Privacy Policy

Inner Harmony Sound Massage
Last updated: 4 September 2026

1. About this policy

This privacy policy explains how Inner Harmony Sound Massage collects, uses, stores and shares personal information when you visit www.innerharmonysoundmassage.co.uk, make an enquiry, book or receive a treatment, communicate with us, or provide information about a child. It also explains your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and related privacy law.

Inner Harmony Sound Massage provides sound massage and complementary wellbeing treatments. These services are intended to support relaxation and wellbeing and are not a substitute for medical diagnosis or treatment.

2. Who is responsible for your information

The data controller is Heidi Doughty, trading as Inner Harmony Sound Massage (“Inner Harmony”, “we”, “us” or “our”). This means Heidi decides why and how personal information is used.

For any privacy question or request, please contact Heidi using the details above.

3. Information we collect

Depending on how you interact with us, we may collect:

  • identity and contact details, such as your name, email address, telephone number and address;

  • enquiry and booking information, including appointment dates, service requested, location, preferences, cancellations and correspondence;

  • payment and transaction information, such as the amount paid and payment status; we do not normally retain full payment-card details;

  • health, wellbeing and accessibility information that you or a parent or guardian provides, including relevant medical conditions, medication, pain, pregnancy, sensory needs, allergies, disabilities, emotional wellbeing, treatment goals, contraindications and information needed to adapt a session safely;

  • consultation and treatment records, including consent, session notes, observations, adaptations, outcomes and follow-up information;

  • communications, including emails, website messages and telephone notes;

  • technical and usage information, such as IP address, browser or device information, pages visited, referring pages and cookie identifiers; and

  • marketing preferences and any consent given for testimonials, photographs or promotional communications.

Please provide only relevant information. If you give us personal information about someone else, you should have authority to do so and should make this policy available to them where appropriate.

4. Children and parent or guardian information

Where a client is under 18, we may collect the child’s name, date of birth or age, relevant health and developmental information, treatment needs, safeguarding information where necessary, and consultation and treatment records. We also collect the name, contact details, relationship and consent of the person with parental responsibility or legal guardianship.

A parent or guardian must provide the information and consent required for treatment unless the law permits the child to make the relevant decision independently and we are satisfied that the child has sufficient understanding. We will explain the treatment in an age-appropriate way and seek the child’s agreement wherever practicable. A parent or guardian should tell us if circumstances affecting parental responsibility, consent, collection or safeguarding change.

We do not knowingly use a child’s information for direct marketing. We do not publish a child’s name, image, testimonial or treatment story without specific, separate and appropriately informed permission from the parent or guardian and, where appropriate, the child.

5. How and why we use personal information

We use personal information to:

  • respond to enquiries and arrange consultations and appointments;

  • assess whether a treatment is suitable, identify contraindications, adapt sessions and provide treatments safely;

  • maintain accurate consent, consultation and treatment records;

  • take payment, issue receipts, manage cancellations and keep business and tax records;

  • communicate about appointments, aftercare, service changes and questions;

  • protect clients, children, practitioners and others, including responding to safeguarding or emergency concerns;

  • manage complaints, insurance matters and legal claims;

  • operate, secure and improve the website and understand its use; and

  • send optional news or offers where you have consented or another lawful direct-marketing rule permits this and a clear opt-out is provided.

6. Our lawful bases

We rely on one or more lawful bases depending on the activity:

  • Contract and steps before a contract: to answer a booking request, arrange and deliver a treatment, administer the booking and take payment.

  • Legal obligation: to keep tax and accounting records, respond to lawful requests and meet applicable safeguarding or other legal duties.

  • Legitimate interests: to run and protect the business, maintain appropriate records, respond to general enquiries, prevent fraud, establish or defend legal claims and improve services. We use this basis only where our interests are not overridden by your rights and interests, with particular care for children.

  • Consent: for optional marketing, non-essential cookies, testimonials, photographs or other uses where consent is appropriate. You may withdraw consent at any time without affecting earlier lawful use.

  • Vital interests: in a rare emergency where using or sharing information is necessary to protect someone’s life and consent cannot reasonably be obtained.

7. Special-category health information

Health information is special-category personal data and receives additional protection. In addition to an Article 6 lawful basis, we normally rely on your explicit consent—or the explicit consent of a person authorised to act for a child—to collect and use health information for suitability assessment, treatment planning, delivery, records and follow-up. Explicit consent is requested separately on the client form and can be withdrawn for future processing.

Withdrawal may mean we cannot safely provide or continue a treatment. We may retain information already recorded where another legal basis and special-category condition applies, for example where necessary to establish, exercise or defend legal claims or protect vital interests in an emergency. We do not sell health information or use it for advertising profiles.

