How we handle your data
Privacy & Cookie Policy
What we collect, why, how long we keep it, who processes it on our behalf and the rights you have under UK GDPR.
Last updated: 6 September 2026
1. Who is responsible for your data
NextGEN Physio Ltd ("NextGen Physio", "we", "us") is the data controller for personal information collected through this website and our email programme. Company registered in England and Wales, 17433294. Data protection contact: info@nextgen-physio.com.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | First name, email address, parent/guardian status | Guide download forms, account signup, checkout |
| Account | Account email, password (hashed by our auth provider), two-factor status for admins, roles and entitlements | You, when you create an account |
| Purchase | Products bought, checkout reference, amount, currency, payment status, purchase date, the consent tick-boxes you gave at checkout and the wording version | You and Stripe |
| Marketing engagement | Which guides you downloaded, which conditions you are interested in, which nurture sequence you are in, email opens and link clicks, subscribe/unsubscribe events | Your interactions with our emails and site |
| Technical | IP address, browser and device type, pages viewed, referring page, approximate location, session information | Automatically, when you use the site |
| Health information | Symptoms, diagnosis, injury history and rehabilitation progress - only where you choose to share it, mainly in the 12-Week Online Rehab service | You, or the parent/guardian |
We do not receive or store your full card details. Payments are processed by Stripe.
Health information is special category data under UK GDPR and needs both a lawful basis and an Article 9 condition. Where we process it for clinical care, we rely on Article 9(2)(h) (health or social care by a professional bound by confidentiality); otherwise we rely on your explicit consent. Our self-guided products are deliberately designed so you do not have to give us health information to buy them.
3. Children’s information
We market to parents, guardians and adults buying resources for young athletes. Accounts and purchases are for adults aged 18 or over.
Where a parent or guardian provides information about a child, they are responsible for having authority to do so. Where we process children’s personal data, for example within an online rehab episode of care - we apply appropriate safeguards, collect the minimum needed, and take account of the ICO Age Appropriate Design Code (Children’s Code). We do not profile children for marketing purposes and do not send marketing to children.
4. Why we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Take payment, deliver your programme, provide the members library, manage your account, provide support and handle refunds | Contract |
| Send the free guide you requested and the follow-up educational emails for that condition | Consent (withdrawable at any time) |
| Send educational and promotional emails to existing customers about similar products | Legitimate interests / soft opt-in, with unsubscribe in every email |
| Keep a record of the consents you gave at checkout | Legal obligation and legitimate interests (evidencing compliance) |
| Deliver clinical care and keep clinical records | Contract, plus Article 9(2)(h) for health data |
| Site security, fraud prevention, error monitoring and service improvement | Legitimate interests |
| Tax, accounting and legal record-keeping | Legal obligation |
| Non-essential cookies and analytics | Consent |
We do not use health information for unrelated marketing, and we do not sell your data.
5. Who processes data for us
| Provider | What they do |
|---|---|
| Stripe | Payment processing and checkout |
| Supabase (via Lovable Cloud) | Database, authentication, file storage and hosting |
| Resend | Sending transactional and marketing email, including delivery and engagement events |
| Vimeo | Hosting exercise videos in the members library |
| Rehab Guru | Appointment booking for the 12-Week Online Rehab service |
| Optional "Sign in with Google" authentication |
Each acts on our instructions under a data-processing agreement. We may also share information with professional advisers, or with authorities where the law requires it. Where a provider processes data outside the UK, transfers are covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
6. Cookies and similar technology
We set only strictly necessary cookies by default. Anything else, analytics or marketing - is off until you consent using our cookie banner, and you can change or withdraw your choice at any time via "Cookie settings" in the footer.
| Category | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Sign-in session, security, remembering your cookie choice, keeping checkout working | No, required for the site to function |
| Analytics | Understanding which pages and guides are useful, in aggregate | Yes |
| Marketing | Measuring campaign performance and advertising effectiveness | Yes |
Our emails include a small tracking pixel and redirected links so we can see opens and clicks. This is used to tailor the education you receive and to stop sending to people who are not interested. Unsubscribing stops it; you can also block images in your email client.
Stripe checkout and Vimeo video playback set their own cookies when you use those features; both are necessary for the feature you asked for.
7. How long we keep it
- Marketing contacts and engagement history: while you are subscribed, then up to 24 months of inactivity, after which we delete or anonymise. Unsubscribe records are kept indefinitely so we do not email you again.
- Purchase and consent records: 7 years, for tax and to evidence the consents given at checkout.
- Account and entitlement data: while your account exists, then up to 12 months.
- Clinical records for online rehab: retained in line with professional guidance for health records (adults 8 years; children until their 25th birthday, or 26th if aged 17 at the last entry).
- Technical logs: usually up to 12 months.
8. How we protect it
- Encryption in transit (HTTPS) and at rest with our hosting provider.
- Row-level security in the database so each account can only reach its own records.
- Paid programme files served through short-lived signed links rather than public URLs.
- Two-factor authentication (authenticator app) required for administrative accounts.
- Access to customer data limited to those who need it, with audit-friendly logging.
No system is perfectly secure, but we will notify you and the ICO where required if a breach is likely to affect your rights.
9. Your rights
Under UK GDPR you can ask us to:
- give you access to the personal data we hold about you;
- correct inaccurate data;
- delete data where there is no overriding reason to keep it;
- restrict or object to processing, including profiling for marketing;
- provide your data in a portable format;
- withdraw consent at any time, including by unsubscribing.
Email info@nextgen-physio.com and we will respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113), though we would rather have the chance to put things right first.
10. Automated decision-making
We do not make decisions about you by purely automated means that have legal or similarly significant effects. Our email sequences are automated in timing and topic only, based on the condition guide you requested and whether you have purchased.
11. Changes to this policy
We will update this page when our processing changes and revise the "last updated" date. Material changes affecting how we use your data will be communicated by email where we hold your address for that purpose.
This document is provided for transparency and does not constitute legal advice to you.
