« Legal & Policies

Privacy Policy

Last updated:
July 2026

1. Important Information and Who We Are

This Privacy Policy aims to give you information on how Physitrack and our group companies collect, process, and secure your personal data.

Physitrack PLC and/or our group companies are the controller and responsible for your personal data (collectively referred to as "Physitrack", "we", "us" or "our" in this Privacy Policy).

Controller and processor roles. 

Physitrack acts in different privacy roles depending on the data, service, jurisdiction, and relationship involved. For personal data that we collect and use for our own account administration, billing, security, corporate, legal, direct customer-relationship, product-safety, compliance, and service-administration purposes, Physitrack acts as a controller, business, organisation, responsible entity, or equivalent role under applicable law. When a healthcare organisation, Health Practitioner, clinic, health system, hospital, or other customer uses our EMR, patient-management, clinical-documentation, exercise-prescription, remote-care, telehealth, interoperability, or integration features to process patient information, that customer generally determines why and how the patient information is used and acts as the controller, covered entity, health information custodian, trustee, health agency, responsible person, organisation, or other responsible health entity, as applicable. Physitrack processes that information on the customer’s documented instructions as a processor, service provider, business associate, business associate subcontractor, sub-processor, information manager, or equivalent role, as applicable. Our Data Processing Agreement, Business Associate Agreement, customer contract, and applicable product terms may contain additional terms governing that processing and will control to the extent they apply to customer-controlled patient information.

If you are a patient and your information is contained in a clinical record created, received, maintained, transmitted, exported, or otherwise managed by your healthcare provider through the Services, your healthcare provider is normally the primary point of contact for questions about that record and for requests to access, correct, amend, restrict, delete, export, transfer, or receive a copy of it. We will assist the relevant customer with those requests as required by applicable law and our contract with the customer. Rights relating to clinical records may be subject to healthcare-specific access, correction, amendment, legal-record, audit-history, record-integrity, retention, legal-hold, patient-safety, professional, payer, regulator, and continuity-of-care requirements.

Data Protection Officer: dpo@physitrack.com. Address: 4th Floor, 140 Aldersgate Street, London, EC1A 4HY.

2. The Data We Collect About You as Controller

We collect, use, store and transfer different kinds of personal data about Health Practitioners, corporate representatives, patients, students and companies using the Services, including: Identity Data (e.g. name, NHS ID); Contact Data (address, email, telephone); Customer Relationship Data (business name, job title, communications records); Transaction Data (payment details and purchases); Technical Data (IP address, login data, browser information); Profile Data (API token, password, preferences); Usage Data (service usage information); Marketing and Communications Data (newsletter preferences); Financial Data (bank/credit card details); and Service Data (analytics and performance data).

For patients and students, the personal data Physitrack processes as a controller depends on the service and relationship involved and may include Usage Data, Contact Data, Identity Data, Health Data and Technical Data. Patient clinical information that we process on behalf of a Healthcare Customer is addressed separately in Section 3.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose, as this does not directly or indirectly reveal your identity.

Where Physitrack acts as a controller, we may process Special Categories of Personal Data, sensitive information or health information only where this is necessary for the relevant purpose and permitted by applicable law. This may include limited Health Data needed to provide a direct service, address support or security matters, establish or defend legal claims, or meet legal or regulatory obligations. Patient clinical information processed on behalf of a Healthcare Customer is addressed in Section 3.

3. The Data We Collect About You as Processor

We act as a processor (or service provider, business associate or subprocessor, as applicable) to Health Practitioners and other Healthcare Customers. In this role we process personal data on their behalf and on their documented instructions, and not for our own purposes.

Depending on which parts of the Services the relevant Healthcare Customer has enabled, the data we process in this role includes:

  • Exercise prescription and remote care data — Identity Data (including a national health identifier such as an NHS number where the customer uses that field), the exercise programs and questionnaires assigned to you, your adherence to them, outcome and self-reported measures, and related Usage Data and Technical Data.
  • EMR Data — personal data, health information, PHI, clinical information, personal health information, special category personal data, sensitive information, consumer health data where applicable, and related metadata entered, uploaded, generated, imported, accessed, stored, transmitted, exported, or otherwise processed through the EMR or a connected clinical workflow. Depending on the Healthcare Customer’s configuration and the features enabled, this may include: identity and demographic information such as name, date of birth, administrative sex, gender identity, Aboriginal and/or Torres Strait Islander status, ethnicity, race, preferred name, pronouns, interpreter or language needs, and other sensitive demographic information selected by the Healthcare Customer; contact and care-network information such as address, phone, email, emergency contact, GP or referring practitioner, care team, and authorised contacts; clinical intake and record information such as allergies, medicines, other medical conditions, safety or red-flag responses, presenting complaint, symptom history and severity, body-area information, functional impact and goals, free-text clinical notes, diagnoses or diagnosis codes, body-chart entries, treatment information, outcomes, and care-plan information; appointment, scheduling, consent, payment-status, and patient-communication information where enabled; RTM, exercise, adherence, and outcome data from enabled Physitrack services; consultation audio, transcripts, and draft clinical documentation where an enabled recording, speech-to-text, or AI-scribe feature is used; interoperability, referral, export, transfer, or integration records; and audit records of access to and changes to the record.

