Privacy Notice
STILLWELL
Privacy Notice
Personal Care Membership, website visitors and business contacts
|
Data controller |
Stillwell Wellness Ltd, trading as Stillwell® |
|
Company number |
16965118 |
|
Registered office |
Hillview, Tan Y Bryn, Hen Lon, Dinbych, United Kingdom, LL16 5BE |
|
Privacy contact |
info@stillwellclub.com |
|
Effective date |
29 July 2026 |
|
Service eligibility |
Adults aged 18 and over |
|
PRIVACY IN ONE MINUTE Stillwell uses the minimum information reasonably needed to operate memberships and provide proactive wellbeing check-ins. Sensitive wellbeing information is given additional protection. We do not sell personal information. Corporate partners receive only anonymised, aggregated insights as part of routine reporting—not individual check-in notes or disclosures. |
|
This Privacy Notice explains how Stillwell Wellness Ltd (“Stillwell”, “we”, “us” or “our”) collects, uses, shares, protects and retains personal information. It applies to Members, prospective Members, website users, corporate or sponsored participants, business contacts and people who communicate with us.
1. Who is responsible for your information?
1.1 Stillwell Wellness Ltd is the data controller for the personal information described in this Notice. This means we decide why and how it is used.
1.2 We have not appointed a statutory Data Protection Officer at this stage. Privacy questions and rights requests should be directed to our Privacy Lead at [INSERT PRIVACY EMAIL ADDRESS] or to the registered office above.
1.3 Stillwell® is a registered trademark used by Stillwell Wellness Ltd.
2. The information we collect
We collect only information reasonably relevant to the purposes explained in this Notice. Depending on your relationship with Stillwell, this may include the following:
|
Category |
Examples |
|
Contact and identity |
Name, age confirmation, postal address, email, telephone number, membership ID and preferred contact arrangements. |
|
Account and payment |
Membership plan, start and renewal dates, payment status, invoices, refunds and limited transaction information. Full card details are normally held by the payment provider, not Stillwell. |
|
Appointment and communications |
Booking history, attendance, rescheduling, emails, messages, enquiries, complaints and service correspondence. |
|
Wellbeing information |
Wellbeing pulse responses and information you choose to discuss about mental or physical health, sleep, stress, energy, relationships, work pressures, routines, goals and support needs. |
|
Check-in records |
Brief notes of check-ins, agreed actions, resources supplied, signposting, practitioner observations and follow-up requirements. |
|
Safeguarding and incident information |
Information about actual or suspected risk, harm, abuse, neglect, emergencies, allegations, disclosures, actions taken and relevant third parties. |
|
Corporate or sponsored access |
Employer or sponsor name, work contact details, eligibility, enrolment status and funding information. Employers should not provide detailed health information. |
|
Technical and website |
IP address, device and browser information, access logs, security events, cookie choices, page interactions and website analytics where enabled. |
|
Feedback and impact |
Satisfaction surveys, service feedback, outcomes, anonymised measures and case-study material where separate permission has been obtained. |
|
Marketing preferences |
Opt-ins, opt-outs, campaign engagement and records showing when and how a preference was obtained. |
We do not routinely record the audio or video of check-ins. If recording were ever proposed for a specific purpose, we would explain it beforehand and obtain any consent required by law.
3. Special-category and criminal-offence information
3.1 Information about physical or mental health, disability, racial or ethnic origin, religion, sexual orientation, sex life, trade-union membership and some related inferences is special-category data and receives extra protection.
3.2 Wellbeing conversations may also incidentally include allegations, suspicions or information about criminal conduct. We process this only where necessary and where a lawful condition under the Data Protection Act 2018 applies.
3.3 For routine wellbeing information that you choose to provide, our Article 6 basis is normally performance of the Membership contract and our separate Article 9 condition is your explicit consent under Article 9(2)(a).
3.4 For safeguarding, emergencies or legal claims, we may instead rely on legal obligation, vital interests, recognised or other legitimate interests, Article 9(2)(c), Article 9(2)(f), or substantial public interest under Article 9(2)(g) and an applicable condition in Schedule 1 of the Data Protection Act 2018, including safeguarding of children and individuals at risk where the legal tests are met.
3.5 Stillwell will maintain an Appropriate Policy Document where required and will complete or review a Data Protection Impact Assessment for processing likely to create a high risk.
4. How we obtain information
4.1 Most information comes directly from you through registration, consent forms, wellbeing pulse assessments, check-ins, messages, calls, website forms, surveys and complaints.
4.2 Where an employer, sponsor or referral partner provides access, we may receive limited information such as your name, work email, eligibility and enrolment status. We will provide this Notice no later than our first communication or within the period required by law.
4.3 We may receive payment status from payment providers, booking information from scheduling services, technical information from website and security providers, and information from professional advisers, insurers, regulators or public authorities where lawful.
4.4 Please avoid giving unnecessary personal information about another person. Where a check-in includes third-party information, we will handle it proportionately and may be unable to provide that person with this Notice where an exemption applies or doing so would create risk.
