Privacy and personal information

BodyRepair Privacy Policy

This policy explains how BodyRepair collects, uses, stores, protects and shares personal information when you use our public website, contact services, application and connected health, recovery and performance pathways.

Effective date: 3 August 2026
Last reviewed: 3 August 2026

Publication information is incomplete.

The legal entity, address and any applicable ICO registration details must be completed before this privacy policy is treated as final.

Privacy at a glance

Your information should remain understandable, relevant and under appropriate control.

BodyRepair processes personal information to provide its website, user accounts, health-led pathways, programme tools, support services and optional professional collaboration.

We explain why

We aim to explain what information is collected and why it is needed.

We limit collection

We seek to collect only information relevant to the service, pathway or enquiry.

You control sharing

Optional professional access is intended to remain permission-based and revocable.

You have rights

Data-protection law provides rights concerning access, correction, restriction and other uses of personal data.

1. Who is responsible for your information?

The data controller

The organisation responsible for deciding how and why personal information is processed through BodyRepair is:

Organisation:
REPLACE WITH LEGAL ENTITY NAME

Address:
REPLACE WITH REGISTERED OR BUSINESS ADDRESS

Privacy contact:
hello@bodyrepair.online

ICO registration number:
REPLACE IF APPLICABLE

2. What does this policy cover?

Services covered by this notice

This privacy policy applies to personal information processed through:

  • The public BodyRepair marketing website
  • Contact forms and support enquiries
  • BodyRepair user accounts
  • Health, rehabilitation, fitness and performance pathways
  • Running routes, session records and available motion indicators
  • Measurements, symptoms, treatment and recovery records
  • Nutrition, wellbeing and medication records entered by users
  • Optional professional sharing and collaboration
  • Mobile, Progressive Web App and future compatible wearable services

Separate or additional privacy information may be provided when a specific feature requires more detailed explanation at the point where information is collected.

3. Information we may collect

The information depends on how you use BodyRepair.

A visitor using the public website provides far less information than a registered user completing a health-led BodyRepair pathway.

Identity and account information

  • Name
  • Email address
  • Telephone number
  • Account identifier
  • Authentication and account settings
  • Organisation or professional role

Contact and support information

  • Enquiry category
  • Message content
  • Related pathway
  • Support correspondence
  • Accessibility feedback
  • Partnership or media enquiries

Health and pathway information

  • Health conditions declared by the user
  • Injury and surgical history
  • Symptoms, pain and movement restrictions
  • Medication and treatment records
  • Pregnancy or postnatal information where relevant
  • Professional restrictions or recommendations

Activity and performance information

  • Exercise and session records
  • Sets, repetitions and training load
  • Running distance, pace and duration
  • Routes and location information
  • Recovery, fatigue and readiness records
  • Programme and pathway progress

Body and wellbeing measurements

  • Weight and circumference measurements
  • Body-composition estimates
  • Heart rate and blood-pressure records
  • Sleep, stress, energy and soreness
  • Mobility and functional milestones
  • Optional progress photographs

Nutrition and behaviour information

  • Meals and ingredients
  • Calories and macronutrients where entered
  • Hydration records
  • Appetite, hunger and fullness
  • Craving and trigger records
  • Behavioural reflections

Device and technical information

  • IP address
  • Browser and device type
  • Operating system
  • Application and error logs
  • Security and access logs
  • Cookie and preference information

Sensor and wearable information

  • GPS and route location
  • Accelerometer and gyroscope outputs
  • Motion indicators
  • Connected wearable readings
  • Device connection and battery status
  • Voice-command events where enabled

4. Health and special-category information

Some BodyRepair information requires additional protection.

Information concerning health, injury, treatment, medication, pregnancy and related matters may constitute special-category personal data under UK data-protection law.

Where BodyRepair processes this information, it must identify both an Article 6 lawful basis and an additional condition permitting the processing of special-category information.

Legal-basis confirmation required.

Before launch, BodyRepair must confirm the precise lawful bases and special-category conditions that apply to each clinical and health-data workflow. These depend on the final operating model, contracts, professional roles and purpose of the processing.

BodyRepair should also provide relevant just-in-time notices where sensitive information is requested, explaining why the information is needed and whether providing it is optional or necessary for pathway access.

