
Appointments: luke@lukewellortherapy.com

Privacy Policy
Last Updated: 24th June 2025
​
This Privacy Policy describes how we collect, use, and protect your personal information when you visit our website, www.lukewellortherapy.com, and interact with us.
​
Please read this Privacy Policy carefully. By using and accessing our Site, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access the Site.
​
1. Information We Collect
To advertise our services and facilitate direct appointment inquiries via our contact form or email, we collect and process certain limited personal data.​
A. Information you directly provide to us: This is information you voluntarily provide when you interact with our Site by filling out our contact form or by sending us an email inquiry to arrange an appointment.
-
Contact Form Information: When you use our contact form, we collect your name, contact telephone number, and email address.
-
Communication Content: Any information you provide within your messages when you communicate with us (e.g., details about your inquiry or feedback regarding hypnotherapy services), whether through the contact form or direct email.
B. Information collected automatically via Wix: When you visit and use our Site, certain information is automatically collected from your device by Wix, our website platform. This is standard for most websites.
-
Usage Data: Information about how you interact with our Site, such as the pages you visit, the time spent on pages, and your Browse path.
-
Device Information: Your IP address, browser type, operating system, and unique device identifiers.
-
Cookies and Similar Technologies: Our Wix website uses cookies and similar tracking technologies. These are small text files placed on your device that help our website function, provide security, and enable us to understand basic website usage (through Wix's analytics). We also use these technologies to support features like embedded content from third parties (e.g., YouTube, social media) which may set their own cookies, as identified and managed by our Usercentrics Consent Management Platform.
-
For more detailed information about the types of cookies used, their purpose, and how you can manage your cookie preferences, please refer to our separate Cookie Policy.
-
​​
2. How We Use Your Information
We use your personal information for the following purposes, primarily based on different legal bases under the GDPR:
-
To Respond to Your Inquiries and Facilitate Appointments (Contractual Necessity or Legitimate Interest):
-
To respond to your direct contact requests and appointment inquiries received via the contact form or email.
-
To communicate with you regarding your potential or booked hypnotherapy appointments.
-
To provide information about our hypnotherapy services.
-
-
For Our Legitimate Interests (where your rights and freedoms do not override these interests):
-
To understand and analyse basic website usage patterns (via Wix analytics) to improve the content and functionality of our informational site.
-
To maintain the security and integrity of our website.
-
To detect and prevent technical issues or fraud.
-
-
To Comply with Legal Obligations:
-
To meet any legal or regulatory requirements that apply to our services (e.g., record-keeping).
-
3. How We Share Your Information
We generally do not share, sell, or rent your personal information to third parties, except in the following limited circumstances:​​
-
Service Providers (Wix & Usercentrics): We use Wix.com as our trusted website platform provider. Wix processes data necessary for the operation, security, and basic analytics of our website. Additionally, we utilise Usercentrics (integrated via Wix) as our Consent Management Platform (CMP). Usercentrics processes limited personal data, such as your IP address (often anonymised), browser information, and your consent choices, to record and manage your cookie preferences in compliance with data protection regulations. You can find more information on how Usercentrics processes data in their Privacy Policy here: https://usercentrics.com/privacy-policy/ . Their access to your personal information is solely for performing these services on our behalf, and they are obligated to protect it.
-
Legal Compliance: We may disclose your information if required to do so by law, court order, or in response to valid requests by public authorities.
​
4. International Data Transfers
As our website is hosted by Wix, a global service provider, your personal data collected via the website may be stored and processed in countries outside of the European Economic Area (EEA) or the UK, where data protection laws may differ.
​
Where such transfers occur, Wix implements appropriate safeguards to ensure your data is protected to a standard similar to that within the EEA/UK. These safeguards typically include using Standard Contractual Clauses (SCCs) approved by the European Commission or the UK government.
​
By using our website, you acknowledge that your information may be transferred to and processed in these countries through Wix's infrastructure.