5. Why we use information and our lawful bases
Data protection law requires us to identify a lawful basis for each purpose. Special-category or criminal-offence information also requires a separate condition. Our principal purposes and bases are:
|
Purpose |
What we do |
Lawful basis / special-category condition |
|
Enquiries and steps before joining |
Responding to enquiries, explaining the service and setting up an application. |
Steps requested before entering a contract; legitimate interests in responding efficiently. |
|
Membership administration |
Creating the account, taking payment, booking check-ins, communicating about the service, handling cancellation and providing contractual benefits. |
Performance of the membership contract; legal obligation where records are required by law. |
|
Routine Personal Care delivery |
Conducting check-ins, recording proportionate notes, tracking agreed actions, supplying resources and signposting. |
Performance of the contract. For any special-category data, explicit consent under Article 9(2)(a). |
|
Safeguarding and serious risk |
Assessing and responding to a safeguarding concern or serious risk, including proportionate sharing where necessary. |
Legal obligation, vital interests, recognised or other legitimate interests, depending on the circumstances. For special-category data: Article 9(2)(c), 9(2)(g) with DPA 2018 Schedule 1 paragraph 18 where applicable, or another condition required by law. |
|
Service safety and quality |
Supervision, quality assurance, complaints, incident review, security, fraud prevention and legal claims. |
Legitimate interests in operating a safe, effective and accountable service; legal obligation; establishment, exercise or defence of legal claims. Special-category conditions are applied where needed. |
|
Impact measurement |
Measuring engagement, retention, outcomes, signposting and satisfaction; producing anonymous statistics. |
Legitimate interests in evaluating and improving the service. Identifiable special-category analysis is based on explicit consent or another documented condition; anonymous information is not personal data. |
|
Corporate reporting |
Providing employers or sponsors with anonymised, aggregated usage and impact information. |
Legitimate interests and contract administration. We do not provide individual wellbeing content to employers as part of routine reporting. |
|
Marketing |
Sending information about relevant Stillwell services, products or events. |
Consent where required; otherwise legitimate interests and the permitted customer ‘soft opt-in’ under PECR. Every electronic message includes an easy opt-out. |
|
Legal and regulatory compliance |
Tax, accounting, insurance, regulatory enquiries, rights requests and lawful disclosures. |
Legal obligation, legitimate interests and legal claims as applicable. |
|
YOUR RIGHT TO OBJECT You have the right to object at any time to processing for direct marketing. You may also object to other processing based on legitimate interests or a recognised legitimate interest. Email the Privacy Lead or use the unsubscribe facility in a marketing message. We will stop direct marketing and will assess any other objection in accordance with the law. |
6. Explicit consent for wellbeing information
6.1 Before intentionally recording or using special-category wellbeing information for routine service delivery, we will seek a clear, specific and separate explicit-consent statement.
6.2 You control what you choose to discuss. Membership is not conditional on disclosing any particular diagnosis or health condition. However, if you do not permit us to process information necessary for a requested feature, we may be unable to provide or safely continue that part of the service.
6.3 You may withdraw explicit consent at any time by contacting the Privacy Lead. Withdrawal does not make earlier lawful processing unlawful. We will stop consent-based processing unless another lawful condition applies, and will explain any effect on service delivery or record retention.
6.4 Consent for routine wellbeing processing is separate from consent to receive marketing, use a testimonial, publish a case study or record a call.
7. Corporate and sponsored memberships
7.1 A corporate partner or sponsor may pay for access and receive enrolment or utilisation information needed to administer the arrangement.
7.2 Routine employer reporting is limited to anonymised and aggregated information, such as participation, engagement, broad themes and group-level outcomes. We apply minimum-group and disclosure controls where needed to reduce re-identification risk.
7.3 We do not routinely tell an employer what an identifiable Member discussed, their wellbeing responses, signposting or check-in notes. Identifiable information will be shared with an employer only with the Member’s specific permission or where a legal or safeguarding basis requires that particular disclosure.
7.4 Corporate participation should be voluntary. An employer should not attempt to obtain Stillwell credentials, require disclosure of check-in content or make employment decisions from individual Stillwell data.
8. Who we share information with
Where necessary and lawful, information may be shared with:
· Authorised Stillwell employees, officers, sessional practitioners, contractors and supervisors who need it for their role
· Providers of secure hosting, client records, booking, payments, email, telephone, video, analytics, backups, authentication and cybersecurity
· Professional advisers, auditors, insurers, accountants and legal representatives
· Emergency, NHS, health, social-care, safeguarding or specialist services where a proportionate disclosure is necessary and lawful
· Police, courts, regulators, tax authorities or other public bodies where required or permitted by law
· A purchaser, investor or successor in connection with a genuine business transaction, subject to confidentiality and data-protection safeguards
· Corporate partners only in the limited manner described in section 7
Suppliers acting as processors must follow our documented instructions, protect the information and use it only for the agreed service. Some recipients, such as regulators or professional advisers, may act as independent controllers.
