Privacy Policy
Please read the following important “Privacy Policy” before you apply to subscribe to the Physiopedia Plus Services.
1. Who we are
1.1. We are Physiopedia International SL (“we”, “us”, “our”, “PISL”), a company registered in Andorra under company number 933846H with our registered office at CTRA. Del Prats Sobrians 003 14, Edifici Prats Sobrians Bloc A Escala A, Arinsal, AD400 La Massana, Andorra.
1.2. We operate the Physiopedia Plus platform at members.physio-pedia.com, providing online continuing professional development (CPD), AI-assisted learning tools, and telehealth solutions (together, the Plus Services) to physiotherapy and rehabilitation professionals worldwide.
1.3. You can contact us about data protection matters at: [email protected]
1.4. Given the nature and scale of our processing activities, we are not required to appoint a Data Protection Officer under applicable data protection law. For any data protection queries, please use the contact details above or reach out to our regional representative in your jurisdiction (see Section 2).
2. Our data protection representatives
2.1. As an Andorran-registered company offering services to individuals worldwide, we have appointed data protection representatives in the following jurisdictions:
2.1.1. UK Representative (UK GDPR, Article 27): GDPRLocal Ltd, Adam Brogden, 1st Floor Front Suite, 27-29 North Street, Brighton, England BN1 1EB (Privacy requests: https://physiopedia-international-sl.gdprlocal.com/uk)
2.1.2. EU Representative (EU GDPR, Article 27): Instant EU GDPR Representative Ltd, Adam Brogden, Office 2, 12A Lower Main Street, Lucan, Co. Dublin K78 X5P8, Ireland (Privacy requests: https://physiopedia-international-sl.gdprlocal.com/eu)
2.1.3. Swiss Representative (Swiss FADP, Article 14): GDPRLocal Ltd, Adam Brogden, Via Luigi Lavizzari 4, 6850 Mendrisio, Switzerland (Privacy requests: https://physiopedia-international-sl.gdprlocal.com/swiss)
2.2. You may contact any of these representatives to exercise your data protection rights in your jurisdiction.
3. Scope and applicable law
3.1. This privacy policy is drafted to comply with UK GDPR and the Data Protection Act 2018 as our baseline framework. It is intended to meet the standards required under EU GDPR (Regulation (EU) 2016/679), the Swiss Federal Act on Data Protection (FADP, SR 235.1), and the Andorran Law on the Protection of Personal Data (LQPD, Law 29/2021), which share the same core principles. We consider compliance with these frameworks to represent a high standard of data protection that we apply to all users regardless of location.
3.2. We serve our community of users on a global basis. This privacy policy reflects our obligations under the frameworks listed above and will be updated if our obligations materially change.
3.3. Our United States-based users should be aware that our processing is governed primarily by the data protection frameworks described above. However, if you are located in the United States, additional rights may apply to you depending on your state of residence. We do not sell your personal data. See Section 13 for further information.
3.4. Specifically, regarding the US Health Insurance Portability and Accountability Act (HIPAA), we are not a covered entity or business associate and we do not process patient protected health information. This means that HIPAA’s privacy and security requirements do not apply to our platform, and you should not submit any patient health information to us. See Section 4.11 for details of our telehealth integration.
4. The data we collect and why
4.1. Account registration and management
4.1.1. We collect: full name, email address, password (stored in hashed form), country, and IP address. Users may also voluntarily provide professional credentials, licence/registration details, and details of their governing professional body at onboarding or at any time via their profile. This information is not required to access the platform.
4.1.2. Why: To create and manage your subscription account, verify your professional status, authenticate your access, and provide the Plus Services.
4.1.3. Legal basis: We process this data on the basis that it is necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR). Processing your registration data is necessary for us to perform our obligations under that contract — without this information, we cannot create your account, authenticate your access, or deliver the Plus Services to you.
4.1.4. Professional registration and licence numbers: These numbers are not treated as health data. This information is not required — users may add it voluntarily to their profile. Where provided, it is used to ensure the correct CPD or CEU (Continuing Education Unit) credits appear on certificates and, where applicable, to fulfil accreditation reporting obligations to relevant professional bodies (see Section 4.7).
4.2. CPD and learning records
4.2.1. We collect: course completion records, assessment results, CPD/CEU credits earned, learning log entries, certificate data, and professional jurisdiction.
4.2.2. Why: To provide your personalised CPD portfolio (ePortfolio), generate certificates, and maintain verifiable records of your professional development. These records have ongoing significance for professional regulatory compliance in many jurisdictions.
