Privacy Policy
The Body Lab 11 Oxford Lane, Ranelagh, Dublin thebodylab.ie
Last updated: 23/07/2026
1. Introduction
The Body Lab ("we", "us", "our", "the Clinic") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website (www.thebodylab.ie), book an appointment, receive treatment at our clinic, or otherwise interact with us — including via our social media accounts.
We process personal data in accordance with:
The General Data Protection Regulation (EU) 2016/679 ("GDPR")
The Data Protection Act 2018 (Ireland)
The ePrivacy Regulations (S.I. No. 336/2011, as amended), governing cookies and electronic communications
Relevant health and clinical record-keeping standards applicable to physiotherapy practice in Ireland
Data Controller: The Body Lab, 11 Oxford Lane, Ranelagh, Dublin, Ireland Contact: [info@thebodylab.ie] / [+35312554450]
If you have any questions about this policy or how we handle your data, please contact us using the details above.
2. What Personal Data We Collect
2.1 Data you provide directly
Identity data: name, date of birth, gender, PPS number (only if required for insurance/medical claims)
Contact data: address, email address, phone number
Health data (special category data): medical history, current and past injuries, symptoms, diagnoses, treatment notes, clinical assessments (e.g. SOAP notes), imaging or referral letters you provide, medication information, GP/consultant details, and outcomes of treatment
Payment data: billing details, insurance provider details (we do not store full card numbers — these are processed by our payment provider)
Appointment data: booking history, attendance, cancellations, communications with clinic staff
Emergency contact details, where provided
2.2 Data collected automatically via our website
Technical data: IP address, browser type, device type, operating system
Usage data: pages visited, time on site, referral source, click behaviour
Cookies and tracking technologies: see Section 7 below (Google Tag Manager, Google Analytics 4, and Google Ads conversion tracking)
2.3 Data from third parties
Referral letters or clinical information from GPs, consultants, or other healthcare providers (with your consent or as part of your care pathway)
Booking and scheduling data via our practice management software (Cliniko)
Data from health insurers, where you submit a claim through us
3. Legal Basis for Processing
We rely on the following legal bases under GDPR:
Purpose Legal Basis Providing physiotherapy treatment and clinical care Article 9(2)(h) — provision of health care; Article 6(1)(b) — performance of a contract Maintaining clinical records Article 9(2)(h); legal obligation under professional record-keeping standards Appointment booking and reminders Article 6(1)(b) — contract; Article 6(1)(f) — legitimate interest Billing, insurance claims Article 6(1)(b) — contract; Article 6(1)(c) — legal obligation Marketing communications (email/SMS) Article 6(1)(a) — consent Website analytics and advertising cookies Article 6(1)(a) — consent, obtained via cookie banner Responding to queries Article 6(1)(f) — legitimate interest Complying with tax, insurance, or regulatory obligations Article 6(1)(c) — legal obligation
Health data is "special category data" under Article 9 GDPR and is subject to additional safeguards, including restricted access, encryption where applicable, and processing only by staff directly involved in your care.
4. How We Use Your Data
We use your personal data to:
Assess, diagnose, and provide physiotherapy treatment
Maintain accurate clinical records as required for continuity of care and professional accountability
Schedule, confirm, and remind you of appointments
Process payments and insurance claims
Communicate with you about your treatment, including follow-ups
Send marketing communications, only where you have opted in (you can withdraw consent at any time)
Improve our website and services through analytics
Comply with legal, tax, and regulatory obligations
Respond to queries submitted via our website, phone, or social media
We do not use your health data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Who We Share Your Data With
We do not sell your personal data. We share data only where necessary, including with:
Cliniko (our practice management and booking software provider) — acts as a data processor for appointment scheduling, clinical notes storage, and billing
Payment processors, for handling transactions
Health insurers, where you request a claim be processed through us
Referring or treating healthcare professionals (GPs, consultants, other allied health professionals), with your consent, where relevant to your care
Google (Google Analytics 4, Google Tag Manager, Google Ads), for website analytics and advertising performance measurement — see Section 7
Professional advisors (accountants, solicitors, insurers), where necessary for our legitimate business operations
Regulatory or legal authorities, where required by law
Where third-party processors are based outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data Retention
We retain personal data only as long as necessary for the purposes it was collected:
Clinical/health records: retained for a minimum of 8 years from the date of last treatment for adult patients, in line with general clinical record-keeping guidance for healthcare practitioners in Ireland. Records for patients who were minors at the time of treatment are retained until the patient reaches 25 years of age (or 26 if they were 17 at the conclusion of treatment), or 8 years from the date of last contact, whichever is longer.
Billing and financial records: retained for 6 years, in line with Irish Revenue requirements.
Marketing consent records: retained until consent is withdrawn, plus a reasonable period to evidence compliance.
Website analytics data: retained per the retention settings in Google Analytics (typically 14–26 months) unless otherwise configured.
After the applicable retention period, data is securely deleted or anonymised.
7. Cookies and Website Tracking
Our website uses cookies and similar technologies to operate effectively and to understand how visitors use our site.
7.1 Types of cookies used
Strictly necessary cookies: required for the website and booking system to function (no consent required)
Analytics cookies: Google Analytics 4 (GA4), implemented via Google Tag Manager (GTM), to understand website traffic and user behaviour
Advertising cookies: Google Ads conversion tracking, used to measure the effectiveness of our advertising and link bookings made through Cliniko back to ad campaigns
7.2 Consent
Non-essential cookies (analytics and advertising) are only set with your consent, gathered via the cookie banner on our website. You can withdraw or change your consent at any time via the cookie settings link in our website footer, or by adjusting your browser settings.
7.3 Third-party cookie policies
For more information on how Google processes data via GA4, GTM, and Google Ads, see Google's Privacy Policy at policies.google.com/privacy.
8. Your Rights
Under GDPR, you have the right to:
Access the personal data we hold about you
Rectify inaccurate or incomplete data
Erasure of your data ("right to be forgotten"), subject to our legal obligation to retain clinical records for the periods set out in Section 6
Restrict processing in certain circumstances
Data portability, where technically feasible
Object to processing based on legitimate interest or for direct marketing purposes
Withdraw consent at any time, where processing is based on consent (this does not affect the lawfulness of processing before withdrawal)
Lodge a complaint with the Data Protection Commission (DPC), the supervisory authority in Ireland
To exercise any of these rights, contact us at [insert email address]. We will respond within one month, as required by GDPR.
Data Protection Commission (Ireland): 21 Fitzwilliam Square South, Dublin 2, D02 RD28 Website: dataprotection.ie
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
Restricted access to clinical records, limited to treating practitioners and authorised administrative staff
Secure, password-protected practice management software (Cliniko)
Encryption of data in transit and at rest, where supported by our software providers
Regular review of access permissions and data-handling procedures
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children's Data
Where we treat patients under 18, we collect data with the consent of a parent or guardian, who has rights on the child's behalf regarding access, rectification, and erasure until the child reaches an appropriate age of maturity.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact:
The Body Lab 11 Oxford Lane, Ranelagh, Dublin Email: [info@thebodylab.ie] Phone: [+35312554450] Website: thebodylab.ie