This policy applies to: chehomeopathy.com, cheonline.co.uk, the CHE mobile application, and all related services operated by CHE Health and Wellbeing Ltd.
Data Controller: CHE Health and Wellbeing Ltd | ICO Registration: ZB035578
Data Protection Officer: Marcus Fernandez | [email protected]
CHE Health and Wellbeing Ltd and its subsidiaries — CHE Online Ltd, CHE London Ltd and CHE Pro Ltd (together “CHE”, “we”, “us”) — are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). This policy sets out our obligations as a data controller and the rights available to you.
The Data Protection Act 2018 supplements the UK GDPR and together these constitute the primary data protection legislation in the United Kingdom following Brexit. Non-compliance can result in significant fines (up to £17.5 million or 4% of annual global turnover, whichever is higher), enforcement action, and reputational damage.
This policy applies to:
Under UK GDPR (Article 5), all personal data must be:
The data controller (CHE) is responsible for demonstrating compliance with these principles (accountability).
CHE processes personal data on the following lawful bases, depending on the processing activity:
CHE may process special category data (UK GDPR Article 9) such as health information (e.g. medical certificates for deferral applications, disability-related adjustments). This is processed only where:
Special category data is subject to heightened security controls and access restrictions.
You have the following rights in relation to your personal data, which you can exercise by contacting our Data Protection Officer. We will respond within one calendar month.
CHE shares personal data with third-party processors only where:
Key processors include: Stripe, PayPal, Kajabi, Thinkific, ActiveCampaign, ConvertFlow, and Xero. A Register of Processors is maintained by the DPO.
Transfers of personal data outside the UK are subject to UK GDPR Chapter V. CHE uses Standard Contractual Clauses (SCCs) and/or relies on ICO adequacy decisions/regulations to protect such transfers. The DPO maintains records of all international transfers.
Personal data is retained in accordance with CHE’s Retention Schedule, which is reviewed annually. Key periods are set out in the Privacy Policy. Data that is no longer required is securely deleted or anonymised.
CHE takes appropriate technical and organisational measures to ensure data security, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
If you believe your personal data has been subject to a breach, please contact our Data Protection Officer immediately at [email protected].
CHE has appointed a Data Protection Officer: Marcus Fernandez ([email protected]). The DPO is responsible for monitoring compliance, providing advice, and acting as the contact point for the ICO.
In accordance with Article 30 UK GDPR, CHE maintains a Record of Processing Activities documenting all personal data processing we carry out. This record is reviewed and updated at least annually, and is available to the ICO on request.
Data protection is considered at the design stage of all new projects, systems and processes. Data minimisation, pseudonymisation and appropriate access controls are applied as a default.
When you interact with our services, you have a responsibility to:
This policy is reviewed annually, or sooner in response to significant legal or operational changes, by the DPO and Senior Management Team.
Email: [email protected]
Post: CHE Health and Wellbeing Ltd, 4th Floor, 100 Fenchurch Street, London EC3M 5JD
Tel: 020 3405 4580
ICO Registration: ZB035578