Data Privacy Policy for You Happy First – at a glance

The GDPR (General Data Protection Regulation) makes it law for us to make sure you are aware of and understand how we use and store your personal data and your data rights.

What is personal data?

It includes any information that can be used to identify you like your name, contact details, photo and ‘special category data’, which includes health and other sensitive information like a Medical Screening form for appointments, sessions, workshops and any information you choose to share before, during and after your attendance.

It also includes any private information you may choose to share during a session, workshop or event.

Data is collected, used and stored by: Alexandra Datwyler

Why do we need to collect your information/data?

To be able to offer workshops, events and other services, to communicate with you as well as promote our offerings in newsletters and on social media. Also, to comply with insurance, and to process financial transactions.

How do we use and store your data?

We take keeping your data safe very seriously

  • We will only collect the minimum information necessary
  • We will only store it for as long as necessary
  • We keep paper data/forms/records safe in a locked cabinet
  • We keep digital records on our computers, phones or tablets private and only we have access

We work with other people (3rd party companies and data processors) for admin and marketing.

  • We choose well known companies who comply with data privacy rules, for newsletter signups, contact forms and appointment scheduling.

Know your rights – you have the…

Right to be informed – see the full policy for all details

Right to have access asking for a copy of your data

Right to rectification – to correct, revise or remove data

Right to erasure – to have your data deleted and ‘be forgotten’

Right to restrict processing – request limitations to how we use your data

Right to data portability – to ask for your data to be given to you to use for another service

Right to object – to us using your data for specific purposes

Rights related to automated decision-making including profiling

Please note: When you agree to You Happy First’s Data Privacy Policy, you agree to the way your personal data is used and stored by Alexandra and any 3rd parties they work with. You also agree that you understand your data rights (see the full document to be fully informed) and have contacted Alexandra if you have any question or concerns before agreeing.

Please see the full policy for exceptions where data will be stored long term or cannot be recalled/deleted.

You Happy First – Alexandra Datwyler

Contact: alexandra@youhappyfirst.com

Registered with the ICO (Information Commissioners Office) required for all UK data controllers

 

OVERVIEW (updated 25th February 2025)

Paper files are locked away in a filing cabinet and only Alexandra has access. Alexandra has a ‘tidy desk’ policy. Personal and sensitive information is never left out where it is visible to others.

Digital files. Computer, phone and tablet are password protected at all times. Alexandra takes care in every way possible to avoid loss or theft. Information gets synced/shared between these and backed up using cloud storage with its own security & encryption in place. Access is password protected and only Alexandra knows the passwords. External hard drive or memory stick back up is stored in a locked filing cabinet when not in use.

3rd party companies and data controllers used by You Happy First for communication, data storage, file transfers and more, have their own strict security in place with their own policies incl. for website cookies, needed for some functions to work. You Happy First's online accounts with all 3rd party companies are password protected.

 

Data Privacy Policy for You Happy First Unite

Introduction

The General Data Protection Regulation (GDPR, which came into effect in May 2018) is EU law and formed part of the data protection regime in the UK, until the UK left the EU in 2020. The UK Data Protection regime is now set out in the UK DPA 2018 (Data Protection Act 2018) and the EU GDPR has been retained in UK law as the UK GDPR.

We adhere to both the UK DPA 2018 and the EU GDPR.
We are aware there are a growing number of other location specific Data Privacy Laws around the world Overview of Data Privacy Laws Around The World. It is impossible for us to study the full content and follow all updates for every one of these at all times. We ask anyone from outside the UK and EU, to get in touch if you have any specific Data Privacy concerns or requests beyond the DPA 2018 and EU GDPR.

GDPR makes it law for businesses who store any data about you to make sure you are aware of how your data is used, and that you understand your rights.

This requires us to explain this to you in a transparent and easy to understand way separate from other Terms and Conditions. Our business is aimed at adults, but we may also work with younger people and people whose first language is not English. We aim to word this policy in the simplest way possible.

If you have any questions please do not hesitate to get in touch (details below).

Who is collecting your Data

You Happy First – Alexandra Datwyler

Email: alexandra@youhappyfirst.com

Our business name is You Happy First, and we will use the words ‘YHF’, ‘Alexandra’ or ‘we’ in this policy. Alexandra is the ‘Data Controllers’, responsible for the way the data you share with us is handled.

We work with 3rd party businesses and people (based outside our business) who are called ‘Data Processors’. We use their services to be able to do everything we need to do for administration, marketing, organising workshops, classes, meetings and other services (see list below ‘who do we share your data with’).

What is your Personal Data

Anything that can be used to identify you. It can be obvious information like your name, phone number or email. But there are also lots of other ways to identify a person.

We use both the words Data and Information for the same purpose in this policy.

We take our responsibility to keep your information safe very seriously and will never share your information with anyone without your clear permission. We wish for you to feel in safe and respectful hands.

We will use the words ‘you’ and ‘yours’ in this policy to describe you as the person using our services.

Know your rights

It is a top priority for us to do all we can to make sure we deal with your data in a way that respects all your rights. You have the…

Right to be informed

About the way we collect and use your personal data. That is what this policy is all about.