The standard EMR intake does not, by itself, include payer claims or insurance revenue-cycle-management data, identity-document images, or biometric identity templates unless those features are separately enabled. Beta Environments are subject to the stricter restrictions described below and must not be used for live billing, reimbursement, claims, or other production workflows. If additional payer, insurance, identity-verification, or other functionality is introduced or enabled, the relevant notices and this Privacy Policy will be updated where required.

Where a parent, guardian, carer or other authorised person provides information on behalf of a patient, EMR Data may also include that person’s identity and contact details, relationship to the patient and the basis on which they are authorised to act.

Some of this information is Special Category Personal Data, sensitive information, health information or PHI under applicable law. We process it only as necessary to provide the Services to the relevant Healthcare Customer.

The Healthcare Customer determines what information is collected, which enabled fields are used, who may access it and how long it is kept. For configurable patient intake forms, the Healthcare Customer determines which available fields are included and whether an included field is optional or required; Physitrack does not designate the Aboriginal and/or Torres Strait Islander status field as inherently mandatory. Retention of data we process in this role follows the customer’s instructions and the applicable customer agreement, DPA or BAA. Where no customer-specific retention period applies, our Data Retention Policy applies. See Section 9 (Data Retention).

Beta, pilot, preview, sandbox, demonstration, and evaluation environments. Unless Physitrack expressly identifies an environment in writing as approved for production clinical use and the required privacy, security, contractual, implementation, and compliance steps have been completed, beta, pilot, preview, pre-release, sandbox, demonstration, and evaluation environments must not be used to enter, upload, import, record, dictate, display, store, transmit, or otherwise process real patient data, PHI, personal health information, Special Category Personal Data, sensitive information, consumer health data, EMR Data, production data, live clinical data, or other personal data relating to an actual patient or other third party. Such environments are intended for synthetic, dummy, anonymised, or other non-live test data only and must not be used for diagnosis, treatment, clinical decision-making, patient communications, emergency communications, legal medical records, billing, reimbursement, claims, regulatory reporting, or other clinical or production purposes unless Physitrack expressly states otherwise in writing. This restriction does not prevent Physitrack from processing limited personal data about beta users themselves, such as identity and contact information, account and authentication data, Technical Data, Usage Data, support communications, and feedback, where reasonably necessary to provision, administer, secure, support, evaluate, and improve the beta and the Services in accordance with this Privacy Policy. Beta users must not include real patient or other third-party personal data in prompts, free-text fields, uploads, recordings, transcripts, feedback, or support requests.

4. How Is Your Personal Data Collected?

We use different methods to collect data from and about you including through: direct interactions, where you may give us your Identity, Contact and Financial Data by filling in forms, by corresponding with us by post, phone, email, chatbot or otherwise; automated technologies, where we (and our third-party partners) automatically collect Technical Data as you interact with our website, using cookies and similar technologies; and third parties, from whom we may receive data such as payment providers, LinkedIn, and Health Practitioners.

For EMR and clinical workflows, information may also be collected directly from a patient, authorised representative or clinician through booking and intake forms, questionnaires, clinical documentation, patient portals, communications and, where enabled, consultation recording or transcription; from a Healthcare Customer’s existing systems or enabled Physitrack services through customer-authorised integrations, APIs or data imports; from referral sources; from devices or connected services enabled by the customer; and from records generated when authorised users access, edit, export, transmit or otherwise use the EMR. We describe integration methods at a high level here because the specific systems and technical methods available may vary by customer and configuration.

5. How We Use Your Personal Data

The first table below describes the ways we use personal data when Physitrack acts as controller and the legal bases we rely on. The separate EMR table that follows describes customer-directed processing where Physitrack acts as processor, service provider, business associate or subprocessor; it does not create an independent purpose for Physitrack to use patient clinical records.

‍

Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To register you as a new User and set up an account/profile(a) Identity

(b) Contact
Performance of a contract with you; and/or consent where required by applicable law.
To provide you with our services, including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(c) operating our Services

(d) providing our Services
Identity; Contact; Financial; Transaction; Marketing and Communications; Customer Relationship; Service Data; Health Data (controller processing only).(a) Performance of a contract with you; (b) necessary for our legitimate interests (including to recover debts due to us); and/or (c) consent where applicable or required by law.
To process your account/profile data for the purposes of publishing such data on our Services and elsewhere through our services(a) Identity

(b) Contact

(c) Profile

(d) Service Data
Performance of a contract with you; and/or consent where applicable or required by law.
To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or Privacy Policy

(b) Asking you to leave a review or take a survey

(c) to communicate with you for example in order to resolve any functionality issues.
(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e) Customer Relationship
(a) Performance of a contract with you; (b) necessary to comply with a legal obligation; (c) necessary for our legitimate interests (including to keep records updated and understand use of our products and services); and/or (d) consent where applicable or required by law.
For security monitoring purposes and to administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)(a) Identity

(b) Contact

(c) Technical
(a) Necessary for our legitimate interests (including operating our business, administering IT services, maintaining network and information security, preventing fraud and supporting corporate transactions); and/or (b) necessary to comply with a legal obligation.
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences(a) Technical

(b) Usage
Necessary for our legitimate interests (including to understand and improve our website, products, services and customer experience); and, for cookies or similar technologies, consent where required by applicable law.
To make suggestions and recommendations to you about goods or services that may be of interest to you, to send you our newsletter where you have opted into receiving it(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

