Skip to main content
Privacy notice

How we look after your information.

What we collect, why, and the rights you have over it. Plain English, no surprises.

Last updated 22 June 2026.

1. Who we are

Acca Preventive Health Ltd, trading as ONE Personal Wellness ("we", "our", "us"), is the data controller responsible for your personal data. We are a wellness hub incorporated on 13 March 2023 and operating from Ground Floor, 32-36 May Street, Belfast, BT1 4NZ. We are registered with the Information Commissioner's Office as a data controller.

Registered name: Acca Preventive Health Ltd. Company number: NI695352 (Northern Ireland). Date incorporated: 13 March 2023. ICO registration reference: ZB719071. ICO registration date: 09 July 2024, renewal due 08 July 2026.

Our named Data Protection Lead is Zac Barnett, responsible for overseeing how we handle your personal data, responding to subject access requests, and acting as our point of contact with the Information Commissioner's Office. Email hello@onepersonalwellness.com or call +44 2890 134407.

2. Information we collect

Identity Data
full name, date of birth, gender, profile photograph.
Contact Data
email address, telephone number, postal address, emergency contact details.
Wellness Intake Data
responses to our wellness intake and pathway assessment, consent forms, GP details where you choose to share them, allergies, current medications and contraindications, plus session notes recorded by wellness hub staff. This is classified as special category data under UK GDPR and is processed with your explicit consent. The wellness intake is a screening tool, not a medical record, and is not used to diagnose, treat, or provide medical advice.
Financial Data
payment card details for memberships, sessions, basket overages and shop purchases are tokenised and processed securely by Stripe (including the in the hub BBPOS WisePOS E terminal). We never store full card numbers. Transaction history, account credit balances, invoice records, and membership billing information are processed via Stripe.
Account Data
email, encrypted password, membership tier, booking history, token allowance usage.
Technical Data
IP address, browser type and version, device information, operating system, pages visited, referring URL, session duration.
Marketing Data
your preferences for receiving marketing communications, newsletter subscription status, opt out records.

3. How we collect your data

Direct interactions
when you create an account, book a session, complete a wellness intake or consent form, purchase a membership or bundle, subscribe to our newsletter, apply for a membership, submit a contact form, or communicate with us by email, phone, or in the hub.
Automated technologies
cookies, server logs, and analytics tools collect technical data when you browse our website.
Third party providers
Stripe (payments, in the hub Terminal, billing portal), email delivery services, and hosting providers.

4. How we use your data

  • Processing and managing bookings, baskets, appointments and rescheduling.
  • Administering your account, membership, and token entitlements.
  • Reviewing your wellness intake to ensure your session is suitable and safe.
  • Processing payments and generating invoices.
  • Sending appointment reminders, post-session review requests and aftercare information.
  • Marketing communications including newsletters, wellness tips, and promotional offers with your consent.
  • Internal analytics, service improvement, and business reporting.
  • Preventing fraud and maintaining security.
  • Complying with legal and regulatory obligations.

5. Lawful bases for processing

Performance of a contract, Article 6(1)(b): processing bookings, managing accounts, administering memberships and bundle packages.

Legitimate interests, Article 6(1)(f): improving our services, internal analytics, sending appointment reminders, fraud prevention, maintaining security.

Consent, Article 6(1)(a): marketing communications, newsletter subscriptions, and processing special category wellness data.

Legal obligation, Article 6(1)(c): maintaining financial records, responding to regulatory requirements, tax compliance.

6. Special category data (wellness intake)

We collect wellness information through a wellness intake and pathway assessment to ensure your session is suitable and safe for you. This includes responses about your general health, allergies, current medications and contraindications, plus consent forms and session notes recorded by wellness hub staff. This is a screening tool, not a medical record, and is not used to diagnose, treat, or provide medical advice.

We process this data with your explicit consent under Article 9(2)(a) UK GDPR, which you provide when completing the wellness intake during the booking process. You may withdraw this consent at any time by contacting us, although this may mean we are unable to provide certain experiences safely.

7. Data sharing and third parties

We do not sell, rent, or trade your personal data. We may share data with the following categories of recipient, all of whom are bound by data processing agreements:

Payment processor: Stripe (card payments online, in the hub via the BBPOS WisePOS E Terminal, membership billing, customer billing portal, and refunds).

Email delivery services: for appointment confirmations, reminders, and marketing communications.

Hosting and infrastructure: cloud hosting providers for our website and database.

Professional advisers: accountants, lawyers, or insurers where necessary for the operation of our business.

Legal authorities: where required by law, regulation, or to protect our legal rights.

8. International transfers

Your data may be processed by service providers located outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office, or adequacy decisions where applicable.

9. Data retention

Account and booking data
for the duration of your account plus 6 years after your last interaction, for legal and regulatory purposes.
Wellness intake data
retained for 3 years from the date of your last visit, then securely deleted. As a screening tool, not a medical record, it is held only for as long as needed to assess suitability for repeat sessions.
Marketing preferences
until you unsubscribe or withdraw consent.
Financial records
7 years as required by HMRC.
Bundle and credit records
retained while the balance is outstanding (these do not expire), plus 6 years after full redemption for financial audit purposes.

10. Your rights under UK GDPR

Right of Access (Article 15): request a copy of the personal data we hold about you.

Right to Rectification (Article 16): request correction of inaccurate or incomplete data.

Right to Erasure (Article 17): request deletion of your data where there is no compelling reason for continued processing.

Right to Restriction (Article 18): request that we limit processing of your data in certain circumstances.

Right to Data Portability (Article 20): request transfer of your data to another service provider in a structured, commonly used, machine-readable format.

Right to Object (Article 21): object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email hello@onepersonalwellness.com. We will respond within 30 days. There is no charge for most requests, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

11. Cookies and tracking

Our website uses essential cookies (authentication, session, security), functional cookies (your preferences) and, with your consent, analytics cookies that help us understand how visitors use our site so we can improve it. You can manage preferences through the cookie banner shown on your first visit, and configure your browser to refuse cookies, although this may limit functionality. See our Cookies page for the full breakdown.

12. Data security

  • Encryption of all data in transit (TLS/SSL) and at rest.
  • Secure authentication with bcrypt-hashed passwords.
  • Role-based access controls (Owner, Staff, Member) with granular permissions.
  • Row-level security policies enforcing data isolation per user.
  • Long-lived authenticated sessions with explicit log-out and 30-day refresh-token expiry.
  • Regular security audits.
  • PCI DSS-compliant payment processing via Stripe.
  • We never store full card details.
  • Automated database backups and disaster recovery procedures.

13. Children's privacy

Our services are not directed at individuals under 18. We do not knowingly collect personal data from children under 18.

14. Marketing and communications

When you create an account you may subscribe to our marketing communications. You can opt out at any time by clicking unsubscribe in any marketing email, updating preferences in your account, or contacting hello@onepersonalwellness.com. Opting out of marketing does not affect transactional communications such as booking confirmations, appointment reminders, and account-related notifications.

15. Changes to this policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. For significant changes we may notify you by email or through a notice on our website.

16. Complaints

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve the matter. If you remain dissatisfied you have the right to lodge a complaint with the Information Commissioner's Office: ico.org.uk, helpline 0303 123 1113, address Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

17. Contact us

Acca Preventive Health Ltd, trading as ONE Personal Wellness. Ground Floor, 32-36 May Street, Belfast, BT1 4NZ. Company No. NI695352 (Northern Ireland). Data Protection Lead: Zac Barnett, hello@onepersonalwellness.com. Phone: +44 2890 134407.