Right to have access

You can send a formal written request to ask for a copy of the data we hold about you at any time. We will do this as soon as possible and no later than one month.

Right to rectification

You can send a formal written request to ask us to correct, revise and update any of the personal data we hold about you at any time. We will do this as soon as possible and no later than one month.

Right to erasure

Also called the right to be forgotten. You can send a formal written request asking for all your data to be deleted at any time. We will do this as soon as possible and no later than one month (see the table above for possible situations where exemptions apply. For example, where a photo was used in a workshop manual and already distributed widely or to comply with insurance and tax accounting).

Right to restrict processing

If, for example, you believe the data we have collected about you is not accurate or collected unlawfully, you can send a formal written request to request limitations on how we use your data.

Right to data portability

You can send a formal written request asking for your data to be given to you to re-use with another health service or organisation. We will do this as soon as possible and no later than one month.

Right to object

You have the right to question our purpose for holding your information in a formal written request, and we must be able to clearly explain why we store this information about you within a month. We trust this policy explains this well already. See ‘please be aware’ below.

Rights related to automated decision-making including profiling

We will never send you e-mails and communication based on automatic computer selection, like some bigger companies may do. We personally choose when and how we communicate with you. If you say yes (give your consent) to join our mailing list, we may use an internal label/tag to very simply identify if you are a client, workshop participant, student, etc. This information is contained only within our Mailchimp online marketing account and is only visible to Alexandra and possibly a Data Processor (someone helping us with admin tasks) working under our instructions. This will help us identify who we would like to send a specific promotional email to, about a workshop for example, which is only relevant to some people.

Please be aware: exceptions may apply to the above rights in some cases, such as in the fulfilment of any obligations for legal purposes, or to comply with our Professional Indemnity and Liability Insurance and Tax accounting, where information must be kept for a number of years. See the charts above for full details, and the description of Lawful Basis further below. Please contact Alexandra if you have any concerns or questions.

Children’s rights

Children are defined as: anyone under age 18. Children have the same rights as adults.

Relating to Data, GDPR says that anyone age 13 plus, is able to give their own consent, especially when someone offers a service directly to them (often online).

For further information about your rights

Please contact the ICO (Information Commissioners Office), or visit their website:

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/

If you wish to contact us about anything related to your rights or have any complaints please contact us using the details at the top of this policy.

What data do we collect, how do we store it and for how long

We collect and store different kinds of data about you.

For some of our services we need to process information/data about your health and other sensitive data. This is classed as ‘special category data’ and anyone asking for this kind of information must have taken extra steps to make sure they have a very clear reason to do so.

NOTE: Special category data include information about your racial or ethnic background, political opinion, genetics, sexual orientation, religious, ideological or philosophical beliefs, trade union membership, criminal conviction and information relating to mental and physical health.

We only process any of this kind of information when we are requesting you to fill in the medical screening form for our workshops. You may also choose to share this type of information when you take part in a class or send us enquiries and feedback via email or other channels of communication.

We may ask for your consent to share your information as a testimonial. If you agree, you will have the choice to remain completely anonymous or give your permission to share just your initials or your full name and other information that could identify you (like your town, profession and a photo).

We store the minimum amount of information about you for the minimum amount of time needed, in order for us to provide our services like workshops, courses, classes and other events, newsletters and promoting our work.

Examples:

“If you subscribe to our email newsletter we only need your name and email address”

“For us to assess if you are suitable for a particular session or workshop, we will give you an opportunity to share more specific, sensitive and private information on a Medical Screening Form. Whilst we cannot verify if you give full disclosure of any medical issues, we encourage you to do so in order for us to provide the safest possible environment and make necessary adjustments if applicable.”

The law states that we need to let you know what happens with this personal information/data. See the charts above for a full description.

There are different reasons why we might hold some data longer than others.

Examples:

“To comply with our insurance we must store any medical screening forms for up to 10 years.”

“If you give your permission to share a photo with us and it is used in a workshop manual, it may be impossible to delete it completely if you should wish to do so later, after the manuals have been distributed. How any photos may be used will be clearly explained and you will always be asked for your full permission/consent before having any photos taken. We respect your privacy highly.”

“When you sign up to our newsletters you will always have the option to unsubscribe any time you wish.”

We do regular data reviews and destroy or delete any data once it is no longer necessary or reasonable to store it. We make sure any devices we throw out, recycle or give to another person is wiped clean of any information back to the factory setting.

Why do we need to collect your data

It is important for us to highlight that this policy is all about your data/personal information. This is different to the Terms and Conditions you may sign to attend a workshop or buy a product from our online shop. The law says that you must be informed and understand how your data is used in a separate statement to other terms.

We have many different needs to collect data about you such as:

  • to be able to reply to enquiries via telephone, email, WhatsApp, Messenger and other platforms for communication
  • to manage workshop or class bookings and communicate with you before and after
  • to collect written, audio or video testimonials
  • to collect photos for promotional use
  • to register you for, and communicate with you before and after, a workshop
  • to register you for, and communicate with you about, online meetings or other events we host
  • to send you news and updates if you have subscribed to our mailing list
  • in case we need to have your basic financial details to make refunds
  • to comply with our insurance policy

    GDPR have several categories of ‘Lawful Basis of Processing Data’. These describe different reasons businesses and organisations may have for handling your data. All data controllers (like us) must be clear under which lawful basis we have the right to collect your data.