(f) Marketing and Communications
(a) Necessary for our legitimate interests (to develop our products/services and grow our business); and/or

(b) Consent
To establish or defend legal claims(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Service Data
Necessary for our legitimate interests (the protection and assertion of our legal rights, your legal rights and the legal rights of others).
To obtain or maintain insurance coverage, managing risks and/or obtaining professional advice.(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Service Data
Necessary for our legitimate interests (the proper protection of our business against risks).
To ensure that those prescribing tailored and personal exercise programs to patients via Physitrack are able to validate that they have selected the correct patient recipient against their NHS number. In addition, the NHS number can be used to search for existing patient profiles within the Physitrack environment when adding to or amending a current or previous program.(a) Identity (including NHS ID)(a) Performance of a contract with you.

(b) Necessary for our legitimate interests (to ensure accurate identification).
To operate and administer our referral, reseller, partner and commission-based affiliate arrangements, including notifying an Affiliate Partner that a discount or referral code associated with them has been used, and that a trial or subscription linked to that code has started, converted, renewed or been cancelled, so that we can calculate and pay commission owed to that Affiliate Partner.(a) Identity

(b) Contact

(c) Transaction

(d) Customer Relationship

(e) Marketing and Communications
(a) Necessary for our legitimate interests (operating our commercial partner and referral programs and paying commission properly owed under those arrangements); and/or

(b) Consent, where you were notified when entering a discount or referral code that doing so may result in your name, email address and trial/subscription status being shared with the relevant Affiliate Partner.

How we process EMR Data for Healthcare Customers

Customer-directed purposeExamples of EMR DataOur processing framework
Create, maintain, access, transmit, export, and support the patient record and enabled clinical workflow.Identity and contact details; demographics; intake responses; clinical notes; diagnoses or diagnosis codes; treatment information; body-chart entries; outcomes and RTM data; consents; appointments; communications; imported and exported records; interoperability metadata; and other enabled record fields.Healthcare Customer’s documented instructions, the applicable DPA or customer agreement, the applicable BAA where HIPAA applies, and applicable law.
Provide enabled AI-assisted documentation, transcription, and workflow support.Consultation audio; transcripts; clinical context; draft notes or documentation; intake summaries; and limited technical or usage metadata needed to provide the featureHealthcare Customer’s documented instructions and the applicable DPA, BAA, customer agreement, and approved subprocessor controls. We do not use EMR Data, PHI, patient clinical information, patient recordings, transcripts, or de-identified patient-record data to train or fine-tune AI models, and approved AI subprocessors are not permitted to use EMR Data, PHI, patient clinical information, patient recordings, transcripts, or de-identified patient-record data for their own model training.
Support intake, scheduling, patient communications, enabled payments, record transfers, and authorised integrations.Identity and contact details; appointment information; consents and communication preferences; communication content; payment status or transaction metadata where enabled; records imported from or exported to customer-authorised systems; referral or transfer information; and audit records.Healthcare Customer’s instructions, the applicable DPA or customer agreement, the applicable BAA where HIPAA applies, and the laws and provider contracts applicable to the enabled feature.
Support privacy, security, compliance, audit, service integrity, and incident response.Access logs, audit trails, authentication events, security telemetry, configuration metadata, support records, and limited record information necessary to investigate, remediate, or document a security, privacy, legal, or compliance matter.Healthcare Customer’s instructions, the applicable DPA or customer agreement, the applicable BAA where HIPAA applies, and legally permitted security, compliance, and business-associate or processor functions.

AI-assisted EMR features. Where an AI-scribe, speech-to-text, intake-readback, summarisation, drafting, or other AI-assisted EMR feature is enabled, patient information is processed only to provide the requested feature on behalf of the Healthcare Customer and in accordance with applicable contractual, privacy, and security safeguards. We do not use EMR Data, PHI, patient clinical information, patient recordings, transcripts, or de-identified patient-record data to train or fine-tune AI models, and approved AI subprocessors are not permitted to use EMR Data, PHI, patient clinical information, patient recordings, transcripts, or de-identified patient-record data for their own model training. Consultation audio is processed only when the relevant recording, transcription, or AI-assisted feature is started or otherwise enabled and subject to the Healthcare Customer’s applicable notice, consent, or other legal requirements. AI-generated drafts and other AI-assisted outputs are intended for review, correction, and approval by an authorised clinician before they are relied upon for patient care or incorporated into the clinical record. AI-assisted outputs may be incomplete, inaccurate, delayed, or unsuitable for a patient’s circumstances and are not emergency alerts, medical advice, diagnosis, treatment instructions, or a substitute for professional judgment.

6. Disclosures of Your Personal Data

We may share your personal data for business and commercial purposes, such as operating the Services, with the parties set out below for the purposes set out in the table above:

  • Health Practitioners who use the Services to collect and process your personal data.
  • Service providers acting as processors who provide IT, hosting and system administration services identified at support.physitrack.com/subprocessors.
  • Affiliates as a controller and/or processor for business and commercial purposes (meaning Physitrack's own corporate group of companies — see "Affiliates" in the Glossary. This is distinct from Affiliate Partners, described below, who are external to the Physitrack group).
  • Affiliate Partners — external commercial, referral, reseller or commission-based partners with whom we operate a discount code, referral or affiliate program (see "Affiliate Partners" in the Glossary), for the purpose of administering that arrangement and calculating and paying commission owed to them. We only share the minimum data necessary for this purpose — typically your name, email address, and the status of your trial or subscription — and, where reasonably practicable, we will notify you at the point you use a discount or referral code that this sharing may occur.
  • Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
  • HM Revenue & Customs, regulators and other governmental authorities who require reporting of processing activities in certain circumstances.
  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them.

