The Rehab Lab online exercise prescription software uses personal data in order to provide its services to subscribers and their clients. The Rehab Lab takes the privacy and security of this data seriously and implements technical and organisational measures designed to protect it.
The General Data Protection Regulation (GDPR) governs the processing of personal data relating to individuals in the European Economic Area. Personal data may include information such as names, e-mail addresses, contact details and online identifiers.
This page explains how The Rehab Lab processes personal data, our role as a Data Controller and Data Processor, how long data is retained, and the measures available to subscribers to manage personal data held within The Rehab Lab.
Please also refer to The Rehab Lab's Privacy Policy.
The Rehab Lab has appointed a team member, based in New Zealand, to the role of Data Protection Officer (DPO). The Rehab Lab's DPO oversees internal data-protection practices as well as wider privacy and GDPR compliance matters.
You can contact our DPO at the following e-mail address:
data.protection@therehablab.com
The Rehab Lab acts as a Data Controller for personal information relating directly to our subscribers and their accounts. This may include information such as a subscriber's name, contact e-mail address, contact address, username and account information.
Subscribers may request access to, correction of, export of, or deletion of their personal data where applicable. Requests can be made by contacting The Rehab Lab's Data Protection Officer.
We provide subscribers with the option to opt out of marketing, product-update and special-offer e-mails. This does not include communications necessary for the administration, security or operation of an account, such as payment information, subscription notices, security notifications, service information or client requests that have been sent to The Rehab Lab in error.
Please note: The Rehab Lab does not store credit card information on our systems. Card payments are processed by Windcave, our payment processor.
When a subscriber chooses to store information about their clients within The Rehab Lab, the subscriber is the Data Controller of that information and The Rehab Lab acts as the Data Processor.
Client information processed through The Rehab Lab may include information such as a client's name and e-mail address. Subscribers determine whether this information is entered into The Rehab Lab and are responsible for establishing an appropriate lawful basis for processing their clients' personal data.
The Rehab Lab does not use client information for marketing and will not independently contact a subscriber's client except where necessary to provide a service requested by the subscriber, such as delivering a rehabilitation programme, or where otherwise required by law.
If a subscriber receives a valid request from a client relating to access, correction, portability or deletion of their personal information, The Rehab Lab will provide reasonable assistance to the subscriber in fulfilling that request where the relevant information is processed through The Rehab Lab.
Subscribers can delete individual client records from within The Rehab Lab. Deletion removes the client record from the active production system. Historical copies may remain temporarily within secure disaster-recovery backups until those backups expire in accordance with the backup-retention schedule described below.
Subscribers may request assistance with the export or deletion of client data by contacting The Rehab Lab's DPO at
data.protection@therehablab.com.
Subscribers may also choose not to use The Rehab Lab's Client section. The Client section can be disabled for all users within a subscription account by contacting The Rehab Lab Support or our DPO.
Active subscriptions
While a subscription is active, The Rehab Lab retains the subscriber's account data and any client data stored by the subscriber as required to provide The Rehab Lab's services.
Subscribers remain responsible, as Data Controllers, for determining what client information they enter into The Rehab Lab and how long that information should be retained. Client records can be deleted from the active The Rehab Lab system by authorised users at any time.
Expired subscriptions
When a subscription expires, access to the account is suspended. The Rehab Lab retains the subscriber's account and associated data for up to 12 months following the subscription expiry date.
This retention period allows a subscriber to reactivate their subscription without losing their existing account information, client records and rehabilitation programmes.
If the subscription is not reactivated within 12 months of its expiry date, the subscriber account and its associated data will be permanently deleted from The Rehab Lab's active production system.
Early deletion
A subscriber may request deletion of their account and associated data before the end of the 12-month retention period by contacting The Rehab Lab's Data Protection Officer at
data.protection@therehablab.com.
For security purposes, The Rehab Lab may require verification that a deletion request has been made by an authorised account holder before carrying out the deletion.
Once an account has been deleted from the active production system, it cannot be recovered through normal use of The Rehab Lab.
Information retained for legal purposes
Deletion of a subscriber account does not necessarily require The Rehab Lab to delete information that it is legally required to retain independently of the subscriber account.
For example, The Rehab Lab may retain invoices, payment and transaction records, and other information where retention is necessary to comply with applicable accounting, taxation, legal or regulatory requirements.
Information retained for these purposes will be retained only for the applicable purpose and retention period and will not remain available as part of the subscriber's active The Rehab Lab account.
The Rehab Lab maintains secure off-site database backups for security, disaster recovery and business continuity purposes.
When personal data is deleted from The Rehab Lab's active production database, historical copies of that information may remain temporarily within database backups created before the deletion occurred.
Backup retention schedule
Daily recovery points are retained for up to 30 days.
Weekly recovery points are retained for up to 8 weeks.
Monthly recovery points are retained for up to 12 months.
Database backups are automatically deleted when their applicable retention period expires. The Rehab Lab does not retain indefinite or permanent database backups. Consequently, personal data deleted from the active production system may remain within a historical disaster-recovery backup for up to 12 months following deletion.
Historical backups are maintained solely for security, disaster recovery and business continuity purposes and are not used as part of The Rehab Lab's normal operation.
If a historical database backup is restored, The Rehab Lab will take appropriate steps to ensure that applicable deletion requests and relevant data changes made after that backup was created are reapplied before the restored database is returned to normal production use.
