Privacy Policy
Privacy Notice
Who I am
This privacy notice explains how your personal information is collected, used and protected when you use my Ayurvedic Yoga Massage services.
Business name: Jonathan Waterlow
Therapist: Jonathan Waterlow
Contact: jon@yogamassage.uk
What information I collect
I collect and store:
Basic details: your name, contact information and, if supplied, emergency contact details.
Health information: relevant medical history, current health conditions, medications, allergies, injuries, pregnancy status and other information you choose to share for safe treatment.
Appointment information: dates and times of sessions, treatment notes and any communications related to your care.
This information is classed as personal data and some of it is special category data (health information) under UK data protection law.
Why I collect your information (lawful basis)
I collect and use your information in order to:
Provide safe and appropriate Ayurvedic Yoga Massage and related services.
Identify any contraindications or necessary adaptations to treatment.
Maintain accurate treatment records as required by my professional insurance (Balens) and good practice guidelines.
Manage appointments, payments and client communications.
The main legal bases under UK GDPR are:
Contract / Legitimate interests: to provide the service you have requested.
Provision of health care and explicit consent: for processing health‑related information necessary for safe treatment.
How your information is stored
Intake forms completed online are stored securely in my Jotform account, which uses encrypted connections and EU‑based data centres. Access is protected by a strong password and two‑factor authentication.
Copies of your records (for example, downloaded PDFs or treatment notes) are stored in password‑protected or encrypted digital folders and/or in locked physical storage.
Only the therapist (and, where strictly necessary, technical providers acting under contract, such as web or form hosting) has access to your identifiable information.
How long I keep your information
To meet insurance, legal and tax requirements, I normally keep client records for up to 6 years after your last appointment, after which they are securely deleted or destroyed, unless a longer period is required due to an ongoing complaint, claim or legal obligation.
Sharing your information
Your information is treated as confidential. I will not sell or share your data with third parties for marketing. I may share information only when:
You explicitly ask me to, or give written consent (for example, to communicate with another health professional).
I am legally required to do so (for example, by a court order or for tax/audit purposes).
There is a serious and immediate risk of harm to you or others, in which case I may need to contact appropriate services.
In all cases, I aim to share the minimum necessary information.
Your rights
Under UK data protection law, you have the right to:
Access a copy of the personal information I hold about you.
Ask me to correct any inaccurate or incomplete information.
In some circumstances, ask me to restrict or erase your information, or object to how it is used (subject to legal/insurance obligations to keep records).
Lodge a complaint with the Information Commissioner’s Office (ICO) if you are unhappy with how your data is handled.
If you wish to exercise any of these rights, please contact me using the details above.
Website and online contact
If you contact me through my website or online forms:
I will use the information you provide only to respond to your enquiry, manage bookings, and provide services.
My website may use essential cookies or analytics; if so, this will be explained in a brief cookies notice or banner with options to manage your preferences.
Changes to this notice
This privacy notice may be updated from time to time to reflect changes in law or in how I work. The latest version will always be available on my website.