Data Map, Risk Defence & Operational Guide
| ENW: | The Healing Link (referred to as “THL”, “WE” and “US” in this document) |
DATA SHARING AND ROLES OVERVIEW
| THL | PRIMARY DATA CONTROLLER | What data is collected Why it’s collected How it is used See THL Privacy Policy |
| PRACTITIONERS | INDEPENDENT DATA CONTROLLER | See their own individual GDPR and Privacy Policy |
| ACCOUNTANT | INDEPENDENT DATA CONTROLLER | See their own individual GDPR and Privacy Policy |
| Zoho (email, forms, campaigns) | DATA PROCESSOR | Processes data on behalf of THL Purpose: Forms, CRM, email, marketing Data Location UK/European Union data centres Risk Potential international transfer of personal data by processor or sub-processors Mitigation: Zoho DPA reviewed and retained. Zoho states that personal data will not be transferred outside of the UK/EU unless the transfer complies with applicable data protection laws. Provider documentation reviewed regularly Zoho Dpa |
| HOSTINGER (Website hosting, forms) | DATA PROCESSOR | Host THL website and its data Purpose : Website hosting, website builder, domain management, forms, backup management of automated daily website and database backups for disaster recovery and service continuity. Data Location : UK/EU hosting selected Risk : Personal data may be processed by hosting infrastructure, support teams, or authorised sub processors Mitigation : Hostinger DPA and Privacy documentation reviewed, shared and retained. Appropriate safeguards required for any international transfers. Provider documentation reviewed periodically Data Processing Addendum is found in their T&C |
| NAMECHEAP | INDEPENDENT DATA CONTROLLER | Domain registrar for THL: using Withheld for Privacy to replace personal data in public WHOIS directories, complying with GDPR to prevent public disclosure. Limits the sharing of user data with third parties and maintains a Data Processing Addendum |
| STRIPE | MIXED ROLE DATA CONTROLLER AND PROCESSOR | PROCESSOR: When handling payments on behalf of THL Purpose: Payment processing, transaction management, fraud protection Data Processing Addendum is located within Stripe Terms & Conditions. CONTROLLER: Fraud prevention, regulatory compliance, financial reporting. No DPA required as legally responsible for processing themselves |
| MICROSOFT AZURE (MICROSOFT CORPORATION) | DATA PROCESSOR (OR SUB-PROCESSOR TO HOSTINGER) | Provides secure cloud storage for backup files and disaster recovery purposes. Storage of additional backup copies controlled by THL. Manages retention of data backed up from Hostinger. Data Processing Addendum is part of their service agreement |
| BACKWPUP (WEBSITE PLUG IN) | SOFTWARE SUPPLIER | Facilitates transfer and management of weekly backups between Hostinger and Azure, and manages retention of back up logs on Hostinger. |
| COOKIEYES (WEBSITE PLUG IN) | DATA PROCESSOR | Manages cookie consent and may collect consent records, IP addresses, consent timestamps and other compliance data. Data Processing Addendum is part of their service agreement |
| BREVO | DATA PROCESSOR | Provides SMTP email delivery services for website-generated emails, including contact form notifications, practitioner enquiries and administrative communications. Processes email addresses and message cpntent for transmission and delivery. Data Processing Addendum is part of their Terms of Use |
1. LAWFULNESS, FAIRNESS & TRANSPARENCY
Data must be processed legally, fairly and transparently, ensuring individuals know how their information is used.
- Data collected in order to fulfil services agreed, respond to queries, provide agreed communications, to fulfil legal and tax obligations
- Legitimate interests – PRACTITIONERS have joined our service/directory – clients need contact details to access services – expectation of this is included in our platform model and Practitioners Terms of Service Agreements or Contract (to include that their contact details will be displayed/shared, who can access them, whether they are public or client only)
- PRACTITIONERS expect visibility and provide THL with the data they wish to share publicly on our website
- Clients expect to be able to find practitioners or be referred to them
- THL has a clear matching/facilitation purpose
- Transparency to CLIENTS – it must be clear that we are showing them PRACTITIONER contact information, we must state how to use it and that PRACTITIONERS are INDEPENDENT PROVIDERS
- Users are informed on entering website by Cookie Notices, Privacy Policy, AI Policy, T&C and onboarding sequences which can be viewed via our Legal Hub.
- Third Parties include Stripe (payments), Therapists (if pre agreed) and Accountant
- We hold a Legitimate Interests Assessment (LIA) internally for auditing purposes
2. PURPOSE LIMITATION
Data must be collected for specified, explicit and legitimate purposes and not used for unrelated purposes.
- Data is collected to fulfil services agreed, for use on the platforms, matching with appropriate sequences and communication purposes
- PRACTITIONERS collect data independently directly from the CLIENT for their own therapeutic purposes, we do not share information with them unless requested by the CLIENT and disclaimer placed on file.
3. DATA MINIMISATION
Only the minimum amount of data necessary for the intended purpose should be collected.
- THL only collects what data we need
- We do not collect excessive data – Zoho forms (required fields are minimal needed, additional is by CLIENT discretion)
4. ACCURACY
Personal data must be accurate, kept up to date and rectified or erased without delay if incorrect.
- Users can update their own data by contacting our nominated person using a dedicated email address, requests will be dealt with within 2 weeks unless it requires a deeper investigation whereby THL have the right to increase timescale to a max of 2 months.
- Therapists maintain their own data
- Data Privacy Complaint form embedded in website and connected to dedicated email address
5. STORAGE
Data should only be kept for as long as necessary, after which it must be deleted or archived.
- Refer to Data Retention Policy
- Therapists and accountant have their own retention obligations
- Refer to our Security Policy
6. INTEGRITY & CONFIDENTIALITY (SECURITY)
Appropriate technical and organisational security measures must be in place to protect data against the unauthorised access, loss or damage.
- Hostinger – Security Policy
- Zoho – UK Privacy Policy
- Stripe – Secure payments
- THL – Security Policy
- Brevo – Security Policy
- Microsoft Azure – Legal Pages
Backups and Disaster Recovery
BackWPup is used as a technical tool to create and transfer backups. Backup files are stored in Microsoft Azure. THL has assessed that BackWPup does not act as a data processor in relation to stored backup data because back up files are hosted by the supplier.
7. ACCOUNTABILITY
Data controllers are responsible for complying with the GDPR and must be able to demonstrate this compliance.
- This document
- Contracts and DPA’s in place with Third Party Tools (Internal Compliance Log)
- Clear role definitions
- Namecheap: Infrastructure accountability
- Accountant : Legal/financial compliance role
- THL is registered with ICO as a Data Controller – demonstrating compliance with UK data protection legislation
POLICY UPDATED: 18th August 2026
