Desert Rose Wellness is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it and how we use it — in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Desert Rose Wellness is a private wellness sanctuary based in Borehamwood, North London, UK, providing advanced beauty treatments, holistic therapies, body contouring, infrared sauna and wellness coaching.
Data Controller
Alexandra, Desert Rose Wellness
Email: alexandra@desertrosewellness.co.uk
Phone: 07932 322 971
Location: Borehamwood, Hertfordshire
2. Data We Collect
Contact & Booking Information
- Full name, email address, phone number
- Appointment date, time and service requested
Health & Treatment Information
- Medical history relevant to treatments (collected via consultation forms)
- Skin type, allergies, contraindications, pregnancy status
- Treatment notes and progress records
Health data is special category data under UK GDPR. We process it only with your explicit consent and solely for the purpose of delivering safe, appropriate treatments.
Technical Data
- IP address and browser type (collected via website analytics)
- Pages visited and session duration
3. How We Use Your Data
- Booking management: To confirm, manage and follow up on your appointments via Cal.com
- Treatment delivery: To provide safe and personalised treatments based on your health consultation
- Communication: To send appointment reminders, aftercare advice and responses to your enquiries
- Marketing (with consent): To send newsletters and offers — you may opt out at any time
- Legal compliance: To meet our obligations under health, safety and tax regulations
4. Legal Basis for Processing
- Contract: Processing necessary to fulfil your booking
- Legitimate interests: Business administration and service improvement
- Explicit consent: For health data and marketing communications
- Legal obligation: For record-keeping required by law
5. Third-Party Services
We use the following services that may process your data:
- Cal.com — online booking platform
- WhatsApp / Meta — direct messaging
- Google Analytics — anonymised website usage
- Hostinger — website hosting (EU/EEA servers)
We do not sell your personal data to any third party.
6. Data Retention
- Booking and treatment records: 7 years from last treatment (UK health and tax requirements)
- Marketing consent records: Until you withdraw consent
- Website analytics: Aggregated and anonymised after 26 months
7. Your Rights Under UK GDPR
You have the right to access, rectify, erase, restrict, or port your data; to object to processing; and to withdraw consent at any time. To exercise any right, email alexandra@desertrosewellness.co.uk. We will respond within 30 days.
You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.
8. Cookies
Our website uses essential cookies only. If we introduce analytics or marketing cookies in future, we will update this policy and request your consent.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. Paper consultation records are kept securely and destroyed after the retention period.
10. Changes to This Policy
We may update this policy from time to time. The date at the top of this page shows when it was last revised. Significant changes will be communicated to existing clients by email.
11. Contact Us
Desert Rose Wellness
Email: alexandra@desertrosewellness.co.uk
Phone: 07932 322 971
Borehamwood, Hertfordshire, UK