top of page

Privacy Policy

This Privacy Policy explains how your personal information is collected, used, and protected in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

Gabriela Irvine

 Shiatsu Practitioner

152-1 Cowgate Edinburgh EH1 1RP Scotland

This is the address used for all data‑protection matters, including requests for access, correction, or deletion.

Information Collected

I collect and process the following information:

  • Your name and contact details

  • Booking information

  • Relevant health information required to provide safe and appropriate Shiatsu sessions

  • Session notes and treatment records

  • Any information you choose to share through the contact form

  • Technical website data (see Website Data Collection section below)

This information is collected directly from you.

Lawful Basis for Processing

Your information is processed under:

  • Consent — when you contact me or provide information voluntarily

  • Contract — to arrange, confirm, and deliver booked sessions

  • Legitimate interest — to maintain professional records and ensure safe practice

  • Legal obligation — to retain treatment records for the required period

How Your Information Is Used

Your information is used to:

  • Confirm and manage bookings

  • Communicate about sessions, changes, or follow‑up

  • Provide safe and appropriate treatment

  • Maintain professional records as required by UK law and industry standards

Your information is not used for marketing unless you explicitly request updates.

Health Information & Session Notes

Health information and session notes are considered special category data under UK GDPR. They are processed solely for the purpose of providing safe, suitable treatment.

These records are stored securely and confidentially.

Data Retention

In line with professional requirements for complementary therapy practice, treatment records are stored securely for 7 years from the date of your last session.

After this period, records are securely deleted or destroyed.

Data Storage & Security

Your information may be stored in email correspondence, booking messages, and secure session notes. All records are kept confidential and only the practitioner has access.

Sharing Your Information

Your information is never sold or shared with third parties. Information may only be shared if required by law or if you request a referral and give explicit written consent.

Appropriate measures are in place to protect data from loss, misuse, or unauthorised access.

Your Rights

You have the right to:

  • Access your personal data

  • Request corrections

  • Request deletion (unless legal retention applies)

  • Withdraw consent

  • Request a copy of the information held about you

Requests can be made through the contact form.

Website Data Collection & Cookies

This website may collect limited technical information through cookies and similar technologies. This is standard practice and helps ensure the website functions correctly.

Types of Data Collected

Non‑personal technical data may be collected automatically:

  • Device type and browser

  • Pages visited and time spent on the site

  • Basic usage statistics

  • IP address (anonymised where possible)

  • Cookie preferences

This does not include personal or health information unless you submit it through the contact form.

Purpose of Collection

Technical data is collected to:

  • ensure the website functions properly

  • improve user experience

  • maintain security

  • understand general website usage

  • support accessibility and performance

Processing is carried out under legitimate interest (UK GDPR Article 6).

Cookies

The site may use:

  • essential cookies

  • performance/analytics cookies

  • preference cookies

You can manage or disable cookies through your browser settings.

Third‑Party Services

Your website builder may use:

  • hosting providers

  • analytics tools

  • embedded booking or contact forms

These services may process anonymous usage data. They do not receive personal or health information unless you submit it directly.

​

Security

All website data is handled in accordance with UK GDPR and the Data Protection Act 2018.

Personal Data Submitted Through the Website

Any personal information you choose to submit — such as through the contact form, booking messages, or email — is processed according to this Privacy Policy and stored securely for 7 years when related to treatment records.

Questions or Concerns

If you have any questions about how your information is handled, stored, or protected, you’re welcome to get in touch through the contact form.

bottom of page