Privacy Policy
1. How we use your personal data
We may collect sensitive personal data, such as health information, for the purposes of providing our services to you. We will collect and use this data only when it is necessary and with your consent or to fulfill our contractual obligations. Non-sensitive personal data refers to details such as your name, email address, and contact details. We will only share your non-sensitive personal data for marketing purposes with your explicit consent, and you have the right to withdraw this consent at any time.
2. Data retention
We will retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. For example, we are required to retain certain information for six years after you cease to be a client for tax purposes. Other data may be retained for a different period as required by law or for the legitimate interests of our business.
3. your rights
You have the following rights in relation to your personal data:
-
The right to access your data (subject access request)
-
The right to rectify inaccurate or incomplete data
-
The right to erase your data (in certain circumstances)
-
The right to restrict processing of your data
-
The right to object to processing of your data
-
The right to data portability (in certain cases)
For more information about your rights, please refer to the ICO website or contact us directly.
4. Disclosure of personal data
We may need to share your personal data with:
(i) Service providers who offer IT, system administration, or business support
(ii) Professional advisors, including lawyers, auditors, insurers, or accountants
(iii) Regulatory authorities such as HMRC
(iv) Third parties involved in the sale, merger, or transfer of our business or assets
(v) Healthcare professionals, where relevant, for treatment purposes
We require these third parties to handle your data securely and in compliance with the law.
5. INternational transfers
Some of our third-party providers are based outside of the EEA. In these cases, we ensure that appropriate safeguards are in place to protect your data, such as the use of Standard Contractual Clauses (SCCs), a code of conduct, or certification. If these safeguards are not in place, we will request your explicit consent before transferring your data, and you have the right to withdraw your consent at any time.
6. Keeping your data up to date
We strive to keep your data accurate and up-to-date. Please notify us promptly if there are any changes to your personal data (such as a change of address) so that we can update our records accordingly.
7. Data security
We employ a range of security measures to protect your data, including encryption, secure servers, and access control procedures to prevent unauthorized access or disclosure. Only authorized personnel with a business need will have access to your personal data, and they are required to maintain confidentiality.
8. Complaints
If you are unhappy with how we process your personal data, please contact us first so we can attempt to resolve your concerns. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
We may change this Privacy Policy from time to time and shall notify you of any changes.