Privacy Notice – The Untold You

Effective Date: 19th June 2025
Last Updated: 19th June 2025

The Untold You ("we", "us", or "our") is committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR). This notice explains how we collect, use, and protect your personal data when you visit our website or use our services.

1. Who We Are

The Untold You is a provider of [brief description of services, e.g., personal development coaching, therapy, etc.], based in the United Kingdom.

Data Controller:
The Untold You
lucy@theuntoldyou.com

2. What Data We Collect

We collect and process the following personal data:

  • Contact Information: Name, email address, phone number (via contact forms).

  • Scheduling Information: Name, email, phone number, selected appointment details (via Acuity).

  • Technical Data: IP address, browser type, and device information (via Squarespace analytics).

We do not collect any special category data (such as health or medical information) unless you voluntarily provide it and it is necessary for the service provided.

3. How We Collect Your Data

We collect data when you:

  • Fill out a contact form on our website.

  • Book an appointment via our scheduling tool (Acuity).

  • Interact with our website, which may collect limited technical data via cookies.

4. Why We Use Your Data (Lawful Bases)

We process your data on the following lawful bases under UK GDPR:

  • Contractual Necessity: To provide you with services you request, including appointment scheduling and responding to enquiries.

  • Legitimate Interests: To manage our business, improve user experience, and analyse website traffic.

  • Consent: For direct marketing, where applicable. You can withdraw consent at any time.

5. How Your Data Is Stored

  • Contact Forms: Data is securely stored on Squarespace servers.

  • Scheduling: Data is stored within Acuity Scheduling, a service operated by Squarespace.

  • Both platforms are GDPR-compliant and implement industry-standard security measures.

6. Data Sharing and Transfers

We do not sell or rent your personal data.

We may share data with trusted third-party service providers (e.g., Squarespace and Acuity) to help us deliver our services. These providers are bound by strict data protection obligations.

Your data may be transferred outside the UK. When this occurs, we ensure that adequate safeguards (such as Standard Contractual Clauses) are in place to protect your data.

7. How Long We Keep Your Data

We retain personal data only as long as necessary for the purposes outlined in this notice or as required by law. Typically, we keep:

  • Contact form enquiries: up to 12 months.

  • Appointment data: up to 7 years (for business and legal reasons).

8. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data.

  • Request correction or deletion.

  • Object to or restrict processing.

  • Withdraw consent at any time.

  • Lodge a complaint with the UK Information Commissioner’s Office (ICO): www.ico.org.uk

To exercise your rights, please contact us at [insert email address].

9. Cookies and Analytics

Our website uses cookies for functionality and analytics. You can manage your preferences through your browser settings or via the cookie banner on our site.

10. Updates to This Privacy Notice

We may update this Privacy Notice from time to time. Any significant changes will be communicated via our website.