    We will always ask for your ‘consent’ (your permission) wherever it is possible and applicable. It gives you the greatest control over how your data is used. This means you will be asked to personally show you have seen and agree with our Data Privacy Policy, either with your signature or by ticking a box, so we are on the same page and agree to work together based on a clear understanding.

    In situations where we are not able to give you full control over how we process and store your data through consent – as an example; having to store some files for a length of time, to comply with our insurance and tax accounting (also mentioned in other areas of this policy) – We are aware of the category called ‘Legitimate Interest’. We want to be clear that the way we handle your data is appropriate and necessary for the purposes of working with you and making our services available to you (again, explained in more details in other parts of this policy). Therefore we continuously assess if the information we are asking for is necessary and only process the minimum amount of data.

    Who do we share your data with

    Firstly – Data we never share with anyone else

    All health and other sensitive information you share with us in connection with a workshop, a class, in an email or other communication directly with us, is only seen by us. We store all health and sensitive securely in a locked filing cabinet in our office/home and/or password protected on our computer/phone/tablet.

    Data shared with 3rd party Data Processors

    We are the Data Controllers ultimately responsible for carefully choosing the Data Processors we work with, such as other companies who need to have their own data privacy policies in place. When we work with another person, such as an admin help, we have a contract between us to ensure they also understand fully how to manage and protect your data in the same way we do.

 

To run a business and offer services that involve digital and online systems, we feel it is reasonable to acknowledge, that it is impossible to check out every single aspect of each 3rd party company whose services we use. We choose to use companies that are very well known and already used by thousands of other professionals. They are based both in and outside the EU and may have their own 3rd party connections to provide their services. See the links below if you wish to explore this further. They will be storing the data we share about you – or you share yourself, for example if you sign up to a newsletter or share on social media – on systems designed to have the highest standards of security in place.

• Email provider
Our email provider is SiteGround. When you email us, you choose to share information through SiteGround.
Privacy policy: https://www.siteground.co.uk/viewtos/data_processing_agreement?scid=2&lang=en

• Stripe
You have the option to pay for our services using Stripe. Any transactions you do through Stripe are purely registered with Stripe. Our Stripe account will have a list of all transactions, but we do not store any financial details about you this way.
Privacy policy: https://stripe.com/gb/privacy

• Mail Chimp – Online contact management/email marketing tool
If you subscribe to our mailing lists your name and email will be stored on this system. You can always unsubscribe any time you like.
Privacy Policy: https://mailchimp.com/legal/privacy/

• Zoom – Online meeting and conferencing tool
If you attend one of our online workshops, classes or meetings, you will be required to download the Zoom app and you may share basic details like your name and where you are calling from when joining a meeting. Sometimes meetings are recorded and shared with the group who attended the meeting.
Privacy Policy: https://explore.zoom.us/en/privacy/

• Social Media – Facebook, Instagram, YouTube.
We used to share and may do so in the future, a collection of content such as photos, quotes, videos and more on Social Media and we posted videos on YouTube to promote our website. These posts may be forwarded and shared further by other users. We will of course only share any private information/data, if we have full permission to do so.

• Electronic communication – Email, SMS/text, WhatsApp, Messenger etc We communicate across several different platforms and apps. Access to our phones, computers and tablets are always password protected and never shared with, or available to, anyone else.

• WeTransfer – Online temporary file sharing
WeTransfer store files so they can only be accessed by a person using a unique link that is emailed directly to them. The files are available to download for a week on WeTransfer’s system and are then deleted.
Privacy policy: https://wetransfer.com/legal/privacy

• External hard drives & USB sticks/flash drives
We use external hard drives and USB sticks to back up data and these are locked away in our filing cabinets.

• Public Events. If we are invited to do a public talk or join an online audio or video meeting, hosted by someone else on their platform, we do not collect or store any information about you. The host may do, so check with them before joining, if you have any queries about Data Privacy. Any information you may share in a Q&A session or comment on a public platform – sometimes live or shared later on YouTube and in other public places – is of course your own responsibility.

Data Breach Policy

It is impossible to always be completely fault free from computer or human errors. Yet we certainly aim to try our very best. If a security breach, loss, accidental or otherwise unauthorised destruction, changes, use or sharing of your data does happen, by us or one of the 3rd parties we work with, we will let you know as soon as we are aware and always within 72 hours.

We will keep a log of any incidents and if there is a risk to your rights and freedoms from the breach we will, by law, also notify the ICO.

Further reading

ICO, Information Commissioners Office: https://ico.org.uk/your-data-matters/

Changes to this privacy policy

We will update this policy within a reasonable time, if the law changes, or if we make any business decisions that directly relate to the policy, such as changing the 3rd party companies or data controllers we work with.

Last updated on 25th February 2025