Privacy Policy
Last updated: 11 September 2026
1. Introduction
At The Salty Sanctuary & www.thesaltysanctuary, your privacy matters to us. We are committed to handling your personal information responsibly, securely and transparently.
This Privacy Policy explains how The Salty Sanctuary ("we", "us", "our") collects, uses, and protects your personal information when you visit www.thesaltysanctuary.com (the "Site") or make an enquiry, book an appointment or use our services — including Pilates, osteopathy, facials, breathwork, and TMJ release — whether booked online, in person, or by phone. It also explains your rights under UK and EU data protection law.
The Salty Sanctuary operates in the United Kingdom and processes personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as applicable, and, where relevant, the EU GDPR.
2. Information We Collect
The information we collect depends on how you interact with us.
Contact and personal information
Name
Email address
Telephone number
Address, where required
Date of birth or age, where relevant to the services we provide
Booking and appointment information
When you book an appointment with us, we may collect:
The service you have booked
Appointment date and time
Booking history
Appointment notes
Information needed to manage or administer your appointment
Online bookings may be made through Cliniko or another third-party booking platform. Information submitted through these platforms may be processed by the relevant provider on our behalf, and may also be subject to that provider's own privacy policy.
Health and wellbeing information
Because some of our services involve physical wellbeing and treatment, we may ask you to provide information relevant to your presenting complaints, health, medical history, physical condition, symptoms, injuries, medications, allergies or other wellbeing considerations. This is particularly relevant to services such as Osteopathy, Massage, Pilates, Facials, Breathwork and TMJ release.
This is "special category data" under UK/EU GDPR. We only collect it with your explicit consent, and only to the extent needed to deliver a safe and appropriate treatment or service to you. We only ask for information that is reasonably relevant to providing our services safely and appropriately.
Payment information
We offer payment in person and online. Where you pay online, payment is processed by a third-party payment provider. We do not store complete payment card details ourselves (see Section 6).
Website and technical information
When you visit our website, certain technical information may be collected automatically, such as:
IP address
Browser type
Device type
Operating system
Pages visited
Approximate location information
Information about how you interact with our website, collected via cookies and similar technologies (see Section 7)
We do not knowingly collect information from children under 16 (see Section 11).
3. How We Use Your Information and Our Legal Basis
Purpose
Managing and confirming bookings, classes, or memberships
Assessing your needs and providing appropriate treatment or instruction
Processing payments
Responding to enquiries and customer service
Sending newsletters or marketing (only if you've opted in)
Improving our Site and services, analytics
Preventing fraud and ensuring Site security
Complying with legal, regulatory, insurance and professional obligations
Legal basis (UK/EU GDPR)
Performance of a contract
Performance of a contract / explicit consent (special category data)
Performance of a contract
Performance of a contract / legitimate interests
Consent
Legitimate interests
Legitimate interests
Legal obligation
We will never sell, rent or trade your personal information. We will not use your personal information for unrelated purposes without a lawful basis for doing so.
4. Health and Fitness Information
Because health-related information is sensitive, we:
only ask for what's necessary to deliver a safe class or session;
only collect it with your clear, explicit consent (e.g. a tick-box on an intake form, not a pre-ticked box);
limit access to this information to those who need it to deliver your service;
do not use it for marketing purposes; and
retain it only as long as necessary (see Section 9), or as long as required for insurance/liability purposes.
You can withdraw consent to hold this information at any time by contacting us, though this may affect our ability to safely provide certain services to you.
Sharing with other healthcare practitioners. As part of providing osteopathic care, there may be circumstances relating to your treatment, ongoing care, or diagnosis that require us to share your medical records with other healthcare practitioners — for example, your GP, a consultant, a surgeon, or a medical insurer. Where this is needed, we will always tell you first, unless we're under a legal obligation that prevents this. We do not sell or broker your data to anyone.
5. Confidentiality and Internal Access
Confidentiality is central to how we work. We keep who visits us, when, and any personal or medical details you share strictly confidential, and:
All client and patient records — booking details, contact information, and (for osteopathy) clinical case notes — are stored electronically in Cliniko, which is GDPR-compliant, password-protected, and access-controlled.
We do not keep paper-based client or patient records; everything is managed digitally through Cliniko.
Access is limited to those who need it to do their job. As sole practitioner and data protection contact, Paige has access to full booking and treatment records. If we ever bring on additional staff, any reception or administrative access will be limited to contact and booking details only — never clinical notes — and this policy will be updated accordingly.
