PhysioWorkplace
Privacy Policy
Last updated 11 August 2026
This notice explains how Meadow Arc handles personal data for the PhysioWorkplace website, pre-launch service, and transactional communications.
Who is responsible
Meadow Arc, Sweden, operates PhysioWorkplace and is responsible for account, website, support, security, and service-administration data. Contact us at privacy@physioworkplace.com.
For patient information entered by a clinic, the clinic normally acts as controller and Meadow Arc acts as processor under the applicable customer agreement and data processing terms.
Data we handle
We may handle contact and account details, workplace membership, authentication and security events, support communications, service usage, technical diagnostics, and billing or agreement information.
Clinical or patient information is handled only when an authorised clinic uses those product functions. Transactional email must not contain clinical content.
Why we use data
We use data to provide and secure the service, authenticate users, deliver requested invitations and account messages, support customers, prevent abuse, meet legal obligations, and improve reliability.
Our legal bases may include performing a contract, legitimate interests in operating and securing the service, legal obligations, and consent where required.
Service providers and transfers
We use carefully selected providers, including Google Cloud and Firebase for application infrastructure, Amazon Web Services for transactional email, and Cloudflare for network and access protection.
Clinical records and clinical content are kept in our selected Swedish cloud regions. Firebase Authentication processes account identifiers and sign-in security data, including email address, IP address, and user-agent information, in the United States. Where processing involves an international transfer, we use applicable contractual and organisational safeguards.
Retention and security
We retain data only for the service, security, contractual, and legal periods that apply to it. Retention differs between active accounts, audit evidence, support records, backups, and deleted accounts.
We use access controls, encryption, environment isolation, monitoring, and documented recovery procedures. No system can guarantee absolute security.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is the legal basis.
Contact privacy@physioworkplace.com. You may also complain to the relevant data-protection authority, including the Swedish Authority for Privacy Protection (IMY).