{"id":3,"date":"2026-04-22T14:36:35","date_gmt":"2026-04-22T14:36:35","guid":{"rendered":"https:\/\/healhqstudio.com\/?page_id=3"},"modified":"2026-04-27T15:06:11","modified_gmt":"2026-04-27T15:06:11","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/healhqstudio.com\/?page_id=3","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"3\" class=\"elementor elementor-3\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ea35dc9 e-flex e-con-boxed e-con e-parent\" data-id=\"6ea35dc9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-107a2a4 elementor-widget elementor-widget-text-editor\" data-id=\"107a2a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p class=\"p1\">HEALHQ STUDIO &#8211; PRIVACY POLICY<\/p>\n<p class=\"p1\">Thank you for checking out our privacy policy. We take our client&#8217;s privacy seriously are<\/p>\n<p class=\"p1\">committed to protecting your privacy and handling your information in a responsible way while<\/p>\n<p class=\"p1\">you use our website and services. We want you to understand that this is a safe place for you to<\/p>\n<p class=\"p1\">discuss your feelings and concerns, and we operate in a highly confidential environment. This<\/p>\n<p class=\"p1\">policy sets out how data is collected and processed through the use of our website and when you<\/p>\n<p class=\"p1\">use our services.<\/p>\n<p class=\"p1\">We encourage you to read this policy alongside any other privacy notices we might provide, so<\/p>\n<p class=\"p1\">you&#8217;re fully in the loop about how and why we use your information.<\/p>\n<p class=\"p1\">Who&#8217;s in charge of your data?<\/p>\n<p class=\"p1\">The controller of your data is HEALHQ Studio (trading name of Jonathan Gunton), and we can be<\/p>\n<p class=\"p1\">contacted on:<\/p>\n<p class=\"p1\">Business Address: 17 Bushy Park, Totterdown, Bristol, BS4 2EG<\/p>\n<p class=\"p2\"><span class=\"s1\">Email address: <\/span>info@healhqstudio.com<\/p>\n<p class=\"p1\">ICO Registration Number: ZC093286<\/p>\n<p class=\"p1\">Not happy with something?<\/p>\n<p class=\"p1\">We&#8217;re committed to treating your personal data with respect, transparency, and care. If you ever<\/p>\n<p class=\"p1\">have questions or concerns about how your data is used, we want to hear from you, and we&#8217;ll do<\/p>\n<p class=\"p1\">our best to resolve things quickly and fairly. Under the Data (Use and Access) Act 2025, you have<\/p>\n<p class=\"p1\">the right to raise a complaint about how your personal data is handled. Here&#8217;s how:<\/p>\n<p class=\"p1\">Step 1: Email us at <span class=\"s2\">info@healhqstudio.com <\/span>with a brief description of your concern. You don&#8217;t<\/p>\n<p class=\"p1\">need to use legal language &#8211; just tell us what&#8217;s worrying you.<\/p>\n<p class=\"p1\">Step 2: We&#8217;ll acknowledge your message and respond without undue delay, usually within 10<\/p>\n<p class=\"p1\">working days.<\/p>\n<p class=\"p1\">Step 3: If you&#8217;re not satisfied with our response, you can escalate your concern to the Information<\/p>\n<p class=\"p1\">Commissioner&#8217;s O^ice (ICO) at <span class=\"s2\">www.ico.org.uk<\/span>.<\/p>\n<p class=\"p1\">What type of data do we collect about you?<\/p>\n<p class=\"p1\">&#8216;Personal data&#8217; is information that identifies you. If we&#8217;ve removed your identity (by making the<\/p>\n<p class=\"p1\">data anonymous), it won&#8217;t be classed as personal data. We might collect, use, store, and share<\/p>\n<p class=\"p1\">various types of personal data about you as follows:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Identity details such as first and last name.<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Contact details such as your address, email address and telephone number.<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Technical information such as your internet protocol (IP address), your login data,<\/p>\n<p class=\"p1\">browser type, version, time zone setting and location, operating system and platform, and<\/p>\n<p class=\"p1\">other technology on the devices you use to access our website (if\/when our website<\/p>\n<p class=\"p1\">becomes live).<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Financial information such as your bank account and payment card details.<\/p>\n<p class=\"p1\">2<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Transaction information including details about payments to and from you via Stripe,<\/p>\n<p class=\"p1\">PayPal or bank transfer, and other details of services you have purchased from us.<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Usage information about how you use our website and services.<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Marketing information such as your preferences on receiving marketing from us, along<\/p>\n<p class=\"p1\">with your communication preferences.