Skip to content

Privacy Policy

Last updated 16 September 2026 · Applies to Advanced Wellness Ltd (company number 17100614), trading as vFlow. How we collect, use and protect your personal and health data.

01Who we are

This policy explains how Advanced Wellness Ltd (company number 17100614), trading as vFlow, collects, uses and protects your personal data when you visit our website, book a treatment, or receive care from us in person, including at partner gym and sports centre locations.

We are the data controller for the personal data described in this policy. We are registered with the Information Commissioner's Office (ICO) as a data controller.

02What we collect

We collect different information depending on how you interact with us:

  • Contact and account details: name, email, phone number, date of birth (to confirm you're 18 or over), and address if needed for invoicing or a mobile appointment.
  • Booking and transaction data: appointment history, treatments received, and payment confirmation. We do not store full card details ourselves — payments are handled by a third-party payment processor.
  • Health information: medical history, current medications, allergies, your answers during clinical screening, and notes your clinician makes about your treatment. This is special category data under UK GDPR and we handle it with extra care, as set out below.
  • Website and device data: IP address, browser type, and how you use our site, collected via cookies and similar technologies. See our Cookie Policy for detail.
  • Usage analytics: we measure how our site is used so we can improve it. This includes a cookieless tool that never identifies you, and — only if you accept cookies — Google Analytics. You can decline analytics cookies at any time.
  • Security information: technical signals our booking and sign-in pages use to tell real visitors apart from automated bots.
  • Communications: anything you send us by email, form, or phone, including complaints or feedback.

We never send your health information to an analytics or advertising provider, and we never use it for marketing.

03Where we get it from

  • From you, when you book, complete screening, or contact us.
  • From your clinician, who records your treatment and any observations on the day.
  • From the person who made the booking, if you are part of a group booking. If you book for other people, please only give us their details with their agreement.
  • From our payment processor, which confirms whether a payment went through.
  • Automatically, through cookies and our hosting and security systems.

04How we use it, and our legal basis

We only use your data where the law allows. The table sets out what we do and the legal basis for each. Health data needs a second, stricter condition under Article 9 of UK GDPR, which is shown where it applies.

What we doOur legal basis
Screening you and deciding whether treatment is suitableContract. For health data, Article 9(2)(h): providing health care under the responsibility of a registered health professional.
Providing your treatment and keeping clinical recordsContract and legal obligation. For health data, Article 9(2)(h).
Managing bookings, deposits, payments, refunds and remindersContract.
Handling complaints, incidents and reports to regulators such as the CQC or MHRALegal obligation. For health data, Article 9(2)(h), or Article 9(2)(f) where needed for a legal claim.
Contacting emergency services if you become unwellVital interests. For health data, Article 9(2)(c).
Keeping our website secure and blocking fraud and automated abuseLegitimate interests in running a safe, reliable service.
Analytics cookiesConsent, given through our cookie banner.

Asking for your consent to treatment is a clinical requirement. It is separate from our legal basis for holding your records, which is why we may need to keep clinical records even if you later ask us to delete them.

Where we rely on legitimate interests, we weigh them against your rights and reasonable expectations first. If we ever need to use your data for a new purpose, we will explain it and its legal basis before we do.

05Emails we send you

We send service emails about your bookings. These include booking and payment confirmations, screening invitations and outcomes, appointment reminders, aftercare guidance, and cancellation notices. They are part of the service you have asked for, so they do not need separate marketing consent.

After a visit we may send you one email asking for feedback, including an optional link to leave a Google review. We send it no more than once every 90 days, and you can tell us to stop at any time by replying to that email.

We only send marketing emails to people who have opted in. Every marketing email includes an unsubscribe link, and saying no never affects your bookings.

06Who we share it with

We don't sell your data, and we don't share it for anyone else's marketing purposes. We do share it, on a need-to-know basis, with:

  • The prescribers and clinicians involved in your care, including at the specific location where you're treated.
  • Your GP or another healthcare professional, with your agreement, or without it only where needed to keep you or others safe.
  • Hosting, database, booking and website security providers who process data on our behalf, under contracts that require them to protect it (our data processors).
  • Our payment processor, to take payment securely.
  • Our email delivery provider, to send booking confirmations, reminders and other messages about your appointments.
  • Analytics providers, only where you have accepted analytics cookies.
  • Regulators and authorities where we're legally required to report — for example, the Care Quality Commission, MHRA, or in response to a valid legal request.
  • Our insurers and professional advisers, if needed to investigate or respond to a complaint or claim, and a buyer or their advisers if the business is ever sold or reorganised.

07International transfers

Some of our providers store or process data outside the UK. Where that happens, we use safeguards approved under UK law, such as an adequacy decision or the ICO International Data Transfer Agreement. You can ask us which safeguard applies.

08How long we keep it

We keep personal data only for as long as we need it. Our main retention periods are:

RecordHow long we keep it
Clinical and screening records8 years after your last treatment
Complaints10 years after the complaint is closed
Booking and payment records6 years, for accounting and tax purposes
Analytics dataAs set out in our Cookie Policy

When a retention period ends we delete or anonymise the data. Where we can't delete something straight away, we restrict access to it until we can.

09Keeping it secure

We use appropriate technical and organisational measures to protect your data. Only the clinicians and staff who need your information to do their job can see it, and our team is trained on confidentiality.

If a data breach affects you, we will tell you and the ICO where the law requires it.

10Cookies

Our website uses cookies and similar technologies to help it function and to understand how it's used. Only cookies the site needs to work are set without asking. Full detail, including how to change your choice, is in our Cookie Policy.

11Your rights

Under UK GDPR, you have the right to:

  • Ask what personal data we hold about you, and get a copy of it.
  • Ask us to correct anything that's inaccurate or incomplete.
  • Ask us to delete your data, though this may be limited where we have a legal or clinical governance reason to keep clinical records for a set period.
  • Ask us to restrict how we use your data while a question about it is resolved.
  • Ask for your data in a portable format, where that right applies.
  • Withdraw consent at any time, where consent is our basis for processing.

You can also object to any processing we base on legitimate interests. If you do, we will stop unless we have compelling grounds to continue, and we will tell you if that is the case.

To make a request, email hello@vflowhealth.co.uk. We may need to confirm your identity first, so that your information isn't given to the wrong person. We reply within one month, and will tell you if a complex request needs up to two months more. There is no fee unless a request is clearly unfounded or excessive.

12Under-18s

Our treatments are for adults aged 18 and over only. We don't knowingly collect personal data from anyone under 18 through our booking systems, and we ask that under-18s don't submit their own details through our website. If you think a child has given us their details, contact us and we will delete them.

13Other websites

Our site links to other websites, such as partner venues and social media. They have their own privacy policies, and we aren't responsible for how they handle your data.

14Changes to this policy

We may update this policy from time to time, for example if our services or legal obligations change. We’ll post the updated version here with a new "last updated" date, and let you know directly if a change materially affects how we use your data.

15Contact & complaints

For any question about this policy or your data, contact us at hello@vflowhealth.co.uk. If you are unhappy with how we have handled your data, please tell us first so we can put it right.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator:

Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · Helpline: 0303 123 1113 · ico.org.uk

We review this policy regularly and update it when our services or the way we use your data change. If anything here is unclear or looks out of date, contact us and we will put it right.