Privacy Policy
Last updated: 20 September 2026
Connected Flow respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how Connected Flow collects, uses, stores, and protects personal information when you visit our website, contact us, book a class or appointment, receive treatment or other services, or otherwise interact with our business.
This Privacy Policy explains how Connected Flow handles personal information in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Connected Flow is a sole-trader health and wellbeing business operated by Chris Edwards. For data protection purposes, Connected Flow is the Data Controller for all personal information processed in connection with its business and services.
Data Controller: Christopher Edwards (T/A Connected Flow)
Email: info@connectedflow.co.uk
ICO registration: ZC249293
Data Access: Restricted solely to the owner of Connected Flow.
Data Protection Officer: Connected Flow does not have a statutory requirement to appoint a Data Protection Officer (DPO). As a small sole-trader business, Connected Flow does not carry out large-scale processing or regular monitoring that would require a DPO. Responsibility for data protection and compliance rests directly with the owner.
2. What Personal Information We Collect
The information collected depends on how you interact with Connected Flow:
Contact Information: Name, email address, telephone/mobile number, and postal address (where necessary).
Booking & Service Information: Class and appointment bookings, dates/times, attendance records, booking history, cancellation details, and confirmation of fitness to participate or receive services.
Health & Medical Information (Special Category Data): Health-related information provided via online booking forms, pre-session health questionnaires, direct email communications, intake forms, or consultations. This may include medical conditions, injury history, physical limitations, assessment data, treatment notes, and required session adaptations. Health information is special category data under UK GDPR. We collect only what is relevant and reasonably necessary to deliver safe classes and therapy.
Payment Information: Digital payments are processed securely via an accredited third-party payment gateway. Connected Flow does not receive or store full payment card details. Cash transactions are processed directly and recorded by Connected Flow.
Website Information: Hosted using a secure cloud site builder platform. Connected Flow does not use website analytics services, advertising pixels/trackers, marketing cookies, or visitor profiling tools. Essential technical cookies and platform scripts may be processed by the hosting provider solely to maintain site security, rendering and stability.
3. How We Use Your Information
Personal information is processed where necessary to:
Respond to enquiries and manage bookings, appointments, and cancellations.
Safely assess, adapt, and deliver yoga classes, movement sessions, and soft tissue therapy.
Maintain appropriate client, clinical treatment, accounting, and insurance records.
Communicate with you regarding bookings, appointments, or service updates.
Process digital or cash payments and administer refunds.
Meet legal, tax, accounting, and insurance requirements.
Establish, exercise, or defend legal claims where necessary.
We do not sell, rent, or trade your personal information, nor do we use automated decision-making or profiling.
4. Lawful Bases for Processing (UK GDPR)
Connected Flow processes personal information under the following UK GDPR conditions:
Contract — Article 6(1)(b): Necessary to administer bookings and deliver requested services.
Legal Obligation — Article 6(1)(c): Necessary to comply with UK tax, accounting, and legal requirements.
Legitimate Interests — Article 6(1)(f): Necessary for business administration, client relationship management, physical safety, and defending legal rights.
Consent — Article 6(1)(a): Relied upon where explicit consent is requested for a specific activity (e.g., direct marketing). You may withdraw consent at any time.
5. Health Information & Special Category Data
Health information is special category data under the UK GDPR and subject to additional legal protections.
Processing health data requires both an Article 6 lawful basis and an Article 9 condition under UK GDPR. Health details provided voluntarily via booking forms, pre-session questionnaires, direct emails, or during intake consultations are processed to ensure client safety, adapt practices, and maintain clinical continuity under applicable UK GDPR health and social care conditions. Where necessary for the establishment, exercise, or defence of legal or insurance claims, Connected Flow relies on Article 9(2)(f).
6. One-to-One Treatment and Private Class Notes
For one-to-one treatments and private classes, Connected Flow maintains clinical treatment notes. These include assessment details, relevant medical history provided by you, session notes, and movement adaptations to ensure safety and continuity across future sessions.
All clinical records are held securely within password-protected, encrypted business systems with access strictly restricted to the owner of Connected Flow.
7. Online Booking Platform
Connected Flow utilizes an encrypted, third-party online booking system to manage class schedules, appointments, and client registrations.
