PRIVACY POLICY

Privacy Policy
Privacy Policy: Jessika May Somatics and Sound
Last Updated: April 2026
1. Introduction
Jessika May Somatics and Sound ("we," "us," or "our") is committed to protecting and respecting your privacy. This policy explains how we collect, use, and protect your personal data when you visit our website, book a service, or purchase from our apothecary.
Data Controller: Jessika May Contact: Jessika@somaticsandsound.co.uk Location: Glastonbury, Somerset, UK
2. The Data We Collect
We may collect and process the following data:
-
Identity & Contact Data: Name, email address, phone number, and billing/shipping address.
-
Health & Special Category Data: Information provided by you regarding your health, injuries, or pregnancy (collected only for the safe delivery of somatic and sound services).
-
Financial Data: Payment card details (processed securely via third-party providers like Wix Payments, Stripe, or PayPal; we do not store your full card details).
-
Technical Data: IP address, browser type, and usage data via cookies.
3. How We Use Your Data
We use your information under the following legal bases:
-
Contractual Necessity: To fulfill your orders, process bookings, and deliver services.
-
Consent: When you sign up for our newsletter or provide health information for a 1:1 session.
-
Legal Obligation: For tax and accounting purposes (e.g., keeping records of sales).
4. Special Category (Health) Data
By providing information about your physical or mental health, you give explicit consent for us to use this data solely to ensure your safety during somatic movement and sound healing sessions. This data is held in strict confidence.
5. Data Retention
-
Customer Records: We keep financial records for 6 years as required by HMRC.
-
Health Records: For insurance purposes, client consultation notes are typically held for 7 years following your last treatment.
-
Marketing: We keep your email for as long as you remain subscribed. You can opt-out at any time.
6. Third-Party Sharing
We do not sell your data. We only share data with trusted service providers to run our business:
-
Wix: Our website and booking platform.
-
Payment Processors: Stripe/PayPal/Wix Payments.
-
Email Marketing: [e.g., Mailchimp or Wix ShoutOut].
-
Accountants/Insurance: Only when legally required or for professional indemnity.
7. Your Legal Rights
Under UK GDPR, you have the right to:
-
Access: Request a copy of the data we hold about you.
-
Rectification: Ask us to correct inaccurate data.
-
Erasure: Ask us to delete your data (where legal obligations don't require us to keep it).
-
Withdraw Consent: Unsubscribe from marketing at any time.
To exercise these rights, please contact us at [Insert Email Address].
8. Cookies
Our website uses cookies to enhance your browsing experience and analyze traffic. You can manage your cookie preferences through your browser settings or our website's cookie banner.
9. Complaints
If you have concerns about how we handle your data, please contact us first. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection (www.ico.org.uk).