8. Website, Squarespace and cookies

Our website is hosted and supported by Squarespace. When you browse the site, submit a form, make an online enquiry or use website features, Squarespace may process technical, usage, transaction and form information on our behalf and may set cookies or similar technologies. Squarespace Analytics may provide us with aggregated and usage information about visits to the website.

Some cookies are strictly necessary for the website to function and do not require consent. Analytics, advertising and other non-essential cookies will be used only after the required consent has been obtained. You should be able to accept, reject or manage non-essential cookies through the website cookie banner or settings.

Information may be processed outside the United Kingdom. Where this happens, we use an appropriate lawful transfer mechanism and safeguards.

9. Email and Google Workspace

We use Google Workspace to provide our business email service and to store and manage relevant email communications. Google may process account, contact, message and technical information on our behalf. We use email and telephone to respond to enquiries, administer appointments and provide relevant follow-up. Please avoid sending more health information by ordinary email than is necessary because standard email may not always be fully secure.

Service messages about an existing enquiry or booking are not marketing. Marketing emails will include a simple way to unsubscribe, and you can object or withdraw consent at any time. We may retain a minimal suppression record so that we can respect an opt-out.

10. Sharing information

We do not sell personal information. We disclose it only where necessary to trusted service providers or where lawfully required. Recipients may include:

  • Squarespace for website hosting, forms, commerce features, analytics and cookie controls;

  • Google Workspace for business email and related communication storage;

  • accountants, insurers, professional advisers and legal representatives;

  • a healthcare professional or emergency service where you ask us to share information, give appropriate consent, or an emergency or other lawful exception applies; and

  • the police, local authority, safeguarding bodies, regulators, courts or other authorities where disclosure is required or justified by law.

Providers acting for us may use information only under our instructions and must protect it appropriately. If a provider or recipient processes information outside the UK, we use an adequacy regulation, approved contractual safeguards or another lawful transfer mechanism, as applicable.

11. How long we keep information

We keep personal information only for as long as reasonably needed, including for legal, tax, insurance, safeguarding and claims requirements. Our normal retention periods are:

  • general enquiries that do not become bookings: up to 12 months after the last meaningful contact;

  • adult consultation, consent, health and treatment records: seven years after the last treatment or contact;

  • records relating to a child: until the child’s 25th birthday, or seven years after the last treatment if later, subject to insurer or legal requirements;

  • booking, invoice and financial records: six years after the end of the relevant financial year, or longer if legally required;

  • routine appointment correspondence: up to two years after the last appointment unless it forms part of a treatment, complaint or financial record;

  • marketing records: until consent is withdrawn or you object; a minimal suppression record may be retained to honour that choice;

  • cookie and analytics information: for the period stated in the website cookie settings or cookie notice; and

  • complaint, safeguarding, incident and legal-claim information: for as long as reasonably necessary in light of the matter and applicable limitation, regulatory or insurance periods.

At the end of the relevant period, information will be securely deleted or anonymised. We may shorten or extend a period where there is a documented reason, such as an active complaint, safeguarding matter, legal claim or insurer requirement.

12. Data security

We use proportionate technical and organisational measures designed to protect personal information from loss, misuse, unauthorised access, alteration or disclosure. These include access controls, strong passwords and multi-factor authentication where available, device and software updates, secure backups, limiting access to those who need it, secure disposal and care when sending sensitive information. No online or electronic system can be guaranteed completely secure.

If a personal-data breach creates a risk to people, we will assess it promptly and notify the Information Commissioner’s Office and affected individuals where the law requires.

13. Your data-protection rights

Depending on the circumstances, you may have the right to:

  • be informed about how your information is used and obtain access to it;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase information;

  • ask us to restrict its use;

  • object to processing based on legitimate interests or to direct marketing;

  • receive information you provided in a portable format where the right applies;

  • withdraw consent at any time where processing is based on consent; and

  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not currently make such decisions.

These rights are not absolute. We may need to verify your identity and may retain or continue using information where the law permits or requires. There is normally no charge, and we aim to respond within one month. A parent or guardian may exercise rights for a child where authorised and appropriate; the child’s own rights and evolving capacity will also be considered.

14. Complaints and the ICO

Please contact Heidi first if you have a concern so that we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection:

  • Website: www.ico.org.uk/make-a-complaint/

  • Telephone: 0303 123 1113

  • Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

You may contact the ICO at any time, although it generally recommends raising the matter with the organisation first.

15. Changes to this policy

We may update this policy when our services, suppliers or legal obligations change. The current version and effective date will be shown on the website. Where a change materially affects how we use existing information, we will take reasonable steps to notify affected people and obtain fresh consent where required.