Welcome to The Ayur Chikitsa

Policies

Privacy Policy

Last updated: 8 August 2026 (version V1.2)

Version V1.2. Effective from 8 August 2026. Published 8 August 2026; it takes effect on 8 August 2026 and is not applied to anything you were shown or agreed to before then.

1. Who we are

The Ayur Chikitsa Ltd provides Ayurvedic consultations, traditional Ayurvedic treatments, massage therapies and associated wellbeing services.

For the purposes of UK data-protection law, the data controller is The Ayur Chikitsa Ltd, company number 17314065, registered at 3 Wain Close, Huntington, York, YO32 9YQ, United Kingdom.

Privacy contact: Privacy Lead, by email at contactus@theayurchikitsa.com or by telephone on +44 (0)7377 732335. Please mark written enquiries "Privacy".

Data protection registration

The Ayur Chikitsa is registered with the Information Commissioner’s Office (ICO) for data protection purposes.

ICO Registration / Security Reference: CSN0440283

The Ayur Chikitsa Ltd determines why and how personal information is collected, used, stored and disclosed. We process personal information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy is a privacy notice. Reading it, or being shown it, is not consent to anything. Where we need your consent we ask for it separately and record it separately.

This is version V1.2 of our Privacy Policy. Effective from 8 August 2026. It was published on 8 August 2026 and replaces version V1.1 from its effective date. Earlier versions are kept in our internal policy-version register with the date each was published and took effect.

2. Scope of this policy

This policy explains how we use personal information when you:

  • Visit our website
  • Make an enquiry
  • Join a waiting list
  • Book or request an appointment
  • Pay for a consultation
  • Provide a card guarantee for a treatment
  • Attend a consultation or treatment
  • Communicate with us
  • Make a complaint
  • Exercise a data-protection right
  • Subscribe to marketing communications
  • Otherwise interact with The Ayur Chikitsa Ltd

3. Personal information we collect

The information collected depends on the services you use.

3.1 Identity and contact information

  • Your name
  • Email address
  • Telephone number
  • Postal address, where required
  • Date of birth, where relevant
  • Emergency-contact details, where appropriate
  • Parent or guardian details where services are provided to a child

3.2 Booking and appointment information

  • The consultation or treatment requested
  • Preferred and confirmed appointment dates and times
  • Appointment duration
  • Practitioner and treatment-room information
  • Booking and request status
  • Waiting-list information
  • Alternative appointment proposals
  • Cancellation and rescheduling history
  • Attendance and no-show status
  • Appointment-management activity
  • Relevant communications about your appointment

3.3 Payment and financial information

  • The amount paid or payable
  • Payment status
  • Payment-provider transaction references
  • Refund information
  • Invoice and receipt information
  • Records of cancellation or no-show fee decisions
  • Card-guarantee status
  • Bank-transfer payer name, amount, date and payment reference
  • Manual studio-payment records

We do not receive or store complete payment-card numbers, card security codes or magnetic-stripe information. Online consultation payments and card guarantees are handled through Stripe. Face-to-face card payments are handled through SumUp. Bank transfers are received through our Tide business bank account. The Ayur Chikitsa Ltd does not store full card numbers or card security codes at any time, for any payment method.

A card guarantee is not a payment at the time it is provided. A cancellation or no-show fee is not created or charged automatically merely because an appointment status changes. Any such fee requires a separate authorised administrative decision under our published cancellation policy.

3.4 Communications

  • Enquiries
  • Appointment communications
  • Emails and messages
  • Complaints
  • Privacy and data-rights requests
  • Feedback
  • Confirmation and reminder delivery records
  • Records of decisions and responses
  • Relevant evidence provided in connection with a complaint or request

3.5 Technical and security information

When you use our website, we may collect limited technical information, including:

  • IP address
  • Browser and device type
  • Date and time of requests
  • Pages or services accessed
  • Security and authentication events
  • Cookie preferences
  • Rate-limiting information
  • Limited diagnostic information necessary to maintain and secure the service

We do not intentionally place health information, complaint text, complete email bodies, complete card information or payment secrets in application logs.