The Rehab Lab's database backups are stored within a private Amazon Web Services (AWS) S3 environment. Public access to the backup storage is disabled and backups are protected using server-side encryption. Access to the backup environment is restricted and controlled using AWS identity and access-management permissions.
Communications between users and The Rehab Lab are protected in transit using encrypted HTTPS/TLS connections. The Rehab Lab's production database is hosted on our production server infrastructure. Database backups are created automatically every 24 hours and securely transferred to private Amazon Web Services (AWS) S3 storage for disaster-recovery purposes.
Database backups are protected using access controls and server-side encryption and are automatically expired according to the retention schedule described above.
Below is a list of the principal personal data collected and processed by The Rehab Lab:
Data Collected
Comments
First & Last Name
Used for correspondence and creation of subscriber's subscription invoice/receipt
Username
Used for logging into The Rehab Lab
Password
Stored using a one-way password hash for authentication
E-mail Address
Used for account administration, subscription correspondence, invoices/receipts, security notifications and service communications (encrypted)
Timezone
Used for date and time-related functionality within The Rehab Lab
Contact Address
Used for creation of subscriber subscription invoices/receipts (encrypted)
Data Collected
Comments
First & Last Name
Stored in encrypted form
E-mail Address
Used for sending rehabilitation programmes and related patient access information (encrypted)
Note: Subscribers can choose not to use The Rehab Lab's Client section. The Client section can also be disabled for all users within a subscription account. To request this, please contact The Rehab Lab Support or The Rehab Lab's DPO (data.protection@therehablab.com).
The Rehab Lab relies on selected third-party service providers and infrastructure in order to operate and provide our services. Depending on the service provided, these organisations may process data on our behalf or provide infrastructure used by The Rehab Lab.
Amazon Web Services (AWS)
Service: Cloud infrastructure, storage, e-mail delivery and database backup storage
Location: AWS services may process or store data in regions outside the European Economic Area, including the United States
Policy link
Google Analytics
Service: Website analytics
Location: Google provides services internationally, including from the United States
Policy link
Windcave (Payment Express)
Service: Payment processing
Location: Australia/New Zealand
Policy link
Hotjar
Service: Website analytics and user-experience analysis
Location: Hotjar operates internationally and is headquartered in Malta, European Union
Policy link
The Rehab Lab maintains technical and organisational measures designed to protect personal data and support our obligations under applicable data-protection law.
These measures include encryption of sensitive personal information, secure authentication, encrypted communications, access controls, restricted administrative access, secure off-site backups, defined data-retention periods and processes for responding to requests concerning personal data.
We aim to describe our privacy and data-protection practices in clear language and review our technical and organisational measures as our services and infrastructure evolve.
The Rehab Lab processes subscriber personal data where necessary to provide and administer our services, comply with legal obligations, protect the security of our services, or where another appropriate lawful basis applies.
Where consent is relied upon as the lawful basis for a particular type of processing, consent will be requested and can be withdrawn where applicable.
Subscribers are responsible for establishing an appropriate lawful basis for the client personal data they choose to process through The Rehab Lab.
The Rehab Lab maintains procedures for identifying, assessing and responding to suspected personal-data breaches.
Where a personal-data breach occurs, The Rehab Lab will assess the nature and potential consequences of the breach and will notify affected subscribers, supervisory authorities or other parties where notification is required under applicable data-protection law.
Individuals have the right, in applicable circumstances, to request access to personal data held about them.
Subscribers may contact The Rehab Lab's DPO to request access to personal data for which The Rehab Lab is the Data Controller. Where a subscriber receives a request relating to client data for which the subscriber is the Data Controller, The Rehab Lab will provide reasonable assistance in locating and exporting information processed through our service.
The Rehab Lab provides subscribers with tools to delete individual client records from the active production system.
Subscribers may also request deletion of their entire account and associated personal data by contacting our DPO at
data.protection@therehablab.com.
Account deletion requires verification from an authorised account holder.
When personal data is deleted, it is removed from The Rehab Lab's active production system and is no longer available through normal use of the service.
Historical copies of deleted information may remain temporarily within secure disaster-recovery backups until those backups expire according to The Rehab Lab's backup-retention schedule. Database backups are retained for a maximum of 12 months and are maintained solely for security, disaster recovery and business continuity purposes.
If a backup containing previously deleted personal data is restored, The Rehab Lab will take appropriate steps to ensure that applicable deletion requests are reapplied before the restored database is returned to normal production use.
Certain information may also be retained where The Rehab Lab is legally required to retain it, for example for accounting, taxation, legal or regulatory purposes.
Where the GDPR right to data portability applies, The Rehab Lab will provide relevant personal data in a structured, commonly used and machine-readable format where reasonably possible.
Where a subscriber receives a portability request concerning client data for which the subscriber is the Data Controller, The Rehab Lab will provide reasonable assistance in exporting relevant information held within our service.
To request a data export, please contact The Rehab Lab Support or our DPO
(data.protection@therehablab.com).
The Rehab Lab considers privacy and security when designing, developing and maintaining our services.
Technical and organisational safeguards include encrypted communications, encryption of sensitive stored personal information, password hashing, access controls, restricted administrative access, secure off-site database backups and defined backup-retention policies.
These measures are reviewed and updated as The Rehab Lab's software, infrastructure and security requirements evolve.
The Rehab Lab has appointed a team member based in Auckland, New Zealand, to oversee our internal data-protection practices and privacy and GDPR compliance matters.
Our Data Protection Officer can be contacted at
data.protection@therehablab.com.