Privacy Notice

Last updated: 17 September 2026

This privacy notice explains how Health Harmony Limited, trading as Riverside Natural Health Centre, collects, uses and protects personal information when you use our websites, contact us, book services, visit the centre or otherwise interact with us.

1. Who we are

Health Harmony Limited is a company registered in England and Wales (company number 13871536). Our registered office is:

1-3 Victoria Embankment
Nottingham
NG2 2JY
United Kingdom

For the purposes of UK data protection law, Health Harmony Limited is a data controller where we decide why and how personal information is used.

You can contact us about privacy or data protection at info@healthharmony.org.

2. What this notice covers

This notice applies to personal information processed by Health Harmony Limited through riversidenaturalhealthcentre.co.uk, healthharmony.org, our administrative systems and our business operations.

Riverside Natural Health Centre is also home to independent practitioners. A practitioner may be a separate data controller for their own clinical notes, treatment records and professional correspondence. Where that applies, the practitioner is responsible for explaining how they use and retain that information.

3. Personal information we may collect

Depending on how you interact with us, we may process:

Please avoid sending detailed or unnecessary medical information through general email, WhatsApp or website contact channels unless a practitioner specifically asks you to do so.

4. Why we use personal information and our lawful bases

We use personal information only where we have a lawful basis. Depending on the circumstances, this may include:

Health information is special category personal data. Where Health Harmony Limited itself processes health information, we will also rely on an appropriate condition under Article 9 UK GDPR, depending on the context, such as explicit consent or another condition permitted for health, care, legal or safeguarding purposes. Independent practitioners may rely on different lawful bases and Article 9 conditions for their own clinical records.

5. Generative AI and AI-assisted tools

We may use generative artificial intelligence and AI-assisted software to support administrative and technical work. This can include drafting or summarising routine correspondence, preparing website content, organising information, assisting with internal workflows, troubleshooting technical issues and helping staff prepare non-clinical material.

AI tools we may use include services provided by OpenAI (such as ChatGPT) and AI-enabled website or administrative tools. Where relevant, a provider may process information on our behalf or under its own privacy terms.

We apply data-minimisation principles when using AI. We do not intentionally provide more personal information than is reasonably necessary for the task, and we avoid entering detailed clinical records or special category information into general-purpose AI systems unless there is an appropriate lawful basis, suitable contractual protection and a genuine need to do so.

We do not rely on generative AI alone to make solely automated decisions about individuals that have legal or similarly significant effects. AI-generated material may be reviewed by a person before it is used where accuracy, confidentiality or individual impact matters.

If personal information is included in an AI-assisted workflow, it may be processed by the relevant AI provider in accordance with that provider’s terms, privacy notice and our applicable contractual arrangements. You can read OpenAI’s privacy information at openai.com/policies/row-privacy-policy/.

6. Website analytics, Hotjar and cookies

We use cookies and similar technologies to operate the website, remember choices, measure performance and understand how visitors use the site. Non-essential analytics or marketing technologies are controlled through our cookie-consent tools where consent is required.

Hotjar / Contentsquare

We use Hotjar, which is part of Contentsquare, to help us understand how visitors use and navigate the website. Depending on the features enabled, Hotjar can provide aggregated analytics, heatmaps and session-replay style information showing interactions such as clicks, scrolling, movement through pages, device/browser information and technical usage data.

We use this information to identify usability problems and improve the website. Hotjar is not intended to be used by us to collect clinical notes or detailed medical information. Hotjar processing is subject to our cookie-consent settings and the provider’s privacy and data-processing terms. More information is available at hotjar.com/legal/policies/privacy/.

Google, Jetpack and other analytics

We may also use Google services, including Google Analytics, Google Tag Manager and Site Kit, together with WordPress/Jetpack statistics and similar tools, to understand website traffic, performance and usage. These services may process online identifiers, device/browser data and interaction information.

Cookie consent

We use a cookie-consent platform (currently CookieYes) to record and apply your cookie choices. You can refuse non-essential cookies and, where the consent tool provides the option, change your choices later. Blocking some optional cookies may reduce analytics or personalisation but should not prevent access to the core website.

7. Booking, communications and third-party services

Our website links to or uses third-party services for particular functions. These may include:

When you follow a link to a third-party website or service, that provider may become a separate controller of information you give directly to it. Its own privacy notice will then apply.

8. Sharing information

We do not sell personal information. We may share personal information only where reasonably necessary for the purposes described in this notice, including with service providers acting on our behalf, independent practitioners where required to administer a service, professional advisers, payment or booking providers, and authorities where required by law.

Service providers are given access only to information reasonably required for the service they provide and are expected to handle it securely and lawfully.

9. International transfers

Some service providers may process personal information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, we use an appropriate mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard.

10. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected and for any legal, accounting, insurance, regulatory or dispute-resolution requirements.

Retention varies by type of information. For example:

Backups may retain deleted information for a limited period until the relevant backup cycle expires.

11. Security

We use reasonable technical and organisational measures to protect personal information. These include access controls, authentication, software updates, encryption in transit where supported, restricted administrative access and the use of reputable service providers.

No internet or electronic storage system is completely secure. If you believe personal information relating to you has been lost, misused or accessed without authorisation, please contact us at info@healthharmony.org.

12. Marketing

We may send marketing messages where permitted by law, including where you have consented or where an applicable existing-customer rule allows us to contact you about similar services. You can unsubscribe or object to direct marketing at any time.

13. Automated decision-making

We do not currently use website analytics or generative AI to make decisions about you based solely on automated processing that produce legal or similarly significant effects. If this changes, we will update this notice and provide the additional information and safeguards required by law.

14. Your data protection rights

Depending on the circumstances and the lawful basis we rely on, you may have rights to:

Your right to object: where we rely on legitimate interests, you may object to our processing in certain circumstances. You have an absolute right to object to the use of your personal information for direct marketing.

These rights are not absolute and may be limited by law. We may need to confirm your identity before acting on a request.

To exercise a right, email info@healthharmony.org.

15. Complaints

If you have concerns about how we use your personal information, please contact us first so we can try to resolve them.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator. Information about making a complaint is available at ico.org.uk/make-a-complaint/.

16. Children

Our website is not directed specifically at children. Where services are provided to a child or young person, personal information may be processed with the involvement of a parent or guardian where appropriate, taking account of the young person’s age, capacity and applicable law.

17. Changes to this notice

We review this notice periodically and update it when our services, technology or use of personal information changes. We will change the “last updated” date above when we make a material revision.

Health Harmony Limited
Trading as Riverside Natural Health Centre
Company number 13871536
1-3 Victoria Embankment, Nottingham, NG2 2JY
info@healthharmony.org