How we handle your data

Privacy & Cookie Policy

What we collect, why, how long we keep it, who processes it on our behalf and the rights you have under UK GDPR.

Last updated: 6 September 2026

1. Who is responsible for your data

NextGEN Physio Ltd ("NextGen Physio", "we", "us") is the data controller for personal information collected through this website and our email programme. Company registered in England and Wales, 17433294. Data protection contact: info@nextgen-physio.com.

2. What we collect

CategoryExamplesWhere it comes from
Identity and contactFirst name, email address, parent/guardian statusGuide download forms, account signup, checkout
AccountAccount email, password (hashed by our auth provider), two-factor status for admins, roles and entitlementsYou, when you create an account
PurchaseProducts bought, checkout reference, amount, currency, payment status, purchase date, the consent tick-boxes you gave at checkout and the wording versionYou and Stripe
Marketing engagementWhich guides you downloaded, which conditions you are interested in, which nurture sequence you are in, email opens and link clicks, subscribe/unsubscribe eventsYour interactions with our emails and site
TechnicalIP address, browser and device type, pages viewed, referring page, approximate location, session informationAutomatically, when you use the site
Health informationSymptoms, diagnosis, injury history and rehabilitation progress - only where you choose to share it, mainly in the 12-Week Online Rehab serviceYou, or the parent/guardian

We do not receive or store your full card details. Payments are processed by Stripe.

Health information is special category data under UK GDPR and needs both a lawful basis and an Article 9 condition. Where we process it for clinical care, we rely on Article 9(2)(h) (health or social care by a professional bound by confidentiality); otherwise we rely on your explicit consent. Our self-guided products are deliberately designed so you do not have to give us health information to buy them.

3. Children’s information

We market to parents, guardians and adults buying resources for young athletes. Accounts and purchases are for adults aged 18 or over.

Where a parent or guardian provides information about a child, they are responsible for having authority to do so. Where we process children’s personal data, for example within an online rehab episode of care - we apply appropriate safeguards, collect the minimum needed, and take account of the ICO Age Appropriate Design Code (Children’s Code). We do not profile children for marketing purposes and do not send marketing to children.

4. Why we use it, and our lawful bases

PurposeLawful basis
Take payment, deliver your programme, provide the members library, manage your account, provide support and handle refundsContract
Send the free guide you requested and the follow-up educational emails for that conditionConsent (withdrawable at any time)
Send educational and promotional emails to existing customers about similar productsLegitimate interests / soft opt-in, with unsubscribe in every email
Keep a record of the consents you gave at checkoutLegal obligation and legitimate interests (evidencing compliance)
Deliver clinical care and keep clinical recordsContract, plus Article 9(2)(h) for health data
Site security, fraud prevention, error monitoring and service improvementLegitimate interests
Tax, accounting and legal record-keepingLegal obligation
Non-essential cookies and analyticsConsent

We do not use health information for unrelated marketing, and we do not sell your data.

5. Who processes data for us

ProviderWhat they do
StripePayment processing and checkout
Supabase (via Lovable Cloud)Database, authentication, file storage and hosting
ResendSending transactional and marketing email, including delivery and engagement events
VimeoHosting exercise videos in the members library
Rehab GuruAppointment booking for the 12-Week Online Rehab service
GoogleOptional "Sign in with Google" authentication

Each acts on our instructions under a data-processing agreement. We may also share information with professional advisers, or with authorities where the law requires it. Where a provider processes data outside the UK, transfers are covered by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.

6. Cookies and similar technology

We set only strictly necessary cookies by default. Anything else, analytics or marketing - is off until you consent using our cookie banner, and you can change or withdraw your choice at any time via "Cookie settings" in the footer.

CategoryPurposeConsent needed
Strictly necessarySign-in session, security, remembering your cookie choice, keeping checkout workingNo, required for the site to function
AnalyticsUnderstanding which pages and guides are useful, in aggregateYes
MarketingMeasuring campaign performance and advertising effectivenessYes

Our emails include a small tracking pixel and redirected links so we can see opens and clicks. This is used to tailor the education you receive and to stop sending to people who are not interested. Unsubscribing stops it; you can also block images in your email client.

Stripe checkout and Vimeo video playback set their own cookies when you use those features; both are necessary for the feature you asked for.

7. How long we keep it

  • Marketing contacts and engagement history: while you are subscribed, then up to 24 months of inactivity, after which we delete or anonymise. Unsubscribe records are kept indefinitely so we do not email you again.
  • Purchase and consent records: 7 years, for tax and to evidence the consents given at checkout.
  • Account and entitlement data: while your account exists, then up to 12 months.
  • Clinical records for online rehab: retained in line with professional guidance for health records (adults 8 years; children until their 25th birthday, or 26th if aged 17 at the last entry).
  • Technical logs: usually up to 12 months.

8. How we protect it

  • Encryption in transit (HTTPS) and at rest with our hosting provider.
  • Row-level security in the database so each account can only reach its own records.
  • Paid programme files served through short-lived signed links rather than public URLs.
  • Two-factor authentication (authenticator app) required for administrative accounts.
  • Access to customer data limited to those who need it, with audit-friendly logging.

No system is perfectly secure, but we will notify you and the ICO where required if a breach is likely to affect your rights.

9. Your rights

Under UK GDPR you can ask us to:

  • give you access to the personal data we hold about you;
  • correct inaccurate data;
  • delete data where there is no overriding reason to keep it;
  • restrict or object to processing, including profiling for marketing;
  • provide your data in a portable format;
  • withdraw consent at any time, including by unsubscribing.

Email info@nextgen-physio.com and we will respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113), though we would rather have the chance to put things right first.

10. Automated decision-making

We do not make decisions about you by purely automated means that have legal or similarly significant effects. Our email sequences are automated in timing and topic only, based on the condition guide you requested and whether you have purchased.

11. Changes to this policy

We will update this page when our processing changes and revise the "last updated" date. Material changes affecting how we use your data will be communicated by email where we hold your address for that purpose.

This document is provided for transparency and does not constitute legal advice to you.