Last updated: 27/08/2025Soul of Sophia (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or interact with our services.
1. Who We AreSoul of Sophia is the data controller for the personal data collected through this website. If you have any questions about this policy or how your data is handled, please contact:
Email: data@soulofsophia.co.uk
2. The Information We CollectWe may collect and process the following types of personal data:
- Identity Data: name, username, or similar identifiers.
- Contact Data: email address, telephone number, postal address.
- Transactional Data: details about services you have purchased or booked.
- Technical Data: IP address, browser type, time zone, operating system, cookies, and analytics data.
- Usage Data: information about how you use our website and services.
- Marketing & Communications Data: your preferences in receiving marketing from us.
We do not knowingly collect information from anyone under 18 without parental consent.
3. How We Collect Your Data
We collect data through:
- Information you provide directly (e.g. booking forms, newsletter sign-ups, email correspondence).
- Third parties
4. How We Use Your DataWe use your personal data only when lawful. Common purposes include:
- To provide and manage our services.
- To process payments and deliver digital/physical services.
- To respond to enquiries and customer support requests.
- To send newsletters, updates, and marketing (with your consent).
- To comply with legal and regulatory obligations.
- To improve our website, services, and user experience.
5. Legal Basis for ProcessingUnder UK GDPR, we rely on the following lawful bases:
- Contract: to provide the services you request.
- Consent: where you have opted in to receive marketing or newsletters.
- Legal obligation: to comply with UK law (e.g. tax or accounting requirements).
- Legitimate interests: to operate, improve, and secure our business.
6. Sharing Your DataWe do not sell or rent your data. We may share your information with trusted third parties only when necessary:
- Service providers (e.g. IT, hosting, email marketing, payment processors).
- Professional advisers (e.g. legal, banking, accounting).
- Regulators and law enforcement where legally required.
All third parties are required to respect the security of your data and to process it lawfully.
7. International TransfersSome service providers (e.g. email or payment platforms) may transfer your data outside the UK. Where this occurs, we ensure adequate safeguards (such as UK adequacy regulations or Standard Contractual Clauses) are in place.
8. Data SecurityWe use appropriate technical and organisational measures to prevent your personal data from being lost, used, or accessed without authorisation. Access to your personal data is restricted to those who have a business need to know.
9. Data RetentionWe retain your personal data only as long as necessary to fulfil the purposes we collected it for, including legal, accounting, or reporting requirements. Typically:
- Customer and transactional data: up to 6 years (for tax/legal compliance).
- Marketing data: until you withdraw your consent.
10. Your RightsUnder UK GDPR, you have the following rights:
- Right to access the personal data we hold about you.
- Right to correct inaccurate or incomplete data.
- Right to request deletion of your data (subject to legal obligations).
- Right to restrict or object to processing.
- Right to data portability.
- Right to withdraw consent at any time (where processing is based on consent).
To exercise these rights, please contact us at [Insert email]. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): https://ico.org.uk.
12. Third-Party LinksOur website may include links to third-party websites. We are not responsible for their privacy practices, and we encourage you to read their policies.
13. Changes to This Privacy PolicyWe may update this Privacy Policy from time to time. The latest version will always be posted on this page, with the “last updated” date shown at the top.