Aries PhysioCare - UK
UK-GDPR & DPA 2018 Standards

Privacy Policy

Last updated: August 2026 • Aries HealthCare UK Ltd

Aries HealthCare UK Ltd (“Aries PhysioCare”, “we”, “our”) is committed to protecting and respecting your personal and health data in compliance with the UK General Data Protection Regulation (UK-GDPR), the Data Protection Act 2018, and the Information Commissioner's Office (ICO) guidelines.

1. Data We Collect

When you book an in-home or virtual physiotherapy session, we collect demographic information (name, contact phone, residential address, postcode) and special category health data (medical history, current pathology, range of motion measurements, treating physician notes, private health insurance policy numbers).

2. Clinical & Direct Billing Use

Your clinical health records are retained strictly to deliver professional physiotherapy care under the HCPC and CSP Standards of Conduct, Performance and Ethics. When authorized by you, diagnostic details are transmitted securely via Healthcode to your insurer (Bupa, AXA Health, Aviva, Vitality, WPA) for direct billing settlement.

3. Data Security & Retention

All electronic health records (EHR) and video telehealth streams are encrypted end-to-end using 256-bit AES encryption and hosted within secure UK data centres. In accordance with CSP guidelines, adult clinical records are securely retained for 8 years from the date of the last treatment.