Privacy Policy
Privacy Policy — Andrew Amaro Acupuncture
This Privacy Policy explains how Andrew Amaro Acupuncture collects, uses, stores, and protects your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By booking an appointment or using this website, you consent to the practices described below.
1. Data Controller
Andrew Amaro Acupuncture
Reading, United Kingdom
Sole Practitioner: Andrew Amaro
I am responsible for determining how your personal data is collected, used, and protected.
2. Information I Collect
I collect and process the following types of information:
Personal Identification
-
Name
-
Date of birth
-
Contact details (email, phone number, address)
Health & Medical Information
-
Medical history
-
Current symptoms and health concerns
-
Treatment notes and clinical records
-
Relevant lifestyle information This information is necessary for safe and effective acupuncture treatment.
Booking & Payment Information
-
Appointment history
-
Payment confirmations (processed through secure third‑party providers; I do not store card details)
Website & Communication Data
-
Messages sent through the website contact form
-
Cookies or analytics data
3. How Your Information Is Used
Your information is used for:
-
Providing acupuncture and related therapies
-
Maintaining accurate clinical records
-
Managing appointments and communication
-
Ensuring safe, appropriate treatment
-
Meeting legal, regulatory, and insurance obligations
I do not use your data for marketing without your explicit consent.
4. Lawful Basis for Processing
Under UK GDPR, I process your data on the following lawful bases:
-
Consent — when you voluntarily provide information or agree to treatment
-
Legitimate interest — for running and managing the practice
-
Legal obligation — maintaining clinical records as required by law and insurance
-
Provision of healthcare — processing special category health data for treatment purposes
5. How Your Information Is Stored
Your data is stored securely in:
-
Encrypted digital clinical records
-
Password‑protected devices
-
Secure booking and payment platforms
I take appropriate technical and organisational measures to protect your information from loss, misuse, or unauthorised access.
6. How Long Your Information Is Kept
Clinical records are kept for the minimum period required by UK law and professional insurance:
-
Adults: 7 years from the date of the last treatment
-
Children: Until age 25 (or 26 if treated at age 17)
After this period, records are securely deleted or destroyed.
7. Sharing Your Information
Your information is never sold or shared for marketing.
Information may be shared only when necessary:
-
With healthcare providers, but only with your explicit consent
-
With legal or regulatory bodies if required by law
-
With secure third‑party services used for booking, payment, or website hosting (e.g., Wix, Stripe), each of which has its own GDPR‑compliant privacy safeguards
8. Your Rights Under UK GDPR
You have the right to:
-
Access your personal data
-
Request corrections to inaccurate information
-
Request deletion of your data (where legally permissible)
-
Restrict or object to certain types of processing
-
Withdraw consent at any time
-
Request a copy of your data in a portable format
To exercise these rights, contact me directly.
9. Cookies & Website Analytics
This website may use cookies or analytics tools provided by Wix to improve functionality and performance. You can manage cookie preferences through your browser settings.
10. Contact
If you have questions about this Privacy Policy or how your data is handled, contact:
Email: andrewamaroacupuncture@gmail.com