Privacy Policy
Version: V.1
Published: 09/10/26
Review due: 09/10/27 or sooner
ICO no: ZC242325
ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact: 07860 378573 | info@handsonhearthealing.co.uk
Business: Hands on Heart Healing (a sole trader business operated by Melissa JonesManning)
Address: Elmhurst Crescent, St Thomas, Swansea, SA1 8EA
1. Who we are
Hands on Heart Healing provides Reiki, Reflexology, Divine Energy Healing, Crystal Healing and Hypnotherapy. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), the practitioner, Melissa JonesManning (trading as Hands on Heart Healing), is the "data controller" for the personal information described in this notice: the person who decides how and why your information is used.
This notice explains what information we collect about you, why we collect it, how we use and protect it, and what rights you have. Please read it before your first appointment and feel free to ask us anything that is not clear.
Data protection registration: ICO registration reference: ZC242325. We are a sole practitioner and are not required to appoint a Data Protection Officer. For any question about your information, contact us using the details above.
2. The personal information we collect
Depending on how you interact with us, we may collect:
Contact and identity details: name, address, phone number, email address, and date of birth.
Emergency contact details, where you choose to provide them. If you give us details of another person, please let them know that you have shared their details with us.
Health and wellbeing information relevant to your treatment, for example medical conditions, medications, injuries, pregnancy, mental health considerations relevant to treatment, and any other information you share about your physical or emotional wellbeing. This is "special category data" under Article 9 of the UK GDPR and receives extra legal protection (see Section 4).
Where relevant to sessions, information you choose to share about your spiritual or religious beliefs or practices. This is also special category data.
Notes made during and after consultations and treatment sessions, including your reasons for seeking treatment and your progress.
For hypnotherapy sessions, an audio recording of the session, made solely to support accurate transcription and clinical note-taking (see Section 5 for full details).
Appointment and booking history. Appointments are noted in the calendar on the practitioner's phone, using only your first name, the initial of your surname and the appointment time. This calendar is backed up to Apple's iCloud service. Your client folders and treatment notes are not included in that backup.
Financial information: invoices and payment records, including the name and contact details on them. We do not take card payments. You pay by cash, or by bank transfer that you start yourself, so we see your name, the amount and your payment reference on our bank records.
Correspondence between us, such as emails, texts, phone calls, or messages, including messages sent through Facebook Messenger or WhatsApp.
If you contact us through our website or social media, the details you provide in that enquiry. If you message our Facebook page via Messenger, we will see your Facebook profile name and the content of your messages. If you message us on WhatsApp we will see your phone number, profile name and the content of your messages. Please do not send health or other sensitive information through Messenger, WhatsApp, text or email; we will collect what we need securely through our client information and consent form instead.
Birthday voucher details: your email address and your birth month or date of birth, if you have agreed to receive birthday vouchers.
Testimonials (and photographs, if used) that you have given us written permission to publish.
Basic technical data when you visit our website, such as your IP address (see Section 12).
We collect this information directly from you, primarily through our client information and consent form (which we host online using Jotform), in-session conversations, and any follow-up correspondence. We do not buy personal information about you from any other organisation.
3. Why we use your information and our legal basis
We only use your personal information where the law allows us to. Our lawful bases under Article 6 of the UK GDPR are:
Contract: to provide the treatment you have booked, manage appointments, and take payment, and to take steps at your request before you book (such as answering enquiries, including those sent by messenger).
Consent: for anything we do not need to do in order to provide treatment, such as sending appointment reminders by text/email, emailing birthday vouchers and other marketing, recording hypnotherapy sessions, or using your testimonial or photograph. You can withdraw this consent at any time.
Legitimate interests: for basic business administration, and for the security of our records. You have the right to object to processing based on legitimate interests (see Section 10).
Legal obligation: where we must keep certain records, for example for tax purposes.
Health and other special category information about you is only ever processed with your explicit, freely given consent, as described in Section 4, apart from the limited situations in the table below. You do not have to disclose any health information you are not comfortable sharing, but this may affect our ability to safely provide treatment.
