top of page
Windlesham Wellbeing
Privacy and Cookie Policies

Privacy Policy

1. Who We Are

Windlesham Wellbeing (“we”, “us”, “our”) provides nutritional therapy, The Energy Alignment Method, Akashic Record sessions, and Vitafield HILDA diagnostic services. Jo Hookings is the Data Controller responsible for your personal data.

2. What This Policy Covers

This policy explains how we collect, use, store, and protect your personal information when you visit our website (windleshamwellbeing.co.uk), book or attend appointments, purchase on-demand classes, or contact us. It is provided in accordance with the UK GDPR and the Data Protection Act 2018.

3. The Information We Collect

We collect and process the following categories of personal data:

  • Identity & Contact Data: Name, email address, phone number, postal address, and date of birth.

  • Health Data (Special Category Data): Medical history, current symptoms, treatment records, clinical notes, and health information shared during consultations. This is necessary to provide safe care.

  • Booking Data: Appointment details, history, and correspondence managed via our secure booking system.

  • Payment Data: Handled securely by our third-party payment processor for both in-clinic and on-demand payments. We do not store full payment card details.

  • Account & Purchase Data: Your email address and a record of classes you have purchased.

  • Technical & Usage Data: IP address, browser/device information, and cookie data when you use our websites (see our Cookie Policy for more details).

  • Marketing Preferences: Records of whether you have consented to receive updates or newsletters from us.

4. How We Use Your Information and Our Lawful Bases

Under the UK GDPR, we must have a valid lawful basis to process your personal data under Article 6. Where we process special category (health) data, we rely on an additional condition under Article 9.

  • Providing Clinical Care and Keeping Records:

    • Lawful Basis (Art. 6): Contract (to provide services requested) and Legitimate Interests (to run a safe clinical practice).

    • Health-Data Condition (Art. 9): Article 9(2)(h) — provision of health care by a health professional bound by a duty of confidentiality.

  • Managing Bookings & Appointment Reminders:

    • Lawful Basis (Art. 6): Contract.

  • Taking and Recording Payments:

    • Lawful Basis (Art. 6): Contract and Legal Obligation (for tax and financial record-keeping).

  • Selling & Delivering On-Demand Classes:

    • Lawful Basis (Art. 6): Contract.

  • Sending Marketing (Newsletters / Offers):

    • Lawful Basis (Art. 6): Consent. You can withdraw your consent at any time without affecting the care we provide.

  • Website Security & Improvement:

    • Lawful Basis (Art. 6): Legitimate Interests.

  • Meeting Legal, Regulatory & Insurance Obligations:

    • Lawful Basis (Art. 6): Legal Obligation.

    • Health-Data Condition (Art. 9): Article 9(2)(h) — necessary to comply with clinical and legal standards.

5. Clinical Records and Professional Standards

As a Nutritional Therapist and healthcare practitioner, Jo is bound by duties of confidentiality and proper record-keeping. Your clinical records are kept securely and confidentially, and are shared only where you consent or where we are legally or professionally required to do so.

6. Marketing and Advertising Standards (ASA / CAP)

Any marketing we send is intended to be legal, decent, honest, and truthful, in line with the UK Code of Non-broadcast Advertising (the CAP Code), enforced by the Advertising Standards Authority (ASA). We only make health claims we can substantiate, we do not target vulnerable individuals, and any testimonials are genuine and used with consent. Every marketing email includes a clear and easy way to unsubscribe.

7. Cookies and Analytics

Our websites use cookies for essential functionality and, where required, with your consent. You can manage your choices through our cookie banner and your browser settings. For full details, please see our Cookie Policy.

8. Who We Share Your Data With

We use trusted third-party providers (“processors”) under contract, who act only on our instructions. By category, these include:

  • Clinical records & online booking software: To manage appointments and patient records securely.

  • Accounting & invoicing software: To manage payments, tax obligations, and bookkeeping.

  • Secure payment processors: For handling in-clinic and on-demand payments safely.

  • Website hosting, database & content-delivery providers: To run our websites and store digital content securely.

  • Video-hosting providers: For conducting remote video appointments.

  • Banking institutions: Into which customer payments settle.

  • Professional advisers and regulators: Such as our accountant, insurer, or regulatory bodies where legally required.

We never sell your personal data.

9. International Transfers

Some of our service providers may process data outside the UK. Where they do, we ensure appropriate safeguards are in place — such as UK adequacy regulations or the Information Commissioner’s International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses.