4.2.3. Legal basis: We process this data on the basis that it is necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR). We also rely on our legitimate interests in maintaining verifiable CPD records for your benefit (Article 6(1)(f), UK GDPR) — this supports your ongoing professional regulatory compliance and allows you to demonstrate your professional development to regulators, employers, or professional bodies.
4.2.4. Retention: We retain CPD records indefinitely unless you request deletion. This is so that you can access your records at any point in the future, should you need to demonstrate professional compliance to regulators, employers, or professional bodies. You have the right to request erasure at any time.
4.3. Payment processing
4.3.1. We collect: name, email address, billing address, and transaction confirmation details.
4.3.2. Why: To process your subscription payment and maintain financial records as required by law.
4.3.3. Legal basis: We process this data on the basis that it is necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR). We also process this data to comply with our legal obligations for financial record-keeping (Article 6(1)(c), UK GDPR).
4.3.4. Retention: Payments are processed by Stripe and PayPal. Card details are collected directly by these processors and are never stored on our systems. We retain transaction records for 7 years from the transaction date in accordance with standard financial record-keeping obligations.
4.4. Email communications
4.4.1. We collect: name, email address, and email engagement data (open rates, click rates).
4.4.2. Why: To send you service communications, course announcements, newsletters, and promotional content where you have opted in.
4.4.3. Legal basis: We send marketing communications on the basis of your consent (Article 6(1)(a), UK GDPR) — you may withdraw this consent at any time. We also rely on our legitimate interests (Article 6(1)(f), UK GDPR) for essential service communications to active members, as these are necessary to keep you informed about your subscription and the Plus Services.
4.4.4. Withdrawal of consent: You can withdraw consent and unsubscribe at any time via the unsubscribe link in any email. Service communications related to your subscription may continue as necessary for contractual reasons.
4.5. PAI (Physiopedia AI Assistant)
4.5.1. We collect: queries submitted to PAI (clinical and professional questions), session data, account identifier, and IP address.
4.5.2. Why: To provide AI-assisted physiotherapy knowledge and learning support, and to improve the service.
4.5.3. Legal basis: We process this data on the basis that it is necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR). We also rely on our legitimate interests in improving the PAI service (Article 6(1)(f), UK GDPR) — this enables us to enhance the quality and accuracy of the AI-assisted learning support we provide.
4.5.4. Controls: Our platform incorporates technical controls at the prompt level that actively prevent users from submitting personally identifiable patient information (PII). As a result, clinical queries are professional in nature and are not linked to identifiable individuals. Our Terms and Conditions also explicitly prohibit users from submitting patient PII through PAI.
4.5.5. Third party AI systems: PAI is powered by Anthropic PBC, a US-based AI provider operating under a Data Processing Agreement with us (governed by Irish law). Data may be transferred internationally under appropriate safeguards, including Standard Contractual Clauses. We use your PAI queries only to provide and improve the service — your queries are not shared with our AI provider for the purpose of training its models unless we notify you otherwise. PAI query logs are retained until you delete them; retention is user-controlled.
4.6. Institutional accounts
4.6.1. We collect: institutional contact details (name, email, job title, organisation) and, for individual users accessing via institutional subscription, data as described in Section 4.1 above.
4.6.2. Why: To manage institutional subscriptions, provide access to employees and students, and report engagement data back to the subscribing institution.
4.6.3. Legal basis: We process institutional contact data on the basis that it is necessary for the performance of the subscription contract with the institution (Article 6(1)(b), UK GDPR). We also rely on our legitimate interests in engagement reporting and relationship management (Article 6(1)(f), UK GDPR) — this enables us to provide institutions with usage insights and to maintain effective ongoing relationships with our institutional partners.
4.6.4. Reports: Institutions receive engagement reports only in respect of their own users. We retain institutional contact records indefinitely to support ongoing account management, renewal negotiations, and dispute resolution. Individual user data is retained as described in Section 4.1 above.
4.7. Professional accrediting body reporting
4.7.1. We collect: name, email, professional registration/licence number, course completion data, CPD points, and jurisdiction-specific fields required by professional accrediting bodies.
4.7.2. Why: To report your CPD and CEU credits and course completions to professional accrediting bodies on your behalf, where applicable to your jurisdiction and professional body membership.
4.7.3. Legal basis: We report your accreditation data on the basis of legitimate interests (Article 6(1)(f), UK GDPR). Accreditation reporting is a core service feature that enables you to demonstrate professional compliance to regulators and employers. You may object to accreditation reporting at any time by contacting us at [email protected], though this may affect your ability to use accreditation-dependent features of the platform.
