Y CYSYLLTIAD TRWSIO

Gofal Iach Personol

Data Map, Risk Defence & Operational Guide


ENW:The Healing Link (referred to as “THL”, “WE” and “US” in this document)

DATA SHARING AND ROLES OVERVIEW


THLPRIMARY DATA CONTROLLERWhat data is collected
Why it’s collected
How it is used
See THL Privacy Policy
PRACTITIONERSINDEPENDENT DATA CONTROLLERSee their own individual GDPR and Privacy Policy
ACCOUNTANTINDEPENDENT DATA CONTROLLERSee their own individual GDPR and Privacy Policy
Zoho (email, forms, campaigns)DATA PROCESSORProcesses data on behalf of THL
Purpose: Forms, CRM, email, marketing
Data Location UK/European Union data centres
Risk Potential international transfer of personal data by processor or sub-processors
Mitigation: Zoho DPA reviewed and retained. Zoho states that personal data will not be transferred outside of the UK/EU unless the transfer complies with applicable data protection laws. Provider documentation reviewed regularly
Zoho Dpa
HOSTINGER (Website hosting, forms)DATA PROCESSORHost THL website and its data
Purpose : Website hosting, website builder, domain management, forms, backup management of automated daily website and database backups for disaster recovery and service continuity.
Data Location : UK/EU hosting selected
Risk : Personal data may be processed by hosting infrastructure, support teams, or authorised sub processors
Mitigation : Hostinger DPA and Privacy documentation reviewed, shared and retained. Appropriate safeguards required for any international transfers. Provider documentation reviewed periodically
Data Processing Addendum is found in their T&C
NAMECHEAPINDEPENDENT DATA CONTROLLERDomain registrar for THL: using Withheld for Privacy to replace personal data in public WHOIS directories, complying with GDPR to prevent public disclosure. Limits the sharing of user data with third parties and maintains a Data Processing Addendum
STRIPEMIXED ROLE DATA CONTROLLER AND PROCESSORPROCESSOR: When handling payments on behalf of THL
Purpose: Payment processing, transaction management, fraud protection
Data Processing Addendum is located within Stripe Terms & Conditions.
CONTROLLER: Fraud prevention, regulatory compliance, financial reporting. No DPA required as legally responsible for processing themselves
MICROSOFT AZURE (MICROSOFT CORPORATION)DATA PROCESSOR (OR SUB-PROCESSOR TO HOSTINGER)Provides secure cloud storage for backup files and disaster recovery purposes. Storage of additional backup copies controlled by THL. Manages retention of data backed up from Hostinger.
Data Processing Addendum is part of their service agreement
BACKWPUP (WEBSITE PLUG IN)SOFTWARE SUPPLIERFacilitates transfer and management of weekly backups between Hostinger and Azure, and manages retention of back up logs on Hostinger.
COOKIEYES (WEBSITE PLUG IN)DATA PROCESSORManages cookie consent and may collect consent records, IP addresses, consent timestamps and other compliance data. Data Processing Addendum is part of their service agreement
BREVO DATA PROCESSORProvides SMTP email delivery services for website-generated emails, including contact form notifications, practitioner enquiries and administrative communications. Processes email addresses and message cpntent for transmission and delivery. Data Processing Addendum is part of their Terms of Use

1. LAWFULNESS, FAIRNESS & TRANSPARENCY


Data must be processed legally, fairly and transparently, ensuring individuals know how their information is used.

  • Data collected in order to fulfil services agreed, respond to queries, provide agreed communications, to fulfil legal and tax obligations
  • Legitimate interests – PRACTITIONERS have joined our service/directory – clients need contact details to access services – expectation of this is included in our platform model and Practitioners Terms of Service Agreements or Contract (to include that their contact details will be displayed/shared, who can access them, whether they are public or client only)
  • PRACTITIONERS expect visibility and provide THL with the data they wish to share publicly on our website
  • Clients expect to be able to find practitioners or be referred to them
  • THL has a clear matching/facilitation purpose
  • Transparency to CLIENTS – it must be clear that we are showing them PRACTITIONER contact information, we must state how to use it and that PRACTITIONERS are INDEPENDENT PROVIDERS
  • Users are informed on entering website by Cookie Notices, Privacy Policy, AI  Policy, T&C and onboarding sequences which can be viewed via our Legal Hub.
  • Third Parties include Stripe (payments), Therapists (if pre agreed) and Accountant
  • We hold a Legitimate Interests Assessment (LIA) internally for auditing purposes

2. PURPOSE LIMITATION


Data must be collected for specified, explicit and legitimate purposes and not used for unrelated purposes.

  • Data is collected to fulfil services agreed, for use on the platforms, matching with appropriate sequences and communication purposes
  • PRACTITIONERS collect data independently directly from the CLIENT for their own therapeutic purposes, we do not share information with them unless requested by the CLIENT and disclaimer placed on file.

3. DATA MINIMISATION


Only the minimum amount of data necessary for the intended purpose should be collected.

  • THL only collects what data we need
  • We do not collect excessive data – Zoho forms (required fields are minimal needed, additional is by CLIENT discretion)

4. ACCURACY


Personal data must be accurate, kept up to date and rectified or erased without delay if incorrect.

  • Users can update their own data by contacting our nominated person using a dedicated email address, requests will be dealt with within 2 weeks unless it requires a deeper investigation whereby THL have the right to increase timescale to a max of 2 months.
  • Therapists maintain their own data 
  • Data Privacy Complaint form embedded in website and connected to dedicated email address

5. STORAGE

Data should only be kept for as long as necessary, after which it must be deleted or archived.

6. INTEGRITY & CONFIDENTIALITY (SECURITY)


Appropriate technical and organisational security measures must be in place to protect data against the unauthorised access, loss or damage.

Backups and Disaster Recovery
BackWPup is used as a technical tool to create and transfer backups. Backup files are stored in Microsoft Azure. THL has assessed that BackWPup does not act as a data processor in relation to stored backup data because back up files are hosted by the supplier.

7. ACCOUNTABILITY


Data controllers are responsible for complying with the GDPR and must be able to demonstrate this compliance.

  • This document
  • Contracts and DPA’s in place with Third Party Tools (Internal Compliance Log)
  • Clear role definitions 
  • Namecheap: Infrastructure accountability
  • Accountant : Legal/financial compliance role
  • THL is registered with ICO as a Data Controller – demonstrating compliance with UK data protection legislation 

POLICY UPDATED: 18th August 2026