Totus Neurorehabilitation Ltd Privacy Policy
The Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR) set out requirements for the use and processing of your data. We are committed to protecting your privacy and handling your information in a responsible way while you use our website and services. Totus Neurorehabilitation Ltd wants you to understand that this is a safe place for you to discuss your feelings and concerns, and we operate in a highly confidential environment. This policy sets out how data is collected and processed through the use of our website and when you use our services. We encourage you to read this policy alongside any other privacy notices we might provide, so you’re fully in the loop about how and why we use your information.
The term ‘beneficiary’ in this document refers to the individual in primary receipt of the service (also termed the patients, or client). This policy applies to the beneficiary using our services; relatives, friends or litigation friends who interact with our services; and third parties (care professionals, Case Managers and Solicitors, and Insurers).
The data controller for Totus Neurorehabilitation Ltd is Dr Emma Hale.
For all queries relating to Data Protection please contact Totus Neurorehabilitation Ltd on info@totusrehab.co.uk or call 07868 505269. You also have the right to talk to the Information Commissioner’s Office (ICO) at (www.ico.gov.org.uk), but we hope to resolve any issues directly.
Lawful Processing of data
Totus Neurorehabilitation Ltd is registered with the Information Commissioners Office (ICO) to hold data relevant to the service we provide. Personal data is held under UK GDPR for the following reasons:
- Contract – the processing of your data is necessary to fulfil therapy services offered.
- Legal Obligation – the processing of your data is necessary to meet the legal obligations related to your compensation claim.
- Legitimate Interest – for example direct marketing, preventing fraud, securing systems, and administrative transfers between companies.
To provide you with appropriate healthcare or social care services, we may need to process “Special Category Data” (specifically, information concerning your health). Our legal basis for processing this data under the UK GDPR and the Data Protection Act 2018 is Article 9(2)(h), which applies when processing is necessary for:
- Medical diagnosis;
- The provision of health or social care or treatment; or
- The management of health or social care systems and services.
Consents for Health Data: We require specific consent to process Special Category Data which is included on the Therapy Policy & Consents form completed by the beneficiary.
We use data to plan and implement the service, and to improve service delivery and effectiveness. We use data to support compliance with all regulatory requirements. We use personal data to maintain staff and beneficiary safety. We use data for marketing and promotion of Totus Neurorehabilitation Ltd.
We are not involved in the large-scale processing of personal data. Personal data is used only to provide a dedicated service.
Data that we collect
Where we are requested to provide a service to the beneficiary we may collect and process the following information about the beneficiary and (with their consent) significant others such as relatives, friends or litigation friends.
‘Personal data’ is information that identifies the individual. If we’ve removed your identity (by making the data anonymous), it won’t be classed as personal data. We might collect, use, store, and share various types of personal data as follows:
- Identity details such as first and last name, username or similar identifier, marital status and title, date of birth and gender.
- Contact details such as your billing address (of the applicable fee payer) and delivery address, email address and telephone number.
- Technical information such as your internet protocol (IP address), your login data, browser type, version, browser plug-in types and versions, time zone setting and location, operating system and platform and other technology on the devices you use to access our website.
- Information about transactions like details about payments to and from you, and other details of products and services you have purchased from us.
- Account details such as your username, password, purchases or orders made by you, and your interests, preferences, feedback and survey responses.
- Usage information about how you use our website, products and services.
- Marketing information such as your preferences on receiving marketing from both us and third-parties, along with your communication preferences.
Special Category Data
This includes information about the beneficiary’s health, including NHS number, hospital number, GP details, medical records and medico-legal documents containing information about existing and previous medical health conditions, medication details, psychiatric history and any other relevant health information to enable us to carry out our services.
During the provision of services we may also collect protected category data (race and ethnic origin, religious and philosophical beliefs, health, sexual orientation, political opinions, sex life) as well as information regarding criminal convictions.
Third Parties
We will collect and process details of third parties involved in the beneficiary’s care (for example family members, Case Managers, Insurer, Solicitor, Case Manager, other health care professionals) including:
- Full Name
- Profession
- Work address
- Work telephone number
- Financial details
- Contracts relevant to the service offered
We may collect video footage and photographs for clinical purposes; however, these will be collected following signed consent from the beneficiary.
If special category data is collected about a third party (for example a relative engages in their own therapy sessions creating their own health record) their individual consent will be gained for the processing of special category data.
