As of 25th May 2018, all businesses in the EU will be required to adhere to new data protection laws, known as the GDPR (General Data Protection Regulation). These laws govern how businesses collect, store and process individual’s personal data, and all such individuals (also known as a ‘data subject’) will need to give explicit consent if their data is to be collected, stored and processed.
Under the regulation, you have the right to request copies of all data held by us about you, as well as the right to ‘be forgotten’, i.e. all your data would be erased. Additional information may be found at www.eugdpr.org.
2. Customer Data
Ultimate Holistic Escapes collects and stores customer data purely for the purposes of communicating relevant essential information, for example, to send information regarding bookings or payments, in addition to sending newsletters (via email) to those individuals who have subscribed to our mailing list.
The only data we may collect, and store, is the following:
Name (contact name and/or company name)
Telephone numbers (landline or mobile)
History of bookings with us
Financial information, e.g. invoices/receipts and total amounts charged and received
Details of any medical conditions/allergies/contraindications which are detailed on our holistic treatment consultation forms
Where consent is supplied for us to communicate with you via email, we will add your name and email address to our email marketing system and CRM (customer relationship management) software. We do not, under any circumstances, share any other data with third parties.
3. Third party sites and social media
Other data may also be collected via our website and social media pages, in the form of:
Customer reviews: these may be copied to be used on our social media pages or website
Comments, likes and tweets and other interactions to our social media posts
Social media posts, reviews and comments etc. will occasionally be used for promotional purposes, for example by sharing on our social media pages, and they will only show the name of the account to which they are related (i.e. the account that posted); they will not contain any contact information that we would otherwise only keep on file for the purposes described in section 2 above.
Data privacy is extremely important to us and we believe all individuals have the right to specify who has access to their data, and how it is processed. We obtain explicit consent from all customers before storing and using their data for any purpose. Once consent is approved, we will only use the data for internal business functions and for communicating information which we believe will be of importance or interest to the recipient.
We will not send any email communications, nor store personal details, for any individual who:
is not a customer
has not subscribed to one of our mailing lists
has not contacted us directly (via email or social media) and requires a response
For any further information on this policy, or to request copies or deletion of data, please contact us.