EMR Data disclosures

EMR Data is disclosed only as necessary to provide, secure, support, administer, maintain, and improve the customer-directed Services; comply with the Healthcare Customer’s documented instructions; satisfy applicable legal obligations; or perform other activities permitted by the applicable DPA, BAA, customer agreement, and law. This may include disclosure to authorised users of the relevant Healthcare Customer; the patient or an authorised representative where directed by the customer, enabled by the Service, or required by law; approved subprocessors that provide hosting, security, support, communications, speech-to-text, AI processing, interoperability, or other infrastructure needed for the EMR; systems and integrations selected, configured, or authorised by the customer; other healthcare providers, recipients, repositories, or systems where the customer directs or lawfully authorises the disclosure; and regulators, courts, professional bodies, payers, or public authorities where disclosure is required or permitted by law.

We do not disclose EMR Data, patient clinical information, PHI, personal health information, or consumer health data to Affiliate Partners, referral partners, resellers, advertising partners, or marketing partners for their own commercial, advertising, or marketing purposes. Any affiliate, referral, reseller, or commission-related disclosures described elsewhere in this Policy apply to customer, account, subscription, or commercial relationship information, not patient clinical records. Where the minimum-necessary principle, data-minimisation principle, or an equivalent local-law requirement applies, we limit access, use, and disclosure to the information reasonably necessary for the relevant purpose.

Where a Healthcare Customer, authorised user, patient, or authorised representative exports, downloads, prints, transmits, transfers, discloses, or otherwise makes EMR Data available outside Physitrack-controlled systems, the recipient and the Healthcare Customer are responsible for the security, use, disclosure, retention, onward transfer, and further handling of that copy, except to the extent Physitrack remains legally or contractually responsible for its own processing.

7. International Transfers

Where necessary, we may transfer personal data to another country to provide, secure, support, administer, and improve the Services; perform customer relationship management and business operations; use approved subprocessors; respond to support requests; comply with law; or carry out customer-authorised integrations, exports, transfers, and interoperability workflows. Many of our external third parties are based outside the country in which you reside, so their processing of personal data may involve a transfer of data outside your country.

For EMR Data, the primary hosting location is determined by the Healthcare Customer’s contracted service region and product configuration. Additional processing, support access, security operations, or subprocessor processing may occur in locations used by approved subprocessors, as identified in our current subprocessor information and applicable customer contracts. We do not promise customer-selectable data residency except where it is expressly included in the applicable service configuration or contract.

Where personal data is transferred outside the United Kingdom, European Economic Area, Switzerland, Canada, Australia, New Zealand, or another jurisdiction with transfer restrictions, we use transfer mechanisms and safeguards required by applicable law. These may include adequacy decisions, standard contractual clauses, UK transfer mechanisms, transfer risk assessments, supplementary measures, processor or service-provider contractual commitments, or comparable safeguards. Where Australian personal information is disclosed to an overseas recipient, we take the steps required by applicable Australian privacy law, including requirements governing overseas disclosures. Where New Zealand health information is transferred overseas, we apply the safeguards required by the New Zealand Privacy Act and Health Information Privacy Code where applicable.

Healthcare Customers are responsible for ensuring that their instructions to transfer, export, disclose, or otherwise make patient information available outside the relevant jurisdiction are lawful, supported by any required notice, consent, authorisation, contractual term, professional requirement, or other legal basis, and consistent with applicable health-record, confidentiality, interoperability, and continuity-of-care obligations.

How we safeguard personal data when we transfer it internationally

Whenever we transfer your personal data out of your country, we take reasonable steps to ensure a similar degree of protection is afforded to it by using at least one of the following safeguards:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data under applicable law; or
  • Where we use certain service providers, we may use specific contracts approved for use in your country which give personal data the same protection it has in your country.

For EMR Data, the primary hosting location is determined by the Healthcare Customer’s contracted service region and product configuration. Additional processing or support access may occur in locations used by approved subprocessors as identified in our current subprocessor information and applicable customer contracts. We do not promise customer-selectable data residency except where it is expressly included in the applicable service configuration or contract. Where required, we use recognised transfer mechanisms and contractual safeguards, which may include the EU Standard Contractual Clauses and applicable UK transfer mechanisms, together with supplementary measures where appropriate.

Where Australian personal information is disclosed to an overseas recipient, we take the steps required by applicable Australian privacy law, including the requirements governing overseas disclosures. Where New Zealand health information is transferred overseas, we apply the safeguards required by the New Zealand Privacy Act and Health Information Privacy Code where applicable.

For further details of the specific mechanisms we rely on where we transfer your data internationally, please see support.physitrack.com/article/721-what-types-of-data-are-stored-by-physitrack.

