Megazee.com Privacy Policy

How we handle your personal and health information, and the rights you have over it.

Last updated 21 September 2026

[Last updated: ]

The short version

You can read this policy in full below. Here is what it says, without the legal scaffolding.

If you enquire about an appointment, we collect your name, your contact details and a short description of your problem. That description is health information, and the law treats it with extra care. So do we. We use it to arrange and deliver your physiotherapy, to keep the clinical records we are professionally required to keep, and to bill you or your insurer. We do not sell your data. We do not share your health information with advertising platforms, and we do not use what you tell us about your body to target adverts at you. You can ask us for a copy of your records at any time.

One request before you start typing: please keep your enquiry brief. A body area and a sentence is plenty. You will go through your full history with your physiotherapist at your appointment, in a private room, on a secure clinical record. There is no need to send detailed medical information through a web form or an ordinary email.


1. Who we are

Megazee.com Physiotherapy is a private physiotherapy clinic based in Manchester. When we decide how and why your personal information is used, we are the data controller for that information under UK data protection law.

Trading name Megazee.com Physiotherapy
Registered legal entity Megazee Physiotherapy Ltd
Company registration number 00000000
Registered office 14 Bridgewater House, Quay Street, Manchester M3 3HN
Clinic address 14 Bridgewater House, Quay Street, Manchester M3 3HN
ICO data protection register number ZA000000
Privacy contact Practice Manager
Email hello@megaazee.com
Telephone 0161 000 0000

We are not required to appoint a statutory Data Protection Officer, and we have not appointed one. We have instead named a single person who is responsible for data protection at the clinic, and any question, request or complaint about your information reaches them. Write to hello@megaazee.com with “Data protection” in the subject line, or call 0161 000 0000 and ask for the person responsible for data protection.

Every physiotherapist who treats you is registered with the Health and Care Professions Council and is bound by professional standards of confidentiality that sit on top of data protection law. Those duties do not lapse when you stop being a patient.

2. The information we collect

Not everyone gives us everything below. Someone who calls to ask about our fees leaves a much smaller footprint than someone who completes a course of post-operative rehabilitation.

Identity and contact details. Name, date of birth, email address, telephone number, postal address, and the name and number of someone to contact in an emergency where you choose to give one.

Health information. What you write in the “how can we help?” box on our enquiry form. Your symptoms, how long you have had them, what makes them worse. Relevant medical history, previous injuries, surgery, current medication and any conditions that affect your treatment. Assessment findings, working diagnosis, treatment notes, exercise programmes, outcome measure scores, correspondence with your GP or consultant, and any scan reports or images you share with us.

Appointment and payment information. Dates and times, which physiotherapist you saw, attendance and cancellations, fees charged and whether they have been paid. Card payments are processed by our payment provider. We see that a payment succeeded; we do not receive or store your full card number.

Insurance information. Your insurer, policy or membership number, authorisation code, the number of sessions approved and claim correspondence.

Employer or occupational health information. Only where your treatment is funded by an employer or occupational health provider, and only where you have been told what will be reported back to them.

Information from other people. A GP, consultant, surgeon, insurer, solicitor or family member may send us information about you. Where that happens we tell you what we have received unless we are legally prevented from doing so.

Website and technical information. IP address, browser and device type, pages viewed, how you arrived at the site, and identifiers set by cookies. Details are in section 10.

Communications. Emails, form submissions, text messages and notes of telephone conversations. We do not record telephone calls. If that ever changes, we will tell you at the start of the call and update this policy.

Marketing preferences. Whether you have opted in, and when you opted out.

Recruitment information. CVs, application forms and interview notes, where you apply to work with us.

3. Health information gets extra protection, and here is what that means

Information about your physical or mental health is “special category” data under UK GDPR. The bar for handling it is higher, and the law is specific about the grounds we are allowed to rely on.

