23 Whitbarrow Road, Lymm
Mon-Sat: 10am-6pm

Privacy Policy

Last updated: 29 October 2025

Keena Ladies Thai Massage ("we", "our", "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and safeguard your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Information We Collect

We collect and process the following types of personal information:

1.1 Information You Provide Directly

  • Booking Information: Name, email address, phone number, preferred appointment times
  • Health Information: Medical history, health conditions, injuries, allergies, and any other health-related information necessary to provide safe and effective massage therapy
  • Communication Records: Records of correspondence via email, WhatsApp, phone, or in-person conversations
  • Payment Information: Payment details are processed securely through Fresha (our booking platform) and we do not store full payment card details on our systems

1.2 Information Collected Automatically

  • Website Usage Data: IP address, browser type, device information, pages visited, and time spent on our website
  • Cookies: We use cookies to improve your browsing experience. See our Cookie Policy section below for details
  • Analytics: We use Google Analytics to understand how visitors use our website

2. How We Use Your Information

We use your personal information for the following purposes:

  • Service Delivery: To provide massage therapy services, manage appointments, and ensure your safety during treatments
  • Communication: To send appointment confirmations, reminders, and respond to your enquiries
  • Health & Safety: To maintain accurate health records and provide appropriate treatments based on your medical history
  • Legal Compliance: To comply with legal obligations, including health and safety regulations and insurance requirements
  • Business Operations: To manage bookings, process payments (via Fresha), and maintain business records
  • Marketing: To send promotional offers and wellness tips (only with your explicit consent, which you can withdraw at any time)
  • Website Improvement: To analyse website usage and improve user experience

3. Legal Basis for Processing

Under UK GDPR, we process your personal data based on the following legal grounds:

  • Contractual Necessity: Processing is necessary to perform our contract with you (providing massage services)
  • Legal Obligation: Processing is required to comply with legal obligations (health and safety, insurance, tax)
  • Legitimate Interests: Processing is necessary for our legitimate business interests (managing appointments, business operations)
  • Consent: For marketing communications and non-essential cookies, we rely on your explicit consent
  • Vital Interests: In emergency situations, we may process health data to protect your vital interests

4. Third-Party Services

4.1 Fresha Booking Platform

We use Fresha as our booking and payment processing platform. When you book an appointment through Fresha:

  • Your booking information, contact details, and payment data are processed by Fresha
  • Fresha acts as a data processor on our behalf
  • Fresha's privacy policy applies to their processing of your data: www.fresha.com/privacy
  • Fresha is GDPR-compliant and implements appropriate security measures

4.2 Other Third Parties

  • Google Analytics: We use Google Analytics to analyse website traffic. Google Analytics uses cookies to collect anonymous usage data
  • Email Services: We use email services to communicate with clients
  • WhatsApp: For client communications via WhatsApp Business

5. Data Retention

We retain your personal information for the following periods:

  • Health Records: 8 years from the date of last treatment (as recommended by professional insurance requirements)
  • Booking Records: 7 years for tax and accounting purposes
  • Marketing Consent: Until you withdraw consent or 3 years of inactivity
  • Website Analytics: Google Analytics data is retained for 26 months

After these periods, we will securely delete or anonymise your data unless we are legally required to retain it longer.

6. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to Restrict Processing: Request that we limit how we use your data
  • Right to Data Portability: Request your data in a portable format
  • Right to Object: Object to processing based on legitimate interests or for marketing purposes
  • Right to Withdraw Consent: Withdraw consent for marketing or cookies at any time
  • Right to Complain: Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, please contact us using the details in Section 11.

7. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Secure storage of physical health records in locked cabinets
  • Encrypted digital communications
  • Secure password-protected systems
  • Limited access to personal data (only authorised personnel)
  • Regular security reviews and updates
  • Secure disposal of records when no longer needed

8. Cookie Policy

Our website uses cookies to enhance your browsing experience:

Essential Cookies

These cookies are necessary for the website to function and cannot be switched off:

  • Session cookies for website functionality
  • Cookie consent preferences

Analytics Cookies

We use Google Analytics to understand how visitors use our site (with your consent):

  • Page views and navigation patterns
  • Device and browser information
  • Geographic location (city-level only)

You can manage your cookie preferences using the cookie banner that appears on your first visit or by adjusting your browser settings.

9. International Data Transfers

Your data is primarily stored within the UK. However, some third-party services (such as Google Analytics) may process data outside the UK. When this occurs:

  • We ensure adequate safeguards are in place (such as Standard Contractual Clauses)
  • Data is only transferred to countries with adequate data protection laws or approved transfer mechanisms

10. Children's Privacy

Our services are exclusively for adults (18 years and over). We do not knowingly collect or process personal data from individuals under 18 years of age.

11. Contact Information

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Keena Ladies Thai Massage

23 Whitbarrow Road, Lymm, Cheshire, WA13 9AJ

Email: keena@keenamassage.com

Phone: 07766 986749

WhatsApp: Message Us

12. Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: www.ico.org.uk

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending an email notification (if we have your email address)

We encourage you to review this Privacy Policy periodically.