PRIVACY POLICY Last updated: October 2025
1. Introduction Welcome to Inner Balance Acupuncture. Your privacy is important to us, and we are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our website www.innerbalance-acupuncture.co.uk or our services, you agree to this Privacy Policy.
2. Who We Are Inner Balance Acupuncture 34 The Square Aldridge WS9 8QS Email: via the website contact form We act as the Data Controller for the personal information you provide.
3. Information We Collect • Contact details: your name, phone number, email address, and home address. • Health information: details about your medical history, current symptoms, medications, and other information provided during consultation or treatment. • Appointment details: booking dates, treatment notes, and communications regarding your care. • Website usage data: cookies and analytics information (only if you consent).
4. How We Collect Information • When you complete the contact or booking forms on our website. • When you provide information during consultations or treatments. • Through our secure practice management system (Cliniko). • When you communicate with us via email, phone, or text message. 5. How We Use Your Information Your information is used to: • Provide acupuncture and related services. • Manage appointments and clinical records. • Communicate with you about your care, including appointment reminders or follow-up messages. • Maintain accurate records as required by healthcare regulations. • Improve the quality and safety of our services. Marketing or promotional emails will only be sent if you have given explicit consent.
6. Lawful Basis for Processing Under the UK GDPR, we rely on the following lawful bases for processing your personal data: • Contract: to provide the treatment or services you have requested. • Legal obligation: to maintain appropriate clinical records. • Consent: for collecting and processing sensitive health information and for any marketing communications. • Legitimate interest: to communicate essential information such as appointment confirmations or schedule changes.
7. How We Store and Protect Your Data Your information is securely stored using Cliniko, a GDPR-compliant healthcare practice management system. Cliniko encrypts all data and uses secure servers located in the UK/EU. We also take appropriate technical and organisational measures to protect your data from unauthorised access, alteration, disclosure, or destruction.
8. Data Retention We retain your personal and clinical data for a minimum of two years following your last treatment, in accordance with professional and legal guidelines. After this period, your records will be securely deleted or destroyed.
9. Sharing Your Information Your information is not shared with any third parties unless required by law (for example, if there is a legal obligation or a risk of serious harm). All clinical data is securely stored within Cliniko and is not accessible to unauthorised parties.
10. Cookies and Website Analytics Our website uses cookies to enhance user experience. You can accept or decline cookies when you visit our site. • Essential cookies are necessary for website functionality. • Non-essential cookies (e.g., analytics) are used only with your consent. You can change your cookie preferences at any time via your browser settings.
11. Your Data Protection Rights You have the following rights under UK GDPR: • The right to access a copy of your data. • The right to rectification of inaccurate information. • The right to erasure (“right to be forgotten”) in certain circumstances. • The right to restrict processing. • The right to data portability. • The right to object to processing. • The right to withdraw consent at any time (where consent is the lawful basis).
12. Data Breaches In the unlikely event of a data breach, we will take immediate steps to contain and assess the situation and, where required, notify both affected individuals and the Information Commissioner’s Office (ICO) within 72 hours.
13. Updates to This Policy We may update this Privacy Policy periodically. Any changes will be posted on this page with an updated “Last updated” date. 14. Contact Us If you have any questions or concerns about this Privacy Policy or your personal data, please contact: Inner Balance Acupuncture 34 The Square, Aldridge, WS9 8QS Email: via the website contact form