Privacy Policy

The Body Lab 11 Oxford Lane, Ranelagh, Dublin thebodylab.ie

Last updated: 23/07/2026

1. Introduction

The Body Lab ("we", "us", "our", "the Clinic") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website (www.thebodylab.ie), book an appointment, receive treatment at our clinic, or otherwise interact with us — including via our social media accounts.

We process personal data in accordance with:

  • The General Data Protection Regulation (EU) 2016/679 ("GDPR")

  • The Data Protection Act 2018 (Ireland)

  • The ePrivacy Regulations (S.I. No. 336/2011, as amended), governing cookies and electronic communications

  • Relevant health and clinical record-keeping standards applicable to physiotherapy practice in Ireland

Data Controller: The Body Lab, 11 Oxford Lane, Ranelagh, Dublin, Ireland Contact: [info@thebodylab.ie] / [+35312554450]

If you have any questions about this policy or how we handle your data, please contact us using the details above.

2. What Personal Data We Collect

2.1 Data you provide directly

  • Identity data: name, date of birth, gender, PPS number (only if required for insurance/medical claims)

  • Contact data: address, email address, phone number

  • Health data (special category data): medical history, current and past injuries, symptoms, diagnoses, treatment notes, clinical assessments (e.g. SOAP notes), imaging or referral letters you provide, medication information, GP/consultant details, and outcomes of treatment

  • Payment data: billing details, insurance provider details (we do not store full card numbers — these are processed by our payment provider)

  • Appointment data: booking history, attendance, cancellations, communications with clinic staff

  • Emergency contact details, where provided

2.2 Data collected automatically via our website

  • Technical data: IP address, browser type, device type, operating system

  • Usage data: pages visited, time on site, referral source, click behaviour

  • Cookies and tracking technologies: see Section 7 below (Google Tag Manager, Google Analytics 4, and Google Ads conversion tracking)

2.3 Data from third parties

  • Referral letters or clinical information from GPs, consultants, or other healthcare providers (with your consent or as part of your care pathway)

  • Booking and scheduling data via our practice management software (Cliniko)

  • Data from health insurers, where you submit a claim through us

3. Legal Basis for Processing

We rely on the following legal bases under GDPR:

Purpose Legal Basis Providing physiotherapy treatment and clinical care Article 9(2)(h) — provision of health care; Article 6(1)(b) — performance of a contract Maintaining clinical records Article 9(2)(h); legal obligation under professional record-keeping standards Appointment booking and reminders Article 6(1)(b) — contract; Article 6(1)(f) — legitimate interest Billing, insurance claims Article 6(1)(b) — contract; Article 6(1)(c) — legal obligation Marketing communications (email/SMS) Article 6(1)(a) — consent Website analytics and advertising cookies Article 6(1)(a) — consent, obtained via cookie banner Responding to queries Article 6(1)(f) — legitimate interest Complying with tax, insurance, or regulatory obligations Article 6(1)(c) — legal obligation

Health data is "special category data" under Article 9 GDPR and is subject to additional safeguards, including restricted access, encryption where applicable, and processing only by staff directly involved in your care.

4. How We Use Your Data

We use your personal data to:

  • Assess, diagnose, and provide physiotherapy treatment

  • Maintain accurate clinical records as required for continuity of care and professional accountability

  • Schedule, confirm, and remind you of appointments

  • Process payments and insurance claims

  • Communicate with you about your treatment, including follow-ups

  • Send marketing communications, only where you have opted in (you can withdraw consent at any time)

  • Improve our website and services through analytics

  • Comply with legal, tax, and regulatory obligations

  • Respond to queries submitted via our website, phone, or social media

We do not use your health data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Who We Share Your Data With

We do not sell your personal data. We share data only where necessary, including with:

  • Cliniko (our practice management and booking software provider) — acts as a data processor for appointment scheduling, clinical notes storage, and billing

  • Payment processors, for handling transactions

  • Health insurers, where you request a claim be processed through us

  • Referring or treating healthcare professionals (GPs, consultants, other allied health professionals), with your consent, where relevant to your care

  • Google (Google Analytics 4, Google Tag Manager, Google Ads), for website analytics and advertising performance measurement — see Section 7

  • Professional advisors (accountants, solicitors, insurers), where necessary for our legitimate business operations

  • Regulatory or legal authorities, where required by law

Where third-party processors are based outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Data Retention

We retain personal data only as long as necessary for the purposes it was collected:

  • Clinical/health records: retained for a minimum of 8 years from the date of last treatment for adult patients, in line with general clinical record-keeping guidance for healthcare practitioners in Ireland. Records for patients who were minors at the time of treatment are retained until the patient reaches 25 years of age (or 26 if they were 17 at the conclusion of treatment), or 8 years from the date of last contact, whichever is longer.

  • Billing and financial records: retained for 6 years, in line with Irish Revenue requirements.

  • Marketing consent records: retained until consent is withdrawn, plus a reasonable period to evidence compliance.

  • Website analytics data: retained per the retention settings in Google Analytics (typically 14–26 months) unless otherwise configured.

After the applicable retention period, data is securely deleted or anonymised.

7. Cookies and Website Tracking

Our website uses cookies and similar technologies to operate effectively and to understand how visitors use our site.

7.1 Types of cookies used

  • Strictly necessary cookies: required for the website and booking system to function (no consent required)

  • Analytics cookies: Google Analytics 4 (GA4), implemented via Google Tag Manager (GTM), to understand website traffic and user behaviour

  • Advertising cookies: Google Ads conversion tracking, used to measure the effectiveness of our advertising and link bookings made through Cliniko back to ad campaigns

7.2 Consent

Non-essential cookies (analytics and advertising) are only set with your consent, gathered via the cookie banner on our website. You can withdraw or change your consent at any time via the cookie settings link in our website footer, or by adjusting your browser settings.

7.3 Third-party cookie policies

For more information on how Google processes data via GA4, GTM, and Google Ads, see Google's Privacy Policy at policies.google.com/privacy.

8. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you

  • Rectify inaccurate or incomplete data

  • Erasure of your data ("right to be forgotten"), subject to our legal obligation to retain clinical records for the periods set out in Section 6

  • Restrict processing in certain circumstances

  • Data portability, where technically feasible

  • Object to processing based on legitimate interest or for direct marketing purposes

  • Withdraw consent at any time, where processing is based on consent (this does not affect the lawfulness of processing before withdrawal)

  • Lodge a complaint with the Data Protection Commission (DPC), the supervisory authority in Ireland

To exercise any of these rights, contact us at [insert email address]. We will respond within one month, as required by GDPR.

Data Protection Commission (Ireland): 21 Fitzwilliam Square South, Dublin 2, D02 RD28 Website: dataprotection.ie

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Restricted access to clinical records, limited to treating practitioners and authorised administrative staff

  • Secure, password-protected practice management software (Cliniko)

  • Encryption of data in transit and at rest, where supported by our software providers

  • Regular review of access permissions and data-handling procedures

While we take all reasonable steps to protect your data, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children's Data

Where we treat patients under 18, we collect data with the consent of a parent or guardian, who has rights on the child's behalf regarding access, rectification, and erasure until the child reaches an appropriate age of maturity.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact:

The Body Lab 11 Oxford Lane, Ranelagh, Dublin Email: [info@thebodylab.ie] Phone: [+35312554450] Website: thebodylab.ie

Privacy Policy