We are committed to the privacy and security of your personal data. This Privacy Notice describes how we collect and use personal data, in accordance with applicable law and our standards of ethical conduct.
We encourage you to review and check the Website regularly for any updates to this Privacy Notice. We will publish the updated version on the Website and by continuing to deal with us, you accept this Privacy Notice as it applies from time to time.
Data Protection Principles
“Personal data” means any information that enables us to identify you or the beneficiary of your transaction with us (gift vouchers), such as name, email, address, telephone number.
We are committed to complying with applicable data protection laws and will ensure that personal data is:
- Used lawfully, fairly and in a transparent way;
- Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes;
- Relevant to the purposes we have told you about and limited only to those purposes;
- Accurate and kept up to date;
- Kept only as long as necessary for the purposes we have told you about; and
- Kept securely.
- What personal data do we collect and how do we collect it?
We collect personal data when you give it to us, when you register with us (Client Record Card), when you complete forms online (email communication), when you speak with us over the telephone, when you write to us. We will also collect details of transactions you carry out through the Website and of the fulfilment of such transactions.
- We may collect and process the following personal data
- Personal details, such as data which may identify you or the beneficiary of your transaction with us. This may include your name, title, address, email, telephone, and other contact data, date of birth, gender, images, signature, student/police/NHS card details, next of keen, height, weight, occupation, general health questions, conditions and symptoms; and names and personal details of beneficiaries of transactions (“Identity Personal Data”).
How do we use this information, and what is the legal basis for this use?
We process this personal data for the following purposes:
a) To fulfil a contract, or take steps linked to a contract: this is relevant where you make a purchase from us. This includes:
- Verifying your identity
- Taking payments
- Communicating with you
- Providing customer services and arranging the delivery or other provision of products or services
Promoting the safety and protection of our customers, facilities and assets
b) As required by Super Healthy Me to conduct our business and pursue our legitimate interests, in particular:
- We will use your information to provide products and services you have requested, and respond to any comments or complaints you may send us
- We use the information you provide to personalise our website, products or services for you
- If you provide a credit or debit card as payment, we may use third parties to check the validity of the sort code, account number and card number you submit in order to prevent
fraud (see ‘Who will we share this data with, where and when?’ below)
- We monitor customer accounts to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law
- We use the information you provide to investigate any complaints received from you or from others, about our website or our products or services
- We will use data in connection with legal claims, compliance, regulatory and investigative purposes as necessary (including disclosure of such information in connection with legal process or litigation)
c) Where you give us consent:
- We will process the health-related data you provide on the Client Record Card for the purposes of promoting the safety of our customers
- We will send you direct marketing in relation to our relevant products and services
- On other occasions where we ask you for consent, we will use the data for the purpose which we explain at that time
d) For purposes which are required by law:
- Where we need parental / career consent to provide treatment to children 14-18 years old
- In response to requests by government or law enforcement authorities conducting an investigation
Withdrawing consent or otherwise objecting to direct marketing
Wherever we rely on your consent, you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes, such as those set out above. In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can change your communication preferences at any time by contacting us by email or text.
Who will we share this data with?
We will share your personal data for the following purposes:
- Processing of, and analytics into customer segmentation and profiling for marketing services to customers
- Processing of incident reports for customer accidents or injuries incurred on Super Healthy
Me premises or by use of Super Healthy Me equipment Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law, or if required for the legal protection of our legitimate interests in compliance with applicable laws.
Personal data will also be shared with third party service providers, who will strictly process it only as Super Healthy Me instructs, on behalf of Super Healthy Me , for the purposes identified above.
Such third parties include (but not exclusive to) providers of website hosting, marketing communications, call centre operation and identity checking.
In the event that the business is sold or integrated with another business, your details will be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business. Data is adquately protected by EU Commission approved standard contractual clauses. A copy of the relevant mechanism can be provided for your review on request.
What rights do I have?
You have the right to ask us for a copy of your personal data; to correct, delete or restrict (stop any active) processing of your personal data. In addition, you can object to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement, or where we are using the data for direct marketing).
These rights may be limited, for example, if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping. To exercise any of these rights, you can get in touch with us. If you have unresolved concerns, you have the right to complain to an EU data protection authority where you live, work or where you believe a breach may have occurred.
For processing the Client Record Card, the provision of the requested information is mandatory: if relevant data is not provided, then you will not be able to receive treatments.
How do I get in touch with you?
We hope that we can satisfy queries you may have about the way we process your data. If you have any concerns about how we process your data, or would like to opt out of direct marketing, you can get in touch by email firstname.lastname@example.org
Alternatively, you can write to us:
Super Healthy Me
61 Alexandra Road
Or send text message on 07707687138
How long will you retain my data?
Where we process personal data in connection with performing a contract, we keep the data for a minimum of 7 years from your last treatment. Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your request in future.