Privacy policy
Last updated · 10 February 2026
1. Data controller & contact
Physiogenic (operating under the company designated by the clinic) is the Data Controller of your personal data for the purposes of the EU General Data Protection Regulation (GDPR) and the U.S. Health Insurance Portability and Accountability Act (HIPAA). The clinic operating name, registered address and Polish KRS / NIP numbers are visible on every invoice.
Privacy Contact Officer (DPO): all privacy questions, access requests, and complaints can be addressed to dpo@physiogenic.pl. We acknowledge requests within 7 days and respond within 30 days (extendable by a further 60 days for complex cases, per GDPR Art. 12).
2. Information we collect
Personal details
- Full legal name, date of birth, address, phone, email.
- Government identifier (PESEL in Poland, NHS number in the UK, equivalent elsewhere) — only where required for medical billing.
- Profile photo (optional, base64-stored, used only inside the patient portal).
Sensitive health data (GDPR Art. 9 / HIPAA PHI)
- Medical history, current symptoms and conditions, medications, allergies.
- Imaging, lab results, referral letters and other documents you upload.
- Treatment plans, SOAP notes, objective assessment data (ROM, MMT, neurology, balance, cardio).
- Outcome measure scores (Oswestry, QuickDASH and the like) and rehabilitation progress notes.
Other data
- GP / referring physician details, insurance information, emergency contact.
- Financial / payment details (invoices, partial payments, Stripe payment session IDs — full card numbers are never stored on our servers).
- Authentication and security data (hashed passwords, login timestamps, IP address for audit-log entries).
3. Purposes of collection & processing
We collect personal and health data only for the following specific purposes:
- Clinical care — providing safe, effective physiotherapy assessment and treatment.
- Administration — appointment scheduling, reminders (24h / 2h), reschedules, cancellations.
- Billing & accounting — invoice generation, Polish VAT-exemption reporting (medical service art. 43.1.19), KSeF e-invoicing where required.
- Communication — pre-visit instructions, post-session recovery tips, marketing emails (opt-in only, with one-click unsubscribe).
- Legal obligations — record-retention required by Polish health-records law, anti-money-laundering checks where applicable.
We will not use your data for any purpose beyond those listed above without obtaining fresh consent.
4. Consent & legal basis
At sign-up you provide explicit consent (digital signature, GDPR Art. 7) for us to process your personal and health data. You can withdraw consent at any time from your patient profile; withdrawal does not affect the lawfulness of processing already carried out.
Where consent is not the basis, processing is justified by one of:
- Necessity for the provision of medical care (GDPR Art. 9.2.h) — performing physiotherapy under contract.
- Compliance with a legal obligation (GDPR Art. 6.1.c) — tax records, health-records retention, professional reporting.
- Vital interests (GDPR Art. 6.1.d) — emergency disclosure to next-of-kin or emergency services if your life is at risk.
5. Data sharing & third-party disclosures
We may share specific elements of your record under the following circumstances:
- Your GP, referring physician, or hospital — only with your explicit written consent, or when legally required (e.g. court order).
- Private health insurers — for claim reimbursement, only after you sign the corresponding assignment-of-benefits form.
- Public health authority (UODO, NFZ, sanitary epidemiologist) — when required by Polish public-health or data-protection law.
- Sub-processors (listed below) — strictly for the technical operation of the service, bound by a Data Processing Agreement.
Sub-processors
- Resend (US) — transactional email delivery (welcome, reminders, invoice PDFs). SCCs in place.
- Emergent Object Storage (EU) — encrypted medical document storage. EU-region, no transatlantic transfer.
- MongoDB Atlas (EU) — primary database, hosted in EU central region.
- Stripe (EU / US) — payment processing. Card details handled directly by Stripe — we only store an anonymised session ID.
- Backblaze B2 (EU) — encrypted off-site backups for disaster recovery.
- Anthropic / OpenAI / Google AI (US) — large-language-model inference for red-flag screening and treatment-plan suggestions. Only de-identified clinical summaries are sent. Full records are never transmitted.
Overseas transfers
Identifiable health data stays inside the EU. Any non-identifiable summaries that leave the EU (for AI analysis, for example) are transferred under Standard Contractual Clauses and the respective providers' EU adequacy schemes.
6. Data storage, security & integrity
Physical security
- Paper records — kept in locked cabinets in our Warsaw office; only the treating clinician and admin staff hold keys.
- Clinic devices — disk-encrypted; auto-lock after 5 minutes idle; biometric or passphrase unlock.
Technical security
- TLS 1.3 for all client/server traffic; HSTS enforced.
- AES-256 at rest for medical documents; bcrypt for password hashes.
- HttpOnly + SameSite cookies; CSRF anti-forgery tokens.
- Optional TOTP-based two-factor authentication for every role (admin, clinician, reception, patient).
- Daily off-site encrypted backups; 90-day point-in-time recovery.
Staff training
Every clinician and admin completes an annual GDPR + HIPAA + medical-confidentiality refresher. New staff cannot access patient records until they sign a confidentiality agreement and complete the training.
7. Data retention & destruction
- Clinical records — 20 years from the last visit (Polish health-records law); separate 30-year retention for paediatric records (kept until age 25).
- Financial / invoice records — 5 years from the end of the tax year (Polish accounting law).
- Audit logs — 90 days hot storage, then archived for 2 years and securely deleted.
- Marketing communications — until you unsubscribe; the unsubscribe record itself is kept for 3 years to honour your wishes.
When records reach end-of-life they are securely destroyed: paper documents are cross-cut shredded by a certified provider with a Certificate of Destruction; digital records are cryptographically erased (Crypto-Shredding NIST SP 800-88).
8. Your rights
Under GDPR Art. 15–22 you have the right to:
- Access — request a copy of your record (returned within 30 days, machine-readable JSON + PDF).
- Rectification — correct any inaccurate information.
- Erasure ("right to be forgotten") — request deletion, subject to legal retention obligations above.
- Restriction — pause processing while a dispute is resolved.
- Portability — receive your data in a structured, commonly-used format and transfer it to another controller.
- Object — to processing based on legitimate interest or for direct marketing.
- Not be subject to automated decision-making — our AI red-flag screening is advisory only; the clinician makes every clinical decision.
Exercise any of these rights from Profile → Privacy & Data Rights, or by emailing the DPO above.
9. Complaints
If you believe your information has been mishandled, please first contact our DPO (dpo@physiogenic.pl) so we can investigate. If you remain unsatisfied, you have the right to lodge a complaint with the Polish supervisory authority:
- Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
tel: +48 22 531 03 00 · uodo.gov.pl
Outside Poland you may also complain to your national supervisory authority (ICO in the UK, CNIL in France, AEPD in Spain, etc.) or to the U.S. Department of Health & Human Services Office for Civil Rights for HIPAA-related concerns.
10. Updates to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in your patient inbox at least 30 days before they take effect, and (where required) we will request fresh consent before continuing to process your data under the new terms. Non-material clarifications take effect immediately and are noted in the change log at the bottom of this page.
Change log · 2026-02-14: expanded sections 1–10 to full GDPR + HIPAA detail. 2026-02-10: initial publication.
For questions, rights requests, or to revoke consent, email our Data Protection Officer.
dpo@physiogenic.pl