In practice, this is what it changes for you:

  • We rely on Article 9(2)(h), the healthcare provision condition, together with the condition in Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018. That route is only open to us because your information is handled by or under the responsibility of clinicians who owe you a professional duty of confidence.
  • Your health information is never used to decide who sees which advert. We do not build audiences from conditions, we do not send condition-segmented marketing, and we do not pass health-indicative data to advertising platforms. Section 10 explains the technical steps that back this up.
  • Access is restricted to the people who need it for your care and for running the clinic. Reception staff can see that you have an appointment; they do not need your clinical notes, and they are not given routine access to them.
  • Ordinary email is not secure. If you need to send us something detailed, call 0161 000 0000 and we will arrange a secure route.
  • Photographs, video and scan images are treated as clinical records. We only take clinical images with your specific, written, revocable consent, and consent for treatment purposes is separate from consent to use an image publicly. You can say yes to one and no to the other.

4. Why we use your information, and our lawful basis for each purpose

What we do Lawful basis (Article 6) Additional condition for health data (Article 9)
Respond to an appointment enquiry 6(1)(b) steps taken at your request before entering a contract; 6(1)(f) legitimate interests for general enquiries 9(2)(h) healthcare provision, with DPA 2018 Sch 1 Pt 1 para 2
Assess, treat and rehabilitate you 6(1)(b) performance of our contract with you 9(2)(h)
Keep clinical records 6(1)(c) legal obligation; 6(1)(f) our legitimate interest in defensible records 9(2)(h)
Send appointment reminders and programme information 6(1)(b) 9(2)(h)
Take payment, invoice insurers, recover unpaid fees 6(1)(b); 6(1)(f) 9(2)(h), or 9(2)(f) where a legal claim arises
Correspond with your GP, consultant or other clinician 6(1)(f) continuity of care 9(2)(h), normally with your consent to the disclosure
Clinical audit, peer review and improving how we work 6(1)(f) legitimate interests 9(2)(h) management of healthcare services
Safeguarding a child or adult at risk 6(1)(c); 6(1)(d) vital interests 9(2)(b)/(c), or the DPA 2018 safeguarding condition
Handle complaints, claims and insurance matters 6(1)(f); 6(1)(c) 9(2)(f) establishing or defending legal claims
Send marketing emails or texts 6(1)(a) your consent, plus PECR consent Not applicable. We do not use health data for marketing.
Non-essential cookies and analytics 6(1)(a) your consent Not applicable
Recruitment 6(1)(b); 6(1)(f) Only where you volunteer health information for adjustments

Where we rely on legitimate interests we have weighed our interest against your rights and recorded the outcome. Ask us at hello@megaazee.com and we will send you that assessment.

We do not sell your personal information to anyone, and we never will.

5. How long we keep it

“For as long as necessary” is not an answer, so here are actual figures.

Record How long we keep it Why
Adult clinical records 8 years from the last entry or the end of your treatment Aligned to the NHS Records Management Code of Practice, which private practice commonly adopts, and to indemnity requirements
Clinical records for patients under 18 Until the patient’s 25th birthday, or their 26th if the last entry was made when they were 17 As above
Records of a patient who has died 8 years after death As above
Maternity and pelvic health records relating to pregnancy 25 years from the birth of the last child As above
Website enquiries that did not become appointments 6 months, then deleted Data minimisation. We keep them only long enough to handle follow-up contact
Invoices, payment and tax records 6 years plus the current financial year HMRC requirements
Insurance claim correspondence 8 years, in line with the clinical record it relates to Claims handling and audit
Complaints files 8 years from the date the complaint is closed Regulatory and indemnity
Marketing consent records For as long as you are subscribed, plus 2 years after you opt out To prove we had consent, and to honour your opt-out
Website analytics 14 months Tool configuration and minimisation
Unsuccessful job applications 6 months Minimisation and equality monitoring

When a retention period ends, paper records are cross-cut shredded through a confidential waste contractor and electronic records are deleted from live systems, with backup copies expiring on the normal backup cycle. We review these periods at least every two years.

One point that surprises people: you generally cannot have your clinical record deleted on request while it is still within its retention period. That is not us being obstructive. Section 11 explains why.

6. Who we share it with

We share your information only where there is a reason to, and we tell you what that reason is. The categories below are exhaustive.

