Privacy Policy

Privacy Policy

Effective Date: 19/4/2025
Business Name: Divine Lotus
Business Address: Suite 6, Eastgate, 149 Wilenhall Road, Wolverhampton, WV1 2HR
Contact Email: Sarita Rattu
Phone Number: 01902 475369

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our premises, use our services, or interact with us online or offline.

1. Who We Are

Divine Lotus is a provider of professional massage therapy and related wellness services based in the United Kingdom. We are the data controller of your personal data and are responsible for ensuring it is used lawfully, fairly, and transparently.

2. What Personal Data We Collect

We may collect the following types of personal data:

a. Identity Data

Full name

Date of birth

Gender

b. Contact Data

Address

Email address

Phone number

c. Health Data (Special Category Data)

To tailor our massage services safely and effectively, we may collect relevant health-related information, including:

Medical history (e.g., injuries, conditions, allergies)

Information related to current symptoms or areas of concern

Pregnancy status (if relevant)

We only collect this data with your explicit consent.

d. Appointment & Transaction Data

Appointment history

Services booked and received

Payment and billing details (excluding card numbers if processed via third-party processors)

e. Technical Data (if you use our website)

IP address

Browser type and version

Operating system

Referral sources

Website usage data (e.g., cookies)

3. How We Collect Your Data

We collect data from and about you through:

Direct interactions (in-person, phone, email, website form)

Online bookings or purchases

Health intake forms or consultation forms

Automated technologies (e.g., website cookies)

CCTV footage (if applicable, for safety and security purposes)

4. How We Use Your Personal Data

We use your data for the following purposes:

To provide massage and wellness services

To assess suitability for specific treatments

To communicate with you regarding appointments, updates, or changes

To manage payments and accounting

To comply with legal or regulatory obligations

To improve our services and customer experience

With your consent, for marketing purposes (e.g., offers, updates)

5. Legal Bases for Processing

Under the UK GDPR, we rely on the following legal bases:

Performance of a contract – to provide our services

Consent – for processing health data and marketing communications

Legal obligation – to meet regulatory or tax requirements

Legitimate interests – to manage and improve our business and customer relationships

6. Marketing and Communications

We may send you marketing messages by email or SMS if:

You have opted in to receive such communications; or

You are an existing client and have not opted out.

You can opt-out at any time by clicking “unsubscribe” in emails or contacting us directly.

7. Sharing Your Personal Data

We do not sell your personal data. We may share your data with:

Professional service providers (e.g., booking platforms, payment processors)

Regulatory authorities (if legally required)

Insurance providers (only with consent and if necessary for claim purposes)

All third parties are required to handle your data securely and in compliance with the law.

8. International Transfers

We do not routinely transfer your data outside the UK. If we do, we ensure adequate protection is in place, such as Standard Contractual Clauses or adequacy decisions.

9. Data Security

We implement appropriate security measures to protect your data, including:

Secure servers and encrypted communications

Access controls and staff confidentiality agreements

Locked filing cabinets for paper records (if used)

In the event of a data breach, we will notify you and the ICO (Information Commissioner’s Office) as required by law.

10. Data Retention

We retain personal data only as long as necessary, typically:

Client records: 7 years from the date of last treatment (or until age 25 if under 18 at the time of service)

Financial records: 6 years (for tax purposes)

Marketing consents: Until you withdraw consent

After this, data is securely destroyed or deleted.

11. Your Data Protection Rights

You have the right to:

Access your personal data

Request correction or erasure

Object to or restrict processing

Withdraw consent at any time

Data portability (where applicable)

Lodge a complaint with the ICO if you believe your data has been misused

ICO Contact:
Website: https://ico.org.uk
Phone: 0303 123 1113

12. Cookies & Website Data

If you use our website, cookies may be used to improve functionality and user experience. You can control cookie settings in your browser.

See our [Cookie Policy] for more information.

13. Changes to This Privacy Policy

We may update this policy from time to time. The latest version will always be available at our premises and on our website.

Last updated: 19/04/2025

14. Contact Us

If you have any questions or requests related to this policy, please contact:

Divine Lotus
Email: info@divinelotus.co.uk
Phone: 01902 475369
Address: Suite 6, Eastgate, 149 Wilenhall Road, Wolverhampton, WV1 2HR

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.