<\/p>\n<p class=\"p1\">Special Category Data<\/p>\n<p class=\"p1\">This includes information about your health, including information about your existing and<\/p>\n<p class=\"p1\">previous medical health conditions, medication details, psychiatric history, and any other<\/p>\n<p class=\"p1\">relevant health information to enable us to carry out our hypnotherapy and transformational<\/p>\n<p class=\"p1\">services to you.<\/p>\n<p class=\"p1\">We do not collect any other Special Category Data about you (this includes details about your<\/p>\n<p class=\"p1\">race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions,<\/p>\n<p class=\"p1\">trade union membership and genetic and biometric data). Nor do we collect any information<\/p>\n<p class=\"p1\">about criminal convictions and o^ences.<\/p>\n<p class=\"p1\">Consents for Health Data<\/p>\n<p class=\"p1\">We require your specific consent to process Special Category Data so, when you submit your<\/p>\n<p class=\"p1\">details or sign our Terms and Conditions, we will ask you to confirm your consent to this<\/p>\n<p class=\"p1\">processing.<\/p>\n<p class=\"p1\">How do we collect your personal data?<\/p>\n<p class=\"p1\">We use di^erent methods to collect data from and about you. The majority of the time, our<\/p>\n<p class=\"p1\">information is collected directly when you contact us in the following ways:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you enquire about and\/or apply for our services<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you fill in any new client onboarding forms or your initial consultation assessment<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you complete any forms before or during an appointment or session<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Verbally during discussions and hypnotherapy\/transformational sessions<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Correspondence with us via post, phone, email or otherwise<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you subscribe to our service, digital audio products, or newsletter<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you request marketing communications to be sent to you<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>When you give us feedback or contact us<\/p>\n<p class=\"p1\">Automated Technologies<\/p>\n<p class=\"p1\">Another method we may use to collect data includes the use of automated technologies or<\/p>\n<p class=\"p1\">interactions, like website cookies or other similar technologies (if we implement these in future).<\/p>\n<p class=\"p1\">This includes information about your equipment, browsing actions and patterns.<\/p>\n<p class=\"p1\">This data collection helps us to improve user experience, and to gather information about how<\/p>\n<p class=\"p1\">you use our website.<\/p>\n<p class=\"p1\">Third-Party Data<\/p>\n<p class=\"p1\">3<\/p>\n<p class=\"p1\">We may also receive data from third-parties such as:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Technical information from analytics providers (such as Google)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Payment processing information from Stripe and Paypal (our payment processors)<\/p>\n<p class=\"p1\">What happens if you don&#8217;t provide us with the required data?<\/p>\n<p class=\"p1\">Where we need to collect personal data by law, or under the terms of a contract we have with you,<\/p>\n<p class=\"p1\">and you fail to provide that data when requested, we may not be able to perform the contract we<\/p>\n<p class=\"p1\">have or are trying to enter into with you (for example, to provide you with hypnotherapy services<\/p>\n<p class=\"p1\">or transformational programmes). In this case, we may have to cancel a service or product you<\/p>\n<p class=\"p1\">have with us, but we will notify you if this is the case at the time.<\/p>\n<p class=\"p1\">What are the purposes for which we use your personal data?<\/p>\n<p class=\"p1\">The purposes for which we will be using your data include:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To register you as a new client<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To conduct suitability assessments and ensure our services are appropriate for your<\/p>\n<p class=\"p1\">needs<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To provide our hypnotherapy and transformational services, including 1:1 sessions, the<\/p>\n<p class=\"p1\">90-Day Reset Transformation Programme, and digital audio products<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To process and deliver any orders, including:<\/p>\n<p class=\"p1\"><span class=\"s4\">o <\/span>Managing payments, fees and charges via Stripe, Paypal or bank transfer<\/p>\n<p class=\"p1\"><span class=\"s4\">o <\/span>Collecting and recovering money owed to us<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To manage our relationship with you, including:<\/p>\n<p class=\"p1\"><span class=\"s4\">o <\/span>Notifying you about changes to our Terms and Conditions or this privacy policy<\/p>\n<p class=\"p1\"><span class=\"s4\">o <\/span>Asking you to leave a review and\/or take a survey<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To