Protected in transit and at rest
We use SSL for transfers and an encrypted database for stored records.
Privacy and trust
Your privacy is as important as your wellbeing. We collect only the personal data needed to arrange appointments, support your care and improve your experience at our Saint Austell day spa.
We use SSL for transfers and an encrypted database for stored records.
Marketing messages need your consent, and you can change that choice at any time.
You can ask to access, correct or erase personal information we hold about you.
These answers explain what we collect, why we need it and which organisations may process it when you contact or visit Z&B Nurture.
We collect your name, phone number and email address when you make an appointment enquiry or booking. We may also record treatment preferences, consultation answers and relevant health notes when they affect safe massage therapy, beauty services or wellness treatments.
Payment details are entered through our payment provider. Z&B Nurture does not keep full card numbers.
We use your details to confirm appointments, prepare consultations, deliver treatments, take payment and respond to customer support requests. Health notes help our practitioners make safe decisions during your visit.
We send marketing only where you have opted in. Every marketing message includes a clear way to change your preferences.
Our website uses essential cookies for core page features, preference cookies to remember choices and analytics cookies to show us how visitors use the site. Analytics and preference cookies are optional.
A cookie consent banner lets you accept, reject or adjust optional categories. Your browser settings can also remove cookies already stored on your device.
We retain treatment and health records for 7 years after your last visit. Other customer data is kept for 2 years after your last visit, unless a longer period is required for a legal or accounting reason.
We review records when these periods end and securely delete information we no longer need.
We share the details needed to operate the service with our booking platform and payment processors. These providers process information on our instructions and apply their own security duties.
We do not sell personal data or share it with third-party marketers. We may disclose information where the law requires it or where it is needed to protect someone from serious harm.
You can ask us to access, rectify or erase your personal data. You can also request restriction of processing, receive certain information in a portable format or object to processing based on your circumstances.
Marketing consent can be withdrawn at any time. You can raise a concern with the Information Commissioner's Office if you believe we have not handled your request properly.
Data is encrypted at rest and in transit. Access is limited to people who need it for bookings, treatment delivery or customer support, and staff receive privacy and data security training.
We review our booking systems and access controls so we can respond quickly if a security incident affects personal information.
Send a privacy request to [email protected] with the subject line 'Data Protection'. Please include enough detail for us to identify your request. We may ask for proof of identity before releasing personal information.
We aim to respond within one month. Complex requests may take longer, and we will explain the reason if that happens.
Our team can explain how a booking, consultation or marketing preference is handled.