Skip to main content

1. Who we are

This Privacy Policy explains how Primephysio Training UK (“Primephysio”, “we”, “us” or “our”) collects, uses, stores and shares personal data when you visit our website, contact us, register for training, purchase or access our services, use our online forms, or use any application or service that connects to Google Cloud or Google APIs.

Controller: PRIMEPHYSIO TRAINING UK ltd trading as Primephysio Training UK.

Registered address: Registered in England & Wales (14316529)

Contact for privacy requests: support@primephysio.com or info@primephysio.com.

Website: www.primephysio.com

2. Scope of this policy

This policy covers personal data processed through our website, online booking or payment flows, customer support, training services, email communications, and any Google-authorised functionality we operate. It does not cover third-party websites or services that we do not control.

3. Personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and contact data, such as name, email address, telephone number, billing address, organisation, job title and account details.
  • Transaction and service data, such as orders, course registrations, invoices, payment status, booking history, certificates, attendance, support requests, feedback, reviews and correspondence.
  • Technical and usage data, such as IP address, device and browser information, log data, pages viewed, referral source, approximate location, security events and cookie or similar technology identifiers.
  • Marketing preferences, such as whether you have opted in or out of newsletters or promotional communications.
  • Google user data, only where you choose to authorise a Primephysio application or integration to access Google services. The data accessed depends on the permissions/scopes you approve and may include basic Google account profile information and any specific Google service data required for the functionality disclosed to you.
  • Special category data only where necessary and lawful, for example where you voluntarily provide health-related information for accessibility, training support, clinical education context or similar purposes. We will only process such data where we have a valid legal basis and appropriate safeguards.

4. How we collect personal data

  • Directly from you when you complete forms, register, order, book, email us, use live chat, call us, submit feedback or otherwise communicate with us.
  • Automatically through our website, hosting platform, analytics, security tools, cookies and server logs.
  • From service providers that help us operate our website, payments, email, hosting, learning systems, customer support, Google Cloud services and business administration.
  • From Google, only where you complete Google’s authorisation flow and grant our application permission to access specific Google user data.

5. Why we use personal data and our lawful bases

We only use personal data where we have a lawful basis. Our main purposes and lawful bases are:

Purpose

Examples

Likely lawful basis

Provide services

Register users, deliver courses, process bookings, manage accounts, provide certificates and customer support.

Contract or steps before entering a contract; legitimate interests.

Payments and administration

Process transactions, invoices, refunds, accounting records and fraud prevention.

Contract; legal obligation; legitimate interests.

Website and security

Maintain website functionality, prevent misuse, investigate security incidents and keep logs.

Legitimate interests; legal obligation where applicable.

Communications

Respond to enquiries, send service updates and operational notices.

Contract; legitimate interests.

Marketing

Send newsletters, promotions or updates where permitted.

Consent or legitimate interests, depending on the context and applicable marketing rules.

Google-authorised functionality

Provide features that require access to Google services after you approve the requested permissions.

Consent/authorisation through Google OAuth and, where applicable, contract or legitimate interests.

Compliance and legal protection

Meet legal, tax, regulatory, audit and record-keeping requirements; establish or defend legal claims.

Legal obligation; legitimate interests.

6. Google user data and Google API Limited Use disclosure

If our website, application or service requests access to Google user data, we will clearly explain the permissions requested and will only access the minimum data needed to provide the relevant user-facing feature. We will not use Google user data for any purpose that is not disclosed in this Privacy Policy and the applicable consent screen or product notice.

Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We only access, use, store or share Google user data to provide or improve the specific functionality you requested or authorised.
  • We do not sell Google user data.
  • We do not use Google user data for advertising purposes.
  • We do not transfer Google user data to third parties except as necessary to provide or secure the service, comply with law, or as part of a merger, acquisition or sale of assets, and only where appropriate safeguards are in place.
  • We do not allow humans to read Google user data unless you have given us permission for support or troubleshooting, it is necessary for security or abuse investigation, it is necessary to comply with law, or the data has first been aggregated/anonymised so it no longer identifies you.
  • You may revoke Google access at any time through your Google Account permissions page or by contacting us.

7. Cookies and similar technologies

Our website may use cookies and similar technologies for essential website operation, security, performance, analytics, user preferences and, where enabled, marketing. Some cookies may be set by our website platform, payment providers, analytics tools or embedded third-party services.

Where required by law, we will ask for your consent before setting non-essential cookies. You can manage cookies through your browser settings and, where available, our website cookie banner or preference tool. Disabling some cookies may affect website functionality.

