Privacy Policy

Last updated: 14 December 2025

1. Introduction

Tim Beames (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://timbeames.com and use our services.

As a healthcare provider registered with the Health and Care Professions Council (HCPC), we are bound by professional standards of confidentiality and data protection.

2. Information We Collect

Personal Information

We may collect the following personal information:

  • Name and contact details (email, phone number, address)
  • Medical history and health information (with your explicit consent)
  • Payment and billing information
  • Communication preferences
  • Appointment and booking information

Automatically Collected Information

  • IP address and device information
  • Browser type and version
  • Pages visited and time spent on our website
  • Referral source
  • Cookies and similar tracking technologies

3. How We Use Your Information

We use your information for the following purposes:

  • To provide physiotherapy services and healthcare treatment
  • To communicate with you about appointments and services
  • To process payments and maintain financial records
  • To improve our website and services
  • To send you relevant health information (with your consent)
  • To comply with legal and professional obligations
  • To maintain accurate medical records

4. Legal Basis for Processing (GDPR)

Under UK GDPR, we process your personal data based on:

  • Consent: For sending marketing communications and using analytics cookies
  • Contract: To provide healthcare services you have requested
  • Legal Obligation: To comply with healthcare regulations and professional duties
  • Vital Interests: To protect your health and wellbeing
  • Legitimate Interests: To improve our services and website functionality

5. Data Sharing and Disclosure

We may share your information with:

  • Healthcare professionals involved in your care (with your consent)
  • Your GP or referring practitioner (with your consent)
  • Payment processors for billing purposes
  • Legal or regulatory authorities when required by law
  • Professional indemnity insurers if necessary

We will never sell your personal information to third parties.

6. Cookies

We use cookies to:

  • Enable essential website functionality
  • Analyse website traffic and user behaviour (Google Analytics)
  • Remember your preferences

You can control cookies through your browser settings. Disabling cookies may affect website functionality.

7. Data Retention

We retain your personal data in accordance with professional guidelines and legal requirements:

  • Medical records: Minimum 8 years from last treatment (or until age 25 for children)
  • Financial records: 6 years for tax purposes
  • Marketing data: Until you withdraw consent or 2 years of inactivity
  • Website analytics: 26 months (Google Analytics default)

8. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data (subject to legal obligations)
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured format
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for data processing at any time

To exercise any of these rights, please contact us at enquiries@timbeames.com

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • SSL/TLS encryption for data transmission
  • Secure storage of medical records
  • Access controls and password protection
  • Regular security assessments
  • Staff training on data protection

10. Third-Party Services

We use the following third-party services:

  • Google Analytics: Website analytics (anonymised data)
  • Calendly: Appointment booking
  • FormSpark: Contact form submissions
  • Supabase: Secure database hosting

These services have their own privacy policies and are GDPR compliant.

11. Children's Privacy

For patients under 16, we require parental or guardian consent before collecting or processing personal data.

12. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated revision date.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact:

Tim Beames
Email: enquiries@timbeames.com

14. Complaints

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk

Book Free Call