Privacy Policy
1. Introduction
Welcome to In Tune Wellbeing’s privacy policy.
We are committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect your personal data when you interact with us, in accordance with the UK GDPR and the Data Protection Act 2018.
It also explains your legal rights and how to contact us or the Information Commissioner's Office if you have a complaint.
Our website and services are not intended for children under the age of 13, and we do not knowingly collect personal data from children.
2. Who We Are
In Tune Wellbeing is the data controller responsible for your personal data.
Contact details:
In Tune Wellbeing
Claire Branigan
Email: claire@intunewellbeing.co.uk
Address: Foxtail Barn, Fairspear Rd, Leafield, Oxfordshire, OX29 9NT
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO). We would, however, appreciate the opportunity to address your concerns first.
3. The Data We Collect About You
Personal data means any information that can identify an individual.
We may collect, use, store and transfer the following types of personal data:
Identity & Contact Data
First name, last name, title, date of birth, gender, email address, telephone number, and postal address.
Booking Data
Information relating to appointments, coaching sessions, workshops, and events.
Enquiry Data
Information you provide when contacting us via website forms, email, or social media.
Marketing & Communications Data
Your preferences for receiving marketing and your communication preferences.
Technical Data
IP address, browser type, device information, time zone, pages visited, and website usage data.
Payment Data
Payments are processed securely by third-party providers (e.g. Stripe, PayPal). We do not store your full financial details.
Special Category Data (Health Information)
To provide our wellbeing services, we may collect information about your health.
We process this data only where:
You have given explicit consent, in accordance with Article 9(2)(a) UK GDPR
It is necessary to deliver the services you have requested
You may withdraw your consent at any time. However, this may affect our ability to provide services safely and effectively.
4. How Your Personal Data Is Collected
We collect data using the following methods:
Direct interactions
Booking services or events
Submitting enquiries
Signing up to newsletters
Completing forms or surveys
Automated technologies
Cookies and analytics tools that track website usage
Third parties
Payment providers (e.g. Stripe, PayPal)
Booking platforms (e.g. Ticket Tailor)
Website and analytics providers (e.g. Google)
5. How We Use Your Personal Data (and Legal Bases)
We will only use your personal data where the law allows us to.
Purpose Type of Data Legal Basis
To provide services and manage bookings Identity, Contact, Booking, Health Contract + Explicit Consent (for health data)
To process payments Identity, Contact, Transaction Contract
To respond to enquiries Identity, Contact Legitimate Interests
To send newsletters and marketing Identity, Contact Consent
To improve our website and services Technical Data Legitimate Interests
To comply with legal obligations (e.g. tax records) Identity, Financial Legal Obligation
We will never sell your personal data or share it for third-party marketing.
6. Marketing Communications
You will only receive marketing communications from us if:
You have requested information from us, or
You have explicitly opted in
You can unsubscribe at any time by:
Clicking the unsubscribe link in emails
Contacting us directly
7. Sharing Your Personal Data
We share your data only with trusted service providers, including:
Payment processors (Stripe, PayPal)
Booking platforms (Ticket Tailor)
Website hosting and IT providers
Analytics providers (e.g. Google)
All third parties are required to:
Process your data only on our instructions
Keep your data secure
Not use your data for their own purposes
8. International Transfers
Some of our providers may transfer data outside the UK.
Where this occurs, we ensure appropriate safeguards are in place, such as:
UK International Data Transfer Agreement (IDTA)
UK Addendum to Standard Contractual Clauses
9. Data Security
We have implemented appropriate security measures to protect your personal data from:
Loss
Unauthorised access
Misuse or disclosure
We also have procedures in place to deal with any suspected data breach and will notify you and the ICO where required.
While we take security seriously, no system is completely secure, and transmission of data over the internet is at your own risk.
10. Data Retention
We retain personal data only as long as necessary.
Typical retention periods include:
Customer records: 6 years (for legal/tax purposes)
Enquiries: up to 12 months
Marketing data: until you unsubscribe
Health information: up to 6 years after last interaction, unless required longer
We may retain data longer where necessary for legal claims.
11. Cookies
Our website uses cookies to:
Ensure functionality
Analyse website usage
Improve user experience
We use non-essential cookies only with your consent via a cookie banner.
You can manage or disable cookies through your browser settings.
12. Your Legal Rights
Under UK data protection law, you have the right to:
Access your personal data
Request correction
Request erasure
Object to processing
Restrict processing
Request data transfer
Withdraw consent at any time
You will not usually have to pay a fee to exercise your rights.
We aim to respond to all legitimate requests within one month. We may need to verify your identity before processing your request.
13. Complaints
If you are unhappy with how we handle your data, you can contact us.
You also have the right to lodge a complaint with the Information Commissioner's Office:
Website: www.ico.org.uk
14. Changes to This Privacy Policy
We may update this policy from time to time. The latest version will always be available on our website.