3.6 Marketing information

  • Whether you agreed to receive marketing
  • When and how your preference was recorded
  • Marketing messages sent
  • Unsubscribe requests
  • A limited suppression record so that we do not contact you again after you opt out

3.7 Health, consultation and treatment information

Where it is necessary, lawful and properly authorised, we may collect:

  • Relevant medical history
  • Existing health conditions
  • Symptoms and presenting concerns
  • Medication and prescriptions
  • Allergies and sensitivities
  • Injuries
  • Pregnancy status where relevant
  • Contraindications to consultation or treatment
  • Diet, lifestyle and wellbeing information
  • Treatment suitability assessments
  • Consultation notes
  • Treatment plans
  • Treatments and techniques provided
  • Adjustments or modifications made
  • The reasons for treatment decisions
  • Client responses and outcomes
  • Adverse reactions or incidents
  • Aftercare and self-care advice
  • Records of informed consent

This information is special-category personal information under Article 9 of the UK GDPR. It receives additional protection, is only seen by people who need it to deliver or administer your treatment safely, and is never used for marketing.

Health information is collected only where the separate explicit consent described in section 5.9 has been given, and only for the purposes set out there. The same requirement applies to health information collected through paper forms, email, telephone calls or in-person consultations.

4. How we obtain your information

We normally obtain information directly from you. We may also obtain information:

  • From someone making a booking on your behalf
  • From a parent, guardian or authorised representative
  • From Stripe in relation to an online payment or card guarantee
  • From SumUp in relation to a face-to-face card payment
  • From Tide or the banking system in relation to a bank transfer
  • From our website and security systems
  • From an insurer, legal adviser or professional adviser
  • From a public authority where legally appropriate
  • From another practitioner where you have authorised the disclosure

Where information is provided by another person, we may need to verify their authority to provide it.

5. Why we use your information

We use personal information only where we have an identified purpose and lawful basis.

5.1 Enquiries and requested services

We use contact and enquiry information to respond to you and take steps at your request before entering into a contract. Lawful basis: Article 6(1)(b), steps requested before entering into a contract.

5.2 Managing appointments and providing services

  • Check availability
  • Process bookings and requests
  • Confirm appointments
  • Manage waiting lists
  • Send reminders
  • Process cancellations and rescheduling
  • Prepare for consultations and treatments
  • Provide the requested service

Lawful basis: Article 6(1)(b), performance of a contract or steps requested before entering into one.

5.3 Payments, invoices and refunds

  • Process consultation payments
  • Record card guarantees
  • Record studio payments
  • Issue invoices and receipts
  • Process refunds
  • Reconcile bank payments
  • Maintain accounting records
  • Meet tax and financial-reporting obligations

Lawful bases: Article 6(1)(b), performance of a contract; and Article 6(1)(c), compliance with legal obligations.

5.4 Appointment confirmations and reminders

We use contact information to send operational messages about your enquiry, booking, treatment request, payment, cancellation, rescheduling or appointment. These are service communications, not marketing messages. Lawful basis: Article 6(1)(b), performance of a contract or requested pre-contractual steps.

5.5 Website operation and security

  • Operate the website
  • Prevent fraud and misuse
  • Enforce rate limits
  • Protect accounts and appointment links
  • Investigate technical failures
  • Maintain service reliability

Lawful basis: Article 6(1)(f), our legitimate interests in operating a safe, secure and reliable service.

5.6 Complaints, disputes and legal claims

  • Investigate complaints
  • Respond to concerns
  • Meet insurance requirements
  • Establish facts
  • Obtain professional or legal advice
  • Establish, exercise or defend legal claims
  • Comply with applicable legal or regulatory obligations

Lawful bases: Article 6(1)(f), our legitimate interests in resolving disputes and protecting legal rights; Article 6(1)(c), where processing is required by law; and Article 9(2)(f), where special-category information is necessary for the establishment, exercise or defence of legal claims.

5.7 Data-protection requests

We use identity, contact and account information to process access, correction, restriction, erasure, objection and other data-protection requests. Lawful basis: Article 6(1)(c), compliance with a legal obligation.

