Privacy and Cookies Policy
Last updated: 6 June 2026
1. Introduction
1.1 We are committed to safeguarding the privacy of our website visitors, service users, individual customers, customer personnel, and users of our movement coaching and practice management software services.
1.2 This policy applies where we are acting as a data controller with respect to the personal data of such persons; in other words, where we determine the purposes and means of the processing of that personal data. In some cases (particularly where physiotherapy practices or other organisations use our software platform to process their own patients’ data), we may act as a data processor. In those cases we process data only on documented instructions from the controller and in accordance with our Data Processing Agreement.
1.3 We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website and services, we will ask you to consent to our use of cookies when you first visit our website.
1.4 In this policy, "we", "us" and "our" refer to The Movement Bank. For more information about us, see Section 17.
2. The personal data that we collect
2.1 In this Section 2 we have set out the general categories of personal data that we process.
2.2 We may process data enabling us to get in touch with you ("contact data"). The contact data may include your name, email address, telephone number, postal address and/or social media account identifiers. The source of the contact data is you.
2.3 We may process data about your account with us ("account data"). The account data may include your name, email address, username, password (stored in hashed form), profile information, subscription or service details, and organisation details where you represent a business or clinic. The source of the account data is you or your organisation.
2.4 We may process information contained in or relating to any communication that you send to us or that we send to you ("communication data" or "correspondence data"). The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
2.5 We may process information that you provide to us when making enquiries, bookings, or using our coaching or software services ("enquiry data" or "service data"). This may include details of your movement goals, injury history, rehabilitation progress, or other information relevant to the services.
2.6 We may process data about your use of our website and services ("usage data"). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is Google Analytics (with Consent Mode where applicable).
2.7 We may process transaction data including details of services purchased, payment history, and related records ("transaction data"). Payment card details are processed securely by our payment providers and we do not store full card numbers ourselves.
2.8 We may process information about your physical or mental health or other special category data ("health data") where you voluntarily provide it to us in connection with enquiries, coaching services, or use of our software platform. The source of the health data is you. We only process health data with your explicit consent or where another permitted condition under UK GDPR applies (for example, healthcare purposes or vital interests).
3. Purposes of processing and legal bases
3.1 In this Section 3, we have set out the purposes for which we may process personal data and the legal bases of the processing.
3.2 Operations - We may process your personal data for the purposes of operating our website, providing our coaching and software services, managing accounts and subscriptions, generating invoices, and credit control. The legal basis for this processing is our legitimate interests, namely the proper administration of our website, services and business, and/or the performance of a contract with you.
3.3 Relationships and communications - We may process contact data, account data, enquiry data, communication data and/or correspondence data for the purposes of managing our relationships, communicating with you (excluding direct marketing), providing support, and handling enquiries or complaints. The legal basis for this processing is our legitimate interests and/or the performance of a contract.
3.4 Direct marketing - We may process contact data, account data and/or enquiry data for the purposes of creating, targeting and sending direct marketing communications by email, SMS, post and/or telephone. The legal basis for this processing is consent (which you may withdraw at any time).
3.5 Research and analysis - We may process usage data, service data and/or transaction data for the purposes of researching and analysing the use of our website and services, and improving our coaching and software offerings. The legal basis for this processing is our legitimate interests, namely monitoring, supporting, improving and securing our website, services and business generally.
3.6 Record keeping - We may process your personal data for the purposes of creating and maintaining our databases, back-up copies and business records. The legal basis for this processing is our legitimate interests, namely ensuring that we have access to all the information we need to properly and efficiently run our business.
3.7 Security and fraud prevention - We may process your personal data for the purposes of security, the prevention of fraud and other criminal activity. The legal basis is our legitimate interests, namely the protection of our website, services, business and users.
3.8 Insurance, risk management and legal claims - We may process your personal data where necessary for obtaining or maintaining insurance, managing risks, obtaining professional advice, or the establishment, exercise or defence of legal claims. The legal basis is our legitimate interests.
3.9 Legal compliance and vital interests - We may also process your personal data where such processing is necessary for compliance with a legal obligation or to protect your vital interests or the vital interests of another person.
3.10 Healthcare and coaching services - We may process health data and other personal data for the purposes of providing movement coaching, rehabilitation support, and facilitating the use of our practice management software by healthcare professionals and clinics. The legal basis for this processing is your explicit consent and/or the performance of a contract. Where we process patient or client data uploaded into our software platform on behalf of a physiotherapy practice or other organisation, we do so as a data processor under the terms of our Data Processing Agreement with that organisation.
4. Providing your personal data to others
4.1 We may disclose your personal data to our insurers and/or professional advisers insofar as reasonably necessary for the purposes set out in this policy.
4.2 We may disclose your personal data to service providers who assist us in operating our website and delivering our services (including hosting, email delivery, payment processing, analytics, and software infrastructure providers). Your personal data held in our website database will be stored on the servers of our hosting services providers.
4.3 We may disclose your personal data where such disclosure is necessary for compliance with a legal obligation, to protect vital interests, or for the establishment, exercise or defence of legal claims.
4.4 Where we act as a data processor for data uploaded into our software platform, we only share that data with authorised users within the relevant physiotherapy practice or organisation, or with sub-processors bound by appropriate contracts.
