Privacy Policy

Last updated: 7 November 2025

I take your privacy seriously and am committed to protecting your personal information. This notice explains what information I collect, why I collect it, how it is used and stored, and your rights in relation to that information. Please take a moment to read it carefully.

Who I am

I am the data controller for your personal information.

Practice name: Wild Roots Herbal Medicine

Contact: Charlotte

Email: charlotte.herbal@icloud.com

Address: available on request

If you have any questions about this privacy notice or how your data is handled, please contact me using the details above.

The personal information I collect

I collect and store the following types of personal information:

• Your name, date of birth, contact details (email, phone, address)

• Information about your health, medical history, current symptoms, and treatment plans

• Consultation notes, herbal prescriptions, and follow-up information

• Payment and appointment records

• Any relevant correspondence between us (email or messages related to your care)

I only collect information that is necessary and relevant to providing you with herbal medicine consultations and care.

How I obtain your information

I collect your personal data directly from you during consultations, through online booking forms, or via email correspondence.

In some cases, I may receive information from other health professionals or practitioners, but only where you have given consent or requested that information to be shared.

Why I use your information

I use your personal information to provide herbal consultations, formulate prescriptions, and monitor progress; manage appointments, communications, and payments; keep appropriate clinical and business records in line with professional standards; and comply with legal, tax, and regulatory obligations.

I do not use your information for marketing or promotional purposes.

Lawful bases for processing

Under UK data protection law, the lawful bases I rely on are:

• Contract: processing is necessary for providing the herbal consultation or related services you have requested.

• Legal obligation: keeping accurate records as required by professional and tax regulations.

• Legitimate interests: maintaining business and clinical records securely, and improving administrative efficiency, in ways that do not override your rights.

• Consent: in cases where you have explicitly agreed to share information with another healthcare provider.

Because I process information about your health, this also falls under the UK GDPR category of special category data. I rely on Article 9(2)(h) — processing necessary for the purposes of health care or treatment.

Who I share your information with

I treat your information as strictly confidential. It may be shared only:

• With other healthcare professionals, and only with your explicit consent

• With professional insurers, regulators, legal advisers or others if required by law

• With secure service providers who help me run the practice, such as:

• Hostinger, for online booking and website hosting

• Cloud storage and backup services (e.g. iCloud, Google Drive, or Dropbox), used securely and with appropriate safeguards

These service providers act as data processors and only process information on my instructions, under confidentiality and data protection agreements.

I never sell or share your information for marketing purposes.

How long I keep your information

I am required to keep your records for eight years after your last consultation, or until your 25th birthday if you were under 18 at your last appointment, whichever is longer. After this period, if you wish, all records can be securely deleted or destroyed.

Where your information is stored

Your records are stored electronically using secure, password-protected systems.

Cloud storage and backup services may hold data on servers outside the UK/EEA; in such cases, I ensure appropriate safeguards and standard contractual clauses are in place to protect your information.

Your rights

You have the right to access a copy of your personal data; ask for corrections to any inaccurate information; request deletion of your data (where legally possible); object to or restrict certain types of processing; and withdraw consent where you have previously given it.

If you wish to exercise any of these rights, please contact me at charlotte.herbal@icloud.com.

How to complain

If you have any concerns about how I handle your data, please contact me first so I can address them.

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Website: https://ico.org.uk/make-a-complaint/

Telephone: 0303 123 1113

Updates to this notice

This notice is reviewed regularly to ensure it reflects current laws and practice operations. Any updates will be posted on my website and available upon request.