Privacy Policy
Effective Date: 24 April 2025
Abuelita’s Wellbeing CIC is committed to protecting your personal data and respecting your privacy. This policy outlines how we collect, use, store, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
Abuelita’s Wellbeing CIC
Email: info@abuelitas.co.uk
Phone: 0748 159 2374
Data Protection Officer: Simona Ilincariu
2. Purpose of Data Collection
We collect and process your personal data to:
-
Provide holistic therapies and wellbeing services
-
Assess suitability for treatments
-
Communicate about appointments, follow-ups, and relevant services
-
Maintain accurate records for legal and insurance purposes
-
Share updates and promotions related to our services (with your consent)
3. Legal Basis for Processing
Our processing is based on:
-
Consent: You have given clear consent for us to process your data for specific purposes.
-
Contractual necessity: Processing is necessary for a contract we have with you or because you have asked us to take specific steps before entering into a contract.
-
Legal obligation: Processing is necessary for us to comply with the law (not including contractual obligations).
4. Data We Collect
We may collect the following information:
-
Full name, date of birth, and contact details (email, phone, address)
-
Medical history and treatment notes
-
Emergency contact information
-
Preferences and feedback related to our services
5. How We Collect Data
Data is collected through:
-
Online forms (e.g., GDPR/Privacy Consent Form, Medical History Form)
-
In-person consultations and treatment sessions
-
Email, phone, or other communications
6. Data Sharing
We do not share your personal data with third parties (outside Abuelita's Wellbeing CIC) except:
-
With your explicit consent
-
When required by law
-
With service providers who assist in our operations (e.g., secure data storage), under strict confidentiality agreements
7. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes we collected it, including for legal, accounting, or reporting requirements. Typically, this is for a period of 7 years after your last appointment.
8. Your Rights
Under the UK GDPR, you have the right to:
-
Access the personal data we hold about you
-
Request correction of inaccurate or incomplete data
-
Request deletion of your data (subject to legal obligations)
-
Object to or restrict the processing of your data
-
Withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal)
-
Lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been breached
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
10. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on our website, and where appropriate, notified to you by email.
Consent
By engaging with our services, you acknowledge that you have read and understood this privacy policy and agree to the collection and use of your personal data as described.
If you have any questions or wish to exercise your rights, please contact us at info@abuelitas.co.uk or 0748 159 2374.