send you relevant marketing information about our services (if you have consented or<\/p>\n<p class=\"p1\">where we have a legitimate interest)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To enable you to complete a survey<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To administer and protect our practice and website (including troubleshooting, data<\/p>\n<p class=\"p1\">analysis, testing, system maintenance, support, reporting and hosting of data)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To deliver relevant website content to you<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To use data analytics to improve our website, services, marketing, client relationships and<\/p>\n<p class=\"p1\">experiences<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To make suggestions and recommendations to you about services that may be of interest<\/p>\n<p class=\"p1\">to you<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To share necessary information with our accountant for tax and accounting purposes<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To share financial transaction data with Xero (our accounting software) which monitors<\/p>\n<p class=\"p1\">bank accounts for accounting purposes<\/p>\n<p class=\"p1\">4<\/p>\n<p class=\"p1\">What is our legal basis for processing your data?<\/p>\n<p class=\"p1\">We rely on one or more of the following lawful conditions to process your data as outlined above:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To fulfil our contract with you (e.g., providing services you&#8217;ve booked)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>For our legitimate interests (e.g., running our practice, improving services, preventing<\/p>\n<p class=\"p1\">fraud)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>To comply with legal obligations (e.g., tax and accounting requirements)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Your explicit consent (especially for collecting and processing sensitive health data)<\/p>\n<p class=\"p1\">We may process your personal data for more than one lawful reason at a time, depending on the<\/p>\n<p class=\"p1\">specific purpose for which we are using your data. If you&#8217;d like more information on the specific<\/p>\n<p class=\"p1\">legal ground we are relying on, please feel free to contact us.<\/p>\n<p class=\"p1\">Our Lawful Basis: Recognised Legitimate Interests<\/p>\n<p class=\"p1\">We sometimes process your personal data under what&#8217;s called a &#8220;recognised legitimate interest&#8221;.<\/p>\n<p class=\"p1\">This is a lawful basis introduced by the Data (Use and Access) Act 2025. This means we use your<\/p>\n<p class=\"p1\">data in ways that support important public or organisational aims, while respecting your rights<\/p>\n<p class=\"p1\">and freedoms.<\/p>\n<p class=\"p1\">Examples include:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Helping prevent fraud or misuse of our services<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Supporting safeguarding and professional standards<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Responding to emergencies or protecting wellbeing<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Improving accessibility and inclusion in our resources<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Running and growing our hypnotherapy practice e^ectively<\/p>\n<p class=\"p1\">We always carry out a balancing test to make sure our interests don&#8217;t override yours. You have the<\/p>\n<p class=\"p1\">right to object to this type of processing at any time, and we&#8217;ll explain your options clearly.<\/p>\n<p class=\"p1\">If you&#8217;d like to know more or raise a concern, just email us at <span class=\"s2\">info@healhqstudio.com<\/span>. We&#8217;re<\/p>\n<p class=\"p1\">committed to transparency and respectful data use.<\/p>\n<p class=\"p1\">Do we use Cookies?<\/p>\n<p class=\"p1\">Our website is currently not live. When our website goes live in future, we may use cookies to help<\/p>\n<p class=\"p1\">make our website work better for you, remembering your preferences and improving your<\/p>\n<p class=\"p1\">experience. You will be able to control cookie settings in your browser.<\/p>\n<p class=\"p1\">If we do implement cookies, we will update this privacy policy and provide a separate Cookie<\/p>\n<p class=\"p1\">Policy with full details.<\/p>\n<p class=\"p1\">Do we use AI or Automated Decision-Making?<\/p>\n<p class=\"p1\">We do not currently use AI tools or automated decision-making systems in our practice. All<\/p>\n<p class=\"p1\">decisions regarding client suitability, treatment approaches, and service provision are made by<\/p>\n<p class=\"p1\">Jonathan Gunton personally.<\/p>\n<p class=\"p1\">5<\/p>\n<p class=\"p1\">If we introduce AI tools or automated systems in future, we will update this privacy policy and<\/p>\n<p class=\"p1\">obtain any necessary additional consents.<\/p>\n<p class=\"p1\">Do we use your data for marketing purposes?