Website Privacy Policy & Client Data Protection

1. Website Privacy Policy

Who we are

Our website address is:

What personal data we collect and why we collect it


When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: After approval of your comment, your profile picture is visible to the public in the context of your comment.


If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.


If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

What rights you have over your data

If you have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data

Visitor comments may be checked through an automated spam detection service.


2. Client Data Protection

Data Storage & Security

  • Personal data that is held by us is not shared with anyone else.
  • Your written appointment notes are kept in a locked cabinet. They will be kept for 7 years for insurance purposes, after which time they will be destroyed.
  • Your name, email address and phone number will be stored for the purpose of contacting you regarding appointments (in the Studio 7 Office 365 Outlook account).
  • We occasionally send out email newsletters (using MailChimp) that have an opt in option and can be unsubscribed to at any time.

Right to Access of Personal Data

  • We will allow a right of access to both personal data and supplementary information free of charge. Any requests for information will be provided within one month of receiving the request.
  • Where requests are complex and numerous the provision of data will be provided within a two-month period.
  • Where requests are excessive and repetitive and administration fee of £50 will be charged to cover the administrative costs involved.

Right to rectification

We recognise that an individual has the right to have inaccurate personal data rectified or completed if incomplete.

  • Requests for rectification can be made either verbally or in writing.
  • We will ensure that rectification will occur within one month of the request being made.

Right to erasure

  • We recognise the rights of individuals to have their personal data erased.
  • A request for erasure may be made either verbally or in writing.
  • We will respond to the request within one month of it being erased, this time will be extended to two months where the request is complex.

Ensuring accountability and goverance

In accordance with Article 5 (2) we will ensure accountability and governance through the following procedures:

  • Regular internal audits
  • Maintenance of relevant processing documentation
  • Appointment of a Data Protection Officer: Lori McPherson

Data breach procedures

We will report any personal data breaches that risk rights and freedoms of a data subject to the relevant parties involved. All breaches of data will be recorded.