Privacy Policy
Effective date: 01 January 2026
Palm 11 Wellness Hub (“Palm 11”, “we”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website, purchase from us, book treatments/classes, or engage with us.
1) Who we are
Data Controller: Palm 11 Wellness Hub
Address:
Email:
Phone:
2) Information we collect
We may collect:
-
Identity and contact data: name, email, phone number, address (where applicable)
-
Booking and transaction data: appointments, memberships, classes, purchases, payment confirmations (we do not store full card details)
-
Consultation data: verbal and written consultation information relevant to treatments (e.g., allergies, contraindications, preferences)
-
Website usage data: IP address, device/browser, pages visited, referral sources, cookies
-
Marketing preferences: opt-ins/opt-outs, communication history
3) How we use your information
We use personal data to:
-
Process bookings, memberships, and purchases
-
Deliver treatments, classes, and café orders
-
Conduct required consultation and safety checks
-
Manage customer service, queries, and complaints
-
Improve our website and services (analytics)
-
Send marketing communications where you have opted in (or where permitted by law)
-
Prevent fraud and secure our systems
-
Meet legal and regulatory obligations
4) Legal bases for processing
We process personal data where it is necessary for:
-
Contract performance (e.g., fulfilling bookings/purchases)
-
Legitimate interests (e.g., customer support, service improvement, fraud prevention)
-
Legal obligations (e.g., accounting/tax)
-
Consent (e.g., marketing emails, certain cookies)
5) Payments
Payments are processed via third-party payment providers. We receive confirmation of payment and limited transaction details, but we do not store full card details.
6) Sharing your data
We may share data with:
-
Booking/payment providers and website hosting platforms
-
Accountants, professional advisers, and insurers where necessary
-
IT and security providers
-
Regulators or law enforcement where required by law
We do not sell your personal data.
7) Cookies
We use cookies and similar technologies for essential site functionality, analytics, and (where enabled) marketing. You can control cookies through your browser settings and any cookie banner preferences.
8) Data retention
We retain data only as long as necessary:
-
Booking and transaction records: typically up to 6 years for tax/accounting
-
Consultation records: retained for a reasonable period for client safety and insurance purposes
-
Marketing data: until you unsubscribe or request deletion (subject to legal requirements)
9) Your rights (UK GDPR)
You may have the right to:
-
Access your data
-
Correct inaccurate data
-
Request deletion (where applicable)
-
Restrict processing
-
Object to processing
-
Data portability
-
Withdraw consent at any time (for consent-based processing)
To exercise rights, please contact us.
10) Security
We use reasonable administrative, technical, and organisational security measures to protect your data. No method of transmission is 100% secure.
11) Complaints
If you have concerns, contact us first. You also have the right to complain to the Information Commissioner’s Office (ICO).