The booking platform processes contact details, appointment selections, payment status, and any pre-session health information or exercise precautions submitted through booking forms.
The platform also records confirmation that you have agreed to the booking terms, cancellation policy, and fitness to participate.
Connected Flow maintains appropriate contractual and data protection arrangements with the booking platform provider in accordance with UK data protection law.
8. Categories of Data Recipients & Service Providers
To operate the business effectively, Connected Flow shares personal data only with trusted categories of third-party service providers acting as data processors or independent controllers:
Online Scheduling & Booking Providers: To manage appointments, class rosters, and pre-session intake forms.
Payment Processing Gateways: To process digital card transactions securely without exposing payment details to Connected Flow.
Cloud Email & Document Storage Providers: To administer email correspondence, client documentation, and clinical records.
Social Media Platforms: Where you choose to interact with Connected Flow via official business social media pages (subject to the platform provider's privacy terms).
Insurers & Professional Advisers: Shared only where reasonably necessary for insurance administration, professional legal advice, or managing potential/actual claims.
Legal & Regulatory Authorities: Disclosed only where required by statutory law or court order.
Specific vendor identity details may be provided upon request where required by law.
9. Digital Security & Storage Practices
To protect your privacy in an evolving digital environment, Connected Flow implements administrative and technical security controls across its operations:
Access Restrictions: Access to client records, health details, and email correspondence is strictly restricted solely to the owner of Connected Flow.
Account & Credential Security: Business management applications are secured using Multi-Factor Authentication (MFA) where supported, along with strong, unique passphrases and strict session management.
Data Minimization: We collect and retain only the personal and health information that is strictly necessary for your safety, treatment continuity, and legal compliance.
Service Provider Standards: We engage reputable third-party cloud service providers that comply with UK data protection legislation and maintain industry-standard physical and infrastructure security. Specific internal security configurations and storage structures are kept confidential for operational security.
10. International Data Transfers
Connected Flow utilizes cloud-based business applications to manage communications, bookings, and client records.
Some third-party cloud service providers maintain server infrastructure or corporate parent entities located outside the United Kingdom (including in the European Economic Area or the United States). Where personal data is processed outside the UK, Connected Flow ensures that appropriate, legally recognized transfer mechanisms and safeguards are in place in accordance with UK GDPR. These include UK Adequacy Decisions, the UK Extension to the Data Privacy Framework, or standard contractual data protection clauses.
11. How Long We Keep Your Information (Data Category; Retention Period; Legal & Operational Reason)
Client, Clinical & Health Records
7 years from the date of your last session
Maintained for clinical continuity, legal compliance, and establishing or defending insurance claims.
Booking & Attendance History
7 years after the client relationship ends
Business, financial, and client record administration.
Financial & Tax Records
7 years
UK HMRC tax and accounting compliance.
General Enquiries (No Booking Made)
12 months
General administrative follow-up.
Complaints & Legal Disputes
7 years (or longer if unresolved).
Legal and professional insurance protection.
When personal information is no longer required, Connected Flow securely deletes or disposes of it.
12. Your Data Protection Rights
Under UK data protection law, you have the right to:
Access: Request a copy of the personal information held about you.
Rectification: Request correction of inaccurate or incomplete information.
Erasure: Request deletion of your information (subject to mandatory 7-year retention requirements for health records under clinical insurance rules).
Restriction: Ask to limit how your information is processed.
Object: Object to processing based on legitimate interests.
Data Portability: Request transfer of your data in a structured format.
Withdraw Consent: Withdraw consent at any time where processing relies on consent.
To exercise any of these rights, please email info@connectedflow.co.uk.
13. Security Incident Procedure
Connected Flow takes data security seriously. In the event of a security incident or personal data breach, we will assess, contain, and investigate the issue immediately. Where required by law, notifications will be made to the Information Commissioner's Office (ICO) and affected individuals within statutory timeframes.
14. Complaints
If you have concerns about how your data has been handled, please contact Connected Flow first so we can resolve the issue. You also have the right to lodge a complaint directly with the Information Commissioner's Office (ICO) at ico.org.uk.
15. Changes to this Privacy Policy
Connected Flow may update this Privacy Policy from time to time. The latest version will always be published on the Connected Flow website with the updated date at the top.