<\/p>\n<p class=\"p1\">We may send you marketing communications about our services, programmes, digital audio<\/p>\n<p class=\"p1\">products, and other o^erings that may be of interest to you. Our lawful ground for processing your<\/p>\n<p class=\"p1\">personal data to send you marketing communications is either your consent or our legitimate<\/p>\n<p class=\"p1\">interests (namely to grow our practice).<\/p>\n<p class=\"p1\">If we send you marketing communications and you no longer wish to receive them, you can<\/p>\n<p class=\"p1\">opt out anytime by:<\/p>\n<p class=\"p2\"><span class=\"s5\">\u2022 <\/span><span class=\"s1\">Contacting us at <\/span>info@healhqstudio.com<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Clicking on the &#8216;unsubscribe&#8217; button in our marketing communications<\/p>\n<p class=\"p1\">Do we use third-party links?<\/p>\n<p class=\"p1\">Our website (when live) might link to third-party websites, tools and apps. Clicking on these links<\/p>\n<p class=\"p1\">may allow third parties to collect or share your data. We do not control said websites and are not<\/p>\n<p class=\"p1\">responsible for said websites&#8217; privacy policies. When you leave our website, we encourage you to<\/p>\n<p class=\"p1\">read the privacy policy of every website you visit.<\/p>\n<p class=\"p1\">Do we ever share your personal data?<\/p>\n<p class=\"p1\">We take your data&#8217;s security seriously. HEALHQ Studio is a sole practitioner practice with no sta^,<\/p>\n<p class=\"p1\">so your data is not shared with employees or team members.<\/p>\n<p class=\"p1\">However, we may share your personal data with the following parties for specific purposes:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Our accountant \u2013 for tax, accounting and financial compliance purposes<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Xero (accounting software provider) \u2013 which monitors our bank accounts for accounting<\/p>\n<p class=\"p1\">purposes. Xero processes data as a processor in accordance with data protection<\/p>\n<p class=\"p1\">requirements<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Stripe and PayPal (payment processors) \u2013 for processing card payments securely.<\/p>\n<p class=\"p1\">Stripe acts as a data processor and has its own privacy policy<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Professional advisers \u2013 including lawyers, bankers, auditors and insurers who provide<\/p>\n<p class=\"p1\">consultancy, banking, legal, insurance and accounting services<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Professional supervisors \u2013 As a registered member of the General Hypnotherapy<\/p>\n<p class=\"p1\">Register (GHR), we consult with another hypnotherapy professional for supervision<\/p>\n<p class=\"p1\">purposes. This is to ensure we reflect and improve on our practice. When discussing<\/p>\n<p class=\"p1\">clients in supervision we only refer to clients by their first name and identifiable<\/p>\n<p class=\"p1\">information is minimised<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Healthcare professionals \u2013 Sometimes we may need to share details with your GP or<\/p>\n<p class=\"p1\">other healthcare professional. We will always get your consent prior to doing this.<\/p>\n<p class=\"p1\">However, when the information concerns risk of harm to you or another person, we may<\/p>\n<p class=\"p1\">need to disclose information about you without your consent for your own safety or for<\/p>\n<p class=\"p1\">the safety of someone else (as set out in our Terms and Conditions, Section 10)<\/p>\n<p class=\"p1\">6<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>HM Revenue &amp; Customs, regulators and other authorities \u2013 who require reporting of<\/p>\n<p class=\"p1\">processing activities in certain circumstances<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Courts, legal representatives, or other relevant authorities \u2013 where we are required to<\/p>\n<p class=\"p1\">do so by law, or where it is necessary to protect vital interests<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Google \u2013 we store client data using Google services with two-factor authentication (2FA)<\/p>\n<p class=\"p1\">security enabled<\/p>\n<p class=\"p1\">All of the above third parties have a requirement to respect the security of your personal data. We<\/p>\n<p class=\"p1\">do not permit them to use your personal data for their own purposes \u2013 they are only permitted to<\/p>\n<p class=\"p1\">process your data for specified purposes in line with our instructions or their legal obligations.<\/p>\n<p class=\"p1\">Do we ever transfer your data internationally?<\/p>\n<p class=\"p1\">Some of the third-party services we use (such as Google and Stripe) may store or process data<\/p>\n<p class=\"p1\">on servers located outside the United Kingdom and European Economic Area (EEA).