By providing personal information relating to the beneficiary directly to Totus Neurorehabilitation Ltd, you are agreeing to the processing of that information for the purposes for which it was given.
How do we collect personal data?
We use different methods to collect data. The majority of the time, our information is collected directly in the following ways:
- On completion of any new client onboarding forms, including our Therapy Policy & Consents document.
- On completion of any forms before or during an appointment
- Verbally during discussions
- Correspondence with us via post, phone, email or otherwise
- When enquiring about or applying for our services
Another method we may use to collect data includes the use of automated technologies or interactions, like website cookies or other similar technologies. This includes information about equipment, browsing actions and patterns and information about browsing activity on visiting another website that uses the same cookies as us. This means we receive information about how you use these third-party websites.
This data collection helps us to improve user experience, and to gather information about how you use our website. For more information, please refer to our Cookie Policy, which can be accessed via our website.
We may also receive data from third-parties such as:
- Technical information from Analytics providers (our sub processors are listed below)
- Advertising networks such as LinkedIn
- Search information providers such as Google
- Publicly available sources, such as Companies House and company websites
Failure to provide the required data
Where we need to collect personal data by law, or under the terms of our contract, and the data is not provided when requested, we may not be able to perform the contract we have or are trying to enter into (for example, to provide services). In this case, we may have to cancel a service. We will provide notification if this is the case.
Purposes for which we use personal data
The purposes for which we will be using your data include:
- To register a new client.
- To provide our services and to process and deliver any orders, including: a) to manage payments, fees and charges and b) to collect and recover money owed to us.
- To manage our relationship with all parties e.g., to notify about changes to our terms of this privacy policy or to ask individuals to leave a review and/or take a survey.
- To send relevant marketing information about our products and services.
- To administer and protect our practice and website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
- To deliver relevant website content and advertisements and to measure or understand the effectiveness of our advertising.
- To use data analytics to improve our website, products/services, marketing, client relationships and experiences.
- To make suggestions and recommendations about goods or services that may be of interest.
Sharing of the data we collect
We take data security seriously and only allow certain people to access it. We may share personal data with the parties set out below for the purposes as stated above.
- Service providers, acting as processors who provide IT and system administration services.
- Professional advisers including healthcare professionals, lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
- If referred by a third party (health insurance provider, case manager etc) then we may need to share details about the beneficiary’s appointment schedule with the referrer for the purposes of billing and to provide treatment updates.
- As HCPC accredited clinicians, we are obliged to consult with other mental health professionals for supervision purposes. This is to ensure we reflect and improve on our clinical skills. When discussing beneficiaries in supervision we only refer by their first name and identifiable information is minimised. Supervisors are bound by the same GDPR regulations.
- Sometimes we may need to share details with the beneficiary’s GP or a social worker. We will always get consent prior to doing this. When the information concerns risk of harm to the beneficiary or another person then we may need to disclose information about without the beneficiary’s consent for their own safety or for the safety of someone else.
- HM Revenue & Customs, regulators and other authorities who require reporting of processing activities in certain circumstances.
- Debt collection agencies in the event that payment is not received for services rendered. This will be done to recover any outstanding debts, and the debt collectors will process your data solely for this purpose.
- We may need to share personal data with courts, legal representatives, or other relevant authorities for medico-legal purposes. This includes situations where we are required to do so by law, or where it is necessary to protect the beneficiary’s vital interests or the interests of another person. We ensure that this data sharing is conducted lawfully and with due regard for privacy rights.
All of the above third parties have a requirement to respect the security of personal data. We do not permit them to use personal data for their own purposes – they are only permitted to process data for specified purposes in line with our instructions.
We do not sell data to other recipients.
We may transfer your data outside of the United Kingdom/EEA, but only when we can be sure it is protected.
Many of our external third parties are based outside the United Kingdom/EEA and so their processing of your personal data will involve a transfer of data outside the United Kingdom.
Whenever we transfer your personal data out of the United Kingdom, we make sure it is protected by at least implementing one of the following safeguards:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the United Kingdom
- Where we use certain service providers, we may use specific contracts approved by the UK Information Commissioner’s Office and the European Commission which give personal data the same protection it has in Europe.