5. Why we use personal information

Purposes and potential lawful bases

The applicable lawful basis depends on the processing activity. The table below describes the intended framework and must be reviewed against the final BodyRepair service.

Purpose Information involved Potential lawful basis
Create and administer user accounts Identity, contact, authentication and account information Contract and legitimate interests
Deliver BodyRepair pathways and requested services Account, programme, activity, recovery and pathway information Contract; special-category condition required where health data is involved
Conduct health and safety screening Health, injury, symptom, medication and treatment information To be confirmed before operational launch; appropriate special-category condition required
Respond to contact and support enquiries Contact details, enquiry content and technical information Contract steps, legitimate interests or legal obligation depending on the request
Maintain platform security and prevent misuse IP address, access logs, device information and security events Legitimate interests and legal obligations
Enable optional professional sharing Selected health, pathway, treatment and performance records User instruction, contract and an appropriate special-category condition
Process privacy and legal requests Identity, correspondence and verification information Legal obligation
Improve accessibility and platform performance Usage, technical, feedback and error information Legitimate interests, with consent where required for non-essential technologies
Send marketing communications Name, email address, preferences and engagement information Consent or another permitted basis under applicable direct-marketing rules

6. Where information comes from

Most information is provided directly by you.

BodyRepair may receive personal information from:

  • You, when you register, complete a form, create a pathway record or contact us
  • Your device, when location, motion, technical or wearable permissions are enabled
  • A professional you have authorised to contribute information to your account
  • Authentication, hosting, payment or technical service providers involved in delivering the service
  • Public sources where necessary for organisational, professional or partnership enquiries

Where information is obtained from another source, BodyRepair will provide relevant privacy information unless an applicable legal exception applies.

7. Artificial intelligence and automated processing

AI may support organisation and interpretation, but it does not replace professional judgement.

BodyRepair may use artificial intelligence or rule-based systems to organise user-provided information, identify patterns, produce summaries, support pathway generation or surface safety prompts.

BodyRepair does not intend to use unrestricted AI to diagnose medical conditions or independently override defined health and safety rules.

Where a decision produces a legal or similarly significant effect through solely automated processing, BodyRepair will assess whether additional rights and safeguards apply.

8. Who we may share information with

Information is shared only where there is an appropriate reason.

Personal information may be shared with:

  • Hosting, database, authentication, email and technical service providers
  • Payment providers where a paid service is used
  • Professional advisers, auditors and insurers
  • Physiotherapists, trainers, coaches, clinicians or other professionals explicitly authorised by the user
  • Regulators, courts, law-enforcement bodies or public authorities where disclosure is legally required
  • A purchaser, investor or successor organisation as part of a lawful corporate transaction, subject to appropriate safeguards

BodyRepair does not sell personal health information to third parties.

Optional professional access

You decide when selected information is shared.

Where professional sharing is enabled, BodyRepair is designed to provide controlled access to information selected by the user.

  • Explicit user action before sharing
  • Defined professional or recipient
  • Limited information scope
  • Time-limited or revocable access where available
  • Access and contribution records
  • Separation between user entries and professional entries

9. International transfers

Some service providers may process information outside the United Kingdom.

Where personal information is transferred to a country or organisation outside the United Kingdom, BodyRepair will assess the transfer mechanism and safeguards required under applicable data-protection law.

These safeguards may include:

  • UK adequacy regulations
  • Approved contractual safeguards
  • The UK International Data Transfer Agreement
  • An approved UK Addendum to international contractual clauses
  • Transfer-risk assessments and supplementary security measures
Supplier review required.

The final notice should identify the actual categories of international transfers after BodyRepair confirms its hosting, authentication, email, analytics, AI and support providers.

10. How long information is kept

Personal information is not intended to be kept for longer than necessary.

Retention depends on the type of information, the purpose for which it is used and any legal, contractual, safety or dispute-resolution requirements.

Record Indicative retention approach
Contact enquiries Retained only for the period needed to respond, manage follow-up and meet applicable legal requirements
Account records Retained while the account is active and for an appropriate period after closure
Health and pathway records Retained according to the user service, safety requirements, contractual arrangements and the final BodyRepair retention schedule
Professional-sharing records Retained to document permissions, access, recommendations and withdrawal where appropriate
Payment and transaction information Retained for accounting, taxation, fraud prevention and legal requirements
Security and technical logs Retained for a proportionate period needed for security, troubleshooting and misuse prevention
Legal and privacy requests Retained as necessary to demonstrate compliance and respond to disputes or regulatory enquiries
A formal retention schedule must be approved.

