top of page
Root-&-Thrive-pattern-1-RGB.jpg

PRIVACY POLCY

Privacy Notice

This Privacy Notice explains how Root & Thrive Health & Wellbeing Coaching collects, uses, stores and protects your personal information. It also outlines your rights under data protection law.

We use your personal data to provide and improve our services. By using our website or working with us, you agree to the collection and use of information in line with this Privacy Notice.

We keep this Notice under regular review. Last reviewed: September 2026

1. What Information We Collect

We only collect information that is necessary to provide our services or meet legal obligations.

We may collect:

  • Personal details: name, email address, phone number

  • Account information: login details, passwords

  • Payment information: credit/debit card details, billing information

  • Website usage data: IP address, device information, page interactions, session duration

  • Communications: emails, messages, coaching forms, feedback

  • Purchase history

  • Profile information submitted through forms or coaching agreements

We may also use software tools to measure and collect session information such as page response times and browsing patterns.

2. How We Collect Your Information

You may provide personal data in the following ways:

  • Through online forms, website orders or enquiries

  • When providing payment details

  • Through coaching agreements, pre‑ and post‑session forms

  • During coaching sessions, by email or over the phone

3. How We Use Your Personal Data

We use your data for the following purposes:

  • To deliver coaching services and fulfil our contract with you

  • To meet legal and accounting obligations

  • To send relevant marketing information (only where appropriate and beneficial; you can opt out at any time)

  • To create aggregated, non‑personal statistical data to improve our services

  • To comply with laws and regulations

We will never sell your data or share it without your consent unless required by law.

4. Who We Share Your Data With

We keep your information confidential. We may share it only with:

  • Contractors or advisors who support our business (e.g., bookkeeper)

  • Service providers who help deliver our website, email or payment services

  • Regulatory or legal bodies if required (e.g., CNHC)

  • Third parties if we transfer our rights and duties under an agreement with you

All third parties are required to keep your information secure and confidential.

5. Your Rights

You have the right to:

  • Access the personal data we hold about you

  • Request correction of inaccurate or incomplete data

  • Request deletion of your data (where applicable)

  • Restrict processing of your data

  • Unsubscribe from marketing communications at any time

We aim to respond to all requests promptly.

6. How We Keep Your Data Secure

We take your privacy seriously and use appropriate technical and organisational measures to protect your data, including:

  • Secure servers and firewalls

  • Restricted access to authorised personnel only

  • Encryption on devices storing personal information

  • Anti‑virus and malware protection

  • Contractual safeguards with external processors

Our website is hosted on Wix.com, which stores data on secure servers behind a firewall. Payment gateways used through Wix comply with PCI‑DSS security standards.

7. Transfers Outside the EU (Simplified & GDPR‑Compliant)

Some of the services we use may store or process your personal information outside the European Economic Area (“EEA”). This includes:

  • Wix.com (website hosting, forms, databases)

  • Mailchimp (email newsletters and mailing lists)

  • Microsoft Outlook (email communication)

  • Payment processors (e.g., Wix Payments, Stripe, PayPal)

  • Analytics tools (e.g., Wix Analytics, Google Analytics) if enabled

These providers may operate servers in countries such as the United States or Israel.

When your data is transferred outside the EEA, we ensure it is protected by appropriate safeguards, such as:

  • Standard Contractual Clauses (SCCs)

  • Providers certified under the EU–US Data Privacy Framework

  • Contractual and technical measures to ensure secure handling

These steps ensure your data remains protected to GDPR standards.

8. How Long We Keep Your Data

We only keep personal information for as long as necessary:

  • Marketing data: until you unsubscribe

  • Client/member data: for the duration of your membership and 7 years thereafter

  • Enquiry data: until you unsubscribe from marketing emails

9. Website Technical Details

Forms

We use secure electronic forms with built‑in privacy features.

Cookies

Our website uses cookies to support technical functionality. We do not use cookies to collect personally identifiable information.

Analytics tools may use cookies to understand website usage.

You can manage cookies through your browser settings. More information: www.allaboutcookies.org

10. Links to Other Websites

Our website may contain links to external sites. We are not responsible for the privacy practices of those websites. Please review their privacy notices before providing personal information.

11. Complaints

If you have concerns about how your data is used, please contact:

Data Controller Root & Thrive Health & Wellbeing Coaching Email: rootandthrive@outlook.com

If you are not satisfied with our response, you can raise a concern with the Information Commissioner’s Office (ICO) at www.ico.org.uk.

bottom of page