Privacy Policy

Why we collect your personal data, what we do with it, and the rights you have over it.

Last updated: 22 August 2026

When you supply your personal details to this practice, they are stored and processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This notice explains how we handle your data, why we need it, and your rights regarding it.

It covers both the care we provide in clinic and your use of this website.

1. Who we are

The data controller is AND WELLNESS LTD, a company registered in England and Wales (no. 15307999), registered office 30 Westfields Avenue, London SW13 0AU, trading as & Wellness Osteopath Barnes at 1-2 St Ann's Passage, Barnes, London SW13 0AX.

Henry Skane-Davis, the practice principal and a registered osteopath (General Osteopathic Council no. 12075), is responsible for data protection. There is no separate Data Protection Officer; the practice is not required to appoint one.

Contact: henry@andwellness.co.uk or 020 8050 6001.

2. What personal data we collect

If you become a patient, to provide you with effective and safe osteopathic care we collect and store:

  • Your name, date of birth, and contact details
  • Medical history and current health information
  • Treatment notes and progress updates
  • Appointment and billing information
  • The name of your GP, and any correspondence with them or with other clinicians involved in your care, where relevant

If you contact us or use this website, we may also hold:

  • Whatever you choose to tell us in an email, a text or WhatsApp message, a phone call or a voicemail — which, for a clinic, often includes information about your health
  • Booking details you enter into our online booking form, including the appointment type you select
  • The answers you send us from the "Can we help?" tool, if you choose to send them

Health information is "special category" data under UK GDPR and is given the additional protections described below. Much of what people tell a clinic is health information even when it does not look like a medical record — a WhatsApp message saying your back has gone is health data, and we treat it as such.

3. Information this website collects on its own

Nothing that identifies you, and nothing at all unless you allow it. The site sets no cookies of its own, and carries no advertising or tracking.

With your consent, we use Google Analytics to see which pages are read and roughly where visitors came from. It is off until you turn it on, we never send it anything about you personally, and we do not use it for advertising. Because our pages are condition-specific, reading one does tell Google something about what you may be dealing with — which is why we ask rather than assume. Full detail, including the cookies it sets, is in the Cookie Policy.

Our hosting provider, Cloudflare, processes standard server request data (including IP addresses) in order to serve the site and protect it from attack. Two parts of the site are embedded from other companies — the online booking form (Cliniko) and the map (Google) — and neither loads until you allow it. We ask on your first visit, and you can change your answer with "Cookie settings" in the footer. All of this is set out in full in our Cookie Policy.

The "Can we help?" tool. The answers you give it stay in your browser. They are not sent anywhere, and we never see them, unless you press the WhatsApp or email button at the end — at which point they are placed into a message for you to send, and you can edit or discard it before sending.

4. Why we collect this data, and our lawful bases

Contractual necessity (Article 6(1)(b)). When you request treatment and we agree to provide that care, we are entering into a contract, and we need your details to perform it. This also covers taking and managing bookings and payments.

Provision of healthcare (Article 9(2)(h)). Health data is special category data, which needs a condition under Article 9 as well as Article 6. We rely on Article 9(2)(h), for the provision of health care and treatment, together with the corresponding condition in paragraph 2 of Schedule 1 to the Data Protection Act 2018. This processing is carried out by, or under the responsibility of, a professional subject to a duty of confidentiality — in this practice, a GOsC-registered osteopath bound by the Osteopathic Practice Standards.

Legal obligation (Article 6(1)(c)). Keeping clinical records for the periods set out in section 7, and retaining financial records for HMRC.

Legitimate interests (Article 6(1)(f)). Confirming and reminding you about appointments, sending invoices and receipts, responding to your enquiries, keeping the practice secure, and defending legal claims. We have considered your interests and rights and are satisfied these do not override them; you can object at any time (see section 9). We do not rely on legitimate interests for website analytics — that is consent-based, and you are asked.

Consent (Article 6(1)(a)). Our newsletter and general practice updates, which are asked for separately; and website analytics and embedded content, which you are asked about on your first visit to the site. You can withdraw either at any time — analytics and embeds through "Cookie settings" in the footer — and neither affects your care.

5. How we store your records

Paper records. Records created before November 2017 are securely stored in locked filing cabinets. Our offices are locked outside working hours.

Electronic records. Since November 2017 we have used Cliniko, a secure cloud-based practice management system, to store your records. Cliniko holds our data on servers in the UK/EU, practitioner access is password-protected, and the devices used are secured appropriately.