8. Data Security; Security Incidents and Personal Data Breaches

We have put in place reasonable technical, organisational, and administrative security measures designed to meet the requirements of applicable law and to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Because EMR Data may include highly sensitive clinical information, we apply measures appropriate to the risk. Depending on the service and customer configuration, these measures may include role-based access controls, authentication controls, least-privilege access, encryption in transit and at rest, audit logging, tenant separation, secure backups, monitoring, vulnerability management, incident-response procedures, confidentiality obligations, and controls aligned with our information-security management system.

Access to EMR Data by Physitrack personnel is limited to authorised personnel with a legitimate need to access the information for support, security, legal, compliance, or operational purposes and is subject to confidentiality and access-control requirements. Healthcare Customers are responsible for configuring and managing authorised-user access; using unique credentials; applying appropriate role-based and least-privilege permissions; promptly deactivating users who no longer require access; training their workforce; maintaining reasonable endpoint and network security; preventing credential sharing; and protecting copies of patient information exported, downloaded, printed, transmitted, or otherwise transferred from the Services to systems, devices, files, recipients, or environments under the Healthcare Customer’s control.

If a security incident, personal data breach, breach of unsecured PHI, confidentiality incident, or unauthorised access, use, disclosure, alteration, loss, or destruction affects customer-controlled EMR Data, we notify and assist the relevant Healthcare Customer in accordance with applicable law and the customer agreement, DPA, or BAA. The Healthcare Customer is generally responsible for notifying affected individuals, regulators, media, professional bodies, payers, funders, or other persons where legally required of the Healthcare Customer, except to the extent Physitrack has a direct legal obligation to provide notice. We notify individuals and regulators directly where Physitrack has a direct legal obligation to do so and may coordinate with the Healthcare Customer to the extent lawful and reasonably practicable.

No internet-connected service can be guaranteed to be completely secure or continuously available. You remain responsible for using the Services in accordance with applicable instructions, maintaining the security of devices and credentials under your control, and promptly notifying Physitrack or the relevant Healthcare Customer if you believe an account, credential, device, link, or environment has been compromised.

9. Data Retention

We retain personal data for as long as reasonably necessary to fulfil the purposes for which we collected it, including for contractual, legal, regulatory, tax, accounting, reporting, security, audit, business-continuity, dispute-resolution, and claims-related purposes. We may retain personal data for a longer period where required or permitted by applicable law, where necessary to address a complaint or security issue, or where we reasonably believe there is a prospect of litigation or regulatory inquiry relating to our relationship with you. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data; the potential risk of harm from unauthorised use or disclosure; the purposes for which we process the data; whether those purposes can be achieved by other means; and applicable legal, regulatory, tax, accounting, professional, contractual, and other requirements.

EMR Data retention. EMR Data is retained in accordance with the Healthcare Customer’s instructions, the applicable customer agreement and retention schedule, the applicable DPA or BAA, product configuration, and any legal, professional, payer, regulator, or health-record obligations that apply to the relevant clinical record. Healthcare Customers may be required to retain medical records for periods that prevent immediate deletion even when an individual requests erasure. When an EMR account or customer relationship ends, the availability of export, return, deletion, de-identification, anonymisation, archive, and backup expiry for EMR Data is governed by the applicable customer agreement, DPA or BAA, product configuration, Data Retention Policy, and legal requirements. We securely delete, de-identify, anonymise, or render data inaccessible when the applicable retention period ends, subject to lawful retention, legal-hold, audit, backup, security, business-continuity, and disaster-recovery exceptions.

Where Australian privacy law applies, personal information that is no longer required for any lawful purpose will be destroyed or de-identified in accordance with applicable Australian privacy requirements, subject to lawful retention, legal-hold, audit, backup, security, professional-record, clinical-record, business-continuity, and other permitted exceptions. Where EU or UK data-protection law applies, deletion, return, restriction, and retention of personal data processed on behalf of a Healthcare Customer will be handled in accordance with the applicable DPA, applicable law, and the Healthcare Customer’s documented instructions.

Where we use de-identified or anonymised information for permitted analytics, research, statistical, security, compliance, benchmarking, or product-improvement purposes, we apply the de-identification or anonymisation standard required by applicable law and do not treat merely pseudonymised information as anonymous. Where HIPAA applies, PHI used as de-identified information must satisfy an applicable HIPAA de-identification method. We do not attempt to re-identify data that has been treated as anonymous or de-identified for these purposes, except where lawfully required or reasonably necessary to test the effectiveness of de-identification safeguards. Nothing in this Section permits us to use identifiable EMR Data, patient clinical information, PHI, patient recordings, transcripts, or de-identified patient-record data to train or fine-tune AI models.

10. EU Representative

Our representative within the EU with respect to our obligations under European data protection law is Physiotools Oy, incorporated and registered in Finland with company number 0491074-9, whose address is Kehräsaari B, 5th Floor, 33200 Tampere, Finland. Email: data.protection@physiotools.com.

11. Your Legal Rights

Depending on where you live, you may have the right to:

  • Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: if you want us to establish the data's accuracy; where our use of the data is unlawful but you do not want us to erase it; where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the rights set out above, please contact us at dpo@physitrack.com.