4.7.4. Reporting: We currently report to:
(a) HPCSA (Health Professions Council of South Africa): applies to South African members only; and
(b) CE Broker (United States): applies to US members only.
Data transferred to HPCSA relates exclusively to members who are residents of South Africa, and data transferred to CE Broker relates exclusively to members who are residents of the United States. These transfers do not involve personal data of individuals located in the EU, UK, or Switzerland, and accordingly fall outside the scope of the EU GDPR, UK GDPR, and Swiss FADP transfer restrictions.
4.8. Website analytics
4.8.1. We collect: IP address (anonymised), browser type, pages visited, time on site, referral source, and device data.
4.8.2. Why: To analyse site usage and improve platform performance and user experience.
4.8.3. Legal basis: We deploy non-essential analytics cookies on the basis of your consent (Article 6(1)(a), UK GDPR). We also rely on our legitimate interests for essential analytics (Article 6(1)(f), UK GDPR) — this enables us to understand how the platform is used and to improve its performance and user experience.
4.8.4. Third party analytics: We use Google Analytics 4 (GA4). IP addresses are automatically anonymised by default in GA4. Event data is retained for 2 months; user data for 14 months. Google LLC is self-certified under the EU-US Data Privacy Framework. Data is transferred to the US in reliance on Google’s DPF certification and, as a secondary safeguard, Standard Contractual Clauses incorporated in Google’s Data Processing Agreement (DPA).
4.8.5. Consent preferences: You can update your cookie consent preferences at any time via the Cookie Settings link in the footer of our website.
4.9. Customer support
4.9.1. We collect: name, email, account details, and the content of your support communications.
4.9.2. Why: To respond to your enquiries, complaints, and technical support requests.
4.9.3. Legal basis: We process your support communications on the basis of our legitimate interests in responding to your enquiries and maintaining service quality (Article 6(1)(f), UK GDPR). We also process this data where necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR).
4.9.4. Retention: Support communications are retained in Google Workspace indefinitely. Contact form submissions are deleted from our systems after 2 years. Support queries from physiotherapists and other health workers regarding clinical topics are professional in nature and do not constitute health data about the enquirer.
4.10. Instructor and contractor data
4.10.1. We collect: name, address, email, bank and payment details, professional credentials, contract data, tax information, and course royalty records.
4.10.2. Why: To manage course instructor relationships, administer royalty payments, execute contracts via DocuSign, and maintain IP assignment records.
4.10.3. Legal basis: We process instructor and contractor data on the basis that it is necessary for the performance of the contracts we enter into with them (Article 6(1)(b), UK GDPR). We also process this data to comply with our legal obligations for financial and tax record-keeping (Article 6(1)(c), UK GDPR).
4.10.4. Retention: We retain instructor and contractor records indefinitely. This is necessary to maintain defensible records of IP assignments, royalty calculations, and contract terms, and to meet financial record-keeping obligations. The right to erasure applies except where continued retention is required by law.
4.11. Telehealth services (PRO Members)
4.11.1. What we collect and why: For PRO-level members accessing the RehabMyPatient integration, we pass your name, email address, account identifier, and subscription status to RehabMyPatient solely to enable access.
4.11.2. Legal basis: We process your account data for the RehabMyPatient integration on the basis that it is necessary for the performance of the subscription contract you enter into with us (Article 6(1)(b), UK GDPR).
4.11.3. Patient data: No patient personally identifiable information (PII) or protected health information (PHI) is passed to or processed by us under this integration. “PHI” is a US term under HIPAA referring to individually identifiable health information — we include it here because some PRO members may be US-based healthcare providers. Patient data is entered by members directly into RehabMyPatient’s own platform and remains entirely within RehabMyPatient’s systems. Our Terms and Conditions explicitly prohibit users from submitting PII or PHI to our platform. We have confirmed this data segregation in writing with RehabMyPatient.
5. Special category data
5.1. We do not intentionally collect special category data (such as health data, biometric data, or data revealing racial or ethnic origin) about our users.
5.2. Professional registration and licence numbers are not considered special category data.
5.3. Clinical queries submitted to PAI may relate to patients, but our system is designed to prevent submission of PII, and our Terms and Conditions prohibit it. On this basis, we do not process special category data about third parties through PAI.