Who What they receive Why
our practice management provider, our practice management and clinical records system Identity, appointment and clinical data To hold your record and manage your appointments
our hosting provider, our website host and form handler Enquiry form contents To deliver your enquiry to us
our email provider, our email provider Anything sent by email Email delivery and storage
our card payment provider, our payment processor Amount, date, payment status To take card payments. They are the controller for your card details
our accountants, our accountant Invoice and payment data Bookkeeping, tax and audit
Your insurer Your details, authorisation code and the limited clinical information required to support the claim To get your treatment authorised and paid for
Your GP, consultant or other treating clinician A clinical letter or report Continuity of care, normally with your agreement, which we will ask for
Your employer or occupational health provider Only the agreed report content, where they are funding treatment To meet the terms of the funding arrangement, with your knowledge
Our indemnity insurer, solicitors and professional advisers Only what is necessary To handle a complaint, claim or legal obligation
Regulators, courts, the police, coroners, safeguarding teams Only what the law requires or permits Legal obligation, or protection of someone at serious risk
our analytics provider, our website analytics provider Technical and usage data, only if you consent to analytics cookies To understand how the site is used

Every supplier on this list works under a written contract that meets Article 28 of the UK GDPR. They may only use your information on our instructions, must keep it secure, and must delete or return it at the end of the contract.

If Megazee is ever sold, merged or restructured, patient records may transfer to the new provider so that your care can continue. We would tell you before that happened, and the new provider would be bound by the same duties.

Two things we do not do, stated plainly because they are the ones that matter most on a health website: we do not sell personal data, and we do not share health information with advertising or social media platforms.

7. Sending information outside the UK

Some of our suppliers store or process data outside the United Kingdom, most commonly in the European Economic Area, and in some cases in the United States.

Where that happens we make sure one of the following protections is in place before any transfer:

  • the country is covered by UK adequacy regulations, which includes the EEA; or
  • the contract includes the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
  • another safeguard recognised under Article 46 applies.

Our default position is to choose UK or EEA hosting for anything containing clinical information. You can ask us at hello@megaazee.com for a list of the countries your data reaches and a copy of the safeguards we rely on.

8. How we keep it safe

No system is perfectly secure, and anyone who tells you otherwise is overselling. What we can tell you is what we actually do.

  • Information is encrypted in transit and at rest. The website runs over HTTPS on every page.
  • Access follows role. Staff can reach only the records they need for their job, and clinical notes are not open to everyone at the clinic.
  • Multi-factor authentication is enabled on the clinical system, email and website administration.
  • Access to clinical records is logged, and logs can be checked if there is ever a concern.
  • Everyone who works here signs a confidentiality agreement and completes data protection and information governance training when they join, then annually.
  • Paper records are locked away when not in use and never left in public areas of the clinic.
  • Backups are encrypted and restoration is tested.
  • Portable devices are encrypted and can be wiped remotely.

If a breach occurs that is likely to present a risk to you, we report it to the Information Commissioner’s Office within 72 hours of becoming aware of it. If the risk to you is high, we contact you directly, tell you what happened and tell you what to do about it. We will not quietly hope you do not notice.

9. What we ask of you

Please do not send us detailed clinical information, scan reports or photographs by ordinary email unless we have agreed a secure route with you. Please tell us promptly if your contact details change, so appointment information does not reach the wrong inbox. And if you share a household email address or phone with someone, let us know if you would rather we did not leave messages there.

10. Cookies, analytics and advertising

A full breakdown of every cookie, its provider, purpose and lifespan is on our Cookie Policy page. The principles are these.

Strictly necessary cookies run without asking, because the site cannot work without them. They remember your cookie choices and keep the enquiry form secure.

Everything else waits for your consent. Analytics and any functional cookies are blocked until you choose. Our banner offers “Reject all” with the same prominence and the same single click as “Accept all”. Nothing is pre-ticked. There is no cookie wall. You can change your mind at any time using the Cookie settings link in the footer.

Advertising and remarketing trackers are not deployed on clinical pages. No advertising pixel runs on any condition page, symptom page, enquiry form or enquiry confirmation page. The reason is specific: a page view on a URL about pelvic pain or sciatica, sent to an advertising platform alongside an identifier, discloses something about your health that you never agreed to disclose. If we ever run paid advertising, tags will be limited to non-clinical pages and configured to strip health-indicative parameters.

Session recording and heatmap tools are not used on any page containing a form. We do not capture what you type.

Free text from the enquiry form is never sent to analytics, and no health information appears in URLs, page titles or referrer strings.

