Privacy Policy

At Blended Wellbeing (“we”, “our” or “us”), we take your privacy seriously. We are registered with the Information Commissioner’s Office (ICO) and this policy explains how we collect, use, store, and protect your personal data in line with the UK General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018. 

This Privacy Policy should be read alongside, and in addition to, our Terms & Conditions.

1.   Personal Data We Collect

We only collect the data necessary to run Blended Wellbeing effectively and ensure member safety.  This includes:

  • Personal identification information: name (so we know who you are), email address (to send group updates, event details, and important information), phone number (for communication via WhatsApp groups, if used), etc
  • Emergency contact details – essential for safety purposes during events and activities. You confirm that you have permission from any emergency contact to share their details with Blended Wellbeing for emergency purposes
  • Your IP address and device/ browser you are using
  • Information pertaining to any payments you make via our website (not including payment details or personal financial information).

2.   How we Collect Your Personal Date

You directly provide us with most of the personal data we collect.  We collect and process personal data when you:

  • Voluntarily submit a contact form via our website
  • Register online or place an order for tickets
  • Voluntarily complete a customer survey or provide feedback on any of our message boards or via email
  • Use or view our website, via your browser’s cookies.

We may also receive your data indirectly from the following sources:

  • Analytics packages, such as Google
  • Payment platforms we use to process payments (membership fees are processed securely by our payment provider, Stripe. When you make a payment, certain personal information (including your name, billing address and payment information) is provided directly to Stripe for the purposes of processing your payment, fraud prevention and compliance with legal obligations. Stripe processes this information in accordance with its own Privacy Policy. Note we do not store or have any access to your payment details)
  • Third-party mailing platforms that allow us to send you offers, information, etc (we use Mailchimp).

3.   How We Use Your Personal Data

We use your personal data to:

  • Send event invitations, updates, and communications
  • Process memberships and ticket purchases
  • Manage memberships and event participation
  • Provide customer service
  • Ensure member safety at events (using emergency contact information when necessary)
  • Facilitate group communications and coordination
  • Send service updates and marketing, where permitted
  • Operate our website and improve our services
  • Detect fraud or misuse
  • Comply with legal obligations

We do not share your personal data with third parties for marketing purposes, sell your personal data, or use it for activities unrelated to the group.

4.   Marketing Communications

If you have consented, we may send newsletters, event updates, invitations and promotions.  You can unsubscribe at any time via the link in emails or by contacting us at office@tracyhammond.co.uk.

5.   Photos & Social Media

  • Photos and videos may be taken at events and used for group promotion on our website and social media.
  • Where individuals are clearly identifiable, we will ensure there is an appropriate lawful basis for processing and will provide members with information about how they can object or opt out where appropriate.
  • If you prefer not to appear in photos or videos, please inform the event hosts or organisers.

6.   Lawful Bases for Processing

We only use your personal data where we have a lawful basis to do so and we rely on the following lawful bases under GDPR:

  • Contract – to process memberships, bookings ad services
  • Legitimate interests – to administer memberships, organise events, improve our services, prevent fraud and communicate with members, where appropriate
  • Consent – for marketing and optional cookies; you can withdraw consent at any time
  • Legal obligation – where required by law.

7.   Storage and Retention of Personal Data

We store your personal data securely on our hosting platform, which is located in the U.K.

Form data submitted via our website is kept within the website as a copy in case we need to refer to it,

Unless a longer retention period is required or permitted by law, we will only hold your personal data for the period necessary to fulfil the purposes outlined in this Privacy Policy, or until you request that the information be deleted in accordance with your right to erasure (see “Your Rights Under GDPR” section below).

Even if we delete your personal data, we reserve the right to maintain a copy for legal, tax or regulatory purposes but, in such event, we will do so only as long as necessary to fulfil those legal, tax or regulatory purposes.

8.   How We Protect Your Personal Data

We use appropriate technical and organisational measures to protect your personal data from unauthorised access, loss or misuse. For example:

  • We use password-protected systems and secure platforms for all data storage.
  • Access to personal data is limited to what is necessary for group administration and safety, and is only accessible by authorised administrators.
  • We regularly review our data storage and security practices.
  • We will never publicly share your personal data without explicit permission.

