Privacy Policy

SECTION 1 – WHO WE ARE

We are Chelmsford Wellbeing Centre.

SECTION 2 – WHAT DO WE DO WITH YOUR INFORMATION?

When you purchase or contact us through our website, we collect the personal information you give us such as your name, address and email address. We use this information for sales and services communication.

When you browse our website, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. Please see Section 6 for more details about specific cookies we collect.

Email marketing

With your permission, we may send you emails about our store, new products and other updates. We use Mailchimp for email marketing and to communicate with our clients. Mailchimp offers a double opt-in service and offer full visibility of any of your information used by this service and the option to unsubscribe which will delete any of your personal data.

We do not have an expiry on the amount of time we will hold your data for. We do offer withdrawal of consent and deletion of your data at any time upon your request.

SECTION 3 – CONSENT

How do you get my consent?

When you provide us with personal information to complete a transaction or to contact us, we require your acceptance of the content of this privacy policy, that you consent to our collecting it and using it for that specific reason only.

If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.

How do I withdraw my consent or request my data to be removed?

If after you opt-in, you change your mind, you may withdraw your consent for us to store any personal data about you, contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at sales@chelmsfordwellbeingcentre.com or mailing us at:

Chelmsford Wellbeing Centre, 13 Railway Street, Chelmsford, Essex, CM1 1QS

SECTION 4 – DATA

Our website is hosted on Digital Ocean’s servers. Data is stored through Digital Ocean’s data storage, databases and the general hosting application. They store your data on a secure server behind a firewall.

Payment

If you choose a direct payment gateway to complete a purchase or pay an invoice, PayPal stores your credit or debit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.

All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.

PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.

Data breaches

In the rare occurrence of a data breach, which would significantly harm individuals, we will be report it within 72 hours to the ICO. We will also notify any customers affected.

SECTION 5 – THIRD-PARTY SERVICES

In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways, email marketing systems and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.

For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.

In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.

Once you leave our website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy.

Links

When you click on links on our website, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.

SECTION 6 – SECURITY & COOKIES

To protect your personal information, we take precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

If you provide us with your credit or debit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.

Cookies

This site uses only anonymous cookies, meaning that our cookies are not collecting any information which would be enable you to be to identified personally.

Cookies are small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymised tracking data to third party applications like Google Analytics. As a rule, cookies will make your browsing experience better.

However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the Help section of your browser or taking a look at the About Cookies website which offers guidance for all modern browsers.

These are the cookies we use:

Ecommerce Cookies

Here is a list of cookies that we use for our online store. We’ve listed them here so you can choose if you want to opt-out of cookies or not.

To keep track of cart data, our ecommerce platform makes use of 3 cookies:

  • _cart_hash so we know if you’ve added an item to your cart.
  • _items_in_cart so we know how many items you have added to your cart.
  • _session_ if you return to our site, we’ll be able to provide your current cart contents.

The first two cookies contain information about the cart as a whole and helps us know when the cart data changes. The final cookie (_session_) contains a unique code for each customer so that it knows where to find the cart data in the database for each customer. No personal information is stored within these cookies.

Google Analytics Cookies

We use Google Analytics on our website to improve customer experience and make future improvements on our website. They are as follows:

  • collect Used to send data to Google Analytics about the visitor’s device and behaviour. Tracks the visitor across devices and marketing channels.
  • NID Registers a unique ID that identifies a returning user’s device. The ID is used for targeted ads.
  • _ga 2 years Used to distinguish users.
  • _gid 24 hours Used to distinguish users.
  • _gat 1 minute Used to throttle request rate.
  • AMP_TOKEN 30 seconds to 1 year Contains a token that can be used to retrieve a Client ID from AMP Client ID service. Other possible values indicate opt-out, inflight request or an error retrieving a Client ID from AMP Client ID service.
  • _gac_ 90 days Contains campaign related information for the user.

The ga.js JavaScript library present on our website and uses first-party cookies to:

  • Determine which domain to measure
  • Distinguish unique users
  • Throttle the request rate
  • Remember the number and time of previous visits
  • Remember traffic source information
  • Determine the start and end of a session
  • Remember the value of visitor-level custom variables

Specific ga.js cookies are as follows:

  • __utma 2 years from set/update Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing __utma cookies exists. The cookie is updated every time data is sent to Google Analytics.
  • __utmt 10 minutes Used to throttle request rate.
  • __utmb 30 mins from set/update Used to determine new sessions/visits. The cookie is created when the javascript library executes and no existing __utmb cookies exists. The cookie is updated every time data is sent to Google Analytics.
  • __utmc End of browser session Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the __utmb cookie to determine whether the user was in a new session/visit.
  • __utmz 6 months from set/update Stores the traffic source or campaign that explains how the user reached your site. The cookie is created when the javascript library executes and is updated every time data is sent to Google Analytics.
  • __utmv 2 years from set/update Used to store visitor-level custom variable data. This cookie is created when a developer uses the _setCustomVar method with a visitor level custom variable. This cookie was also used for the deprecated _setVar method. The cookie is updated every time data is sent to Google Analytics.

Wordfence Cookies

  • wfvt_# Remembers the user’s submitted data when a comment is submitted in a blog post. The purpose is to auto-populate form fields for subsequent comments, in order to save time for the user.

Cloudflare Cookies

  • __cfduid Used by the content network, Cloudflare, to identify trusted web traffic.
  • __cfduid Used by the content network, Cloudflare, to identify trusted web traffic.
  • expanded Used by the content network, Cloudflare, to optimise website performance.
  • superMinimize Used by the content network, Cloudflare, to optimise website performance.

Your Data

Your data is stored through Digital Ocean’s data storage and databases. They are stored on a secure server behind a firewall. We use SSH to access our servers and use public key authentication when accessing them. We do not have any public facing control panels exposed on our server.

SECTION 7 – CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

QUESTIONS AND CONTACT INFORMATION

If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at sales@chelmsfordwellbeingcentre.com or by mail at:

Chelmsford Wellbeing Centre

Re: Privacy Compliance Officer

13 Railway Street, Chelmsford, Essex, CM1 1QS United Kingdom