Privacy Policy (UK GDPR – Updated 2026)
Who We Are
This website and services are operated by Amanda Brooks, trading as:
- Find Your Inner Harmony
- Peace Within
Amanda Brooks is the Data Controller responsible for your personal data.
If you have any questions about this policy or how your data is handled, you can contact:
📧
🌐 https://www.peacewithin.online
What Data We Collect
We may collect and process the following personal data:
- Name
- Email address
- Telephone number
- Address (where required)
- Appointment and session information
- Communication history (emails/messages)
- Website usage data (via cookies)
We only collect data that is necessary to support your experience and the services provided.
How We Use Your Data
We use your personal data to:
- Provide and manage your appointments and sessions
- Communicate with you about bookings or enquiries
- Send newsletters or updates (only with your consent)
- Improve our services and website
Meet legal and insurance obligations
Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases:
- Consent – for email newsletters and marketing
- Contract – to provide services you have requested
- Legal obligation – to meet insurance and regulatory requirements
- Legitimate interests – to manage and improve our services and communication
Email Marketing
If you choose to receive emails from us:
- You will only be added with your explicit consent
- You can unsubscribe at any time via the link in any email
- Your data is never sold or shared for marketing purposes
We use secure third-party platforms such as
Mailchimp and
Campaign Monitor
to manage communications.
Third-Party Services
We may use trusted third-party providers to support our business, including:
- Email platforms (e.g. Mailchimp, Campaign Monitor)
- Booking systems such as Calendly
- Payment providers (e.g. Stripe, PayPal, bank transfer)
These providers process your data securely and only for the intended purpose.
Data Storage & Security
Your data is stored securely:
- Devices are password-protected and encrypted
- Access is restricted to Amanda Brooks only
- Paper records are stored securely and locked
- Email systems and platforms use secure encryption
While no system is 100% secure, we take all reasonable steps to protect your information.
How Long We Keep Your Data
We retain personal data only as long as necessary:
- Client records are kept for up to 7 years (in line with insurance and professional requirements)
- Email marketing data is kept until you unsubscribe
- You may request deletion at any time (subject to legal obligations)
Your Rights
Under UK GDPR, you have the right to:
- Ask to see what information is held about you
- Request that anything incorrect is updated
- Ask for your information to be deleted (where possible)
- Ask us to stop or limit how your information is used
- Request transfer of your data (data portability)
To exercise any of these rights, please contact us.
Complaints
If you have any concerns about how your data is handled, please contact Amanda Brooks first:
📧
We will respond within 30 days.
If you are not satisfied, you have the right to contact the
Information Commissioner's Office (ICO):
https://www.ico.org.uk
Cookies
We use cookies to:
- Improve website functionality
- Understand how visitors use the site
You can control cookie settings through your browser preferences.
Children’s Data
Our services are not intended for children under 16 without parental consent.
Where work is carried out with children, parent or guardian consent is always required.
Changes to This Policy
We may update this policy from time to time.
The latest version will always be available on this page, with the updated date shown above.