Back to site

Legal

Data Processing Terms

Last updated: 16 August 2026

These terms describe how KinetiqTec processes personal data on behalf of clinics that use the platform. They should be read together with our Privacy Notice and Terms of Service.

Roles

For patient and clinical data entered into KinetiqTec, the clinic is the data controller and Kinetiq Performance Group acts as a processor, processing data only on the documented instructions of the clinic. KinetiqTec is built on Base44, which acts as a sub-processor providing hosting, authentication and the underlying data platform.

Categories of data

  • Patient demographic and contact data.
  • Appointment, scheduling and waiting-list data.
  • Clinical notes, assessments, treatment and rehabilitation data.
  • Exercise prescriptions, outcome measures and progress data.
  • Consent, audit and access-control records.

Purposes of processing

Data is processed only as necessary to provide the platform, including scheduling, clinical documentation, rehabilitation, patient portal access, secure communication, reporting and audit, in line with the clinic's configuration and instructions.

Sub-processors

Base44 provides infrastructure services as a sub-processor. We do not engage sub-processors that materially affect data security without appropriate terms in place. Material changes to sub-processors are communicated in advance where required.

Security measures

Security is supported through authenticated access, role-based permissions, organisation and clinic isolation, record-level permissions, consent records, audit logging and controlled exports. Base44's applicable security documentation governs infrastructure-level controls.

Data subject rights assistance

Where a clinic receives a request from a data subject, KinetiqTec will provide reasonable assistance to enable the clinic to respond, including access to or export of relevant data within the platform where authorised.

Breach notification

We will notify affected clinics of a personal data breach without undue delay where it is likely to result in a risk to data subjects, to the extent permitted and supported by Base44 infrastructure reporting.

International transfers

Where data is transferred or stored outside the applicable region, appropriate safeguards consistent with applicable data protection law are put in place.

Term and deletion

On termination, clinics may request export of their data. Data is then removed subject to applicable legal, accounting or professional retention requirements and Base44's retention processes.

Audit

Clinics may request reasonable information about how these terms are met. Base44's applicable documentation governs infrastructure-level assurance.

This document is provided for general information and does not constitute legal advice. Clinics remain responsible for their own compliance with applicable law and professional obligations. For platform infrastructure, Base44's applicable documentation governs.