Privacy Policy
Last updated: 14 December 2025
1. Introduction
Tim Beames (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://timbeames.com and use our services.
As a healthcare provider registered with the Health and Care Professions Council (HCPC), we are bound by professional standards of confidentiality and data protection.
2. Information We Collect
Personal Information
We may collect the following personal information:
- Name and contact details (email, phone number, address)
- Medical history and health information (with your explicit consent)
- Payment and billing information
- Communication preferences
- Appointment and booking information
Automatically Collected Information
- IP address and device information
- Browser type and version
- Pages visited and time spent on our website
- Referral source
- Cookies and similar tracking technologies
3. How We Use Your Information
We use your information for the following purposes:
- To provide physiotherapy services and healthcare treatment
- To communicate with you about appointments and services
- To process payments and maintain financial records
- To improve our website and services
- To send you relevant health information (with your consent)
- To comply with legal and professional obligations
- To maintain accurate medical records
4. Legal Basis for Processing (GDPR)
Under UK GDPR, we process your personal data based on:
- Consent: For sending marketing communications and using analytics cookies
- Contract: To provide healthcare services you have requested
- Legal Obligation: To comply with healthcare regulations and professional duties
- Vital Interests: To protect your health and wellbeing
- Legitimate Interests: To improve our services and website functionality
5. Data Sharing and Disclosure
We may share your information with:
- Healthcare professionals involved in your care (with your consent)
- Your GP or referring practitioner (with your consent)
- Payment processors for billing purposes
- Legal or regulatory authorities when required by law
- Professional indemnity insurers if necessary
We will never sell your personal information to third parties.
6. Cookies
We use cookies to:
- Enable essential website functionality
- Analyse website traffic and user behaviour (Google Analytics)
- Remember your preferences
You can control cookies through your browser settings. Disabling cookies may affect website functionality.
7. Data Retention
We retain your personal data in accordance with professional guidelines and legal requirements:
- Medical records: Minimum 8 years from last treatment (or until age 25 for children)
- Financial records: 6 years for tax purposes
- Marketing data: Until you withdraw consent or 2 years of inactivity
- Website analytics: 26 months (Google Analytics default)
8. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal obligations)
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for data processing at any time
To exercise any of these rights, please contact us at enquiries@timbeames.com
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- SSL/TLS encryption for data transmission
- Secure storage of medical records
- Access controls and password protection
- Regular security assessments
- Staff training on data protection
10. Third-Party Services
We use the following third-party services:
- Google Analytics: Website analytics (anonymised data)
- Calendly: Appointment booking
- FormSpark: Contact form submissions
- Supabase: Secure database hosting
These services have their own privacy policies and are GDPR compliant.
11. Children's Privacy
For patients under 16, we require parental or guardian consent before collecting or processing personal data.
12. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated revision date.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact:
Tim Beames
Email: enquiries@timbeames.com
14. Complaints
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk