1. Who we are
This website is operated by Donna Nicol, Nicdon Ltd offering somatic healing and energy healing services, trading under the name Nicdon Ltd. Donna Nicol is registered with the Information Commissioner’s Office (ICO) in the United Kingdom.
Registered business address: Aberdeen, Scotland, United Kingdom
Email: [email protected]
Website: donnanicol.com
For the purposes of UK data protection law, Donna Nicol is the data controller for personal information collected through this website and through the provision of her services.
2. What personal data we collect
We collect personal data in the following ways:
When you contact us or book a session
- Your full name
- Your email address
- Your phone number (if provided)
- The content of your message or enquiry
When you sign up to the email list or download the free guide
- Your first name
- Last name?
- Your email address
When you become a client
In addition to the above, we may collect and hold:
- Information about your physical and emotional health, including details of chronic pain, anxiety, grief, or other conditions you share with us
- Notes made during or after sessions
- Any other personal information you choose to share in the context of your healing work
Important: Information about your physical or emotional health is classified as special category data under UK GDPR. We collect and process this information only with your explicit consent, and only for the purpose of providing you with healing services.
3. Why we collect your data (legal basis for processing)
We process your personal data on the following legal bases:
- Consent: Where you have given us explicit consent to process your data — for example, by signing up to our email list or by agreeing to our client intake process. You may withdraw consent at any time by contacting us at [email protected]
- Contractual necessity: Where processing is necessary to provide services you have requested or to fulfil a booking or payment.
- Legitimate interests: Where we have a legitimate business interest in processing your data — for example, to respond to an enquiry — and that interest does not override your rights.
- Legal obligation: Where we are required to retain records by law, such as financial records for tax purposes.
4. How we use your data
We use your personal data for the following purposes:
- To respond to your enquiries and messages
- To book, confirm, and manage sessions
- To deliver the services you have requested, including private healing sessions, group healing circles, and monthly membership content
- To send you the free guide you requested
- To send you our email newsletter and occasional updates (only where you have opted in)
- To process payments
- To maintain records of client sessions for professional purposes
- To comply with our legal and regulatory obligations
We will never use your personal data for automated decision-making or profiling, and we will never sell your data to third parties.
5. How we share your data
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
We may share your data with the following trusted third-party service providers, strictly for the purpose of delivering our services:
- Zoom Video Communications: used to deliver online sessions. Zoom’s privacy policy is available at zoom.us/privacy.
- Mailchimp (Intuit): used to manage our email list and send newsletters. Mailchimp’s privacy policy is available at mailchimp.com/legal/privacy.
- Scheduling and payment provider: used to manage bookings and process payments.
- Stripe: The scheduling and payment integration uses Stripe for payment processing. Stripe is fully PCI-compliant and securely handles all transactions. The Stripe Privacy Policy can be found at the following link: https://stripe.com/privacy
- Website hosting provider: our website is hosted on WordPress via ElevateOM. Data submitted through our website contact and sign-up forms is processed by our hosting provider as part of normal website operation.
All third-party providers are required to process your data only on our instructions and in accordance with UK GDPR.
6. How long we keep your data
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law.
- Enquiry and contact data: retained for 12 months from the date of your last contact, unless you become a client.
- Client session records and health data: retained for 7 years from your last session
- Email list data: retained until you unsubscribe. You may unsubscribe at any time using the link at the bottom of any email.
- Financial records: retained for 6 years from the end of the relevant tax year, as required by HMRC.
7. Where your data is stored
Your personal data is primarily stored within the United Kingdom and the European Economic Area (EEA). Some of our third-party service providers, including Zoom and Mailchimp, may transfer data to the United States. Where this occurs, appropriate safeguards are in place in accordance with UK GDPR, including standard contractual clauses approved by the ICO.
8. Your rights
Under UK data protection law, you have the following rights:
- The right to access: you can request a copy of the personal data we hold about you.
- The right to rectification: you can ask us to correct inaccurate or incomplete data.
- The right to erasure: you can ask us to delete your personal data in certain circumstances.
- The right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
- The right to data portability: you can ask us to provide your data in a portable format where technically feasible.
- The right to withdraw consent: where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- The right to object: you can object to processing based on legitimate interests or for direct marketing purposes.
To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.
9. How we protect your data
We take the security of your personal data seriously. We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. Session notes containing health information are stored securely and are not shared with any third party without your explicit consent.
Please be aware that no method of electronic transmission or storage is completely secure. While we do our best to protect your personal data, we cannot guarantee its absolute security.
10. Children’s data
Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from children under the age of 18. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete it promptly.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The date at the top of this page will always show when it was last reviewed. We encourage you to check this page periodically.
12. Contact us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact:
Donna Nicol
Email: [email protected]
Address: Aberdeen, Scotland, United Kingdom