Sub-processors
We are required to inform you of sub-processors that we use in the processing and storage of your data. The sub-processors we use and location of their privacy policies are:
- Microsoft – http://www.privacy.microsoft.com/en-GB/privacystatement
- Google mail and G-Suite – https://safety.google/privacy
- Xero – Http://xero.com/uk/about/legal/privacy/
- Zoom – https://zoom.us/privacy
- Qunote – www.qunote.com/privacy-policy/
- WhatsApp – https://www.whatsapp.com/legal/privacy-policy
- SignRequest – https://signrequest.com/en/privacy-notice
- Kaseya – https://www.kaseya.com/legal/kaseya-privacy-statement/
AI Usage
Artificial Intelligence (AI): AI refers to the use of computer systems, software, or applications that are designed to perform tasks that would normally require human intelligence. This includes, but is not limited to, capabilities such as learning, reasoning, problem-solving, perception, language understanding, and interaction.
We may use AI tools to assist with the provision of our services, including ChatGPT and note taking software. Any AI tools we employ are used in compliance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR).
When using AI tools, we ensure:
- Personal data is processed lawfully, fairly, and transparently.
- Data minimisation principles are upheld, meaning we only provide AI tools with the information strictly necessary for the intended purpose.
- Robust security measures are in place to protect your personal data during any processing involving AI tools.
- When using AI tools, we ensure that personal data is retained only for as long as necessary to fulfil the purposes outlined in our policy, after which it is securely deleted or anonymised.
We have listed below the specific AI tools we are using within our business, the purpose, the types of data we are collecting and our legal basis for this processing.
| AI Tool Name | Purpose | Types of Data Used | Legal Basis for Processing |
| Heidi | Note taking tool, preparing transcriptions of meetings or therapy sessions. | Meeting notes, audio recordings, therapy notes, health data | Explicit Consent |
| ChatGPT | Assists with preparation of goal forms, and information sheets, and produces visual images and materials for use in therapy. | Anonymous Goal data and generic clinical information. Business data. | Legitimate interest |
| Google Gemini | Assists with structure and grammar in emails and documents written and held in GSuite. Assists with preparation of goal forms, and information sheets, and produces visual images and materials for use in therapy. | Written documents including emails. Anonymous Goal data and generic clinical information. Business data. | Legitimate interest |
| Google Gemini | Summarises video meetings and provides meeting notes | Audio data from video meetings | Explicit consent |
| Microsoft co-pilot | Enhance business productivity within the Microsoft 365. Helps users with tasks such as writing, summarising, and analsing data. A chat interface, called Copilot Chat, provides information based on the user’s work context and the web. | Writing and summarising documents and analysing data. Integrates with web based information. | Legitimate interest |
| Adobe AI Assistant | Generates summaries, answers questions, and assists understanding of data. It can also be used to create content, generate insights, and optimise projects. | Written documents including emails | Explicit consent |
| Zoom AI | Meeting assistance, summarisation and recording. Content generation, summarisation of calls, messages and chat, whiteboard. | Recordings, verbal, and written communications. | Explicit consent |
| Claude AI | Assists with preparation of goal forms, and information sheets, and produces visual images and materials for use in therapy. Used for business documents. | Anonymous Goal data and generic clinical information. Business data. | Legitimate interest |
For further enquiries on our AI usage or to exercise your rights, please contact us using the details provided in this policy.
Retention Period
We only keep data as long as necessary for the reasons we collected it.
By law we have to keep medical information about patients for 7 years after treatment has finished. We are obliged to keep cognitive assessment data for 20 years. For any children we treat, we are obliged to retain the medical information until the child’s 25th birthday. By law we have to keep basic information about our clients (including contact, identity, financial and transaction data) for 6 years after they cease being clients for tax purposes.
For information that does not fall under the definition of basic, to determine the appropriate retention time, we look at what kind of data it is, how sensitive it is, the risks if it is misused, why we need it, and if there are other ways to achieve the same goals. We also consider applicable legal, regulatory, tax, accounting and other requirements.
Discovery Calls
Where we conduct a discovery call or initial consultation with a prospective client, the following retention periods apply:
- Where no clinical judgement was formed: If the call was exploratory in nature and we collected only basic contact details (such as your name, email address and telephone number), and you do not proceed as a client, we will securely delete that information within one month of the call. This aligns with the storage limitation principle under UK GDPR.