5.8 Marketing

We may send marketing messages where you have actively agreed to receive them, or where the limited existing-customer exception applies and we have offered a clear opportunity to opt out. You may unsubscribe at any time. Lawful basis: Article 6(1)(a), consent, or Article 6(1)(f) where the lawful customer soft opt-in is properly used alongside the Privacy and Electronic Communications Regulations. We do not add you to a general marketing list merely because you make a booking. Marketing messages always identify us and provide a simple method of opting out.

5.9 Health and treatment information

For each health-processing purpose we have documented the applicable Article 6 lawful basis, the applicable Article 9 condition, why the information is necessary, why less intrusive information is insufficient, who may access the information, how long it will be retained and what safeguards apply. The approved wording is set out below.

Article 6 lawful basis

UK GDPR Article 6(1)(b) — contract and requested pre-contractual steps. We process health, contraindication and suitability information where it is objectively necessary to assess whether the requested Ayurvedic consultation or treatment can be provided safely and to deliver the service requested by the client.

UK GDPR Article 6(1)(f) — legitimate interests. We retain proportionate consultation, consent and treatment records where necessary to document the service provided, demonstrate our duty of care, meet professional indemnity requirements, investigate complaints and establish, exercise or defend legal claims. Our legitimate interests are balanced against the client's rights and freedoms through data minimisation, restricted practitioner access, defined retention periods, security controls and individual-rights procedures.

Article 9 condition

UK GDPR Article 9(2)(a) — explicit consent. We obtain the client's separate, explicit consent before collecting or using health information for:

  • pre-consultation suitability screening
  • identifying allergies, medication and contraindications
  • planning and safely providing the requested consultation or treatment
  • recording treatment responses, outcomes and aftercare

Consent is obtained through a separate affirmative statement, is not pre-ticked or implied, identifies the health information and purposes involved, and is recorded with the date and policy version. The client may withdraw consent for future processing, although this may mean that we cannot safely continue the consultation or treatment.

UK GDPR Article 9(2)(f) — establishment, exercise or defence of legal claims. Where necessary and proportionate, relevant health, consultation, consent and treatment records may be retained or used to investigate complaints, obtain legal or insurance advice, demonstrate the practitioner's duty of care, or establish, exercise or defend actual or prospective legal claims. Article 9(2)(f) is not used as a blanket basis for all health information. Only information relevant and necessary for those purposes is retained or used.

Supporting decision and assessment

Evidence reference: HDLBA-2026-08-02-v1 — Health Data Lawful Basis Assessment. Decision owner: Kiranmaye Cartier, Director and Privacy Lead, The Ayur Chikitsa Ltd. Approved by Kiranmaye Cartier on 02/08/2026, review date 02/08/2027.

Assessment conclusion, purpose by purpose:

  • Pre-consultation health screening — Article 6(1)(b) and Article 9(2)(a).
  • Consultation and treatment delivery — Article 6(1)(b) and Article 9(2)(a).
  • Treatment-record retention — Article 6(1)(f), together with Article 9(2)(f) where retention of the particular health information is necessary and proportionate for potential complaints, insurance matters or legal claims.
  • Complaints, incidents and legal claims — Article 6(1)(f) and Article 9(2)(f).
  • Insurance and professional-record requirements — Article 6(1)(f) and Article 9(2)(f), limited to records necessary to demonstrate consent, suitability, treatment decisions, outcomes, aftercare and duty of care.

Necessity assessment: health information is limited to what is reasonably necessary to identify contraindications, assess treatment suitability, provide the requested service safely and maintain evidence of the care provided.

Safeguards:

  • separate explicit-consent statement
  • treatment consent kept separate from data-processing consent
  • restricted practitioner access
  • role-based database permissions
  • encryption during transmission
  • no health information in email subject lines or application logs
  • individual access, correction, restriction and erasure-review procedures
  • legal-hold protection
  • seven-year adult record-retention period in accordance with the applicable Balens insurance condition
  • seven years after a minor reaches 18 for records concerning minors
  • annual review, or earlier review following a material change

Sources considered: ICO guidance on contractual necessity; ICO special-category data guidance; ICO guidance on explicit consent; ICO guidance on Article 9(2)(f) legal claims; Balens record-keeping and insurance guidance; and The Ayur Chikitsa Ltd Privacy Policy and retention schedule.

