Moss & Moon Wellbeing GDPR & Privacy Policy

1. Introduction

At Moss & Moon Wellbeing, your privacy is sacred. We’re committed to respecting and protecting your personal information, keeping it safe, and being transparent about how it’s used.

This policy explains what personal data we collect, how we use it, and your rights under the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.


2. Who We Are

Moss & Moon Wellbeing is a holistic and spiritual wellbeing hub offering treatments, workshops, readings, and wellbeing retail.
For data protection purposes, Moss & Moon Wellbeing acts as the Data Controller for client information collected through our website, booking system, or in-person services.


3. What Information We Collect

We collect personal information that allows us to provide our services safely and effectively. This may include:

  • Full name, email address, and contact number

  • Address and emergency contact details (if required for treatments)

  • Medical or wellbeing information relevant to your treatment (e.g. allergies, injuries, pregnancy)

  • Booking details and payment confirmations

  • Social media usernames (if you contact us via social media)

  • Marketing preferences (newsletter sign-ups, etc.)

  • For online readings or coaching: relevant notes or messages voluntarily shared during sessions

We only collect information that is necessary for your care, communication, and safety.


4. How We Use Your Information

Your personal information may be used to:

  • Schedule and manage your bookings and appointments

  • Provide treatments, readings, or workshops safely and effectively

  • Contact you with appointment confirmations, reminders, or follow-ups

  • Send newsletters, updates, or event details (only if you’ve opted in)

  • Manage payments, invoicing, and financial records for business compliance

  • Meet our legal and insurance obligations

We will never sell, rent, or share your data with third parties for marketing purposes.


5. Legal Basis for Processing

We process your personal data under one or more of the following lawful bases:

  • Contractual necessity: to deliver your booked treatment, workshop, or service.

  • Legal obligation: to maintain tax, insurance, and health & safety records.

  • Consent: for marketing communications or sensitive health information.

  • Legitimate interest: to manage business operations and improve our services.

You can withdraw consent for marketing or health data processing at any time by emailing admin@mossandmoonyorkshire.co.uk.


6. Data Retention

  • Client treatment and booking records are kept for 7 years (or 7 years after a child turns 18 for minors) in line with insurance and legal requirements.

  • Email and marketing contact information is retained until you unsubscribe or request deletion.

  • Messages received via social media or email are deleted once no longer required for business purposes.


7. Data Storage & Security

We take your privacy seriously and store all data securely:

  • Electronic records are password-protected and stored on secure, encrypted devices or GDPR-compliant systems (e.g. BookWhen, Stripe, MailerLite).

  • Paper records (if used) are kept in locked cabinets within secure premises.

  • Only authorised team members and practitioners have access to personal data where necessary for the delivery of services.


8. Sharing Your Data

We only share your data when absolutely necessary, for example:

  • With practitioners working within Moss & Moon to deliver your booked service (on a need-to-know basis).

  • With payment processors (e.g. Stripe, PayPal) to complete transactions.

  • With professional advisors (e.g. accountants or insurers) for legal compliance.

  • If required by law or to protect someone’s safety.

All practitioners operating at Moss & Moon are independent, self-employed professionals who must also comply with GDPR and maintain their own data protection and insurance policies.


9. Your Rights

You have the right to:

  • Access the personal data we hold about you

  • Request correction of inaccurate data

  • Request deletion of your data (where legally permissible)

  • Withdraw consent to marketing communications

  • Lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data has been mishandled

To exercise any of these rights, please email admin@mossandmoonyorkshire.co.uk.


10. Cookies & Website Analytics

Our website may use cookies or tracking tools to improve your experience and monitor visitor activity.
Cookies can be disabled in your browser settings at any time.
We may use anonymised website analytics (such as Google Analytics) to track visits and improve usability.


11. Marketing & Communications

You will only receive marketing communications from us if you have actively opted in.
You can unsubscribe at any time by clicking the link in our emails or by contacting us directly.


12. Updates to This Policy

This Privacy Policy may be updated occasionally to reflect changes in legislation or business practices.
The most recent version will always be available on our website.


13. Contact Us

If you have any questions, concerns, or wish to exercise your data rights, please contact:

Moss & Moon Wellbeing

e. admin@mossandmoonyorkshire.co.uk

t. 07727115681