​
5. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
​
For example, contact form submissions and direct email inquiry details will be kept for a reasonable period to manage your appointment, respond to your request, or for our legitimate business records. Clinical records are retained for a period of eight (8) years after your last session. For any future clients who are children (under 18 years old), their clinical records will be retained until they reach their 25th birthday, or for 8 years after their last session, whichever is the longer period, in line with professional guidelines and legal best practices for therapeutic records. Please note that at present, I only offer services to adult clients. Information collected via website analytics through Wix is generally anonymised or aggregated.
​
When your personal information is no longer required, we will securely delete or anonymise it.
​​
6. Your Data Protection Rights (GDPR & UK GDPR)
Under the General Data Protection Regulation (GDPR) and UK GDPR, if you are located in the EEA or UK, you have the following rights regarding your personal data. Please note that these rights may not apply in all circumstances, depending on the nature of the data and the legal basis for processing.​
-
The Right to Be Informed: To know how your data is being used.
-
The Right of Access: To request a copy of the personal data we hold about you.
-
The Right to Rectification: To request that we correct any inaccurate or incomplete data we hold about you.
-
The Right to Erasure ("Right to Be Forgotten"): To request that we delete your personal data under certain conditions.
-
The Right to Restrict Processing: To request that we limit the way we use your personal data under certain conditions.
-
The Right to Object: To object to our processing of your personal data under certain conditions (e.g., if we were to send direct marketing, which we do not).
-
Rights in Relation to Automated Decision-Making and Profiling: To object to decisions based solely on automated processing. (Note: Our website does not use automated decision-making or profiling that produces legal effects concerning you).
​
To exercise any of these rights, please contact us using the details provided in the Contact Us section. We will respond to your request within one month.
​
7. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information. These rights are in addition to the data protection rights described for EEA/UK residents.
​
Notice Regarding "Sale" or "Sharing" of Personal Information: Our website displays a "Privacy Information" banner (managed by Usercentrics) that includes a "Do Not Sell My Personal Information" toggle. While our primary purpose for collecting information is to provide hypnotherapy services and facilitate direct appointments, certain technologies used on our website (such as those for analytics or website functionality, as detailed in our Cookie Policy) may involve the sharing of data with third-party service providers. Under the broad definitions of the CCPA/CPRA, such sharing, particularly for cross-context behavioural advertising (even if we do not directly sell data for monetary compensation), may be considered a "sale" or "sharing" of personal information.
​
If you are a California resident, you have the right to opt-out of the "sale" or "sharing" of your personal information. You can exercise this right at any time by activating the 'Do Not Sell My Personal Information' toggle on the 'Privacy Information' banner.
​
Your Specific CCPA/CPRA Rights Include:
-
Right to Know: You have the right to request that we disclose to you the categories and specific pieces of personal information we have collected about you, the categories of sources from which personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, and the categories of third parties to whom we disclose personal information.
-
Right to Delete: You have the right to request the deletion of personal information that we have collected from you, subject to certain exceptions.
-
Right to Correct: You have the right to request the correction of inaccurate personal information we maintain about you.
-
Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right to limit our use and disclosure of sensitive personal information in certain circumstances.
-
Right to Opt-Out of the Sale or Sharing of Personal Information: As noted above, you have the right to direct a business that sells or shares personal information not to sell or share your personal information.
-
Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising any of your CCPA/CPRA rights.
​
To exercise any of these rights, please contact us using the details provided in the Contact Us section. We may need to verify your identity before processing your request.
​
8. Security of Your Information
We take reasonable technical and organisational measures to protect your personal information from unauthorised access, loss, misuse, alteration, or destruction. Our website is hosted by Wix, which implements security features to protect data on its platform. For email communications, your email provider also employs security measures. However, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
9. Third-Party Websites
Our website may contain links to other websites that are not operated by us (e.g., external resources, social media profiles). If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
​
10. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children without parental consent. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from a child without verification of parental consent, we take steps to remove that information from our servers.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
12. Contact Us
If you have any questions about this Privacy Policy, your personal data, or if you wish to exercise your data protection rights, please contact us by email at: luke@lukewellortherapy.com
​
13. Right to Lodge a Complaint
If you are a resident of the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
​
For the UK, the supervisory authority is the Information Commissioner's Office (ICO). Their website is https://ico.org.uk/. For other EEA countries, you can find your local supervisory authority here: https://edpb.europa.eu/about-edpb/board/members_en