9. International transfers
9.1 We aim to select UK-hosted services where reasonably practical, but some suppliers or support teams may process information outside the United Kingdom.
9.2 Before a restricted transfer, we will use an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard, and complete any required transfer risk assessment.
9.3 You may request information about the relevant transfer mechanism from the Privacy Lead. Commercially sensitive or security information may be summarised or redacted where lawful.
10. How long we keep information
We do not keep identifiable information indefinitely. The precise period may depend on the purpose, legal and insurance requirements, risk, complaints and whether a record forms part of a safeguarding or legal matter.
|
Record type |
Normal retention approach |
|
Unsuccessful enquiries |
Normally 12 months after the last meaningful contact. |
|
Membership, billing and contractual records |
Normally 6 years after the Membership ends, reflecting tax, accounting and potential legal-claim periods. |
|
Routine check-in and wellbeing records |
Normally 3 years after the Membership ends, unless a shorter period is appropriate or longer retention is needed for a complaint, safeguarding matter, legal claim or regulatory requirement. |
|
Safeguarding, serious incident and complaint records |
Normally 6 years after final action, or longer where required by law, an insurer, an ongoing risk or the circumstances of the individual case. |
|
Recorded explicit consent and privacy preferences |
For as long as the related processing continues and normally 6 years afterwards where needed to demonstrate compliance. |
|
Marketing records |
Until consent is withdrawn or an objection is received; inactive marketing contacts are reviewed and normally removed after 24 months. A minimal suppression record may be retained to respect opt-outs. |
|
Website security and access logs |
Normally up to 12 months, unless an incident requires longer investigation. |
|
Anonymised statistics |
May be kept indefinitely because properly anonymised information is no longer personal data. |
At the end of the applicable period, information is securely deleted, destroyed or irreversibly anonymised unless a documented legal or safeguarding reason requires longer retention. We will review these periods as the service and legal requirements develop.
11. Security
11.1 We use proportionate organisational and technical measures designed to protect confidentiality, integrity and availability. These include access controls, least-privilege permissions, multi-factor authentication, encryption where appropriate, secure backups, supplier due diligence, confidentiality obligations, training and incident procedures.
11.2 No system can be guaranteed completely secure. Members should use strong passwords, protect devices, avoid sharing account access and tell us promptly about suspected unauthorised access.
11.3 We assess personal-data breaches and notify the Information Commissioner and affected people where the law requires. We may contact you with protective steps following a security incident.
12. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
· Be informed about how your information is used
· Request access to your personal information and a copy of it
· Ask us to correct inaccurate or incomplete information
· Ask us to erase information in certain circumstances
· Ask us to restrict processing in certain circumstances
· Object to direct marketing and to certain legitimate-interest processing
· Receive information you provided in a portable format where the right applies
· Withdraw consent at any time where processing is based on consent
· Complain to the Information Commissioner’s Office
To exercise a right, contact the Privacy Lead. We may need to verify identity and clarify the request. We normally respond within one month, although the law permits an extension for a complex request. Rights are not absolute, and we will explain any lawful refusal or limitation.
13. Automated decision-making and wellbeing flags
13.1 Stillwell does not currently make decisions producing legal or similarly significant effects solely by automated means.
13.2 A wellbeing pulse or system rule may highlight a response for human attention, prioritisation or safeguarding review. A trained person remains responsible for reviewing the context and deciding what action, if any, is appropriate.
13.3 If we introduce significant automated decision-making, we will update this Notice and provide the information and safeguards required by law before it applies.
14. Marketing and cookies
14.1 Service messages about appointments, payments, security, terms or Membership operation are not marketing.
14.2 For promotional email or text to individual subscribers, we rely on consent or the customer soft opt-in where all legal requirements are met. We identify Stillwell and provide an easy opt-out in every message.
14.3 Business-to-business marketing may be based on legitimate interests where permitted, but corporate recipients can opt out. Sole traders and some partnerships are treated as individual subscribers under electronic-marketing rules.
14.4 Our website should provide a separate Cookie Notice and consent controls for non-essential cookies. Rejecting non-essential cookies will not prevent access to core information.
15. Complaints and contacting the ICO
15.1 Please raise a concern with our Privacy Lead first so that we can investigate and try to resolve it.
15.2 You may complain to the Information Commissioner’s Office at any time. Information is available at www.ico.org.uk/make-a-complaint. The ICO’s postal address is Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
15.3 Complaining to Stillwell first does not remove your right to contact the ICO or seek another remedy.
16. Changes to this Notice
16.1 We may update this Notice to reflect changes to the service, suppliers, technology, law or our processing.
16.2 The current version will be published with its effective date. We will draw material changes to the attention of affected people by email, account notice or another appropriate method.
16.3 We will not use previously collected information for an incompatible new purpose without completing the required legal assessment and providing further information or obtaining consent where required.
We are initially limiting membership to 100 people to ensure every member receives consistent, personal support. Members joining during this introductory period will have their £29.99 monthly price protected for 12 months.