Requests about EMR Data

If your request concerns EMR Data held on behalf of your healthcare provider or another Healthcare Customer, please contact that provider or customer in the first instance. The provider or customer controls the clinical record and is generally responsible for responding to requests concerning access, correction, amendment, deletion, restriction, objection, portability, export, transfer, accounting, representative access, and similar patient or data-subject rights. We will assist the provider or customer as required by applicable law and our agreement with them. You may also contact our Data Protection Officer if you are unsure who controls the relevant information.

Rights relating to clinical records may be subject to healthcare-specific retention, access, correction, amendment, record-integrity, audit-history, legal-hold, safety, professional, payer, regulator, and continuity-of-care requirements. For example, a healthcare provider may be legally required to retain a clinical record even where an individual would otherwise have a right to request deletion. Corrections or amendments to a clinical record may need to preserve an audit history rather than silently overwrite the original clinical entry. Where a parent, guardian, carer, substitute decision-maker, personal representative, or other authorised person seeks to act on behalf of a patient, the relevant Healthcare Customer is generally responsible for verifying that person’s authority and configuring access consistently with applicable law and professional obligations.

No fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you and to follow certain procedures to help us verify the request, confirm your identity, and ensure your right to access your personal data (or to exercise any of your other rights). The verification steps we take may differ depending on your country of residence and the request. We will match the information that you provide in your request to information we already have on file to verify your identity. If we are able to verify your request, we will process it in accordance with applicable law. If we cannot verify your request, we may ask you for additional information to help us verify your request. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We will respond to your request within the time period required by applicable law. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

12. Considerations in the United States

HIPAA and Protected Health Information

 Where HIPAA applies, identifiable health information that constitutes Protected Health Information (“PHI”) under HIPAA is handled in accordance with HIPAA, the HITECH Act where applicable, and the Business Associate Agreement (“BAA”) with the relevant covered entity or business associate. Not all health-related information in the United States is PHI; other federal or state privacy laws may apply to health information that falls outside HIPAA or where an applicable HIPAA exemption does not apply.

Where HIPAA applies, we use, disclose, protect, retain, return, and destroy PHI only as permitted by HIPAA and the applicable BAA, including to provide the Services and functionality requested by the relevant Healthcare Customer; carry out documented instructions; perform permitted business-associate functions; use approved subcontractors or sub-business associates; comply with applicable legal requirements; and support privacy, security, audit, and compliance obligations. We do not use PHI or other EMR Data to train or fine-tune AI models. We disclose PHI only as permitted by HIPAA, the applicable BAA, applicable law, or the documented direction of the relevant Healthcare Customer. A patient, authorised representative, or authorised user is responsible for disclosures that they initiate through functionality made available to them.

Interoperability, patient access, and information access

Where U.S. law concerning interoperability, patient access, electronic health information export, information access, or information blocking applies to a Healthcare Customer, the Healthcare Customer is responsible for determining the legal basis, scope, recipient, timing, and professional requirements applicable to any access, exchange, export, amendment, accounting, transfer, or continuity-of-care request. Physitrack will provide contracted Service functionality and BAA-required assistance reasonably necessary to support the Healthcare Customer’s lawful obligations for PHI maintained through the Services. Physitrack may decline or delay an access, exchange, export, or transmission request to the extent necessary to comply with law, protect privacy or security, respect patient permissions, preserve system integrity, comply with the BAA or customer instructions, or operate within the Services’ contracted and technically supported functionality.

US state privacy law disclosures

If you are a resident of a U.S. state with a comprehensive consumer privacy law and that law applies to our processing, you may have some or all of the following rights, in addition to those set out in the “Your Legal Rights” section above: the right to know and access the categories and specific pieces of personal data we have collected about you; the right to correct inaccurate personal data; the right to delete personal data we hold about you; the right to opt out of sale of personal data, sharing for cross-context behavioural advertising where applicable, and certain profiling that produces legal or similarly significant effects; the right to data portability; the right to limit certain uses or disclosures of sensitive personal data where applicable; and, in some states, the right to appeal a refusal to act on a request. We do not discriminate against you for exercising any of these rights. Where we process personal data solely on behalf of a Healthcare Customer, that Healthcare Customer is generally responsible for responding to requests concerning the relevant clinical record, and we assist as required by law and contract.

Consumer health data 

Certain U.S. state consumer health data laws regulate health-related information that may fall outside HIPAA. Depending on the circumstances, Physitrack may process this information on behalf of a Healthcare Customer or may have direct obligations for processing it for its own purposes. Where Physitrack acts only as a processor or service provider for a Healthcare Customer, that customer determines the purpose of the processing and is generally the primary point of contact for consumer requests; we assist the customer as required by law and contract. Where Physitrack has direct obligations, we provide any required consumer health data notice and obtain consent where required. We do not sell consumer health data, and we do not use geofencing around healthcare facilities for purposes prohibited by applicable law. Where applicable law gives you rights in relation to consumer health data, those rights may include confirming whether data is collected, shared, or sold; accessing data; withdrawing consent where applicable; and requesting deletion, subject to statutory exceptions.

Heightened-confidentiality and sensitive health information. Healthcare Customers are responsible for determining whether particular categories of health information are subject to heightened confidentiality, consent, authorization, segmentation, disclosure, or retention requirements under federal or state law, including mental health, substance-use-disorder, reproductive, genetic, HIV/AIDS, minor, disability, sensitive demographic, biometric, and similar information. Healthcare Customers are responsible for configuring and using the Services consistently with those requirements, providing required notices, obtaining required consents or authorizations, and honoring applicable patient, consumer, or representative rights. Physitrack will comply with obligations imposed on it by applicable law, the applicable BAA, and any applicable data-processing or service-provider terms.

