This policy explains what personal information we collect when you use this website, why we collect it, and what your rights are. We keep this deliberately short and plain.
Last updated: [DATE — e.g. 1 August 2026]
The short version. This website sets no cookies. There is no analytics, no tracking, no advertising and no third-party content of any kind — the fonts and images are served from this website itself. The only personal information we receive is what you type into the reservation or contact form, and we only use it to reply to you about the retreat.
1. Who we are
This website is operated by [FULL LEGAL OR TRADING NAME — e.g. Lydia Marne Yoga] ("we", "us", "Lydia"), the organiser of the 2027 Lake District Spring Yoga Retreat.
Contact for any privacy question or request:
Email: hello@lydiamarneyoga.co.uk [REPLACE WITH REAL EMAIL]
Postal address: [POSTAL ADDRESS — required if you want to accept written requests]
We are the "data controller" for the information described below, which means we decide how and why it is used.
2. Cookies and tracking — we don't use any
This website does not set cookies, does not use local storage to identify you, and contains no analytics, advertising, social media pixels, session recording or fingerprinting of any kind. Fonts and images are hosted on this site rather than loaded from a third party, so simply reading these pages does not share your visit with anyone else.
Because we set no cookies and do no tracking, there is no cookie banner and nothing for you to consent to or switch off.
If this ever changes — for example if we later add analytics — we will update this policy and ask for your consent first where the law requires it.
3. What we collect, and why
When you reserve a place
The reservation form collects your name and email address, together with the room you selected, the price, the balance, the deposit amount and the retreat dates (these last items are added automatically so we know what you asked about).
We use this to contact you about your reservation, confirm availability, arrange your deposit and administer your booking.
Lawful basis: taking steps at your request before entering into a contract (UK GDPR Article 6(1)(b)), and our legitimate interests in responding to enquiries and running the retreat (Article 6(1)(f)).
When you use the contact form
We collect your name, email address and the message you write, and use them only to answer you.
Lawful basis: our legitimate interests in responding to people who contact us (Article 6(1)(f)).
Health, dietary and accessibility information
Please do not put detailed health information into the forms on this website. If you need to tell us about an injury, medical condition, allergy or access requirement, we will ask you for it by email once your place is confirmed, and we will only use it to keep you safe and comfortable on the retreat.
Some of this is "special category" data under UK GDPR. Where it applies, we rely on your explicit consent (Article 9(2)(a)), which you can withdraw at any time by emailing us — though we may then be unable to accommodate a requirement safely.
Marketing
Reserving a place does not add you to a mailing list. We will only send you marketing about future retreats if you separately and clearly opt in, and every such email will have an unsubscribe link.
4. Who processes your information
We use a small number of trusted service providers ("processors") who handle data on our instructions:
- Netlify — hosts this website and receives the form submissions. Netlify's servers also keep short-term technical logs (including IP addresses) for security and to keep the site running. Netlify is based in the United States; transfers are covered by the safeguards in its data processing terms, such as UK/EU Standard Contractual Clauses.
- Our email provider — [e.g. Google Workspace / Microsoft 365 — NAME YOUR PROVIDER], which stores the emails we exchange with you.
- The venue and caterer — we share only what is necessary to run your stay, such as your name, room allocation and any dietary requirement you have given us.
We do not sell your information, and we never share it for anyone else's marketing.
5. How long we keep it
- Enquiries that don't lead to a booking: deleted within [12 months].
- Booking records: kept until the retreat has taken place and any queries are resolved, then deleted within [12 months].
- Payment and accounting records: kept for 6 years after the end of the relevant tax year, as UK tax law requires.
- Health, dietary and access information: deleted within [3 months] of the retreat ending.
6. Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal information we hold about you;
- have inaccurate information corrected;
- ask us to delete your information ("right to erasure");
- ask us to restrict how we use it, or object to our use of it;
- ask us to transfer it to you or another provider ("data portability");
- withdraw consent at any time, where we relied on consent.
To exercise any of these, email hello@lydiamarneyoga.co.uk. We will respond within one month, and we won't charge you.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office (ICO), the UK's data protection regulator: ico.org.uk, helpline 0303 123 1113. We'd appreciate the chance to put things right first.
7. Security
This website is served over an encrypted HTTPS connection, and form submissions are sent encrypted. Access to submissions and email is protected by strong passwords and two-factor authentication. No system can be guaranteed perfectly secure, but we take reasonable and appropriate steps to protect your information.
8. Children
This retreat is for adults and this website is not directed at children. We do not knowingly collect information from anyone under 18.
9. Changes to this policy
If we change this policy we will update the date at the top of this page. If the change is significant and affects people who have already booked, we will let them know by email.
A note for the site owner: replace every [BRACKETED] item above with your real details before going live, and consider having a solicitor review this alongside the booking terms. If you handle personal data as a business in the UK you may also need to pay the ICO data protection fee — check the self-assessment at ico.org.uk. Delete this note once you're done.