milton Keynes Sports Therapy Limited (“we”, “us”) takes your privacy seriously. This page explains what personal data we collect when you use this website or book a treatment, what we do with it, and what choices you have. We’re the data controller for everything described here.
What we collect
When you book or contact us, we collect:
- Contact details — your name, email, and (optionally) your mobile number. Giving a number is entirely optional and you can book without one. If you do give us one, we use it to reach you about your appointment — and, if you have agreed to it, to send you a text reminder before it. We never use it for marketing and we never pass it to anyone else for theirs.
- Booking details — the treatment, the therapist, the date and time, and the price you paid.
- Payment data — handled by SumUp, our payment provider. We never see or store your card number; SumUp sends us a confirmation that payment cleared.
- Clinical notes — only if you tick the consent box on the booking form. Notes are written by the therapist after your appointment to help with continuity of care. They are encrypted before they touch the database.
- Site usage — anonymised page-view and funnel data via PostHog. No cookies are set; we cannot identify you from this data.
Lawful basis
We rely on:
- Contract — to provide the treatment you booked and process payment.
- Legal obligation — to keep booking and financial records as required by HMRC.
- Legitimate interest — to send transactional emails (confirmation, reminder, cancellation), and to run anonymised analytics so we can improve the site.
- Explicit consent — to record clinical treatment notes, and separately to send you text-message reminders. These are two separate permissions: withdrawing one leaves the other exactly as it was. You can decline either at booking time and withdraw either later (see below).
Who else sees your data
We share the minimum necessary with a small set of UK/EU/US processors:
- SumUp (payments) — your name, email, and the booking total. SumUp is the card-data controller.
- Clerk (staff sign-in) — staff identity only. Customers are not in Clerk.
- Amazon Web Services (hosting, EU regions) — the database and app servers.
- PostHog (analytics) — anonymised usage events; no cookies, no identifiers.
- Email provider (transactional) — sends booking confirmations, reminders, and cancellation messages.
We do not sell or rent your data. We do not use it for marketing without separate consent.
How long we keep it
We hold data only as long as we need it. Our retention rules differ by category to match the UK regulatory floors that apply to each:
- Clinical treatment notes — at least 8 years from the date of your last treatment, in line with Chartered Society of Physiotherapy and professional-indemnity guidance. Where that guidance requires a longer period — for example for anyone treated as a child — we keep them for at least that long.
- Financial and booking records — 6 years, as required by HMRC for accounting purposes.
- Contact details and other personal data — 2 years from your last booking, after which we delete or anonymise it.
Treatment notes consent
Clinical notes are only created if you tick the consent box at booking. We store the timestamp and IP address of your consent for audit purposes. You can withdraw consent at any time by emailing our contact form. On withdrawal we stop adding new notes; existing notes are retained for the professional retention period above unless you also ask us to delete them.
Text message reminders
If you give us a mobile number and agree to it, we may send you a short text reminding you of an upcoming appointment. That is the only thing we use it for — we do not send marketing texts, and we do not share your number with anyone for theirs.
Giving a number is optional. If you do not give us one, we simply do not text you, and nothing else about your booking changes. If you gave us a number before we offered reminders, we will not start texting you unless you agree to it.
You can stop the reminders at any time — from the link in your booking email, by telling us at your next appointment, or through our contact form. Stopping them takes effect immediately and does not affect your treatment notes consent, your bookings, or the emails we send you about them.
Your rights
Under UK GDPR you can ask us to:
- tell you what data we hold about you (subject access);
- correct anything that’s wrong;
- delete your data, where we’re not required to keep it by law (we can’t delete financial records inside the HMRC window, for example);
- port your data to another provider in a machine-readable format;
- object to a particular use, or restrict how we use it.
Email our contact form to exercise any of these. We aim to respond within 30 days.
Security
The site runs over HTTPS. Clinical notes are encrypted with AES-256-GCM before being written to the database; the encryption key is held outside the database. Payments are handled entirely by SumUp’s PCI-compliant infrastructure. We log access to identifiable data and review it periodically.
Cookies
We don’t set marketing or tracking cookies. The site uses a small number of strictly necessary cookies that keep you signed in (staff only) and remember your booking session while you’re mid-flow. No cookie consent banner is needed because no consent-bearing cookies are set.
Complaints
If you’re unhappy with how we handle your data, please contact us first at our contact form and we’ll do our best to put it right. If you’re still unsatisfied, you have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.
Changes
We may update this policy from time to time — material changes will be flagged on the booking form or by email. The current version is dated at the top of this page. See also our terms and cancellation policy.