Summary of what we do and why
| What we do |
Information involved |
Lawful basis (UK GDPR Art. 6) |
Extra condition for health data (Art. 9) |
| Providing your treatment, booking and managing appointments |
Contact details, booking history, treatment notes |
Contract (Art. 6(1)(b)) |
Health information: your explicit consent (Art. 9(2)(a)) |
| Taking and recording payments |
Name, amount and payment reference (cash, or bank transfers you make) |
Contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)) |
Not applicable |
| Keeping health and wellbeing records so treatment is safe |
Health, medication and contraindication information; session notes |
Contract (Art. 6(1)(b)) |
Your explicit consent (Art. 9(2)(a)) |
| Audio recording of hypnotherapy sessions |
Session audio |
Your consent (Art. 6(1)(a)) |
Your explicit consent (Art. 9(2)(a)) |
| Appointment reminders by text or email |
Name, phone number or email, appointment time |
Your consent (Art. 6(1)(a)) |
Not applicable |
| Birthday vouchers and other marketing |
Name, email address, birth month or date of birth |
Your consent (Art. 6(1)(a)) |
Not applicable |
| Publishing testimonials or photographs |
Your name or initials, testimonial or photograph |
Your consent (Art. 6(1)(a)) |
Not applicable unless the content reveals health or beliefs, in which case your explicit consent (Art. 9(2)(a)) |
| Accounting and tax records |
Invoices and payment records |
Legal obligation (Art. 6(1)(c)) |
Not applicable |
| Security of records and basic business administration |
Records, correspondence, technical data |
Legitimate interests (Art. 6(1)(f)) |
Not applicable |
| Protecting you or others from serious harm, or responding to legal claims or complaints |
Relevant parts of your record |
Legal obligation, vital interests or legitimate interests (Art. 6(1)(c), (d), (f)), depending on the situation |
Where health data is involved: protecting vital interests (Art. 9(2)(c)) or legal claims (Art. 9(2)(f)), or safeguarding (DPA 2018, Schedule 1) |
Birthday vouchers and marketing
If you have agreed, we may email you a birthday voucher during your birthday month. We use your email address and birth month for this only. We do not use any marketing platform, we do not sell or share your details for marketing. You can also tell us at any time that you no longer wish to receive them, and we will stop straight away.
Testimonials and photographs
We only publish a testimonial or photograph with your explicit written consent, which tells you where it will appear. You can withdraw your consent at any time and we will remove it from our website and social media. We cannot recall copies that other people have already shared or saved.
Do you have to give us your information?
You do not have to give us any information, but we need your contact details, and relevant health information, to book and safely provide treatment. If you choose not to provide it, we may not be able to treat you. Giving us marketing, testimonial or photograph consent is entirely optional and does not affect your treatment.
Automated decisions
We do not make any decisions about you using automated processing or profiling.
4. Special category (health) data
Because our treatments relate to physical, mental and spiritual wellbeing, some of the information we hold about you is "special category data", a category of information the law treats as more sensitive, including data about health, and data revealing religious or philosophical beliefs.
We process this information on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR, given in writing on our client information and consent form, which explains exactly what will be recorded and why. We only use it as far as necessary to provide you with a safe and appropriate treatment, and in line with our internal Special Category Data Policy, which sets out the additional safeguards we apply.
You can withdraw your consent to us holding or using this information at any time, although this will not affect anything we have already done with it, and may mean we are unable to continue providing treatment to you.
In rare situations we may need to use or share health information without your consent: for example, to protect someone from serious harm (see Section 7), or to establish, bring or defend a legal claim.
5. Audio recording of hypnotherapy sessions
For hypnotherapy sessions, we may make an audio recording of your appointment. This section explains how and why we do this, alongside the information about special category data in Section 4.
Purpose: We record hypnotherapy sessions solely to help the practitioner transcribe the session accurately and prepare clear, reliable written clinical notes afterwards. Recordings are not used for training, marketing, or any other purpose, and are not shared with anyone outside the practice.
Legal basis: We only record a session with your consent. Under Article 6(1)(a) of the UK GDPR we rely on your consent to make the recording. Because the recording captures special category (health) data, we also rely on your explicit consent under Article 9(2)(a). This is given separately and specifically for the recording itself, in addition to your general treatment consent described in Section 4. Refusing to be recorded will not affect your treatment: we will take handwritten notes instead.
Storage and security: Audio recordings are made and held only on the practitioner's iPhone, which is protected by a passcode and biometric (fingerprint or face) access. They are not copied to iCloud or any other cloud service, and are not stored in our Proton Drive backups. Access is limited to the practitioner only.
Retention: Audio recordings are temporary. They are deleted permanently as soon as your written clinical notes have been completed, and in any event within 7 days of the session, whichever happens first. Permanent deletion includes removing the recording from the phone's "Recently Deleted" folder.
Your rights: You can withdraw your consent to being recorded at any time, including part-way through a session, without it affecting your therapy or any other treatment we provide. If you withdraw consent, we will take handwritten notes instead. Withdrawing consent does not affect the lawfulness of anything already done with a recording before you withdrew it.
6. Children and young people
We do occasionally treat clients under the age of 18. Where we do, we apply the following additional safeguards:
For clients under 16, our client information and consent form, including consent to process any health or other special category data, must be completed and signed by a parent or legal guardian before any treatment takes place. We also seek the young person's own agreement to treatment, in an age-appropriate way, wherever they are able to give it.