You can withdraw consent at any time where consent is the basis we rely on. Withdrawal does not affect processing that was lawful before you withdrew.

6. Information you must provide

Certain information is needed to:

  • Respond to your request
  • Arrange an appointment
  • Confirm your identity
  • Process a payment
  • Meet legal requirements
  • Assess whether a treatment is appropriate and safe

Where information is necessary for a contract or safety assessment and you do not provide it, we may be unable to accept or continue a booking or provide the requested service. Providing information for marketing is always optional.

7. Consent to treatment

Consent to the collection or use of personal information is separate from consent to receive a consultation or treatment. Agreeing to one never implies agreeing to another, and none of them is created by you simply reading this policy. This is not consent.

Before a treatment involving touch, undressing, draping or a particular technique, we will explain:

  • The nature of the treatment
  • What the treatment involves
  • Areas of the body that may be treated
  • Appropriate clothing or draping arrangements
  • Material risks or expected reactions
  • Reasonable alternatives
  • Your right to pause or stop the treatment

Treatment consent is an ongoing process. You may ask questions, request adjustments or withdraw consent to a treatment at any time. We keep dated evidence of relevant treatment consent in the treatment record, in line with Balens' guidance.

8. Who we share information with

We disclose information only where necessary for providing services, administering the business, meeting legal obligations or protecting legal rights. We do not sell personal information.

8.1 Authorised personnel

Information may be accessed by authorised practitioners, administrators and privacy personnel who need it for their role. Access to health and treatment information is restricted to authorised personnel.

8.2 Technology and service providers

  • Lovable, for the application platform and hosting services
  • Supabase, used within the platform architecture for database, authentication and storage services
  • Cloudflare, for website delivery and security services
  • Resend, for transactional email delivery
  • Stripe, for online payments, refunds and card guarantees
  • SumUp, for face-to-face card transactions
  • Tide, as our business bank account provider

The exact legal role of a provider may vary by processing activity. The summary below was checked against the actual configuration of this website — the hosting platform, the database, authentication, file storage, server functions, email delivery and the payment code paths — rather than assumed.

The summary gives each provider, what we use it for, its role, the information involved, and where processing happens and how international transfers are addressed. We keep a fuller internal provider and compliance register, including our own verification work and any outstanding checks, and we review it as part of our data-protection governance. If you would like more detail about a particular provider, please contact our Privacy Lead.

Stripe processes prepaid consultation payments made through this website and securely stores the limited card guarantee used to secure a ritual appointment; card details are entered directly with Stripe and never reach our website or our database. Stripe may process a cancellation or no-show fee, but only where an authorised administrator has explicitly decided that the fee applies and has recorded the reason. No fee is ever charged merely because an appointment's status changes.

SumUp processes face-to-face card payments taken at the York Treatment Studio. This website records only the SumUp transaction or receipt reference needed to reconcile the payment.

Tide is our business bank account. Tide is not our face-to-face payment processor, and there is no connection of any kind between this website and Tide: the website sends Tide nothing. Where you pay by bank transfer, the banking system gives our bank the payer name, the sending account information supplied through that system, the payment amount and date, the payment reference and other bank-transaction information. For that banking data our bank is an independent recipient and controller under its own terms and regulatory duties. It is not our data processor, and it receives no health, intake or treatment information from us.

8.3 Professional and regulatory recipients

  • Accountants
  • Professional indemnity insurers, including Balens or the relevant insurer underwriting the policy
  • Legal advisers
  • Professional bodies
  • Regulators
  • Courts
  • Law-enforcement organisations
  • Public authorities where disclosure is required or legally justified

8.4 Business changes

If the business is sold, transferred, reorganised or ceases trading, information may be transferred to an appropriate successor subject to legal, professional and confidentiality safeguards.