No online system is completely secure, but we take security seriously.

9.   Sharing of Personal Data

We do not sell or rent your personal data to third parties.

We may share your personal data with trusted third-party service providers who help us run our business, and only to the extent necessary. These include:

  • Essential service providers (Mailchimp, Stripe, Google Drive, WhatsApp/Facebook) to facilitate group operations, communications, and securely handle payment transactions, Platform-dependent privacy policies also apply
  • Website hosting and IT service providers to operate and improve our website
  • Accountants and legal advisers.

All trusted third-party service providers are reputable services with appropriate security measures and GDPR compliance.  They must protect your data and process it lawfully. We do not allow them to use your personal data for their own purposes.

We may also disclose your personal data in the following circumstances:

  • Emergency situations where sharing emergency contact information is necessary for member safety
  • When we have your explicit consent to share your personal data
  • Where we are legally obligated to provide information, for example to comply with a court order or regulatory requirement.

10.  International Data Transfers

Your data is primarily stored within the UK and the European Economic Area (EEA). However, from time to time, we may transfer your personal data to countries outside of these regions (for example, to third-party service providers, such as Mailchimp).  Where this happens, we ensure that appropriate safeguards are in place so that your data receives a level of protection equivalent to that provided under GDPR.

11.      Your Rights Under GDPR

You have the following rights regarding your personal data::

  • Right to access – the right to request copies of the personal data we hold about you
  • Right to rectification – the right to correct any inaccurate or incomplete information
  • Right to erasure – the right to request deletion of your personal data
  • Right to restrict processing – the right to limit how we use your personal data
  • Right to data portability – the right to request that we move, copy or transfer your personal data to another organisation, or directly to you, under certain conditions
  • Right to object – the right to object to certain uses of your personal data
  • Right to withdraw consent – the right to unsubscribe from communications or leave the group at any time

To exercise any of these rights, please contact: office@tracyhammond.co.uk

We will respond to your request within 30 days.

It is important that the personal data we retain about you is accurate and current. Please keep us informed if your personal data changes.

12.      Cookies

Cookies are text files placed on your device to collect standard internet log information and visitor behaviour information. The cookie identifies your browser but will not let a website know any personal information about you, such as your name and/or address. When you visit our website, we may collect information from you automatically through cookies or similar technology.

For further information, visit allaboutcookies.org. 

We use cookies in a range of ways to improve your experience on our website, including:

  • Keeping you signed in
  • Understanding how you use our website.

Our website uses the following types of cookies:

  • Strictly necessary cookies – these are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website or make use of e-billing services.
  • Analytics/performance cookies – these are used to recognise and count the number of visitors and understand how visitors use our website. This helps us improve it.
  • Functionality cookies – these are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

You can set your browser not to accept cookies, and the above website tells you how to remove cookies from your browser.  However, note that in a few cases, some of our website features may not function as a result. .

13.  Children’s Privacy

Our services are intended for women aged 18 years and over. We do not knowingly collect personal data from children under 13 years.  If you believe a child has provided us with personal data, please contact us at office@tracyhammond.co.uk and we will delete it promptly.

14.  Links to other websites

This website may, from time to time, provide links to other websites. We are not responsible for the content of those websites. Our Privacy Policy applies only to our website, so if you click a link to another website, you are advised to read their privacy policy.

15.  Contact Information

Data Controller: Blended Wellbeing

ICO Registration No: ZA753228

Contact: office@tracyhammond.co.uk

For any questions about this Privacy Policy, your data rights, or how we handle your personal data, please contact us using the details above.

16.  Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Members will be notified of any significant changes via email or group communications.

Continued participation in the group following notification of changes to this Privacy Policy constitutes acceptance of the updated policy.

17.  Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

By joining Blended Wellbeing you acknowledge that you have read and agree to this Privacy Policy.

Let’s keep this a safe, fun, and connected community

Last Updated: July 2026