- Where a clinical judgement or risk-related decision was made: If, during the discovery call, we formed any clinical assessment of suitability, noted a safeguarding concern, or made any risk-related decision, we will retain a brief record of that call even if you do not proceed as a client. This is consistent with good clinical governance and is supported by UK GDPR’s provisions for processing in the context of health-related data and legal claims. In such cases, retention periods will follow applicable professional body guidance – 7 years for adults from the date of the call, and until the individual’s 25th birthday where the prospective client was a child at the time of the call.
Children’s Information and Consent
We work with children and young people of different ages, and the rules about consent vary depending on age and circumstances.
Age and Consent
- Under 13: We always require consent from a parent or person with parental responsibility.
- Ages 13-15: We usually require parental consent, though young people may be able to consent themselves if they fully understand the implications (assessed case-by-case).
- Ages 16-17: Young people can generally consent to processing of their health data themselves, though we may involve parents/carers with the young person’s agreement.
- Age 18+: Adults provide consent themselves. We will not share information with parents without explicit consent (except in safeguarding situations).
Verifying Parental Authority
We verify parental authority by:
- Requesting confirmation of relationship to the child
- Checking parental responsibility (we may request documentation such as court orders if parents are separated)
- Confirming with schools or referring professionals where appropriate
If you are a parent, guardian, or educator and have questions about how we handle children’s data, just email us at info@totusrehab.co.uk.
When Young People Turn 16 or 18
When a young person turns 16, they gain the right to consent to health data processing. When they turn 18, they have full control over their information. For ongoing cases, we will discuss how to manage consent and communication going forward.
Separated Parents
If parents are separated, both parents with parental responsibility generally have equal rights to information about their child, unless court orders specify otherwise. Please inform us of any relevant arrangements or restrictions.
Website use
We are committed to safeguarding the privacy of our website visitors.
By visiting the website and submitting information on the contact form the user agrees that we can use their personal data as described in the privacy policy. When contacting us through the contact form we collect the individual’s name, email address, telephone number and any additional information provided.
Our website may include links to third party services and websites. This privacy policy does not extend to third party services or websites. We cannot be responsible for the privacy policies and practices of the owners or operators of any third party site and recommend that you view the privacy policy for each site you visit.
Cookies
Cookies are small files transferred to your computer’s hard drive through your web browser. They are used to make websites work more efficiently, and provide information to the owners of the site.
Our website uses cookies to provide users with the most relevant and useful information about our services and to help our website run effectively. For more information about cookies we use, please read our cookie policy.
Data Processing Safeguards
In line with UK GDPR the Totus Neurorehabilitation Ltd Data Protection Policy is available on request. This details our process in the event of a data breach. Our data protection risk assessment is reviewed yearly. All Associate therapists must be registered with the Information Commissioners Office and are expected to abide by UK GDPR. We only use software from accredited sources.
Right to Access, Erasure, Correction and Transfer
You have the following rights regarding your personal data:
- Access: You can request a copy of the personal data we hold about you. This is known as a “data subject access request.” As health professionals we hold the right to withhold access if we believe that access would cause harm. In such circumstances we would make reasonable effort to discuss this with the individual and approach the request within a best interests framework.
- Correction: If the personal data we have about you is incomplete or incorrect, you can ask us to correct it.
- Erasure: You can ask us to delete your personal data. It’s important to note, however, that there might be legal reasons that prevent us from fulfilling this request, particularly in relation to health care records. Such requests will be managed on a case-by-case basis.
- Objection: In certain situations, you have the right to object to the processing of your personal data.
- Restriction of Processing: You can request that we restrict the processing of your personal data under specific circumstances.
- Data Portability: You have the right to request the transfer of your personal data directly to you or to a third party of your choice.
- Withdrawal of Consent: At any point where we rely on your consent to process your personal data, you have the right to withdraw this consent. Withdrawal of consent will not affect the legality of the processing done before the consent was withdrawn. Should you withdraw your consent, we might be unable to provide you with certain products or services. We will inform you if that is the case when you withdraw your consent.
If you wish to exercise any of the rights set out above, please contact us on info@totusrehab.co.uk
We will not charge any fees for a request access personal data. However, a reasonable fee may be charged if the request is clearly unjustified, repetitive or excessive. We also reserve the right to not comply in this scenario. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if the request is particularly complex or involves multiple requests.
Our privacy policy is reviewed periodically. Please check back regularly to view our latest version.
May 2026