6. Who we share your data with
6.1. We share personal data only where necessary and with appropriate safeguards in place.
6.2. Our key processors and recipients are:
| Category | Processor / Recipient | Details |
| Infrastructure and Hosting | Kinsta | Hosting and storage, servers in Netherlands, EU |
| Payment Processing | Physiopedia Plus Ltd | UK company; acts as payment processor on behalf of PISL under a Data Processing Agreement (Stripe and PayPal act as sub-processors) |
| Payment Processing | Stripe | US-based sub-processor; DPF-certified; collects payment and billing details directly from customers; SCCs in place as secondary safeguard |
| Payment Processing | PayPal | US-based sub-processor; DPF-certified; collects payment and billing details directly from customers; SCCs in place as secondary safeguard |
| AI Services | Anthropic PBC | US-based; processes PAI query data under a Data Processing Agreement; SCCs in place; governed by Irish law |
| CRM | Pipedrive | EU entity based in Estonia; data hosted on AWS (Amazon Web Services) EU servers; DPA in place; SCCs cover UK and Swiss transfers |
| Sendy | Self-hosted by us on Kinsta, Netherlands — no third-party transfer | |
| Contract Execution | DocuSign | US-based; DPF-certified; SCCs in place as secondary safeguard |
| Accounting | Xero | Australia-based (no adequacy decision); SCCs in place for international transfers |
| Analytics | Google Analytics / Google LLC | US-based; DPF-certified; SCCs in place as secondary safeguard |
| Communications | Google Workspace | US-based; DPF-certified; SCCs in place as secondary safeguard |
| Accreditation Bodies | HPCSA; CE Broker Inc. | HPCSA (South Africa) — South African members only; CE Broker (US) — US members only |
| Telehealth | RehabMyPatient | UK-based; PRO members only; account identifier and subscription status only |
| Support Forms | Ninja Forms | Contact/support form submissions; stored on Kinsta, Netherlands — no third-party transfer |
| Institutions | Subscribing institutions | Receive engagement reports on their own users only |
6.3. We do not sell your personal data to any third party. We do not share your data with advertisers.
7. International transfers
7.1. We are based in Andorra and our users are located worldwide. Personal data may be transferred outside your country of residence.
7.2. Where we transfer personal data to countries without an adequacy arrangement, we rely on one or more of the following safeguards: (a) the EU-US Data Privacy Framework (DPF), including its UK Extension, where the recipient is a US-based organisation that has self-certified under the DPF; (b) Standard Contractual Clauses (SCCs) approved by the European Commission and, for transfers from Switzerland, SCCs incorporating the Swiss Federal Data Protection and Information Commissioner’s approved annexes; or (c) other appropriate safeguards recognised under applicable data protection law (such as binding corporate rules or an applicable derogation). We have conducted Transfer Impact Assessments for transfers to jurisdictions without an adequacy arrangement and, where required, have implemented supplementary technical and organisational measures to ensure an essentially equivalent level of protection. Copies of relevant SCCs, DPAs, or other transfer documentation are available on request.
7.3. Specific transfer arrangements are described for each processing activity in Section 4.
7.4. Andorra benefits from adequacy decisions under both the EU GDPR and the UK GDPR, and is treated as adequate for transfers from Switzerland. As we are established in Andorra, your personal data is processed in (and therefore transferred to) Andorra in reliance on these adequacy decisions.
7.5. Where we rely on the EU-US Data Privacy Framework (including its UK Extension), we have verified that the relevant US-based processors are listed on the US Department of Commerce’s Data Privacy Framework List. Where we rely on Standard Contractual Clauses for transfers from Switzerland, those clauses incorporate the annexes approved by the Swiss Federal Data Protection and Information Commissioner.
8. How long we keep your data
8.1. Retention periods for each category of data are described in Section 4. In summary:
| Data Category | Retention Period |
| Account data | Indefinitely unless you request deletion |
| CPD and learning records | Indefinitely unless you request deletion |
| Payment records | 7 years from transaction date |
| PAI query logs | Until you delete them (user-controlled) |
| Email marketing | Until consent withdrawn or account closed (unsubscribe suppression list retained indefinitely) |
| Support communications | Indefinitely (Google Workspace); 2 years (contact forms) |
| Instructor/contractor records | Indefinitely |
| Analytics | Event data: 2 months; user data: 14 months |
8.2. Where we retain data indefinitely, this is on the basis of legitimate interests and is reviewed annually. You retain the right to request erasure at any time (see Section 9).
