PRIVACY POLICY
Lucy Clarke Nutrition & Acupuncture
(Last updated June 2026)
This privacy policy explains how Lucy Clarke Nutrition & Acupuncture collects, stores, and uses your personal data, in accordance with the UK GDPR and the Data Protection Act 2018.
WHY I COLLECT YOUR INFORMATION
I need to collect personal information about you and your health in order to provide you with the best possible care. When you request treatment and I agree to provide it, this forms a contract between us. You have the right to refuse to provide your information, but please be aware that I would then be unable to offer treatment.
I collect and process your data under the following legal bases:
- Contract performance – to deliver the services you have booked and paid for.
- Legal obligation – to meet the professional and regulatory standards required by my registration bodies (BANT, CNHC, BMAS).
- Legitimate interest – to manage appointments, communicate about your care, and maintain clinical records as required by professional indemnity insurance guidelines.
- Explicit consent – for any non-essential communications, and for the processing of special category data including health information and genetic data.
HOW I USE YOUR INFORMATION
Your contact details may be used to:
- Confirm, remind you of, or rearrange appointments
- Send updates and information directly related to your care
- Process payments for services
With your explicit consent, I may also contact you by email with health-related information, newsletters, or other content relevant to your interests. You can withdraw this consent at any time by contacting me directly or using the unsubscribe link in any email.
HOW YOUR INFORMATION IS STORED
Clinical records
Nutritional therapy and acupuncture intake forms, consultation notes, test results, and correspondence are stored securely within Practice Better – a GDPR-compliant patient management platform designed specifically for healthcare professionals, accessible only by me.
Paper treatment notes
Acupuncture treatment notes and meridian charts made during sessions are stored in a locked filing cabinet at the clinic premises, accessible only by me.
Communications
Email and appointment communications may be stored on my password- and fingerprint-protected work phone and computer, used solely for professional purposes.
Social media
My social media accounts (Instagram, Facebook) are password protected. Please do not send sensitive health information via direct messages – email me at lucy@lucyclarke.co.uk instead.
SPECIAL CATEGORY DATA – GENETIC AND HEALTH INFORMATION
Health data and genetic data are classified as special category data under UK GDPR (Article 9) and are subject to additional protections. I process this data only with your explicit consent and only where it is necessary to provide the services you have requested.
Where nutrigenomic testing is undertaken as part of your care, your genetic data is processed by specialist third-party laboratory providers under their own data governance policies and security frameworks. I will always make clear when this applies and will not order genetic testing without your explicit consent.
THIRD-PARTY DATA PROCESSORS
In the course of providing services, your data may be shared with the following third parties. Data is shared only where necessary and only with your knowledge and consent where required.
Patient management
- Practice Better (practicebeetter.io) – clinical records, intake forms, and appointment management. GDPR-compliant.
Payment processing
- Stripe (stripe.com) – online payments. Stripe processes payment card data under its own privacy and security policies.
- Zettle by PayPal (zettle.com) – in-clinic card payments. Zettle processes payment card data under its own privacy and security policies.
Neither Stripe nor Zettle have access to your clinical or health records.
Laboratory and functional testing providers
Where functional testing is undertaken as part of your care, your name and relevant details may be shared with laboratory providers including (but not limited to) Medichecks, Nationwide Pathology Labs, Inuvi Labs, Lifecode Gx, and Regenerus. This information is shared only with your explicit consent and only where necessary to fulfil your testing request.
Email communications
- MailerLite (mailerlite.com) – email newsletters and health communications, sent with your consent. MailerLite is GDPR-compliant. You can unsubscribe at any time using the link in any email.
Website analytics
Google Analytics and Google Tag Manager are used to understand how visitors use this website. This data is anonymised and aggregated and does not identify you personally. Please refer to the Cookie Policy for full details.
HOW LONG YOUR DATA IS RETAINED
- Acupuncture records are kept for a minimum of 7 years after your last appointment, or until age 25 for children and young people (whichever is later), in line with professional and insurance guidelines.
- Nutritional therapy records are kept for a minimum of 7 years after your last appointment, or until age 25 for children and young people (whichever is later), in accordance with BANT professional guidelines.
- After the applicable retention period, personally identifying information is securely destroyed. Any anonymised insights retained for practitioner development purposes cannot be traced back to you.
YOUR RIGHTS
Under UK GDPR you have the right to:
- Access the personal data I hold about you
- Request corrections to any inaccurate information
- Withdraw consent for non-essential communications at any time
- Request erasure of your data, provided the legal retention period has passed
- Object to processing based on legitimate interest
- Lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk if you feel your data has not been handled appropriately
EXTERNAL LINKS
This website may contain links to other websites. I have no control over the privacy practices of external sites and recommend reading their privacy policies before providing any personal information.
CONTACT
If you would like to exercise any of your data rights, or have any questions about how your information is handled, please contact me directly.
- Data Controller: Lucy Clarke, Lucy Clarke Nutrition & Acupuncture
- Email: lucy@lucyclarke.co.uk
- Address: 15 Porterfield Road, Inverness, IV2 3HW
COMPLAINTS STATEMENT
If you are not satisfied with my response, you have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK’s independent authority for upholding information rights. Further information can be found on the ICO website at www.ico.org.uk.