10. How Long We Keep Your Data

  • Clinical Records: Retained in line with professional indemnity guidance — generally at least 8 years after your last treatment for adults, and for children until their 25th birthday (or 8 years after the last contact, whichever is longer).

  • Booking, Payment & Tax Records: Retained as required by law for 6 years.

  • Marketing Data: Retained until you unsubscribe or ask us to stop.

11. How We Protect Your Data

We use appropriate technical and organizational measures — including secure, access-controlled systems, encryption in transit, and reputable processors — to keep your information safe and to prevent unauthorized access, loss, or misuse.

12. Your Rights

Under the UK GDPR, you have the right to:

  • Be informed about how your data is used.

  • Access the personal data we hold about you (Subject Access Request).

  • Have inaccurate data corrected.

  • Request erasure of your data (subject to our legal clinical record-keeping duties).

  • Restrict or object to our processing.

  • Request data portability.

  • Withdraw consent at any time.

To exercise any of these rights, please email us at windleshamwellbeing@gmail.com. We will respond within one month.

13. Complaints

If you have any concerns about how we handle your data, please contact us first so we can put things right. You also have the right to lodge a complaint with the UK data protection regulator:

Information Commissioner’s Office (ICO)

14. Use of Artificial Intelligence (AI)

We use artificial intelligence (AI) in a limited and transparent way:

  • Some images on our websites are original photographs, taken and used with consent, that have been subtly animated using AI to add gentle movement.

  • We do not use AI to make decisions about your care, process your health information, or use AI chatbots to interact with you.

  • Where we use AI to help prepare general (non-personalized) educational or exercise material, no personal or health information is entered, and all content is personally reviewed by Jo before use.

If our use of AI changes, we will update this policy and provide any disclosures required by law.

15. Changes to This Policy

We may update this policy from time to time. The latest version will always appear on this page, with the “last updated” date shown.

Cookie Policy

Cookie Policy

1. Introduction

Our website uses cookies to ensure our site runs smoothly, stays secure, and functions correctly. A cookie is a small text file that a website saves on your computer or mobile device when you visit the site. Because our website is built on the Wix platform, certain essential cookies are placed on your device automatically to maintain technical stability and security.

2. Why We Use Cookies

We only use strictly necessary (essential) cookies. These cookies are vital for the website's technical operation, security, and basic navigation. Because these cookies are strictly required to deliver a secure connection and a functioning website, they do not require prior user consent under data protection regulations (such as GDPR and PECR) and cannot be turned off.

3. Cookies Placed on Your Device

Below is the full list of essential cookies placed automatically by our website:

  • client-session-bind

    • Purpose: Used for API protection and platform security.

    • Category: Strictly Necessary

    • Duration: Session (Expires when your browser closes)

  • server-session-bind

    • Purpose: Used for API protection and secure backend server routing.

    • Category: Strictly Necessary

    • Duration: Session (Expires when your browser closes)

  • XSRF-TOKEN

    • Purpose: Used for security purposes to prevent Cross-Site Request Forgery (CSRF) attacks.

    • Category: Strictly Necessary

    • Duration: Session (Expires when your browser closes)

  • hs

    • Purpose: Used for platform security and integrity via the Hive security system.

    • Category: Strictly Necessary

    • Duration: Session (Expires when your browser closes)

  • bSession

    • Purpose: Used for system effectiveness and backend performance measurement.

    • Category: Strictly Necessary

    • Duration: 30 minutes

  • svSession

    • Purpose: Identifies unique visitors and tracks user sessions for core functionality.

    • Category: Strictly Necessary

    • Duration: Persistent (1 to 2 years)

How to Manage Cookies Through Your Browser

While you cannot disable these essential cookies through a cookie banner on our site, you can control, block, or delete cookies at any time directly through your web browser settings. Please note that blocking all cookies (including essential ones) may cause parts of our website to stop functioning correctly.

To manage cookies in your browser, look for the "Privacy", "Security", or "Clear Browsing Data" menus. You can find instructions for the most popular browsers below:

 Enforcement

Cookie rules are overseen by the Information Commissioner’s Office (ICO). Following the Data (Use and Access) Act 2025, the ICO’s powers under PECR were strengthened, with penalties for serious breaches aligned to those under the UK GDPR (up to £17.5 million or 4% of annual global turnover). We take our obligations seriously and keep our cookie practices under review.

6. Contact & complaints

If you have questions about our use of cookies, please contact windleshamwellbeing@gmail.com. You also have the right to complain to the ICO — ico.org.uk · 0303 123 1113.

bottom of page