Essential Osteopathy - Privacy Policy

This Privacy Policy explains how I collect, use and protect your personal information when you attend Essential Osteopathy for treatment. I am committed to maintaining your privacy and handling your information securely and lawfully in line with UK GDPR, the Data Protection Act 2018 and the General Osteopathic Council’s standards of practice.

Essential Osteopathy
2nd Floor
4 Lynedoch Place
Glasgow G3 6AB


1. What information I collect

To provide safe and effective osteopathic care I collect the following information:

  • Your name, contact details and date of birth

  • Your medical history and current symptoms

  • Details of injuries, operations, illnesses and medications

  • Lifestyle information relevant to your condition

  • Treatment notes and clinical findings

  • Appointment and billing information

  • Communication preferences

  • Information you provide through online intake forms, email or during appointments

I may also collect information if you complete optional surveys or questionnaires.


2. Why I collect your information

I collect and use your information to:

  • Provide osteopathic assessment and treatment

  • Make clinical decisions and maintain accurate medical records

  • Contact you about appointments and administrative matters

  • Provide exercises and advice after treatment

  • Manage billing and accounting

  • Meet my professional and legal obligations as a regulated healthcare provider

Your information is not used for automated decision making.


3. Legal basis for processing your information

Under UK GDPR I process your information under the following legal bases:

  • Performance of a contract: to provide you with osteopathic treatment

  • Legal obligation: to maintain clinical records for required retention periods

  • Vital interests: where information is needed to protect you or others

  • Legitimate interests: for appointment reminders, practice administration and service updates

  • Consent: for optional marketing communications

You may withdraw consent for marketing at any time.


4. How I store and protect your information

I take confidentiality and data security seriously. I ensure that:

  • Electronic records are stored securely within Jane app, a GDPR-compliant medical records system with password-protected access

  • Any older paper records are kept in a locked filing cabinet accessible only to Essential Osteopathy staff

  • Clinic devices are password protected and protected by recognised security software

  • Only information needed to provide you with care is accessed

I do not sell your information and do not share it for marketing or commercial purposes.


5. Use of digital tools (administrative support only)

To support efficient clinical administration I may use secure digital tools to help organise information or prepare written exercises and advice after your appointment. These tools are used only to support admin tasks and do not make clinical decisions or influence your treatment. Any information handled in this way is kept confidential and used only to support the smooth running of the clinic.


6. Who your information may be shared with

Your information is kept confidential and is not shared unless necessary and lawful. Routine access is limited to:

  • Your osteopath

  • Jane app, which manages appointment booking, billing and medical records

  • Mailchimp, if you choose to receive optional newsletters

Your information may also be shared in rare circumstances where:

  • Required by law

  • There is a serious risk of harm that prevents withholding information

  • You give written consent for information to be shared with another healthcare professional

Your information is never shared with third parties for commercial use.


7. Marketing communication

I may send occasional newsletters or service updates through Mailchimp. These are optional and you can unsubscribe at any time using the link in the email or by contacting the clinic.


8. Retention of your information

Clinical records must be retained for:

  • Eight years from the date of your last appointment

  • Until age 25 for patients under 16

  • Until age 26 for patients aged 17 at last appointment

After these periods your information is securely destroyed.


9. Access to your information

You have the right to:

  • Access the information I hold about you

  • Request corrections to inaccurate data

  • Ask for certain information to be erased where legally appropriate

  • Withdraw consent for optional communications

  • Request a copy of your records

Requests can be sent to:
fiona@essentialosteopathy.co.uk
or by phone: 07887 655007

If you have concerns about how your data is handled you may contact the Information Commissioner’s Office (ICO).


10. Data protection lead

Fiona McIntosh (registered osteopath) is the data protection lead for Essential Osteopathy. The clinic is registered with the ICO.

Blog Categories