ProviderWhat we use it forRoleInformation involvedLocation and transfers
Lovable (Lovable Labs Incorporated)Website and application platform, hosting, database, sign-in, file storage and server functions.Acts for us on our instructions as our platform provider, and engages its own providers (Supabase and Cloudflare below).All information stored by the website, including health and intake information, account and sign-in data, and security records.Processing takes place on the provider's platform and may involve locations outside the UK. Transfers are addressed through the provider's published data-processing terms and the safeguards in them.
Supabase (Supabase, Inc.)The managed database, authentication service and file storage used within the platform.Engaged by our platform provider rather than contracted directly by us.All stored website records, plus sign-in and session information.The database region provisioned by the platform, which may be outside the UK. Transfers are addressed through the platform provider's terms.
Cloudflare (Cloudflare, Inc.)Delivery of our pages and the running of server functions close to you.Engaged by our platform provider rather than contracted directly by us.Request information, including IP address, and anything passing through a request or response.A global delivery network, so the serving location depends on where you are. Transfers are addressed through the platform provider's terms.
Resend (Resend, Inc.)Sending transactional emails such as confirmations, reminders and privacy-request acknowledgements.Acts for us on our instructions.Your name, email address and the content of the message we send you. No treatment notes are sent by email.United States and European Union, per the provider's documentation. Transfers are addressed through the provider's data-processing terms.
Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.)Online payments, refunds and the card guarantee used to secure a ritual appointment.Acts for us for the payments we ask it to take, and as a controller in its own right for payment-fraud and regulatory purposes.Payment amount, currency, references and your card details, which you enter directly with Stripe and which never reach our website or database.United Kingdom, European Union and United States, with transfers addressed through the provider's published terms.
SumUp (SumUp Limited)Card payments taken in person at the York Treatment Studio.Acts as the payment provider for in-person card transactions under its own terms.Card transaction information handled by SumUp. We keep only the transaction or receipt reference needed to reconcile the payment.United Kingdom and European Union. No restricted international transfer identified.
Tide (business bank account provider)Our business bank account, used where you pay by bank transfer.An independent recipient acting as a controller under its own banking terms. It is not our processor and receives no health or treatment information from us.Bank-transfer information supplied through the banking system, such as payer name, amount, date and reference.United Kingdom. No restricted international transfer identified.

9. International transfers

Some technology providers or their approved subprocessors may process information outside the United Kingdom. We do not claim that all information stays in the UK. Where a restricted international transfer takes place, we will use an applicable legal mechanism, which may include:

  • A UK adequacy regulation
  • The UK International Data Transfer Agreement
  • The UK Addendum to approved standard contractual clauses
  • Another legally permitted safeguard

You may contact us for information about the safeguards relevant to your information.

10. How long we retain information

We retain information only for as long as it is necessary for the purpose for which it was collected, insurance requirements, financial obligations, complaints, legal claims and regulatory responsibilities.

CategoryHow long we keep it
10.1 Adult consultation and treatment recordsA minimum of seven years after the client's last treatment or consultation. This includes health and consultation forms, medical and contraindication information, consent records, treatment plans, practitioner notes, session records, treatment outcomes, adverse-event records and aftercare advice.
10.2 Records concerning minorsAt least seven years after the client reaches the age of 18, normally meaning retention until at least the client's 25th birthday. Additional parent, guardian, capacity and safeguarding records may also be retained.
10.3 Vulnerable adultsMay be retained for longer than seven years where reasonably required by our insurer, an unresolved complaint, a potential or active legal claim, safeguarding concerns, the person's circumstances or a documented legal hold.
10.4 Complaints, incidents and claimsNormally at least seven years after closure or the last related treatment, whichever is later, and longer where a claim, investigation, insurance matter or legal hold remains open.
10.5 Appointment recordsRecords forming part of the consultation or treatment history are kept for the same period as the associated treatment record. Booking enquiries, abandoned requests and waiting-list records that do not result in treatment are normally kept for up to 12 months after the last activity.
10.6 Financial and accounting recordsSix years from the end of the company financial year to which they relate, and longer where HMRC has opened a compliance check, a transaction covers more than one accounting period or another legal requirement applies.
10.7 Card-guarantee and fee-decision recordsOnly as long as reasonably necessary to administer the appointment, demonstrate the client's authorisation, resolve a dispute, meet insurance or accounting requirements, or establish or defend a legal claim. Complete card details are not stored.
10.8 Marketing recordsWhile you remain subscribed. Where you unsubscribe, we may retain a minimal suppression record so that your preference continues to be respected.
10.9 Privacy requestsNormally up to three years after closure, or longer where a complaint, dispute or legal hold applies.
10.10 Security and technical logsA short period appropriate to their purpose, and longer where required to investigate fraud, misuse, a security incident or a legal claim.