5. International transfers of your personal data
5.1 We may transfer your personal data to countries outside the UK and/or EEA where appropriate safeguards are in place, such as UK adequacy regulations, EU adequacy decisions, or standard contractual clauses approved by the ICO or European Commission.
5.2 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
6. Retaining and deleting personal data
6.1 This Section 6 sets out our data retention policies and procedures, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data.
6.2 Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
6.3 We will typically retain:
- Account data: for as long as your account remains active and for a reasonable period afterwards (usually up to 3 years) to allow reactivation or to meet legal/tax obligations.
- Enquiry and correspondence data: for up to 3 years after last contact, or longer if required for legal or insurance purposes.
- Health data: only for as long as necessary to provide the service or as required by applicable professional or legal guidelines.
- Usage data (Google Analytics): in line with Google’s default retention settings (currently up to 26 months, subject to your cookie preferences).
- Transaction data: for at least 6 years to meet tax and accounting requirements.
6.4 We may retain your personal data where such retention is necessary for compliance with a legal obligation or to protect vital interests.
7. Security of personal data
7.1 We will take appropriate technical and organisational precautions to secure your personal data and to prevent the loss, misuse or alteration of your personal data. These include encryption in transit (HTTPS), access controls, and regular security reviews.
7.2 You acknowledge that the transmission of unencrypted (or inadequately encrypted) data over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
7.3 You are responsible for keeping any password you use for accessing our website or services confidential. We will never ask you for your password except when you log in through our official login process.
8. Your rights
8.1 In this Section 8, we have listed the rights that you have under data protection law.
8.2 Your principal rights under data protection law are:
(a) the right to access - you can ask for copies of your personal data;
(b) the right to rectification - you can ask us to rectify inaccurate personal data and to complete incomplete personal data;
(c) the right to erasure - you can ask us to erase your personal data;
(d) the right to restrict processing - you can ask us to restrict the processing of your personal data;
(e) the right to object to processing - you can object to the processing of your personal data;
(f) the right to data portability - you can ask that we transfer your personal data to another organisation or to you;
(g) the right to complain to a supervisory authority - you can complain about our processing of your personal data; and
(h) the right to withdraw consent - to the extent that the legal basis of our processing of your personal data is consent, you can withdraw that consent.
8.3 These rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
8.4 You may exercise any of your rights in relation to your personal data by written notice to us, using the contact details set out below.
9. Third party websites
9.1 Our website includes hyperlinks to, and details of, third party websites.
9.2 In general we have no control over, and are not responsible for, the privacy policies and practices of third parties.
10. Personal data of children
10.1 Our website and services are targeted at persons over the age of 16.
10.2 If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.
11. About cookies
11.1 A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
11.2 Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
11.3 Cookies may not contain any information that personally identifies a user, but personal data that we store about you may be linked to the information stored in and obtained from cookies.
12. Cookies that we use
12.1 We use cookies for the following purposes:
(a) authentication and status - we use cookies to identify you when you visit our website and as you navigate our website, and to help us determine if you are logged into our website;
(b) security - we use cookies as an element of the security measures used to protect user accounts, including preventing fraudulent use of login credentials, and to protect our website and services generally;
(c) analysis - we use cookies to help us to analyse the use and performance of our website and services; and
(d) cookie consent - we use cookies to store your preferences in relation to the use of cookies more generally.
13. Cookies used by our service providers
13.1 Our service providers use cookies and those cookies may be stored on your computer when you visit our website.
13.2 We use Google Analytics. Google Analytics gathers information about the use of our website by means of cookies. The information gathered is used to create reports about the use of our website. You can find out more about Google's use of information by visiting https://www.google.com/policies/privacy/partners/ and you can review Google's privacy policy at https://policies.google.com/privacy.
13.3 We may use a Facebook pixel on our website. Using the pixel, Facebook collects information about the users and use of our website. The information is used to personalise Facebook advertisements and to analyse the use of our website. To find out more about the Facebook pixel and about Facebook's use of personal data generally, see the Facebook cookie policy at https://www.facebook.com/policies/cookies/ and the Facebook privacy policy at https://www.facebook.com/about/privacy.
14. Managing cookies
14.1 Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
(a) https://support.google.com/chrome/answer/95647 (Chrome);
(b) https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
(c) https://help.opera.com/en/latest/security-and-privacy/ (Opera);
(d) https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
(e) https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari); and
(f) https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
14.2 Blocking all cookies will have a negative impact upon the usability of many websites.
14.3 If you block cookies, you will not be able to use all the features on our website.
15. Cookie preferences
15.1 You can manage your preferences relating to the use of cookies on our website by clicking the banner as you enter the website.
16. Amendments
16.1 We may update this policy from time to time by publishing a new version on our website.
16.2 You should check this page occasionally to ensure you are happy with any changes to this policy. Material changes will be notified by email where we hold a valid email address for you.
17. Our details
17.1 This website is owned and operated by The Movement Bank™.
17.2 Our principal place of business is at Longcroft House, 2-8 Victoria Avenue, London, EC2M 4NS, UK.
17.3 You can contact us:
(a) by post, to the postal address given above;
(b) using our website contact form;
(c) by email, to hello@themovementbank.com.