Privacy Policy.
Privacy Policy
This Privacy Policy explains how Your Sleep Support and Your Sleep Clinic (“we”, “our”, “us”) collect, use, and protect your information. We comply with UK GDPR, the Data Protection Act 2018, and PECR.
Health data: Because our services involve adult CBT-I and children’s sleep support, we may process special category data (e.g., health details) with your explicit consent only.
1. Who we are
We are the data controllers for the services we provide.
2. Data we collect
- Contact & account: name, email, phone, address, booking details.
- Payments: records from our payment processor (we do not store card numbers).
- Adult service info (CBT-I): sleep history, routines, relevant health details you voluntarily provide.
- Children’s service info: child’s first name, age, sleep/feeding history, relevant health information provided by a parent/guardian.
- Communications: emails, messages, forms.
- Technical: IP address, device/browser data, analytics and cookies (see Cookies).
Special category Health-related information is processed only with your explicit consent.
3. How we use your data
- Provide and personalise sleep services (adults & children).
- Manage bookings, reminders, and follow-ups; provide resources.
- Process payments via secure third parties.
- Send optional newsletters/marketing where you consent (unsubscribe anytime).
- Comply with legal, tax, safeguarding, and insurance obligations.
- Improve our website and services (aggregate, non-sensitive insights).
4. Lawful bases
- Contract: to deliver services you book.
- Consent: for health (special category) data, for marketing emails, and non-essential cookies.
- Legal obligation: tax, safeguarding, and insurance record-keeping.
- Legitimate interests: limited, non-intrusive improvement and site security.
6. Retention
- Client records (incl. intake & session notes): up to 7 years to meet insurance/legal requirements.
- Emails & correspondence: as long as relevant to active services.
- Marketing contacts: until you unsubscribe or we prune inactive lists.
7. Your rights
You can:
- Request access to your data and get a copy.
- Ask us to correct inaccuracies.
- Request deletion (where not required by law/insurance).
- Withdraw consent at any time (this may limit service delivery).
- Object or restrict certain processing.
- Complain to the ICO (ico.org.uk).
8. Children’s data
For children’s services, information is provided by a parent or legal guardian. We do not knowingly collect data directly from children under 16. Consents are recorded, and access to children’s records is strictly limited.
10. Security
- Encrypted accounts and devices; strong passwords and MFA.
- Access limited to the data controller; least-privilege principle.
- No paper records unless essential (stored securely and shredded).
11. International transfers
When data leaves the UK, we use recognised safeguards such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs) as appropriate.
12. Contact
To exercise your rights or ask questions:
Your Sleep Support: help@yoursleepsupport.com
Your Sleep Clinic: info@yoursleepclinic.com
Address: Enniskillen, Co. Fermanagh, Northern Ireland
13. Changes to this policy
We may update this policy to reflect changes in law or our practices. We’ll post the new version here with a new “Last updated” date.