We do not discriminate against you for exercising any of these rights. 

To exercise a right described in this section, please contact us at dpo@physitrack.com. We may need to verify your identity before responding, as described in the "Your Legal Rights" section above. You may also designate an authorised agent to make a request on your behalf, subject to our ability to verify the agent's authority to act on your behalf.

Washington "My Health My Data Act" notice

Washington State’s My Health My Data Act (“MHMD”) regulates certain “consumer health data,” including some health-related information that may fall outside HIPAA. Depending on the circumstances, Physitrack may process this information on behalf of a Healthcare Customer or may have direct obligations under MHMD for processing it for its own purposes.

Where Physitrack acts only as a processor or service provider for a Healthcare Customer, that customer determines the purpose of the processing and is generally the primary point of contact for consumer requests; we assist the customer as required by law and contract. Where Physitrack has direct obligations under MHMD, we provide any required consumer health data notice and obtain consent where required. We do not sell consumer health data, and we do not use geofencing around healthcare facilities for purposes prohibited by MHMD.

Where MHMD gives you rights in relation to consumer health data, those rights may include confirming whether data is collected, shared or sold; accessing data; withdrawing consent where applicable; and requesting deletion, subject to statutory exceptions. If the data is held for your healthcare provider or another Healthcare Customer, contact that provider/customer first. You may also contact us at dpo@physitrack.com if you are unsure who controls the relevant information.

13. Considerations in Australia

If the Australian Privacy Act 1988 (Cth) applies to the handling of your personal data, this Section applies. In this Privacy Policy, references to “Special Categories of Personal Data” should be read, where the Australian Privacy Act applies, as including “sensitive information” under that Act. Health information and information about racial or ethnic origin receive additional protection. Sensitive information is collected, used, and disclosed only as permitted by applicable law, including where valid consent is required or a permitted health situation or other legal exception applies.

Where a Healthcare Customer enables Australian EMR or intake functionality, the Healthcare Customer is responsible for determining the purpose of collection; providing required collection notices; obtaining and retaining any consent or other legal authority required for health information and sensitive information; deciding whether a field is optional or required for its workflow; verifying the authority of parents, guardians, carers, substitute decision-makers, or other authorised representatives; and complying with applicable health-record, access, correction, transfer, retention, and professional obligations. Physitrack processes the information on that Healthcare Customer’s behalf in accordance with the applicable customer agreement, DPA or equivalent terms, Privacy Policy, and applicable law.

Aboriginal and/or Torres Strait Islander status. Where a Healthcare Customer enables this EMR intake field, Physitrack processes the information on that customer’s behalf as part of the patient’s demographic and health-service record. The Healthcare Customer decides whether to include the field and whether an included field is optional or required for its workflow; Physitrack does not make this field inherently mandatory. The information may be provided by the patient or an authorised representative, entered by an authorised clinician, or received through a customer-authorised integration. It is available to authorised users according to the Healthcare Customer’s permissions and, where necessary, to limited authorised Physitrack personnel as described in Section 8. The Healthcare Customer is responsible for determining and communicating the specific health-service purpose for collecting the field and for obtaining consent or other legal authority where required. We do not use identifiable Aboriginal and/or Torres Strait Islander status for advertising or marketing, and we do not use it to train AI models. Any use of genuinely de-identified or anonymous information is governed by Section 9.

Personal information that is no longer required for any lawful purpose will be destroyed or de-identified in accordance with applicable Australian privacy requirements, subject to lawful retention, legal-hold, audit, backup, security, professional-record, clinical-record, business-continuity, and other permitted exceptions. Where Australian personal information is disclosed to an overseas recipient, we take the steps required by applicable Australian privacy law, including the requirements governing overseas disclosures.

13A. Considerations in Canada

Where Canadian federal, provincial, or territorial privacy or health-information law applies, the relevant Healthcare Customer is generally responsible for determining whether it is a health information custodian, trustee, organisation, public body, service provider, affiliate, information manager, or other regulated entity and for complying with applicable notice, consent, safeguarding, access, correction, retention, breach-notification, residency, and service-provider requirements. Physitrack processes personal information and personal health information in accordance with the applicable customer agreement, DPA or equivalent terms, Privacy Policy, and law, including by using contractual, technical, and organisational safeguards appropriate to the sensitivity of the information.

If your request concerns personal health information held by Physitrack on behalf of a Canadian Healthcare Customer, please contact that Healthcare Customer first. We will assist the Healthcare Customer as required by applicable law and our agreement with it. Where Physitrack has direct obligations under applicable Canadian privacy law, we will respond to requests and provide notices in accordance with that law.

13B. European Health Data and Interoperability Developments

To the extent European Union, United Kingdom, or Member State law concerning electronic health data, interoperability, patient access, health-record portability, or cross-border health-data exchange becomes applicable to the Services or to a Healthcare Customer, Physitrack and the Healthcare Customer will comply with the obligations applicable to them. Healthcare Customers remain responsible for determining their professional, controller, healthcare-provider, legal-record, retention, and health-record obligations, including the lawful basis and professional requirements for making electronic health data available to patients, other healthcare providers, authorised representatives, or other recipients. Physitrack will provide the contracted functionality and DPA-required assistance within the Services’ supported configuration.