<\/p>\n<p class=\"p1\">Whenever we transfer your personal data out of the United Kingdom, we make sure it is protected<\/p>\n<p class=\"p1\">by implementing one or more of the following safeguards:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>We only transfer your personal data to countries that have been deemed to provide an<\/p>\n<p class=\"p1\">adequate level of protection for personal data<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Where we use certain service providers, we rely on specific contracts approved by the UK<\/p>\n<p class=\"p1\">Information Commissioner&#8217;s O^ice which give personal data the same protection it has<\/p>\n<p class=\"p1\">in the UK<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>We use service providers (such as Google and Stripe) that have robust data protection<\/p>\n<p class=\"p1\">frameworks and security measures in place<\/p>\n<p class=\"p1\">Please contact us if you want further information on the specific safeguards used when<\/p>\n<p class=\"p1\">transferring your personal data out of the United Kingdom.<\/p>\n<p class=\"p1\">How secure is your data with us?<\/p>\n<p class=\"p1\">We have strong security measures in place to keep your personal information safe:<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>All client data is stored securely using Google services with two-factor authentication<\/p>\n<p class=\"p1\">(2FA) enabled<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Only Jonathan Gunton has access to your personal data<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Data is processed in accordance with strict confidentiality requirements as a registered<\/p>\n<p class=\"p1\">member of the General Hypnotherapy Register (GHR)<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Payment data is processed securely through Stripe, which is PCI DSS compliant<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>We maintain appropriate technical and organisational measures to protect against<\/p>\n<p class=\"p1\">unauthorised or unlawful processing and against accidental loss, destruction or damage<\/p>\n<p class=\"p1\">In the rare circumstances that there is a personal data breach, we have procedures in place and<\/p>\n<p class=\"p1\">will notify you, along with the Information Commissioner&#8217;s O^ice (ICO), when we&#8217;re legally<\/p>\n<p class=\"p1\">required to.<\/p>\n<p class=\"p1\">7<\/p>\n<p class=\"p1\">Children&#8217;s Data &amp; Age-Appropriate Design<\/p>\n<p class=\"p1\">Our services are only available to clients aged 18 years and over. We do not knowingly collect or<\/p>\n<p class=\"p1\">process personal data from children or minors under the age of 18.<\/p>\n<p class=\"p1\">If we become aware that we have inadvertently collected personal data from someone under 18,<\/p>\n<p class=\"p1\">we will delete that information promptly.<\/p>\n<p class=\"p1\">What is our process for retaining your data?<\/p>\n<p class=\"p1\">We only keep your data as long as necessary for the reasons we collected it.<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Medical\/clinical records (including session notes, health information, and treatment<\/p>\n<p class=\"p1\">records): We retain these for 7 years after treatment has finished, in line with<\/p>\n<p class=\"p1\">professional standards and regulatory requirements<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Basic client information (including contact, identity, financial and transaction data): We<\/p>\n<p class=\"p1\">retain this for six years after you cease being a client, for tax and accounting purposes<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Initial enquiries: If you contact us with an initial enquiry and share personal details but<\/p>\n<p class=\"p1\">do not then become a client, we will delete your personal information after four weeks.<\/p>\n<p class=\"p1\">If you confirm you do not want to pursue a service within those four weeks, we will destroy<\/p>\n<p class=\"p1\">the information immediately<\/p>\n<p class=\"p1\"><span class=\"s3\">\u2022 <\/span>Accounting and financial records: Retained in accordance with legal requirements<\/p>\n<p class=\"p1\">(typically 6-7 years)<\/p>\n<p class=\"p1\">For information that does not fall under the above categories, to determine the appropriate<\/p>\n<p class=\"p1\">retention time, we consider what kind of data it is, how sensitive it is, the risks if it&#8217;s misused, why<\/p>\n<p class=\"p1\">we need it, and applicable legal, regulatory, tax, and accounting requirements.<\/p>\n<p class=\"p1\">What are your legal rights in relation to your data?<\/p>\n<p class=\"p1\">You have the following rights regarding your personal data:<\/p>\n<p class=\"p1\">1. Access (Subject Access Request): You have the right to ask us what personal data we hold<\/p>\n<p class=\"p1\">about you and to receive a copy of that data. We&#8217;ll respond within one calendar month, but if we<\/p>\n<p class=\"p1\">need to verify your identity first, we may pause the clock while we do so. This helps protect your<\/p>\n<p class=\"p1\">data and ensures we&#8217;re sharing it with the right person. To make a request, just email us at<\/p>\n<p class=\"p1\"><span class=\"s2\">info@healhqstudio.com <\/span>with the subject line &#8220;Subject Access Request&#8221; or &#8220;DSAR Request&#8221;. You<\/p>\n<p class=\"p1\">don&#8217;t need to use legal language &#8211; just let us know what you&#8217;d like to see or understand.