Privacy Policy
This Privacy Policy explains how I collect, use, and protect your personal information in line with the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025. I am committed to handling your data responsibly, transparently, and securely.
For any privacy related queries my contact details can be found here
Information I Collect & Why
To give professional reflexology treatments I will need to ask and keep information about your health. I will only use this for informing reflexology treatments and for any advice I give about your treatment.
I may collect and store:
-
Contact details: name, email, phone number, emergency contact
-
Health information: medical history, lifestyle details, treatment notes
-
Booking and payment information: appointment records, invoices (no card details stored)
-
Website or social media enquiries: messages, forms, or feedback
Your information is used to:
-
Provide safe and effective reflexology and Indian head massage treatments
-
Manage bookings, communication, and payments
-
Meet legal, insurance, and professional obligations
-
Send optional updates or newsletters (only with your consent)
Lawful Basis for Processing
I process your personal data under:
-
a) Consent (e.g., receiving newsletters) - you can remove you consent any time by contacting me directly in writing by email at - simplesteptherapies@proton.me
-
b) Contractual obligation (providing treatments and managing bookings)
-
c) Legal obligation (insurance, HMRC requirements)
1.1 'Claims occurring' insurance - records kept for 7 years after the last treatment
1.2 Law regarding children's records - kept until they aged 25
1.3 CNHC requires I keep records for 8 years
-
d) Special category data (health information processed under Article 9(2)(h): healthcare provision) - to fulfill my role as a healthcare practitioner bound under AOR confidentiality and AOR code of conduct.
-
e) Recognised Legitimate Interests (DUAA 2025) only for:
1.1 to provide the best possible treatment options and advice
1.2 Safeguarding vulnerable individuals
1.3 Responding to emergencies that pose a risk to life or health
I will only share information in these situations when necessary and appropriate.
Protecting Your Data
-
Paper records are stored securely and accessible only to me
-
Digital records are encrypted and password‑protected
-
Data is never shared with third parties unless legally required or with your explicit consent
-
Records are retained for 7 years in line with insurance and HMRC rules
- After the period of retention, records are then permanently deleted including all medical records & documents from my secure cloud based server (protondrive), and all emails from my email provider (protonmail). Paper records are shredded.
Your Rights
You have the right to:
-
Access your personal data - you can ask me for copies of your personal data
-
Rectification: You can request corrections if you think personal information is inaccurate or incomplete.
- Erasure- you can ask for your personal details to be erased in certain circumstances
-
Withdraw consent for communications
- To restrict or object to the processing of your data in certain circumstances.
- To ask that I transfer the data you gave me to another organisation or to you in certain circumstances.
-
Make a Subject Access Request (SAR) SARs will be handled using a reasonable and proportionate search, and I may pause the response deadline if I need more information from you.
You do not have to pay for exercising your rights, and I have 1 month to respond to you.
Therapists Rights
If you don't agree to the therapist keeping records of information about you and your treatments, or if you don't allow them to use the information in the way they need to for treatments, they may not be able to treat you.
Your therapist must keep records of treatment for a certain period as described above, which may mean even if you ask them to erase any details about you, they might have to keep these details until after that period has passed (by law).
Your therapist can move your details between their computer and IT systems without your permission if your details are being protected from being seen by others.
GDPR Complaints Procedure
At Simple Step Reflexology, I take data protection seriously. If you have concerns about how your personal information has been handled, you have the right to raise a complaint.
This procedure explains how to do that and what you can expect.
You can raise a data protection concern by contacting me directly:
Email: simplesteptherapies@proton.me
Owner: Alex Cronk, Sole Trader
Location: Roundhill, Brighton, UK
Please include:
-
Your name
-
What your concern relates to
-
Any relevant dates or details
What Happens Next
I will:
-
Acknowledge your complaint within 30 days
-
Review and investigate the issue without undue delay
-
Contact you with a clear explanation of the outcome
-
Record the complaint in my GDPR Complaints Log (required under DUAA 2025)
If You Are Not Satisfied
If you are unhappy with the outcome, you may escalate your concern to the Information Commissioner’s Office (ICO):
Website: www.ico.org.uk Phone: 0303 123 1113
Under the DUAA 2025, clients must raise concerns with the organisation first before contacting the ICO.
Data Processors & Third‑Party Services
Email & Communication Providers
-
ProtonMail (Proton AG). Primary email and file storage provider. All active business communication and client records are held within Proton’s encrypted infrastructure.
-
Google (Gmail). Temporarily used to receive booking notifications from Calendly. Emails received here are deleted promptly and not stored long‑term. Google acts as a data processor under UK GDPR during this transitional period.
Booking & Scheduling
-
Calendly. Used for appointment scheduling. When a client books an appointment, Calendly generates a confirmation email that is currently routed through Gmail before being transferred to ProtonMail. Calendly processes client contact details and appointment information for scheduling purposes.
Email Marketing & Newsletters
- Mailchimp (Intuit Inc.). Used to manage mailing lists and send newsletters or wellbeing updates. Mailchimp processes subscriber names and email addresses and stores them securely within its platform. You can unsubscribe from Mailchimp emails at any time using the link provided in each message.
Cookies (website)
This website uses cookies to ensure it functions correctly and to help me understand how visitors use the site.
Types of cookies used:
-
Essential cookies: Required for the website to operate. These cannot be disabled.
-
Analytics cookies: Used to understand visitor behaviour and improve the site. These may run without explicit consent under the Data (Use and Access) Act 2025, but you can opt out at any time through your browser settings.]
Managing Cookies:
You can control or delete cookies through your browser. For more information, visit: https://www.allaboutcookies.org
By continuing to use this website, you agree to the use of essential cookies.
success.