UK GDPR Compliance
At Midlands Therapeutic Massage Services, we are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR). This page explains how we comply with your rights under UK GDPR and the data we may process when you interact with our website.
Scope and Applicability
This UK GDPR compliance statement applies to visitors of our website, midlandsmassagetherapy.co.uk. While we do not collect personal data through user registration or databases, we may automatically gather limited information via cookies and web analytics tools to improve site functionality and user experience. This data is processed solely for legitimate business purposes and in full compliance with UK GDPR.
Your Rights Under UK GDPR
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: You may request confirmation of whether we hold your personal data and obtain a copy of it.
- Right to rectification: You may request correction of any inaccurate or incomplete personal data we hold.
- Right to erasure: You may request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to restriction of processing: You may request we limit how we use your data under certain conditions.
- Right to data portability: You may request your data in a structured, commonly used format, where technically feasible.
- Right to object: You may object to processing based on legitimate interests, including profiling.
How We Comply
We do not store personal data in user accounts or databases. Any data collected via cookies or analytics (e.g., IP address, browsing behaviour) is anonymised or pseudonymised where possible. We use only essential cookies for site functionality and non-essential cookies only with your prior consent. Our third-party analytics providers are GDPR-compliant and bound by data processing agreements.
Data We Process
When you visit our website, we may automatically collect:
- IP address (anonymised)
- Browser type and operating system
- Pages visited and time spent on site
- Cookie identifiers (for session and preference management)
This data is not linked to any identifiable individual unless you voluntarily contact us via our contact form.
Legal Basis for Processing
Our processing of personal data is based on the following lawful grounds under UK GDPR:
- Legitimate interests: To ensure website security, improve user experience, and analyse traffic patterns.
- Consent: For non-essential cookies and analytics, we obtain explicit consent via our cookie banner.
How to Exercise Your Rights
To exercise any of your rights under UK GDPR, please contact us directly at:
Include your full name, the right you wish to exercise, and any relevant details (e.g., email address used on our site). We will respond without undue delay and within one month.
Response Timeframes
We are required by UK GDPR to respond to your requests within one month of receipt. In complex cases, this may be extended by two further months, and we will inform you of any delay and the reasons for it.
No Discrimination Policy
You will not be denied services, charged different prices, or receive a different quality of service for exercising your rights under UK GDPR. We respect your privacy and will not penalise you in any way for asserting your data protection rights.
Updates and Changes
We may update this UK GDPR Compliance page periodically to reflect changes in the law or our practices. Any material changes will be posted on this page with an updated effective date.
Contact Information
If you have any questions, concerns, or requests regarding your personal data under UK GDPR, please contact our data protection point of contact:
Ivy Trevelyan
Email: [email protected]
Address: 280 King St, Newtown NSW 2042, Australia
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection. Visit ico.org.uk for more information.