PhysioWorkplace
Privacy Policy
Last updated 11 September 2026
This notice explains how Meadow Arc handles personal data for the PhysioWorkplace website, pre-launch service, and transactional communications.
Who is responsible
Meadow Arc, Sweden, operates PhysioWorkplace and is responsible for account, website, support, security, and service-administration data. Contact us at support@physioworkplace.com.
For patient information entered by a clinic, the clinic normally acts as controller and Meadow Arc acts as processor under the applicable customer agreement and data processing terms.
Data we handle
We may handle contact and account details, workplace membership, authentication and security events, support communications, service usage, technical diagnostics, and billing or agreement information.
Clinical or patient information is handled only when an authorised clinic uses those product functions. Transactional email must not contain clinical content.
Why we use data
We use data to provide and secure the service, authenticate users, manage workplace memberships and invitation links, send requested account and recovery messages, support customers, prevent abuse, meet legal obligations, and improve reliability.
Our legal bases may include performing a contract, legitimate interests in operating and securing the service, legal obligations, and consent where required.
Service providers and transfers
We use carefully selected providers, including Google Cloud and Firebase for application infrastructure, Amazon Web Services for transactional email, and Cloudflare for network and access protection.
Cloudflare Web Analytics gives us aggregated page-view, referring-domain, device, country, and performance measurements for public website pages and embedded public resources. It does not use cookies or local storage, record query strings, or create individual visitor profiles. Web Analytics reports are available to us for up to six months.
Clinical records and clinical content are processed and stored primarily in Finland, with a separate encrypted disaster copy in Sweden. Firebase Authentication processes account identifiers and sign-in security data, including email address, IP address, and user-agent information, in the United States. Where processing involves an international transfer, we use applicable contractual and organisational safeguards.
Retention and security
We retain data only for the service, security, contractual, and legal periods that apply to it. Retention differs between active accounts, audit evidence, support records, backups, and deleted accounts.
We use access controls, encryption, environment isolation, monitoring, and documented recovery procedures. No system can guarantee absolute security.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is the legal basis.
If you can sign in, request a copy of your data through Data export in Settings. Choose the account and workplace information to include; the export is made available in the signed-in service after administrative review and the waiting period. Only contact support@physioworkplace.com if you cannot sign in. Support will help you regain access to your account and determine whether Meadow Arc or your clinic is responsible for the requested information. Do not send health information or identity documents by email. You may also complain to the relevant data-protection authority, including the Swedish Authority for Privacy Protection (IMY).