We honour the Global Privacy Control signal. If your browser sends it, we treat it as an objection to non-essential tracking and do not load it.

11. Your rights

These rights are free to exercise. We respond within one month, and we will tell you if a complex request needs longer, which the law allows by up to two further months.

Access. You can ask for a copy of the personal information we hold about you, including your clinical record. Most people just ask; there is no form and you do not have to give a reason.

Rectification. If something factual is wrong, tell us and we will correct it. Clinical records work slightly differently. A professional opinion recorded at the time is not deleted, because a record that has been rewritten after the fact is no longer a reliable clinical record. Instead we append your correction and your comments so that anyone reading the file sees both. If you disagree with a clinical opinion, that disagreement becomes part of the record.

Erasure. Often described as the right to be forgotten, and it is not absolute. We will delete marketing data, unconverted enquiries and website data on request. We generally cannot delete a clinical record within its retention period, because we need it to provide and defend your care and because keeping it is a legal and professional obligation. We will always explain which parts we can remove and which we cannot.

Restriction. You can ask us to pause how we use your information while a dispute about its accuracy or our legal basis is resolved.

Portability. Where we rely on consent or contract and the processing is automated, you can ask for your data in a structured, machine-readable format, or ask us to send it to another provider.

Objection. You can object to processing we base on legitimate interests. Your right to object to direct marketing is absolute and immediate. Say stop and we stop.

Withdrawing consent. Where we rely on consent, you can withdraw it at any time. That does not make what we did beforehand unlawful, and it will never affect the standard of your care.

Automated decisions. We do not make decisions about your treatment, your fees or your access to appointments using automated processing or profiling. Everything clinical is decided by a person.

To exercise any of these, contact hello@megaazee.com or 0161 000 0000. We may ask you to confirm your identity, because handing a clinical record to the wrong person would be a far worse outcome than a short delay. If someone is acting on your behalf, we need written authority from you first.

Complaints. If you are unhappy with how we have handled your information, please tell us at hello@megaazee.com so we can put it right. You can also complain directly to the Information Commissioner’s Office at any time. You do not need our permission and you do not need to come to us first. The ICO’s complaint route and current helpline number are at ico.org.uk/make-a-complaint, and their postal address is Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

12. Children and young people

We treat patients under 18 where clinically appropriate. Where we do:

  • A parent, guardian or someone with parental responsibility normally consents to treatment and to the handling of the child’s information.
  • Young people who are able to understand what is proposed can consent for themselves. This is often referred to as Gillick competence, and the assessment is made by the treating clinician.
  • A young person’s confidentiality is respected. A competent young person may ask us not to share particular information with a parent, and we will consider that request seriously, subject to our safeguarding duties.
  • Records are kept until the patient’s 25th birthday, as set out in section 5.

Our website is not aimed at children, and we ask that under-16s do not submit the enquiry form without a parent or guardian.

13. About the enquiry form specifically

We designed the form to collect as little as possible. It asks for your name, a contact detail, the body area affected and a short description. That is it.

There is a separate, unticked box if you would like to hear from us about clinic news. It is not bundled with your enquiry, and leaving it unticked has no effect on your appointment. Submitting an enquiry does not sign you up to anything.

A link to this policy sits next to the submit button, so you can read it at the moment it matters rather than hunting for it in the footer.

If you would rather not use a web form at all, call 0161 000 0000. It reaches the same people.

14. Changes to this policy

We review this policy at least once a year, and sooner if our systems, suppliers or legal obligations change. The date at the top always reflects the current version.

Where a change materially affects how we use your information, we will do more than update the date quietly. Current patients will be told directly, by email or at their next appointment.

15. Contact us

Privacy enquiries and rights requests hello@megaazee.com
Telephone 0161 000 0000
Post Data Protection, Megazee Physiotherapy, 14 Bridgewater House, Quay Street, Manchester M3 3HN

If you want to talk to someone rather than write, call 0161 000 0000 and ask to speak to the person responsible for data protection. We would much rather have a five-minute conversation than leave you uncertain about where your information has gone.


See also: Medical Disclaimer · Cookie Policy · Terms and Conditions · Complaints Procedure · Accessibility Statement · Contact our physiotherapy team

[Last updated: ]