For clients aged 16 or 17, we will normally seek consent from both the young person and a parent or legal guardian. Some 16- and 17-year-olds are able to consent to their own treatment; where there is any doubt about a young person's capacity to understand and agree to treatment or to the use of their information, we will also obtain parental or guardian consent.
We apply extra care to information collected about children and young people, including limiting who can access it and thinking carefully about what we record and for how long.
We keep treatment records for clients who were under 18 at the time of treatment until they reach the age of 25 (see Section 8).
We do not email birthday vouchers or other marketing to anyone under 18 without a parent or guardian's consent.
Once a young person turns 18, they may exercise their own rights under Section 10 directly, independently of a parent or guardian.
If you have any safeguarding concerns about a child or young person, please raise them with us directly, or contact the relevant local authority children's services or the police if you believe a child is at immediate risk.
7. Who we share your information with
We do not sell your personal information to anyone. We only share it in limited circumstances:
With your GP or another healthcare professional, but only with your specific consent, or where we believe there is a serious risk to your safety or someone else's.
With service providers who support our business ("processors"). These include Jotform, which hosts our online client intake and consent forms and enquiry form; Proton Drive, which we use to store backup copies of client folders and records securely; Apple, whose iCloud service backs up the calendar on the practitioner's phone; QuickBooks Online, provided by Intuit Limited (part of Intuit Inc., USA), for invoices and accounting records; Microsoft, which provides our email service; and Namecheap, which hosts our website. These providers only act on our instructions and are required to keep your information secure.
Where we are required to by law, for example if requested by a court, regulator, or the police, or where we have serious concerns that a child or an adult at risk may be harmed. In those situations we will share only what is necessary, and where it is safe and lawful to do so we will tell you first.
With a professional body, insurer, or their legal advisers, if needed to respond to a complaint or insurance claim.
Jotform. Our online forms are provided by Jotform (Jotform Ltd, UK, with Jotform Inc., USA) acting as our processor. Your form data is stored on servers in Germany. Jotform may also process it in the USA, and occasionally in the UK and Turkey, and uses Google Cloud and/or Amazon Web Services for storage. Transfers to the USA rely on the UK-US Data Bridge. Transfers to other countries, including Turkey, rely on Standard Contractual Clauses with the UK International Data Transfer Addendum. Jotform's current subprocessors are listed at jotform.com/subprocessors. Our website's contact and booking enquiry forms are Jotform forms: when you use them you are taken to Jotform, and the information you enter is received by us through Jotform.
Proton Drive. We store backup copies of client folders and files using Proton Drive, an end-to-end encrypted cloud storage service provided by Proton AG (Switzerland). Proton acts as our data processor under a data processing agreement and may only handle your data on our instructions. Switzerland is recognised by the UK as providing adequate data protection, so your data is protected to UK standards.
Apple (iCloud). The calendar on the practitioner's phone, which contains only clients' first names, the initial of their surname and appointment times, is backed up to Apple's iCloud service. Apple may store and process this data in the United States and other countries. Apple states that it relies on standard contractual clauses for transfers of personal data from the United Kingdom. Apple's privacy policy is available at apple.com/legal/privacy. Client folders, treatment notes and audio recordings are not stored in iCloud.
Microsoft (email). We use Microsoft to provide our email service, so emails you send us, and our replies, are processed by Microsoft as our processor. Microsoft may process data in the United States and other countries. Microsoft's data protection terms include standard contractual clauses together with the ICO's International Data Transfer Addendum, which are a recognised safeguard for transfers of personal data from the UK.
Namecheap (website hosting). Our website is hosted on servers in the United States by Namecheap, Inc., which acts as our processor. It may collect basic technical data, such as your IP address, to keep the site running securely. This means that technical data is transferred outside the UK. Namecheap's published data processing agreement, which applies to our account, includes standard contractual clauses for transfers of personal data from the UK. Standard contractual clauses are a recognised legal safeguard under UK data protection law. We do not store client records or health information on our website.
Facebook, Messenger and WhatsApp (Meta). If you contact us through our Facebook Page or Messenger or by WhatsApp, your messages are also processed by Meta Platforms, which operates Facebook, Messenger and WhatsApp. Meta is a separate data controller: it handles your information for its own purposes under its own privacy policy (available at facebook.com/privacy/policy and whatsapp.com/legal/privacy-policy), and we do not control how it uses that information. Meta may store or transfer your information outside of the United Kingdom, including to countries that do not have a UK adequacy decision. You can exercise your data protection rights in relation to Meta directly with Meta. If you would prefer not to use these services, you can contact us by using the enquiry form on the website, by phone or by email instead.
