top of page

Privacy Policy

​

Last updated: August 2026

​

Fia Health respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store and protect personal data when you use our website, contact us, book an appointment or receive treatment from us.

​

1. Who we are

Fia Health is an independent osteopathic healthcare practice providing services in Great Dunmow and White Roding, Essex.

For the purposes of UK data protection legislation, Fia Health is the data controller for personal information collected and used in connection with the provision of our clinical services.

​

Fia Health
Email: hello@fiahealth.co.uk
Telephone: 01371 398092
Website: www.fiahealth.co.uk

​

If you have any questions about how your personal information is handled, please contact us using the details above.

​

2. Information we may collect

Depending on how you interact with Fia Health, we may collect and process information including:

​

  • your name;

  • date of birth;

  • address;

  • telephone number;

  • email address;

  • emergency contact details;

  • appointment and booking information;

  • payment and transaction information;

  • correspondence by email, telephone or other communication methods;

  • information you provide through website forms or when making an enquiry;

  • health and medical information relevant to your assessment and treatment;

  • medical history;

  • medication information;

  • details of symptoms, injuries and previous treatment;

  • examination findings;

  • clinical notes;

  • treatment provided;

  • treatment plans and recommendations;

  • relevant reports, letters or other clinical documents; and

  • information necessary to meet our professional, legal and regulatory obligations.

 

Health information is treated as special category personal data and is given additional protection under UK data protection law.

​

3. Why we use your information

 

We may use your information to:

​

  • register you as a patient;

  • arrange and manage appointments;

  • provide osteopathic assessment, treatment and other clinical services;

  • maintain accurate clinical records;

  • communicate with you about your treatment or appointments;

  • send appointment confirmations and reminders;

  • process payments, deposits, invoices and refunds;

  • respond to enquiries;

  • provide information that you have requested;

  • manage the administration and operation of Fia Health;

  • comply with professional, regulatory, insurance, accounting and legal requirements;

  • establish, exercise or defend legal claims where necessary;

  • protect the safety and security of patients, clinicians and the practice; and

  • improve our services and website.

​

Under UK data protection law, we will only process your personal information where we have a lawful basis to do so. Depending on the circumstances, this may include:

​

  • Contract – where processing is necessary to provide services you have requested, such as arranging appointments, providing treatment and processing payments.

  • Legal obligation – where we need to process information to comply with legal, regulatory, professional, tax or accounting requirements.

  • Legitimate interests – where processing is reasonably necessary for the operation, administration, security and improvement of Fia Health, provided that these interests do not override your rights and interests.

  • Consent – where we have specifically asked for your consent and you have freely provided it. You may withdraw your consent at any time where processing relies on consent.

​

Because information about your health is classed as special category personal data, we also require an additional legal condition for processing it. We generally process health and clinical information where this is necessary for the provision and management of healthcare by a healthcare professional, in accordance with UK GDPR and our professional obligations.

​

4. Health and clinical information

​

Information concerning your health is classified as special category personal data under UK GDPR.

​

We process this information where necessary for the provision and management of healthcare and treatment and in accordance with our professional obligations as a healthcare provider.

​

Clinical information will only be collected where it is relevant to your care or where we are otherwise required to keep it for professional, regulatory, insurance or legal purposes.

 

5. Cliniko

​

Fia Health uses Cliniko as its practice management and patient-record system.

Cliniko may be used to manage:

​

  • patient contact details;

  • appointments;

  • clinical records;

  • treatment notes;

  • correspondence;

  • invoices;

  • appointment reminders; and

  • other information necessary for the administration of your care.

 

Personal and clinical information entered into Cliniko is handled in accordance with Cliniko’s applicable privacy, data protection and security arrangements.

 

6. Payments

 

Stripe

 

Fia Health uses Stripe to process certain online payments, including appointment deposits and online billing payments.

​

When you make a payment using Stripe, information necessary to process the transaction may be provided directly to Stripe. This may include payment card information, transaction information and other information required to authorise and process the payment.

​

Fia Health does not normally receive or store your complete payment card details when Stripe processes the transaction.

​

Stripe processes personal information in accordance with its own privacy policy and applicable data protection requirements.

 

LoPay

​

Fia Health uses LoPay to process card payments, including payments made in person.

​

When you make a payment through LoPay, LoPay may process transaction information and limited payment-card information required to complete and record the transaction.

 

LoPay and its payment-processing partners may process certain information for payment processing, fraud prevention, security and regulatory compliance.

​

7. Website and cookies

​

Our website is provided using Wix.