Passwords and access controls are reviewed and updated regularly.
6. Who We Share Your Information With
We do not sell, rent or trade your personal information. We share personal information with the following categories of third parties, only as needed to run our business:
Website platform — Squarespace. Our Site is built and hosted on Squarespace, which processes technical and analytics data as our data processor. See Squarespace's Privacy Policy.
Booking and clinical records — Cliniko. We use Cliniko to manage bookings, appointments, and (for osteopathy) clinical case notes. Cliniko acts as our data processor. See Cliniko's Privacy Policy.
Payment processors — SumUp and/or Stripe. Depending on how you pay, your payment details are processed by SumUp or Stripe. They act as independent controllers for payment processing; see SumUp's Privacy Policy and Stripe's Privacy Policy.
Email marketing — Mailchimp. If you subscribe to our newsletter or marketing emails, your name and email address are processed by Mailchimp. See Mailchimp's Privacy Policy.
Analytics — Google Analytics. We use Google Analytics to understand how visitors use our Site. See Google's Privacy Policy.
Professional advisers and authorities — including our accountant, insurer, and, where relevant to osteopathy, the General Osteopathic Council, where required for legal, accounting, insurance, or regulatory reasons.
Law enforcement or other authorities, where we are legally required or permitted to disclose information.
We do not permit these providers to use your data for their own marketing purposes, and we only work with providers who commit to appropriate data protection standards.
7. Cookies
Our Site uses cookies and similar technologies to:
remember your preferences;
enable core Site and booking functionality; and
understand how visitors use our Site (analytics).
You can control or disable cookies through your browser settings, and where required by law we will ask for your consent to non-essential cookies via a cookie banner. Disabling some cookies may affect Site functionality (e.g. booking features).
8. International Data Transfers
Some of our service providers (including Squarespace and certain analytics or payment providers) may process data outside the UK/EEA, including in the United States. Where this happens, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or reliance on an adequacy decision.
9. Data Retention
We keep personal information only as long as necessary for the purposes described in this policy:
Booking and contract data: for the duration of our relationship with you, plus 7 years, to meet legal, accounting, and insurance requirements.
Health, fitness, and clinical information: retained for 7 years from your last treatment or appointment, except for osteopathy patients, where we follow the Osteopathic Practice Standards: adult patient records are kept for at least 8 years after your most recent appointment, and records for patients who were children or minors at the time of treatment are kept until they turn 25.
Marketing data: until you unsubscribe or withdraw consent.
Technical/analytics data: typically retained for 12–26 months, in line with Google Analytics' default retention settings.
When information is no longer required, we take reasonable steps to securely delete or anonymise it.
10. Your Rights
Under UK and EU GDPR, you have the right to:
Access the personal information we hold about you
Rectify inaccurate or incomplete information
Erase your information ("right to be forgotten"), in certain circumstances
Restrict how we use your information
Object to processing based on legitimate interests or for direct marketing
Data portability — receive your data in a portable format
Withdraw consent at any time, where processing is based on consent (this won't affect processing carried out before withdrawal)
These rights are subject to certain legal conditions and exemptions, so they may not apply in every situation.
To exercise any of these rights, contact us at Paige@thesaltysanctuary.com. We will respond within one month, as required by law.
If you're not satisfied with how we've handled your information, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, or your local EU supervisory authority if you're based in the EU.
11. Under 16s Information
Our services are not directed at children, and we do not knowingly collect personal information from anyone under 16, unless a particular service is specifically offered to children or young people, in which case we will take appropriate additional steps to comply with data protection requirements.
12. Security
We take appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse, including relying on the security measures provided by Squarespace and our other processors. No method of transmission or storage is 100% secure, but we work to protect your information to industry standards.
13. Third-Party Websites and Services
Our website may contain links to third-party websites, booking systems, payment providers or other online services. Once you leave our website or interact directly with a third-party service, that organisation's own terms and privacy policy will apply. We are not responsible for the privacy practices or security of third-party websites and services.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top shows when it was last revised. We encourage you to review this page periodically.
15. Contact Us
If you have any questions about this Privacy Policy, how we use your information, or your data protection rights, please contact us.
The Salty Sanctuary
Website: www.thesaltysanctuary.com
Email: Paige@thesaltysanctuary.com