Precise retention periods should be inserted after the final database, clinical operating model, insurance requirements and contractual arrangements have been reviewed.

11. How information is protected

BodyRepair uses organisational and technical safeguards intended to protect personal information.

Depending on the service and the final technical implementation, safeguards may include:

  • Account authentication and access controls
  • Row-level or record-level access restrictions
  • Encryption in transit and, where appropriate, at rest
  • Logging and review of sensitive access or administrative actions
  • Secure development and vulnerability-management practices
  • Backups, continuity planning and recovery procedures
  • Supplier due diligence and data-processing agreements
  • Staff or contractor confidentiality and access restrictions

No online system can guarantee absolute security. Users should protect their credentials, use strong unique passwords and report suspected unauthorised access promptly.

12. Your data-protection rights

You may have several rights concerning your personal information.

The availability of a particular right can depend on the lawful basis, the type of information and any applicable legal exception.

Right to be informed

Receive clear information about how your personal data is used.

Right of access

Request confirmation and a copy of personal information held about you.

Right to rectification

Ask for inaccurate or incomplete personal information to be corrected.

Right to erasure

Request deletion in circumstances where the right applies.

Right to restriction

Ask for processing to be limited in certain circumstances.

Right to portability

Request eligible information in a structured, commonly used and machine-readable format.

Right to object

Object to certain processing, including direct marketing.

Automated-decision rights

Request appropriate safeguards where solely automated processing produces a qualifying significant effect.

Withdraw consent

Withdraw consent at any time where consent is the basis for processing, without affecting earlier lawful processing.

13. How to exercise your rights

Contact BodyRepair with enough information to identify the request.

To make a privacy request, email:

hello@bodyrepair.online

BodyRepair may need to verify your identity before disclosing, correcting or deleting personal information. You will not normally be charged for exercising a data-protection right, although applicable law permits fees or refusal in limited circumstances involving manifestly unfounded or excessive requests.

14. Complaints

You may raise a concern with BodyRepair or the Information Commissioner’s Office.

Please contact BodyRepair first so that we have an opportunity to investigate and respond.

You also have the right to complain to the United Kingdom’s data-protection supervisory authority, the Information Commissioner’s Office.

Current ICO contact details and complaint procedures should be obtained from the ICO’s official website.

15. Children and young people

Age eligibility and consent arrangements must be clearly defined.

The final BodyRepair service must state whether it is intended for people under 18, the minimum account age and how parental responsibility, consent, safeguarding and age-appropriate privacy information will be managed.

Policy decision required.

Do not remove this section until BodyRepair has formally determined its age eligibility and safeguarding model.

16. Cookies and similar technologies

The website may use essential and optional technologies.

Essential cookies or local-storage technologies may be used to provide security, remember settings, maintain sessions and support core website or application functions.

Optional analytics, advertising or preference technologies should not be activated unless the required notice and consent arrangements are in place.

17. External websites and services

BodyRepair may link to third-party websites, app stores, professional services or compatible device providers. This privacy policy does not control how those separate organisations process personal information.

Review the privacy information provided by the relevant third party before providing information or enabling an integration.

18. Changes to this policy

This policy will be reviewed as BodyRepair develops.

BodyRepair may update this privacy policy to reflect changes in services, suppliers, technology, law or regulatory guidance.

Material changes affecting how personal information is used should be brought to users’ attention before the new processing begins where required.

The effective date and last-reviewed date at the top of this page will be updated when the policy changes.

Privacy contact

Contact BodyRepair about your personal information.

Include enough information for us to understand the request, but do not send passwords, authentication codes or unnecessary health information by ordinary email.

Email:
hello@bodyrepair.online

Address:
REPLACE WITH REGISTERED OR BUSINESS ADDRESS

BodyRepair information

Review how BodyRepair approaches clinical responsibility, AI and accessibility.

The supporting policies explain how the platform is intended to protect users while providing connected health, recovery and performance services.