 

When you visit the Fia Health website, certain technical information may be collected automatically, including:

 

  • IP address;

  • browser and device information;

  • pages visited;

  • website usage information; and

  • cookies and similar technologies.

 

Cookies are small files placed on your device that can help a website function correctly, remember preferences, maintain security and provide information about how the website is being used.

 

Some cookies are strictly necessary for the operation and security of the website and may be used without your consent.

 

Other cookies, such as analytics, performance or other non-essential cookies, will only be used where appropriate consent has been provided.

 

Where required, you can accept, reject or manage non-essential cookies through the cookie consent options provided on the Fia Health website. You can also control or delete cookies through your browser settings.

 

Please be aware that disabling certain cookies may affect how some parts of the website function.

 

Third-party services used through or in connection with our website may also use cookies or similar technologies in accordance with their own privacy and cookie policies.

 

Information collected through the website may be used to operate and secure the website, understand how visitors use it and improve its performance and user experience.

​

8. Email and communications

​

Fia Health may use email, telephone and other electronic communication methods to communicate with patients and respond to enquiries.

​

We may contact you where necessary in connection with:

​

  • appointments;

  • treatment;

  • payment or invoicing;

  • administrative matters;

  • information you have requested; or

  • other legitimate matters relating to your care.

​

Please be aware that ordinary email and telephone communications may not always be completely secure. You should avoid sending unnecessary highly sensitive information by email unless requested or an appropriate secure method has been agreed.

​

9. Who we may share information with

​

We do not sell your personal information.

​

Where necessary and lawful, information may be shared with organisations or individuals involved in operating the practice or providing your care, including:

​

  • Cliniko;

  • Stripe;

  • LoPay;

  • Wix;

  • IT and communications providers;

  • accountants, insurers, legal advisers or other professional advisers;

  • other healthcare professionals involved in your care where appropriate;

  • regulatory or professional bodies;

  • law enforcement agencies, courts or public authorities where required by law; and

  • other organisations where disclosure is necessary to protect your vital interests or those of another person.

 

Where information is shared for your ongoing healthcare, we will only disclose information that is relevant and appropriate.

​

Where consent is required before information is shared, we will seek it unless there is a lawful reason why information can or must be disclosed without consent.

​

10. Keeping your information secure

​

We take reasonable and appropriate measures to protect personal information against:

​

  • unauthorised access;

  • accidental loss;

  • inappropriate disclosure;

  • alteration;

  • destruction; and

  • misuse.

 

Electronic systems used by the practice are protected through appropriate technical and organisational security measures.

​

Access to clinical and personal information is restricted to those who have a legitimate reason to access it.

​

11. How long we keep information

​

We retain personal information only for as long as it is reasonably necessary for the purposes for which it was collected and to meet our professional, regulatory, insurance, tax and legal obligations.

 

Clinical records are retained in accordance with applicable legal requirements, professional standards and guidance issued by the General Osteopathic Council and our professional insurers.

 

The length of time information is kept may vary depending on the type of information, the age of the patient, the nature of the treatment provided and any relevant legal or professional requirements.

 

Where personal information is no longer required, it will be securely deleted, anonymised or destroyed as appropriate.

​

12. Children’s information

​

Fia Health may provide treatment to children.

​

Where appropriate, information may be provided by and communications may take place with a parent, guardian or person with parental responsibility.

​

Clinical information concerning children will be handled with the same level of confidentiality and data protection as information relating to adults, taking account of the child’s age, understanding and applicable professional and legal requirements.

​

13. Your data protection rights

​

Depending on the circumstances, you may have the right to:

​

  • ask for access to the personal information we hold about you;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase certain personal information;

  • ask us to restrict how certain information is processed;

  • object to certain uses of your personal information;

  • request transfer of certain information where applicable; and

  • withdraw consent where processing is based on consent.

 

These rights are not absolute. For example, we may be required to retain clinical records despite a request for deletion where professional or legal obligations require us to do so.

​

To exercise any of these rights, please contact:

​

hello@fiahealth.co.uk

​

We may need to confirm your identity before releasing or changing personal information.

​

14. Complaints

​

If you have concerns about how Fia Health has handled your personal information, please contact us first so that we can investigate.

​

You also have the right to raise a concern with the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator.

​

Further information is available at:

​

www.ico.org.uk

 

15. Changes to this Privacy Policy

​

We may update this Privacy Policy from time to time to reflect changes to our services, technology, legal obligations or the way personal information is processed.

​

The latest version will be published on the Fia Health website with the date it was last updated.

bottom of page