8. Website hosting and service providers

Our website may be hosted or supported by Wordpress and other trusted providers. These providers may process personal data on our behalf to host the website, store data, process payments, deliver emails, provide analytics, secure our services and support our operations. We require service providers to protect personal data and to process it only for authorised purposes.

Payment processing may be handled by Stripe Payments or other payment providers. We do not intentionally store full payment card details on our own systems. Payment providers are responsible for handling card data in accordance with applicable payment security standards.

9. Sharing personal data

We do not sell personal data. We may share personal data with:

  • Website, hosting, IT, security, analytics, email, CRM, learning platform, payment and customer support providers.
  • Professional advisers such as accountants, insurers, auditors and legal advisers.
  • Regulators, law enforcement, courts, government bodies or other parties where required by law or necessary to protect rights, property, safety or security.
  • A purchaser, successor or relevant party in connection with a business transfer, restructuring, merger or sale of assets, subject to appropriate safeguards.
  • Google or Google-related services where you use Google-authorised functionality or where Google Cloud/Google APIs are used to provide, secure or operate the service.

10. International transfers

Some of our service providers may process data outside the United Kingdom. Where this happens, we will use appropriate safeguards where required, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other lawful transfer mechanisms.

11. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including providing services, meeting legal obligations, resolving disputes and enforcing agreements. Typical retention periods include:

  • Account, booking and service records: for the duration of your relationship with us and then for a reasonable period afterwards.
  • Payment, tax and accounting records: usually up to 6 years after the relevant financial year, unless a longer period is required.
  • Marketing data: until you unsubscribe, withdraw consent, or we determine that the data is no longer needed.
  • Support communications: for as long as needed to deal with the enquiry and maintain business records.
  • Security logs: for a limited period appropriate to security, fraud prevention and audit needs.
  • Google user data: only for as long as necessary to provide the authorised functionality, unless a longer period is required by law or you ask us to delete it and we are able to do so.

12. Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These may include HTTPS, access controls, limited staff access, secure hosting, logging, backups, staff confidentiality obligations and supplier due diligence. No system is completely secure, so we cannot guarantee absolute security, but we work to maintain safeguards proportionate to the risk.

13. Your rights

Depending on your location and the circumstances, you may have rights to:

  • Correct inaccurate or incomplete data.
  • Request deletion of your data.
  • Restrict or object to certain processing.
  • Request data portability.
  • Withdraw consent where processing is based on consent.
  • Object to direct marketing at any time.
  • Complain to a data protection authority.

To exercise your rights, contact us at support@primephysio.com or info@primephysio.com. We may need to verify your identity before responding. You also have the right to complain to the UK Information Commissioner’s Office (ICO) if you are unhappy with how we handle your data.

14. Marketing choices

You can unsubscribe from marketing emails using the unsubscribe link in our emails or by contacting us. Even if you opt out of marketing, we may still send non-marketing service messages, such as booking confirmations, policy updates, security notices or account administration messages.

15. Children

Our services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If we learn that we have collected such data without appropriate consent, we will take reasonable steps to delete it. Where services are used by young people, parents, guardians, schools, employers or training organisations may need to provide appropriate consent or authorisation.

16. Third-party links and embedded services

Our website may include links to third-party websites, platforms, videos, maps, payment pages, social media or other embedded services. We are not responsible for the privacy practices of third parties. You should read their privacy notices before providing personal data to them.

17. Changes to this policy

We may update this Privacy Policy from time to time. Changes take effect when posted on our website, unless stated otherwise. If we make material changes, we will take reasonable steps to bring them to your attention, such as updating the “Last updated” date, posting a notice on the website, or contacting affected users where appropriate.

18. Contact us

For privacy questions, requests or complaints, contact:

Primephysio Training UK

Email: support@primephysio.com or info@primephysio.com

Pre-publication checklist for Google Cloud / OAuth verification

  • Publish this policy on a publicly accessible URL with no login required.
  • Link to the policy from the website footer and from the Google OAuth consent screen.
  • Make sure the website homepage clearly describes the app/service functionality.
  • Insert the exact Google API scopes used and why each is needed.
  • Ensure the OAuth consent screen, app name, domain, logo and privacy policy identify the same organisation.
  • Do not claim you do not use cookies if Wix, analytics, embedded tools or consent tools set cookies.
  • Remove all placeholders before publishing.
  • Keep records of the version and publication date.