9. Your rights
9.1. Depending on your location, you may have some or all of the following rights in relation to your personal data:
| Right | Description |
| Right of access | To obtain a copy of the personal data we hold about you |
| Right to rectification | To request correction of inaccurate or incomplete data |
| Right to erasure | To request deletion of your personal data, subject to legal and contractual obligations that require us to retain certain records |
| Right to restriction | To request that we restrict processing of your data in certain circumstances |
| Right to portability | To receive your data in a structured, commonly used format |
| Right to object | To object to processing based on legitimate interests or for direct marketing purposes |
| Right to withdraw consent | Where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing |
| Right not to be subject to automated decision-making | We do not make solely automated decisions that produce legal or similarly significant effects |
9.2. If you are a US resident, you may have additional rights — see Section 13.
9.3. How to exercise your rights: contact us at [email protected] or via your regional representative (see Section 2). We will respond within 30 days. We will not charge a fee unless a request is manifestly unfounded or excessive.
10. Security
10.1. We implement appropriate technical and organisational measures to protect your personal data, including:
10.1.1. SSL/TLS (Secure Sockets Layer / Transport Layer Security) encryption for all data in transit.
10.1.2. Encryption at rest on our hosting infrastructure (Kinsta).
10.1.3. Password hashing (passwords are never stored in plain text).
10.1.4. Role-based access controls.
10.1.5. Two-factor authentication on administrative accounts.
10.1.6. Cloudflare and Google Cloud Platform firewalls and DDoS (Distributed Denial of Service) protection. Cloudflare, Inc. is a US-based provider that is self-certified under the EU-US Data Privacy Framework; where personal data is processed by Cloudflare, this certification provides the transfer mechanism.
10.1.7. Daily automated backups.
10.1.8. PCI-DSS (Payment Card Industry Data Security Standard) compliant payment processing via Stripe and PayPal (card details are collected directly by Stripe and PayPal and never transmitted to or stored on our systems).
10.1.9. Prompt-level controls on PAI to prevent submission of personally identifiable data.
10.2. In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
11. Cookies
11.1. We use cookies and similar tracking technologies on our platform. Non-essential cookies are deployed only with your explicit consent, which you can give, refuse, or update at any time via the Cookie Settings link in the footer of our website.
11.2. For full details of the cookies we use, their purpose, and how to manage your preferences, please see our Cookie Policy.
12. Complaints
12.1. If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with a supervisory authority in your jurisdiction:
12.1.1. UK: Information Commissioner’s Office (ICO) — ico.org.uk
12.1.2. EU: Your national data protection authority (for Irish residents: Data Protection Commission — dataprotectioncommission.ie)
12.1.3. Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
12.1.4. Andorra: Agència de Protecció de Dades d’Andorra (APDA) — apda.ad
12.2. Please contact us first at [email protected] so that we have the opportunity to address your concern before you escalate to a supervisory authority.
13. Additional rights for US residents
13.1. This Section applies to residents of US states with applicable privacy legislation, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and similar comprehensive privacy laws in Virginia, Colorado, Connecticut, Texas, and other states.
13.2. We do not sell your personal data. We do not share your personal data for cross-context behavioural advertising.
13.3. In addition to the rights described in Section 9, you may have the following rights under applicable US state law:
13.3.1. Right to opt out of sale or sharing: As noted above, we do not sell or share personal data for advertising purposes. No opt-out mechanism is required, but you may contact us at [email protected] to confirm.
13.3.2. Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights. Exercising your rights will not result in denial of services, different pricing, or a different level of service.
13.3.3. How to exercise your rights: Submit a verifiable consumer request to [email protected]. We will respond within 45 days and may extend this by a further 45 days where reasonably necessary, with notice.
13.3.4. Authorised agent: You may designate an authorised agent to submit requests on your behalf. We may require written verification of the authorisation.
14. Children
14.1. Our platform is designed for qualified physiotherapy and allied health professionals and students enrolled in accredited programmes. It is not directed at children. We do not knowingly collect personal data from individuals under the age of 18.
14.2. If you believe a minor has provided us with personal data, please contact us at [email protected].
15. Changes to this policy
15.1. We may update this privacy policy from time to time. Where changes are material, we will use reasonable endeavours to notify registered users by email or by a prominent notice on our platform at least 30 days before the changes take effect.
15.2. If you do not agree to the changes, you may cease using the platform and request deletion of your data.
15.3. The date at the foot of this document indicates when it was last updated. We encourage you to review this privacy policy periodically.
16. Contact us
16.1. For any questions about this privacy policy or how we handle your personal data:
Physiopedia International SL
CTRA. Del Prats Sobrians 003 14
Edifici Prats Sobrians Bloc A Escala A
Arinsal, AD400 La Massana
Andorra
Email: [email protected]
16.2. Alternatively, you may contact your regional representative as listed in Section 2.
Last updated: July 2026