QuickBooks Online (Intuit). We use QuickBooks Online, provided by Intuit Limited (part of Intuit Inc., USA), for invoices and accounting records. Intuit acts as our data processor under its data processing agreement. Intuit also uses some information as an independent controller for limited purposes such as product improvement and fraud prevention, as set out in its Global Privacy Statement. We do not record health or other sensitive information in QuickBooks. Intuit may process data in the United States and other countries. Our data processing agreement with Intuit includes standard contractual clauses together with the ICO's International Data Transfer Addendum, which are a recognised safeguard for transfers of personal data from the UK.
Aside from the transfers described above, we do not currently transfer your personal information outside the United Kingdom. If this changes, we will update this notice and ensure appropriate legal safeguards are in place.
8. How long we keep your information
We keep information for no longer than necessary. As a general guide:
Client consultation and treatment records: 7 years from your last appointment, then securely deleted or destroyed. If you were under 18 when treated, we keep them until your 25th birthday. This is a recognised benchmark for professional indemnity insurance, and we may keep records for longer only where our insurer requires it or a complaint or claim is ongoing.
Financial and payment records, invoices and accounting records, including those in QuickBooks: 6 years from the end of the financial year they relate to, in line with HMRC requirements.
Marketing consents and preferences: until you withdraw consent. Your birth month or date of birth is kept as part of your client record, and used for birthday vouchers only while you have consented.
Testimonials and photographs: for as long as they are published, until you withdraw your consent.
Audio recordings of hypnotherapy sessions: deleted when your notes are complete and within 7 days of the session (see Section 5).
Enquiries that do not lead to a booking (including enquiries made by email or messenger, WhatsApp, text or phone): normally deleted within 12 months.
Form submissions held in Jotform: your form submission is kept in Jotform for the same period as your client record (see the first bullet above). When your client record is deleted at the end of that period, we also delete your form submission from Jotform at the same time.
Historic paper records: kept under the same retention periods as digital records, then shredded.
Messages sent through Messenger and WhatsApp also remain on Meta's systems in line with Meta's own policies unless you delete them.
Copies of records held in Proton Drive are deleted on the same schedule as the originals.
Full detail is set out in our Data Retention and Deletion Policy, available on request.
9. How we protect your information
We take the security of your information seriously and use measures appropriate to a small practice handling sensitive data, including:
keeping the small number of historic paper records in a locked, secure filing cabinet, accessible only to the practitioner (we no longer create new paper records);
keeping digital client folders on the practitioner's iPhone, which is protected by a passcode and biometric access, with backup copies in Proton Drive, an end-to-end encrypted cloud storage service protected by two-factor authentication;
protecting our email account with a strong password;
limiting access to your records to the practitioner only, unless you are told otherwise;
making audio recordings only on the phone and deleting them promptly (see Section 5);
securely disposing of records once their retention period ends (shredding paper, permanently deleting digital files);
asking clients not to send health information through Messenger, WhatsApp, text or email and, if health details are sent that way, recording what is needed on our secure consent form and deleting the message where we can; and
having a procedure to deal with any data breach. If a breach is likely to put you at risk, we will report it to the Information Commissioner's Office within 72 hours where required and, if the risk to you is high, tell you without undue delay.
10. Your rights
Under UK data protection law, you have the right to:
be informed about how your personal information is used (as set out in this notice);
access a copy of the personal information we hold about you;
have inaccurate information corrected;
ask us to erase your information in certain circumstances;
ask us to restrict how we use your information in certain circumstances;
object to processing based on legitimate interests, and object to direct marketing at any time (we will stop straight away);
receive certain information in a portable, machine-readable format; and
withdraw consent at any time, where we rely on consent.
To exercise any of these rights, please contact us at info@handsonhearthealing.co.uk or by phone. We will normally respond within one month (this can be extended by up to two further months for complex requests, and we will tell you if so). There is no charge for making a request. We may need to verify your identity before responding, and in some cases the law allows us to withhold or limit what we provide (for example, where records also concern another person). Rights relating to information held by Meta must be exercised with Meta.
11. Complaints
If you are unhappy with how we have handled your personal information, please tell us first at info@handsonhearthealing.co.uk or by phone so we can try to put things right. We will acknowledge your complaint within 30 days, investigate it, and tell you the outcome without undue delay.
You also have the right to complain directly to the UK's data protection regulator, the Information Commissioner's Office (ICO). The ICO may ask whether you have raised your concern with us first:
Website: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Our website and cookies
Our website uses only essential cookies needed for it to work, and we do not use advertising or analytics cookies. Our website is hosted by Namecheap (see Section 7), which may collect basic technical data such as your IP address to keep the site running securely.
Our website contains links to Facebook, Google and Jotform, including the links to our contact and booking enquiry forms, which are hosted by Jotform. These take you to those companies' own sites, which have their own cookie and privacy policies, and we do not control how they use your information.
13. Changes to this notice
We may update this notice from time to time, for example to reflect changes in the law or in how we run the practice. The version number and effective date at the top of this document show when it was last updated. We will let existing clients know if we make a significant change.