Messages. Emails, texts and WhatsApp messages are held on Henry's business account and phone, which are password- or biometric-protected. Clinically relevant information from them is transferred into your Cliniko record, and we keep the messaging thread itself no longer than we need to.

6. Who we share your data with, and who processes it for us

We never sell your data, and we never share it with third parties for their own marketing.

Within the practice, routine access is limited to:

  • Your practitioner(s), for the purposes of providing your treatment
  • Administrative staff who manage appointments and communications, and who do not access your clinical notes

Access by your practitioner and our administrative staff is necessary to provide the care you have asked for. It is not based on consent, and so it is not something we can offer to switch off — but it is limited to what each role actually needs.

We use the following service providers, who process data on our instructions under a contract:

  • Cliniko (Red Guava Pty Ltd) — clinical records and online booking, including the booking form embedded on this website. Data held in the UK/EU.
  • Cloudflare — website hosting and security.
  • Mailchimp (Intuit Inc.) — newsletters and practice updates only, and only if you have opted in. Name and email address only. Mailchimp is based in the USA, and the transfer is made under the UK International Data Transfer Addendum with a transfer risk assessment on file.
  • Google — Google Analytics, and the map embedded on this website. Both load only if you allow them. Google receives the pages you viewed and your approximate location; it receives nothing about you as a patient, and nothing from your clinical record ever reaches it. Google is in the USA and the transfer is covered by Google's data processing terms and the UK Addendum to the EU Standard Contractual Clauses. The site's typefaces are served from our own domain, so Google is not involved in those.
  • WhatsApp (Meta) — only if you choose to contact us that way. WhatsApp messages are end-to-end encrypted in transit, but if you would rather your health information did not pass through Meta's service at all, please phone or email us instead.

We will disclose information beyond this only where we are legally required or permitted to — for example a court order, a safeguarding concern, a regulatory investigation by the General Osteopathic Council, or where there is a risk of serious harm. Where we can tell you that we have done so, we will.

If you ask us to write to your GP, an insurer or another clinician, we will do that with your consent and share only what is relevant.

7. How long we keep your data

Adults: clinical records are kept for 8 years after the date of your last appointment.

Children and young people: records are kept until the patient's 25th birthday, or 8 years after last treatment, whichever is longer.

Financial records: 6 years plus the current financial year, as HMRC requires.

Enquiries that do not become appointments: up to 12 months, then deleted.

Website analytics: retained by Google for 14 months, and only where you have consented.

Marketing consent: until you withdraw it.

We are required to keep clinical records for these periods and cannot delete them earlier on request. After the retention period ends, records are securely destroyed.

8. Keeping your data secure

We use password-protected accounts and devices, encrypted connections, locked physical storage, and providers who are contractually bound to appropriate security standards. No system is completely secure, but if a breach occurred that was likely to result in a risk to your rights and freedoms, we would report it to the Information Commissioner's Office within 72 hours and tell you where we are required to.

9. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data — which is what this notice is for
  • Access the personal data we hold about you, normally free of charge and within one month
  • Rectification of data that is inaccurate or incomplete. Note that a clinical record is a historical document: where you disagree with a clinical opinion we can add your statement to the record rather than delete the original entry
  • Erasure of your data, subject to the retention periods in section 7 that we are professionally obliged to observe
  • Restrict processing in certain circumstances, for example while an accuracy dispute is being resolved
  • Data portability — to receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider
  • Object to processing based on our legitimate interests, and to object to direct marketing at any time, which we will always honour
  • Withdraw consent at any time where processing is based on it, without affecting your care or the lawfulness of what we did before you withdrew it
  • Not be subject to automated decision-making. We do not carry out any automated decision-making or profiling

To exercise any of these, contact us using the details in section 1. We may need to confirm your identity first. We will respond within one month, and will tell you if we need longer because a request is complex.

10. Complaints

If you are unhappy with how we have handled your data, please tell us first — email henry@andwellness.co.uk and we will look into it and reply within 14 days.

You also have the right to complain directly to the Information Commissioner's Office at any time. You do not have to come to us first.

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk/make-a-complaint

Complaints about your treatment rather than your data are covered in our Terms & Conditions.

11. Changes to this notice

We review this notice when what we do changes, and at least annually. The revision date is shown at the top of this page. Where a change is significant we will tell patients directly rather than relying on you to re-read the page.

Osteopathy & Wellness is part of the & Wellness Group. The & Wellness Group aim to deliver the highest quality of care and a personalised experience.