Tão Linda Therapies Back to site
Legal Document

Privacy Policy

Tão Linda Therapies · Last updated: 17 May 2026 · UK GDPR compliant

1. Who We Are

Tão Linda Therapies ("we", "our", "us") is a holistic therapy and wellness practice based in London, United Kingdom. We provide mobile and in-treatment-room aromatherapy massage, somatic massage, Angelic Reiki energy healing, sculpting face massage, Family Constellations therapy and related holistic wellness services.

Data Controller: Tão Linda Therapies
Contact: info@taolinda.com

2. What Personal Data We Collect

We collect personal data only when necessary to provide our services:

  • Contact information: name, email address, phone number
  • Booking details: preferred service, date and time, location
  • Payment information: processed securely by Stripe — we do not store card details
  • Health information: relevant medical history you share voluntarily for therapy purposes
  • Gift voucher recipient details: name and email of the recipient
  • Communication records: enquiries submitted via our contact form
  • Technical data: anonymised IP address (hashed), browser type, pages visited, if analytics cookies are accepted

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

Purpose Legal Basis
Confirming and managing bookings Contract performance
Processing payments via Stripe Contract performance
Responding to enquiries Legitimate interests
Sending booking confirmations and reminders Contract performance
Improving our website (analytics) Consent
Sending our newsletter (if subscribed) Consent
Complying with legal obligations Legal obligation

4. Cookies & Analytics

We use cookies as described in our Cookie Policy. Analytics cookies (Google Analytics) are only activated after you give explicit consent via our cookie banner.

You can change your cookie preferences at any time by clicking "Cookie Settings" in the footer.

5. Data Sharing & International Transfers

We do not sell or rent your personal data. We share data only with the following processors, each bound by a Data Processing Agreement (DPA) under UK GDPR Art. 28:

Processor Purpose Location Transfer mechanism
Stripe Payments Europe Ltd Card payment processing Ireland (EU) — group entities in USA UK adequacy (EU) + SCCs (USA group entities)
Resend Inc. Transactional & marketing email delivery USA UK International Data Transfer Agreement (IDTA)
Google LLC (Analytics, Calendar) Anonymised analytics (consent-based) & therapist calendar sync USA UK Addendum + EU Standard Contractual Clauses
Our hosting provider Application & database hosting EU/UK UK adequacy

Where personal data leaves the UK, we rely on the safeguards above (UK adequacy decisions, UK Addendum to EU SCCs, or the UK International Data Transfer Agreement) together with technical measures (encryption in transit and at rest, pseudonymisation) so that your data continues to enjoy an essentially equivalent level of protection.

You may request a copy of any specific safeguard at info@taolinda.com.

6. Data Retention

We retain personal data only for as long as necessary for the purpose it was collected. Our retention rules are enforced automatically by a scheduled cleanup that anonymises or deletes data when retention periods expire.

  • Customer accounts: kept while your account is active. If you do not book a service, attend an experience, or use a voucher for 3 consecutive years and you have no future confirmed bookings, your account and all linked personal details are automatically anonymised.
  • Therapy bookings, experience bookings, gift vouchers and voucher transactions: identifying details are permanently wiped 6 years after the booking or transaction date. The financial record itself is retained for HMRC tax and VAT obligations (UK Companies Act 2006 s.386 / VAT Act 1994 retention period) but holds no personal data after that point.
  • Consultation, contact and gift-voucher form submissions: the encrypted form data is wiped after 6 years; only an anonymous record (form type and date) is kept for non-identifying statistics. Form submissions are wiped immediately when you delete your account or after 3 years of account inactivity.
  • Newsletter and email-preference subscriptions: kept while you remain subscribed. The subscription record is deleted when you unsubscribe, when you delete your account, or after 3 years of account inactivity.
  • Anonymised website analytics (only if you have consented to analytics cookies): Google Analytics retains aggregated, IP-anonymised data for up to 26 months.
  • Audit and security logs: retained for the period necessary to investigate security incidents and to detect, prevent and respond to fraud (UK GDPR Art. 6(1)(f) — legitimate interests).

You can request immediate erasure of your personal data at any time — see Section 8 (Your Rights Under UK GDPR) below.

7. Data Security

We protect your data using a defence-in-depth set of controls aligned with UK GDPR Art. 32:

  • Encryption at rest: AES-256 encryption for all personal data stored in our database (names, emails, phone numbers, addresses, consultation notes, gift voucher messages, form submissions).
  • Encryption in transit: all traffic to and from our site uses HTTPS / TLS.
  • Email-address pseudonymisation: SHA-256 hashing is used for email lookups so the plaintext email never appears in indexes.
  • Password protection: account passwords are hashed with bcrypt (one-way, salted) — we never store or display your password.
  • Account lockout: after 5 failed sign-in attempts an account is automatically locked for 30 minutes to prevent brute-force attacks.
  • Multi-factor authentication (MFA): all staff/administrator accounts that can access customer data are protected with mandatory time-based one-time codes (TOTP) on top of their password.
  • Rate limiting on authentication, password-reset and contact-form endpoints to mitigate abuse.
  • CSRF protection on every form, plus a strict Content Security Policy with per-request nonces to limit cross-site scripting risk.
  • Audit logging: security-relevant events (sign-ins, MFA changes, data exports, account deletions) are recorded; IP addresses and user-agents are SHA-256 hashed before storage.
  • Principle of least privilege and regular security reviews of code, dependencies and infrastructure.

8. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data (Subject Access Request, Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data — the "right to be forgotten" (Art. 17)
  • Restrict processing of your data (Art. 18)
  • Data portability — receive your data in a portable, machine-readable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time (without affecting prior processing)

Exercise these rights instantly from your account. If you are signed in, open My Account → Your Data Rights to:

  • Download your data — a one-click JSON export of every booking, voucher, form submission and account detail we hold about you.
  • Delete your account — immediate, audit-logged erasure of all personal data linked to you (bookings, gift voucher PII, consultation/contact form submissions, newsletter subscription).

If you don't have an account, prefer to write to us, or want to exercise the rights of rectification, restriction or objection, contact us at info@taolinda.com. We will respond within 30 days as required by Art. 12(3).

9. Complaints

If you have concerns about how we handle your data, you may lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk | Tel: 0303 123 1113

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect any changes. We will notify you of significant changes via email if you have an account or booking with us.

Terms & Conditions Cookie Policy

Developed with ❤️ by PartnerMe AI