Privacy Policy
Last updated: January 2025
1. Who We Are
This website is operated by Anastasia, an independent certified massage therapist based in London, UK. References to "we", "us" or "our" in this policy refer to Anastasia Massage Therapy.
If you have any questions about this privacy policy or how we handle your data, please contact us at: lisa.anastasia1103@gmail.com
2. What Information We Collect
We collect information you provide directly to us when you:
- Submit a booking request through our website form
- Contact us via WhatsApp or telephone
- Send us an email enquiry
The information collected may include your name, phone number, email address, preferred appointment date and time, massage type preference, and any notes you provide about your health or preferences relevant to your treatment.
3. How We Use Your Information
We use the information we collect solely to:
- Respond to your booking request and confirm appointments
- Contact you regarding your appointment
- Provide the massage therapy service you have requested
- Send appointment reminders where you have consented
We do not use your information for marketing purposes without your explicit consent. We do not sell, rent or share your personal information with any third parties for marketing purposes.
4. Legal Basis for Processing
We process your personal data on the following legal bases under the UK GDPR:
- Contract performance — to fulfil the booking and treatment service you have requested
- Legitimate interests — to manage our appointment schedule and communicate with clients
- Consent — where you have explicitly agreed to receive communications from us
5. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with our legal obligations. Booking records are typically retained for 3 years for accounting and legal purposes. You may request deletion of your data at any time (subject to any legal retention requirements).
6. Third-Party Services
Our website is hosted on Vercel. Booking form submissions are processed via Resend for email delivery. These services may process your data in accordance with their own privacy policies. We use these services solely to operate our website and booking system.
We do not use tracking cookies, advertising networks, or analytics services that collect personal data beyond standard server logs.
7. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data
- Object to or restrict our processing of your data
- Data portability — receive your data in a structured format
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at lisa.anastasia1103@gmail.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, or misuse. Our website uses HTTPS encryption for all data in transit.
9. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
