Last reviewed: 10 June 2026
Who we are
Kris Massage Therapist Ltd (“we”, “us”) provides Thai, deep tissue, aromatherapy and related massage treatments from 19 Braddon Road, Loughborough, LE11 5YY. We are the data controller for the personal information described in this policy.
- Company: Kris Massage Therapist Ltd, registered in England and Wales, company number 14845910. Registered office: 95 Ashby Road, Loughborough, LE11 3AB.
- ICO registration: we are registered with the Information Commissioner’s Office as a data controller, registration reference ZB499376.
- Contact: [email protected] or 07591 112 636.
- Website: https://krismassagetherapist.co.uk
What information we collect
- Booking details – your name, email address, phone number and the appointments you book through our online booking system.
- Payment information – card payments are handled securely by our payment provider (see “Payments” below). We never see or store your full card number.
- Health information – before your first treatment we ask you to complete a short consultation form covering relevant health conditions, injuries and medical history, and we keep brief treatment notes (see “Health information” below).
- Enquiries – anything you send us through the contact form, by email or by phone.
- Gift cards – if you buy a gift card we collect the recipient’s name and email address in order to deliver it.
- Website security data – our website’s security services record technical data such as IP addresses to protect the site from spam and attacks.
- CCTV – cameras operate around the outside of the property (see “CCTV” below).
Health information (special category data)
Health details are “special category data” under UK data protection law (UK GDPR and the Data Protection Act 2018) and we give them extra protection. We collect them only with your explicit consent, and only so that your treatment is safe, effective and properly tailored to you. You can withdraw your consent at any time, although without relevant health information we may not be able to treat you safely. Your consultation form and treatment notes are kept confidential, are accessible only to your therapist, and are never used for marketing or shared with anyone else unless we are required to by law.
Payments
Online payments are processed by WooPayments, powered by Stripe, a PCI-DSS compliant payment provider. Your card details are sent directly to the payment provider over an encrypted connection – they are not stored on our website and we cannot see them. Stripe’s privacy policy is available at https://stripe.com/gb/privacy.
Why we use your information (lawful bases)
- To take and manage bookings and payments – performance of a contract.
- To treat you safely (health information) – your explicit consent.
- To keep accounting and tax records – legal obligation.
- To keep the premises and website secure (CCTV, anti-spam, security logging) – our legitimate interests.
- To send you offers or marketing – only with your consent, which you can withdraw at any time.
How long we keep your information
- Booking, order and payment records – 6 years from the end of the tax year they relate to, as required by HMRC.
- Consultation forms and treatment notes – 7 years after your last treatment, in line with insurance and professional guidance.
- Enquiries that do not lead to a booking – up to 12 months.
- CCTV footage – around 30 days, unless needed for a specific incident.
CCTV
CCTV cameras operate around the outside of the property at 19 Braddon Road for the security of clients, staff and the premises, and for the prevention and detection of crime. Footage is viewed only by the business owner, is kept for around 30 days before being automatically overwritten, and is shared only with the police or our insurers where genuinely required.
Who we share your information with
We never sell your information. We share it only with the small number of services needed to run the business:
- our payment provider (WooPayments / Stripe) to process card payments;
- our website hosting provider – the website is hosted on a secure server in the United Kingdom;
- email delivery services used to send booking confirmations and reminders;
- website security and anti-spam services (such as Wordfence and Cloudflare), which process IP addresses;
- the police, our insurers or other authorities where we are legally required to do so.
Cookies
This website uses cookies. Essential cookies make the booking and checkout process work; non-essential cookies are only set with your consent, which you can give or withdraw at any time using the cookie banner. For full details see our Cookie Policy.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal information we hold about you;
- have inaccurate information corrected;
- ask us to delete your information;
- restrict or object to how we use it;
- receive your information in a portable format;
- withdraw any consent you have given, at any time.
To exercise any of these rights, email [email protected] or call 07591 112 636. We will respond within one month. Deletion does not apply to records we are legally required to keep, such as tax records.
Complaints
If you are unhappy with how we have handled your information, please contact us first and we will do our best to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113. Our ICO registration reference is ZB499376.
