Node Wellbeing, Privacy Policy
Node Wellbeing Privacy Policy
Last updated: 20 August 2026
Node Wellbeing (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data when you visit our website, book a session, join our mailing list, or otherwise interact with us, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Node Wellbeing is a meditation and nervous system regulation practice based in Leigh-on-Sea, Essex, run by Hannah Bryant.
Data controller: Hannah Bryant, trading as Node Wellbeing
Contact: hannah@nodewellbeing.com
Website: nodewellbeing.com
If you have any questions about this policy or how we handle your data, please contact us at the email above.
2. What personal data we collect
Depending on how you interact with us, we may collect:
• Contact details — name, email address, phone number
• Booking and session information — sessions attended, class preferences, dates booked
• Payment information — processed by bank transfer; we do not have access to full bank account details
• Health-related information you choose to share — for example, injuries, medical conditions, or pregnancy, if you tell us this so we can teach you safely
• Marketing preferences — if you sign up to our mailing list or newsletter
• Technical data — IP address, browser type, device information, and pages visited, collected automatically via cookies or similar technologies
• Communications — messages you send us via email, social media, or contact forms
3. How we use your data
We use your personal data to:
• Manage bookings for classes, workshops, walks, and 1:1 sessions
• Process payments
• Teach you safely, including making reasonable adjustments where you’ve shared relevant health information
• Send you information you’ve requested, such as newsletters or class updates (only where you’ve opted in)
• Respond to enquiries and provide customer support
• Improve our website and services
• Meet legal and accounting obligations
4. Our legal basis for processing
We rely on the following legal bases under UK GDPR:
• Contract — to book and deliver sessions you’ve paid for
• Consent — for marketing emails and any health information you voluntarily share; you can withdraw consent at any time
• Legitimate interests — to run and improve our business, such as understanding how our website is used
• Legal obligation — for example, keeping financial records
Health-related information is a special category of data under UK GDPR. We only collect this with your explicit consent, and only to the extent necessary to teach you safely.
5. Cookies
Our website uses cookies to help it function properly and to understand how visitors use the site.
• Essential cookies — needed for the website to work
• Analytics cookies — e.g. [Google Analytics], to understand visitor numbers and behaviour
• Marketing cookies — e.g. Meta/Instagram pixel, if used for advertising
You can control or disable cookies through your browser settings, and where required we will ask for your consent via a cookie banner before non-essential cookies are set.
6. Sharing your data
We do not sell your personal data. We may share it with:
• Service providers who help us run the business, such as our booking platform ([insert platform, e.g. Acuity/Fresha]), payment processor, email marketing provider ([insert platform, e.g. Mailchimp]), and website host
• Professional advisers, such as our accountant, where necessary
• Authorities, where required by law
All third parties are required to keep your data secure and only use it for the purposes we specify.
7. International transfers
If any of our service providers store or process data outside the UK, we ensure appropriate safeguards are in place, such as the UK’s International Data Transfer Agreement or adequacy regulations.
8. How long we keep your data
We keep personal data only as long as necessary:
• Booking and payment records: typically 6 years, in line with HMRC requirements
• Marketing contact details: until you unsubscribe or ask us to delete them
• Health information: only for as long as you remain an active client, then securely deleted
9. Your rights
Under UK GDPR, you have the right to:
• Access the personal data we hold about you
• Correct inaccurate data
• Request deletion of your data
• Restrict or object to certain processing
• Data portability
• Withdraw consent at any time (this won’t affect processing carried out before withdrawal)
To exercise any of these rights, contact hannah@nodewellbeing.com. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk if you believe your data hasn’t been handled properly.
10. Keeping your data secure
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse.
11. Children’s data
Our services are aimed at adults. We do not knowingly collect data from children under 16 without parental consent.
12. Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with an updated “last updated” date.