At the end of the relevant retention period, information is securely deleted, anonymised or placed beyond normal operational use unless there is a documented reason to retain it. Records covered by a legal hold are never deleted while the hold is in place.

Balens' published insurance guidance requires a minimum of seven years for adult treatment records and seven years after a minor turns 18. It also notes that vulnerable-adult and legal-claim circumstances may justify longer retention.

11. How we protect information

We use proportionate technical and organisational measures designed to protect personal information. These may include:

  • Role-based access controls
  • Restricted practitioner and privacy-administrator permissions
  • Database row-level security
  • Encryption during transmission
  • Secure server-side secret storage
  • Purpose-specific secure links
  • Token expiry and revocation
  • Payment-provider hosted card handling
  • Audit and decision records
  • Backup and recovery controls
  • Duplicate-payment and duplicate-message protections
  • Security headers
  • Rate limiting
  • Monitoring of booking, payment, email and privacy failures

No internet or storage system can guarantee absolute security. We review and test our controls regularly, and we will tell you and the Information Commissioner's Office where we are required to do so following a personal-data breach.

12. Cookies and browser storage

This website uses only the storage it needs to work, plus optional storage you have agreed to. Essential storage covers security, keeping forms working, session handling and remembering your privacy choices; it does not require your consent.

Optional analytics or similar storage is used only with your permission, which you can change at any time using the cookie settings link in the footer.

A full item-by-item audit of the cookies and browser storage used on this website is published in our Cookie Policy.

13. Your rights

Depending on the circumstances and the lawful basis used, you may have the right to:

  • Request access to your personal information
  • Ask us to correct inaccurate or incomplete information
  • Ask us to erase information
  • Ask us to restrict how information is used
  • Object to processing based on legitimate interests
  • Object to direct marketing at any time
  • Receive certain information in a portable format
  • Withdraw consent at any time, where our processing relies on consent
  • Complain to us, and to the Information Commissioner's Office

Erasure is not automatic and it is not absolute. We will always consider your request, but we may have to refuse it in whole or in part because of accounting and tax law, insurance requirements, an existing or anticipated legal claim, or another legal obligation. Where we cannot erase information we will explain why, tell you what we have done instead, and tell you how to challenge our decision.

There is normally no charge for exercising a right, and we will respond within one calendar month. We may extend that by up to two further months for complex or numerous requests, and will tell you within the first month if we do. We may request proportionate evidence to confirm your identity.

To make a request, use our secure form: Submit a privacy request.

To raise a concern about how we have handled your information: Make a data-protection complaint.

You can also email the privacy contact at contactus@theayurchikitsa.com.

14. Complaints

Please contact us first so that we can investigate and respond: Privacy Lead, The Ayur Chikitsa Ltd, 3 Wain Close, Huntington, York, YO32 9YQ, United Kingdom. Email: contactus@theayurchikitsa.com.

You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone 0303 123 1113. Website: ico.org.uk.

15. Automated decisions, children and other websites

We do not make solely automated decisions about you that have legal or similarly significant effects. Appointment approvals, fee decisions and privacy-request outcomes are all made by a person.

Where services are offered to a child or young person, we will consider the child's age, maturity and understanding, parent or guardian involvement, capacity to consent, safeguarding requirements, treatment suitability, insurance conditions, and additional confidentiality and retention requirements.

Our website links to external websites and social-media services that we do not control. Please read their own privacy information before giving them your details.

16. Changes to this policy

We update this policy when our services, providers or legal responsibilities change, or where we can make it clearer. Each update is published as a new version with its own publication date and effective date, and only an authorised privacy administrator can publish or supersede a version.

Where a change materially affects how information we already hold is used, we will take reasonable steps to tell affected people before the new use begins.

Quick links