
Policies
Privacy policy
How I handle personal data on this site, written for UK GDPR.
1. Who I am
South Coast Mindfulness is run as a sole trader by Elisa Riutta, based in Southsea, Portsmouth, United Kingdom. I am the data controller for the information described below.
You can contact me at info@southcoastmindfulness.com or on +44 7961 378891.
I am committed to protecting and respecting any personal information you share with me. This statement describes what information I collect, how I use it, who I share it with, and the rights you have under UK data protection law.
2. What data I collect
Personal data means any information that can identify a living individual. I may process the following categories of personal data about you:
- Communication data — any message you send me via the contact form on this website, by email, by phone or WhatsApp, by text, or by social media.
- Sign-up data — the name, email address and any additional information you provide when you join the interest list, the members area, or subscribe to updates via Mailchimp.
- Booking data — for taster sessions, day retreats, workshops and 8-week mindfulness courses, I may collect more sensitive information such as any health needs, GP details and emergency contact details. This is special-category (health) data under UK GDPR and is handled with additional care.
- Feedback data — anything you share on feedback forms from my courses and events.
- Payment metadata — records of payments made via bank transfer or PayPal. I do not see or store your card details; PayPal handles those directly.
3. My lawful bases for processing your data
Under UK GDPR, I need a lawful basis for each purpose I use your data for. In practice I rely on the following:
- Contract — to deliver a course, session or event you have booked, and to communicate with you about it.
- Consent — to add you to my email mailing list. You can withdraw consent at any time by clicking the unsubscribe link in any email or by emailing me.
- Legitimate interests — to reply to enquiries, keep basic records of who has attended a course, improve what I offer, and understand how people find my service. I have balanced this against your privacy rights.
- Legal obligation — to keep certain records (e.g. financial records) as required by law.
- Explicit consent (Article 9) — for the collection of any health / medical information provided at booking, which is used only to keep you safe during sessions.
4. How I use your data
- To provide the mindfulness course, event or session you have requested.
- To keep you safe during in-person or online practice, based on any health information you have shared.
- To process payment for my services.
- To reply to enquiries you send me.
- To send you updates about future courses and events — only if you have signed up to my mailing list.
- To reflect on feedback and improve what I offer.
I will not use your data for automated decision-making or profiling.
5. Who I share your data with
I do not sell your data and I do not share it for third-party marketing.
I do use a small number of trusted service providers ("processors") to run this practice. They only see the data they need to do their job:
- Mailchimp (Intuit Inc., USA) — email newsletters, interest lists and contact form on this website.
- Zoom (Zoom Video Communications, USA) — online course and weekly meditation sessions.
- PayPal (PayPal (Europe) S.à r.l. & PayPal Inc.) — payment processing.
- Amazon Web Services (AWS, USA) — website hosting and content delivery (CloudFront). Static site content is served from AWS regions in the UK / EU where possible.
- Google (Google LLC, USA) — email, calendar and Google Analytics. Analytics is used only after you accept analytics cookies.
Where data is transferred to the United States, I rely on the UK equivalent of the EU-US Data Privacy Framework and/or on Standard Contractual Clauses approved by the UK Information Commissioner’s Office. Each of the providers listed above has published its own privacy notice, which sets out their safeguards in detail.
In exceptional circumstances I may also share data:
- With my professional indemnity insurer or legal adviser in the event of a claim.
- With another professional involved in your care, or with your employer, but only with your written consent.
- When disclosure is required by law (for example a court order), or where there is a serious risk of harm to you or someone else. Wherever possible, I will discuss this with you first.
6. How long I keep your data
I keep personal data only for as long as I need it:
- Course attendance records (including any health information provided at booking): 6 years from the end of the course. This retention period is required by my professional indemnity insurer.
- Financial records: 6 years, as required by HMRC.
- Mailing list contact details: for as long as you remain subscribed. When you unsubscribe, your record is removed from the active list and permanently deleted after a short period.
- General enquiries: usually deleted within 12 months if they do not lead to a booking.
7. Data security
- My laptop and phone are password-protected and encrypted.
- Electronic records are stored in reputable UK GDPR-compliant cloud services, protected by strong passwords and, where available, two-factor authentication.
- Paper registration or feedback forms, when used, are kept in a locked filing cabinet.
- I use TLS/HTTPS on this website so any information you send me via the contact form is encrypted in transit.
8. Cookies and this website
This website is a small, static site. It does not run advertising trackers, remarketing, session replay or heatmapping tools.
If you accept analytics cookies, I use Google Analytics to understand broad patterns such as which pages are visited and how people move around the site. This helps me improve the website and notice which information is most useful. Google may process analytics data as part of providing this service.
Analytics is optional. The site asks for your choice before enabling Google Analytics, and you can decline. If you decline, analytics storage remains switched off.
Some pages embed third-party widgets — the Mailchimp email form and, on the members area, the Insight Timer meditation player. These providers may set their own cookies when the widget loads or when you interact with it. You can control cookies through your browser settings.
The site itself uses only functional storage and the analytics consent choice.
9. Your rights
Under UK GDPR you have the right to:
- Ask what personal data I hold about you and receive a copy of it.
- Ask me to correct information that is inaccurate or incomplete.
- Ask me to delete your personal data ("right to erasure"), where I no longer need it and there is no overriding legal reason to keep it.
- Ask me to restrict how I use your data, or object to my using it, in certain circumstances.
- Ask me to transfer your data to another provider ("data portability"), where that is technically possible.
- Withdraw your consent at any time where I am relying on consent as the lawful basis.
To exercise any of these rights, please email me at info@southcoastmindfulness.com. I will respond within one month.
If you are not happy with how I have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO): https://ico.org.uk. I would be grateful if you contacted me first so I can try to resolve the issue directly.
10. Third-party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links, or enabling those connections, may allow third parties to collect or share data about you. I do not control these third-party sites and am not responsible for their privacy policies. When you leave this website, I encourage you to read the privacy notice of every site you visit.
11. Changes to this policy
I may update this policy from time to time — for example, if I start using a new service, or when the law changes. The current version is always the one shown on this page. Please check back occasionally to stay informed.