Privacy Policy

    Last updated: 8/28/2026

    Our Privacy-First Commitment

    We are committed to being the most privacy-preserving hypnotherapy practice possible. Our fundamental principle is data minimization - we collect only what is absolutely necessary, retain it for the shortest time legally permissible, and provide you with complete control over your information.

    Our Privacy Commitment

    • We never sell your data - Your information is never monetized or shared with third parties for profit
    • Minimal tracking - We use only essential analytics and avoid invasive tracking
    • Secure payment handling - Payment information is processed securely and retained only as needed
    • Regular data review - We periodically review and remove unnecessary data

    Information We Collect (Minimized Approach)

    Essential Personal Information Only

    • Name and primary email address (required for service delivery)
    • Phone number (optional, only if you choose to provide it)
    • Minimal account preferences for service customization
    • Communication history (automatically purged after 2 years unless legally required)

    Payment Information (Secure Handling)

    🔒 Secure Payment Processing

    • No stored payment details - We don't store credit card numbers or sensitive payment information
    • Minimal retention - Payment tokens are deleted promptly after processing
    • Transaction records - Basic transaction logs kept for accounting and legal compliance
    • Bank-level encryption - All payment data uses industry-standard encryption
    • PCI DSS compliant - We use trusted payment processors like Stripe

    Health Information (Strictly Controlled)

    • Medical history relevant to treatment (encrypted and access-controlled)
    • Session recordings (only with explicit consent, auto-deleted after treatment completion)
    • Treatment progress notes (anonymized where possible)
    • Mental health assessments (stored with zero-knowledge encryption when feasible)

    Technical Information (Minimal Collection)

    • IP address (automatically anonymized after 30 days)
    • Device type (generalized, no unique identifiers)
    • Essential usage patterns only (no behavioral profiling)
    • No tracking cookies or persistent identifiers
    • Session data purged immediately after use

    How We Use Your Information (Purpose Limitation)

    We follow strict purpose limitation - your data is used only for the specific purposes you've consented to:

    • Direct service delivery only - Provide personalized hypnotherapy services and treatment
    • Essential operations - Schedule appointments, manage your account, and process payments
    • Legal compliance - Meet regulatory requirements (minimal data, shortest retention)
    • Security protection - Prevent fraud and ensure platform security (anonymized data only)
    • No marketing without consent - Service communications only, unless you opt-in to newsletters
    • No analytics or profiling - We don't build behavioral profiles or use your data for business intelligence
    • No AI training - Your personal data is never used to train AI models or algorithms

    🛡️ What we DON'T do: Sell data, create advertising profiles, share with data brokers, use for unrelated purposes, or retain longer than necessary.

    Information Sharing (Absolute Minimum)

    🚫 We NEVER sell, rent, or monetize your personal information. Period.

    We maintain strict confidentiality standards and share information only in these limited, legally mandated circumstances:

    • Your explicit consent: Only when you specifically authorize information sharing
    • Legal obligations: Court orders or regulatory requirements (we contest overly broad requests)
    • Imminent danger: To prevent serious harm to you or others (minimum necessary information only)
    • Essential service providers: Payment processors and hosting (zero-knowledge encryption where possible)
    • Professional consultation: Healthcare professionals for treatment (your consent required, minimal data shared)

    ✅ Our Service Provider Standards:

    • Contractual data protection requirements
    • Regular security audits and compliance verification
    • Immediate data deletion when services end
    • No sub-processing without our approval

    Data Security (Military-Grade Protection)

    We implement best-in-class security measures that exceed industry standards:

    🔐 Encryption & Access

    • AES-256 encryption at rest
    • TLS 1.3 encryption in transit
    • Zero-knowledge encryption where possible
    • Multi-factor authentication required
    • Role-based access controls

    🛡️ Infrastructure & Monitoring

    • HIPAA-compliant hosting (AWS/Google)
    • 24/7 security monitoring
    • Regular penetration testing
    • Automated threat detection
    • Incident response procedures
    • Staff security training - Regular privacy and security protocol updates
    • Secure data disposal - Cryptographic wiping of all storage media
    • Network isolation - Patient data on separate, secured network segments
    • Backup encryption - All backups encrypted with separate keys

    Your Rights (Complete Control)

    You have comprehensive rights over your personal information, and we make exercising them simple:

    📋 Data Access & Control

    • Instant access: Download all your data anytime
    • Real-time corrections: Update information immediately
    • Granular deletion: Delete specific data categories
    • Data portability: Export in standard formats

    🎛️ Privacy Controls

    • Processing restrictions: Limit data use
    • Communication preferences: Granular opt-out options
    • Consent withdrawal: Revoke permissions anytime
    • Automated deletion: Set auto-purge schedules

    Exercise Your Rights: Use our self-service privacy dashboard or contact us - we respond within 24 hours for most requests.

    Data Retention (Absolute Minimum)

    💰 Payment Data Retention

    • Prompt deletion: Payment processing data removed after completion
    • Transaction records: Basic transaction information kept for tax and legal compliance (up to 7 years)
    • No sensitive data: Credit card details, CVV codes not stored by us
    • Secure processing: All payment handling through certified processors

    🏥 Health Data Retention

    • 7 years: Treatment records (as required by medical regulations)
    • 1 year: Session recordings (deleted automatically unless specifically requested to retain)
    • 30 days: Technical session data and logs
    • Immediate: Temporary files and cache data

    Early deletion available: You can request immediate deletion of most data types. We'll comply within 30 days unless legal obligations prevent it (we'll explain why if so).

    International Data Transfers

    If you are located outside our primary jurisdiction, your information may be transferred to and processed in countries with different privacy laws. We ensure appropriate safeguards are in place to protect your information during such transfers.

    Children's Privacy

    Our services are not intended for children under 16 without parental consent. We do not knowingly collect personal information from children under 16 without appropriate parental or guardian consent and involvement in the treatment process.

    Cookies and Tracking (Minimal Approach)

    🍪 Cookie-Free by Default: We use minimal, essential cookies only - no tracking or advertising cookies.

    Essential Cookies Only:

    • Session authentication (deleted when you log out)
    • Security tokens (expired within hours)
    • Basic functionality preferences (no personal data)

    What We DON'T Use:

    • No Google Analytics or third-party trackers
    • No social media tracking pixels
    • No advertising or marketing cookies
    • No cross-site tracking or fingerprinting

    Changes to This Policy

    We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or through our platform. Continued use of our services after changes constitutes acceptance of the updated policy.

    Contact Information

    If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

    Privacy Officer

    Email: contact@willmyway.uk

    Phone: +44 20 4147 4970

    Address: WILL MY WAY LTD
    Unit 13 Freeland Park Wareham Road
    Poole
    BH16 6FA

    Regulatory Compliance

    This Privacy Policy is designed to comply with applicable privacy laws including HIPAA (Health Insurance Portability and Accountability Act), GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and other relevant jurisdictional requirements.