14. Considerations in New Zealand

If the New Zealand Privacy Act 2020 ("NZ Privacy Act") applies to the handling of your personal data, this section will apply.

We will also comply with the New Zealand Health Information Privacy Code 2020 ("HIP Code") when collecting your health information.

We will collect personal data directly from you unless (i) you have authorised the collection of personal data from a third party, (ii) it would not prejudice you for collection to occur through a third party, (iii) collection from you would prejudice the purpose of collection, or (iv) it is not reasonably practicable to collect from you and the information will not be used in a form whereby you are identifiable.

Where the New Zealand Health Information Privacy Code 2020 applies, health information is collected only for a lawful purpose connected with the relevant health agency’s functions and only where collection is necessary for that purpose. Required collection notices must be provided when information is collected from the individual and, for health information collected indirectly on or after 1 May 2026, Rule 3A requires reasonable notification to the individual or their representative unless an exception applies.

We process New Zealand health information in accordance with the customer’s instructions and support applicable requirements concerning security, access, correction, retention, use, disclosure and overseas transfers.

For the purposes of section 7 (International Transfers) of this Privacy Policy, we may transfer your personal data to overseas recipients (i.e. outside New Zealand) located in the countries as set out under the list of Physitrack's Third Party Vendors (sub-processors) which can be found at support.physitrack.com/article/721-what-types-of-data-are-stored-by-physitrack.

15. Glossary

Affiliates - means Physitrack PLC together with its direct and indirect subsidiary and parent companies from time to time (i.e. Physitrack's own corporate group). This is distinct from "Affiliate Partners", defined below.

Affiliate Partners - means external, third-party individuals or businesses with whom we have a commercial, referral, reseller or commission-based arrangement — for example, an individual or company who refers customers to us using a discount or referral code in exchange for commission. Affiliate Partners are not part of the Physitrack group and act as an independent controller of any personal data we share with them for the purposes of that arrangement.

AI-assisted EMR feature - an optional EMR function that uses speech-to-text, artificial-intelligence, machine-learning, or other automated technologies to support a workflow such as transcription, documentation drafting, summarisation, intake read-back, search, organisation of information, auto-population, or other customer-enabled assistance. These features process EMR Data only for the customer-directed purpose described in this Policy and are subject to the applicable customer agreement, DPA or BAA, subprocessor controls, and security requirements. AI-assisted outputs are provisional and require review, correction, and approval by an authorised clinician before they are relied upon for patient care or incorporated into a clinical record.

Authorised User - a person permitted by a Healthcare Customer to access the relevant account, EMR or patient information according to the permissions assigned by that customer.

Beta Environment - any beta, pilot, preview, pre-release, sandbox, demonstration, evaluation, testing, or similar non-production feature, environment, or version of the Services made available by Physitrack for testing, configuration, demonstration, validation, feedback, or evaluation and not expressly approved in writing by Physitrack for production clinical use.

Comply with a legal obligation - means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.

Consumer Health Data - health-related personal data or personal information regulated by a U.S. state consumer health data law where that law applies, including information that may fall outside HIPAA or another healthcare-specific privacy regime.

De-identified / Anonymous Data - information processed so that it is no longer personal data or identifiable health information under the applicable legal standard. Pseudonymized data remains personal data where re-identification remains reasonably plausible.

EMR or Electronic Medical Record - the clinical-record and related patient-management functionality made available through the Services, including any connected workflow or integration identified as part of the EMR offering.

EMR Data - personal data, health information, PHI, personal health information, Special Category Personal Data, sensitive information, consumer health data where applicable, clinical information, and related metadata that a Healthcare Customer, authorised user, patient, authorised representative, or connected system enters, uploads, generates, imports, accesses, stores, transmits, exports, or otherwise processes through the EMR or a connected clinical workflow, including consultation audio, transcripts, AI-assisted draft documentation, intake information, audit records, interoperability records, and record-transfer information where those features are enabled.

Healthcare Customer - a Health Practitioner, clinic, health system, hospital, organisation, public body, health information custodian, trustee, health agency, responsible person, covered entity, business associate, or other customer that uses the Services to process patient or clinical information. Depending on applicable law and the relationship, a Healthcare Customer may act as a controller, covered entity, health information custodian, trustee, health agency, responsible person, organisation, service provider, information manager, or processor.

Health Data - personal data or information relating to an individual’s physical or mental health, healthcare, treatment, condition, diagnosis, disability, clinical measurements or provision of health services, including information treated as health data, health information or PHI under applicable law.

Legitimate Interest - means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

Performance of Contract - means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

Personal Health Information - individually identifiable health information, personal health information, or similar protected health information regulated under Canadian federal, provincial, or territorial privacy or health-information law, or under another applicable jurisdiction’s health-information law.

Production Data - real operational data used or intended for live business, clinical, legal-record, billing, reporting, or other production workflows, including live clinical data and information relating to an actual patient or other identifiable person.

Third Party - means any natural person or legal entity which is not part of the Physitrack group, but which Physitrack has a contractual engagement with for the purposes of receiving services.