<\/p>\n<p class=\"p1\">2. Correction: If the personal data we have about you is incomplete or incorrect, you can ask us<\/p>\n<p class=\"p1\">to correct it.<\/p>\n<p class=\"p1\">3. Erasure: You can ask us to delete your personal data. However, there might be legal reasons<\/p>\n<p class=\"p1\">that prevent us from fulfilling this request (for example, statutory retention requirements for<\/p>\n<p class=\"p1\">clinical and tax records). If such reasons exist, we will inform you when you make your request.<\/p>\n<p class=\"p1\">4. Objection: In certain situations, you have the right to object to the processing of your personal<\/p>\n<p class=\"p1\">data, particularly where we are processing it based on legitimate interests.<\/p>\n<p class=\"p1\">5. Restriction of Processing: You can request that we restrict the processing of your personal<\/p>\n<p class=\"p1\">data under specific circumstances.<\/p>\n<p class=\"p1\">8<\/p>\n<p class=\"p1\">6. Data Portability: You have the right to request the transfer of your personal data directly to you<\/p>\n<p class=\"p1\">or to a third party of your choice in a structured, commonly used, machine-readable format.<\/p>\n<p class=\"p1\">7. Withdrawal of Consent: At any point where we rely on your consent to process your personal<\/p>\n<p class=\"p1\">data (such as for processing health data or marketing), you have the right to withdraw this<\/p>\n<p class=\"p1\">consent. Withdrawal of consent will not a^ect the legality of the processing done before the<\/p>\n<p class=\"p1\">consent was withdrawn. Should you withdraw your consent, we might be unable to provide you<\/p>\n<p class=\"p1\">with certain services. We will inform you if that is the case when you withdraw your consent.<\/p>\n<p class=\"p1\">How to exercise your rights<\/p>\n<p class=\"p1\">If you wish to exercise any of the rights set out above, please contact us at<\/p>\n<p class=\"p2\">info@healhqstudio.com<span class=\"s1\">.<\/span><\/p>\n<p class=\"p1\">We won&#8217;t charge any fees for you to request access to your personal data. However, a reasonable<\/p>\n<p class=\"p1\">fee may be charged if your request is clearly unjustified, repetitive or excessive.<\/p>\n<p class=\"p1\">We try to respond to all legitimate requests within one month. Occasionally it could take us<\/p>\n<p class=\"p1\">longer than a month if your request is particularly complex. In this case, we will notify you and<\/p>\n<p class=\"p1\">keep you updated.<\/p>\n<p class=\"p1\">If you&#8217;re unhappy with how we handle your request, you can raise a concern with the Information<\/p>\n<p class=\"p1\">Commissioner&#8217;s Ofice (ICO) at <span class=\"s2\">www.ico.org.uk<\/span>.<\/p>\n<p class=\"p1\">Changes to this Privacy Policy<\/p>\n<p class=\"p1\">We regularly review our privacy policy to ensure it remains current and compliant with data<\/p>\n<p class=\"p1\">protection laws. Any changes we make will be posted on this page (and on our website when it<\/p>\n<p class=\"p1\">goes live).<\/p>\n<p class=\"p1\">Please keep us updated if your personal data changes (such as your address, phone number, or<\/p>\n<p class=\"p1\">email).<\/p>\n<p class=\"p1\">Contact Us<\/p>\n<p class=\"p1\">If you have any questions about this privacy policy, how we handle your data, or wish to exercise<\/p>\n<p class=\"p1\">any of your rights, please don&#8217;t hesitate to contact us:<\/p>\n<p class=\"p1\">HEALHQ Studio<\/p>\n<p class=\"p1\">Trading name of Jonathan Gunton<\/p>\n<p class=\"p1\">17 Bushy Park, Totterdown, Bristol, BS4 2EG<\/p>\n<p class=\"p2\"><span class=\"s1\">Email: <\/span>info@healhqstudio.com<\/p>\n<p class=\"p1\">ICO Registration Number: ZC093286<\/p>\n<p class=\"p1\">Thank you for reading our privacy policy. We&#8217;re committed to protecting your privacy and<\/p>\n<p class=\"p1\">treating your personal data with the respect and care it deserves.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>HEALHQ STUDIO &#8211; PRIVACY POLICY Thank you for checking out our privacy policy. We take our client&#8217;s privacy seriously are committed to protecting your privacy and handling your information in a responsible way while you use our website and services. We want you to understand that this is a safe place for you to discuss [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/healhqstudio.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3"}],"version-history":[{"count":4,"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":76,"href":"https:\/\/healhqstudio.com\/index.php?rest_route=\/wp\/v2\/pages\/3\/revisions\/76"}],"wp:attachment":[{"href":"https:\/\/healhqstudio.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}