This Privacy Notice outlines how Bliss Spa & Massage collects and processes your personal data through your use of our site and services.
By providing us with your personal data, you warrant to us that you are over 13 years of age.
Bliss Spa & Massage is the data controller and is responsible for your personal data (referred to as “we,” “us,” or “our” in this notice).
We have appointed a Data Protection Officer (DPO) who manages all privacy-related matters. If you have any questions about this notice, please contact our DPO using the details below.
Contact Details
Our full details are:
It is vital that the information we hold about you is accurate and current. Please notify us immediately if your personal information changes by emailing us at info@blissspamassage.co.uk
Personal data refers to any information that can identify an individual; it does not include anonymized data. We may process several categories of personal data about you based on how you interact with us:
We may also combine and use Customer, User, Technical, and Marketing Data to deliver targeted advertisements to you (e.g., through platforms like Facebook) and measure their success. Our lawful ground for this is our legitimate interests in growing our business.
Sensitive Data
We do not collect any Sensitive Data (e.g., race, religion, sex life, political opinions, criminal convictions) through our website.
HOWEVER: To safely and effectively perform any treatment, we must collect sensitive health data from you. This information will be collected during your appointment with the therapist, based on verbal information you provide.
We require your explicit consent for processing this sensitive health data. You will be asked to provide this consent directly to your therapist at the time of your appointment.
Consequences of Not Providing Data
Where we are required to collect personal data (including sensitive health data) by law or under the terms of a contract, and you fail to provide that data when requested, we may be unable to perform the contract (e.g., provide the service). If this results in a cancellation, we will notify you at the time.
We only use your personal data for the purpose it was collected for or a reasonably compatible purpose. We do not carry out automated decision-making or profiling.
We collect data through the following methods:
Our lawful ground for processing your data to send you marketing communications is either your consent or our legitimate interests (to grow our business).
We will always seek your express consent before sharing your personal data with any third party for their own marketing purposes.
Opting Out: You can ask us or third parties to stop sending you marketing messages at any time by:
Note that opting out of marketing does not apply to personal data provided as a result of other transactions, such as purchases or appointments.
We may need to share your personal data with the following parties:
We require all third parties to respect the security of your personal data and use it only for specified purposes and in accordance with our instructions.
We share your personal data within our group of companies, which may involve transferring your data outside the European Economic Area (EEA).
We comply with the General Data Protection Regulations (GDPR) to protect your data. Where we transfer your data outside the EEA, we ensure similar security safeguards are in place by using mechanisms such as:
If none of these safeguards are available, we will request your explicit consent to the specific transfer, which you have the right to withdraw at any time.
We have implemented robust security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorization.
We limit access to your personal data only to employees and partners who have a genuine business need to know that data. They are instructed to process your data only on our instructions and must keep it strictly confidential.
We have procedures in place to manage any suspected data breach and will notify you and any applicable regulator if we are legally required to do so.
We only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including meeting any legal, accounting, or reporting requirements.
Under data protection laws, you have specific rights concerning your personal data, including the right to request:
You can find more details about these rights at the Information Commissioner’s Office (ICO) website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
To exercise any of these rights, please email us at info@blissspamassage.co.uk
We respond to all legitimate requests within one month. You will not have to pay a fee unless your request is clearly unfounded, repetitive, or excessive.
Complaints
If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the ICO. However, we would be grateful if you contacted us first so we can try to resolve your concern directly.
This website may contain links to third-party websites, plug-ins, and applications. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy notice of every website you visit after leaving ours.
You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. Please be aware that if you disable or refuse cookies, some parts of this website may become inaccessible or not function properly. For detailed information about the cookies we use, please see our dedicated policy: https://www.blissspamassage.co.uk/cookie-policy/