Privacy Policy

Effective Date: 15 March 2026
Website: https://sageleafclinic.co.uk/

Sage Leaf Clinic is committed to protecting and respecting your privacy. This Privacy Policy explains how personal data is collected, used, and protected when you visit the website or receive services.

Sage Leaf Clinic is the trading name of Tal Badehi, a sole trader practising in London, United Kingdom.


1. Data Controller

For the purposes of UK data protection law, the data controller responsible for your personal data is:

Tal Badehi
Trading as Sage Leaf Clinic
Practice Address:
18 Devonshire Row
London EC2M 4RH
United Kingdom

Email: tal@sageleafclinic.co.uk
Website: https://sageleafclinic.co.uk/

Sage Leaf Clinic is registered with the UK Information Commissioner’s Office (ICO) as a data controller.


2. Personal Data Collected

Personal information may be collected when you:

  • Submit a message through the website contact form
  • Contact Sage Leaf Clinic via email
  • Contact Sage Leaf Clinic via phone or SMS
  • Attend a consultation or treatment session

The personal data that may be collected includes:

Contact information

  • Name
  • Phone number
  • Email address

Enquiry information

  • Message content submitted through the contact form or email

Health information

Where you become a client, health information relevant to your treatment may be collected, including:

  • Medical history
  • Current symptoms or conditions
  • Medications
  • Lifestyle information relevant to treatment

Health information is considered special category data under UK data protection law and is treated with additional care and confidentiality.


3. How Personal Data Is Used

Personal data may be used for the following purposes:

  • Responding to enquiries submitted through the website
  • Communicating with prospective clients
  • Arranging and managing appointments
  • Providing shiatsu and acupuncture treatments
  • Maintaining treatment records
  • Complying with legal and professional obligations

Your personal data will not be sold, rented, or used for marketing without consent.

Sage Leaf Clinic does not use automated decision-making or profiling when processing personal data.


4. Lawful Basis for Processing

Personal data is processed under the following lawful bases in accordance with the UK General Data Protection Regulation (UK GDPR).

Legitimate Interests

Responding to enquiries and managing communications with prospective clients.

Contract

Processing necessary for providing booked treatment services.

Legal Obligations

Maintaining records where required for legal or regulatory purposes.

Provision of Health Care (Special Category Data)

Health information is processed under Article 9(2)(h) of the UK GDPR, which permits processing where it is necessary for the purposes of preventive healthcare, medical diagnosis, and the provision of health treatment or care.


5. Communication Consent

By contacting Sage Leaf Clinic via the website, email, phone, or SMS, you consent to being contacted through these channels for the purpose of:

  • responding to your enquiry
  • arranging appointments
  • communicating regarding treatment

Communication will only relate to services provided by Sage Leaf Clinic and will not be used for marketing unless explicit consent is given.


6. Storage of Personal Data

Personal information may be stored using secure communication and record-keeping systems including:

  • Email services (including Outlook and Gmail)
  • SMS messaging via mobile device
  • Secure note-taking systems including a reMarkable tablet and associated cloud services
  • Website systems used to process contact form enquiries (WordPress hosted by GoDaddy)

Access to these systems is restricted to the practitioner only.

Some service providers used to store or transmit information may operate servers outside the United Kingdom.

Where personal data is transferred internationally, safeguards are implemented in accordance with UK data protection law. These safeguards may include:

  • the UK International Data Transfer Agreement (IDTA)
  • the UK Addendum to the EU Standard Contractual Clauses (SCCs)
  • participation in the UK Extension to the EU–US Data Privacy Framework, where applicable

These mechanisms are designed to ensure that personal data receives an equivalent level of protection when transferred outside the United Kingdom.


7. Data Security

Sage Leaf Clinic takes the protection of personal and health information seriously.

Reasonable technical and organisational measures are used to protect personal data from unauthorised access, loss, or misuse.

These measures include:

  • password-protected devices used for storing client information
  • restricted access to personal and treatment records
  • secure storage of electronic treatment notes
  • use of reputable communication and storage providers
  • maintaining professional confidentiality in accordance with healthcare practice standards

Only the practitioner (Tal Badehi) has access to treatment records unless disclosure is required by law.


8. Data Retention

Personal data is retained only for as long as necessary.

Treatment Records

Client treatment records and relevant health information are retained for 7 years after the last appointment, in line with common professional practice for health practitioners.

General Enquiries

Information submitted through the contact form that does not result in a booking may be retained for up to 12 months before deletion.

Communication Records

Relevant communications via email or SMS may be retained where necessary for record-keeping relating to enquiries, appointments, or treatment history.


9. Sharing of Personal Data

Personal data is not shared with third parties for marketing purposes.

However, data may be processed by third-party service providers used to operate the business, including:

  • website hosting providers
  • email service providers
  • cloud storage services used for treatment notes

These providers only process personal data as required to deliver their services.

Personal data may also be disclosed where required by law.


10. Cookies

The website may use limited technical cookies required for basic website functionality.

These cookies do not collect personally identifiable information.

The website currently does not use analytics or advertising cookies that track visitors across websites.


11. Your Data Protection Rights

Under UK data protection law, individuals have rights relating to their personal data. These include:

  • the right to access personal data held about you
  • the right to request correction of inaccurate data
  • the right to request deletion of personal data where appropriate
  • the right to restrict or object to certain processing
  • the right to request transfer of your data in certain circumstances
  • the right not to be subject to automated decision-making or profiling

Requests relating to your personal data can be made by contacting:

tal@sageleafclinic.co.uk


12. Complaints

If you have concerns about how your personal data is handled, please contact Sage Leaf Clinic in the first instance.

You also have the right to lodge a complaint with the UK data protection regulator.

Information Commissioner’s Office
https://ico.org.uk/


13. Updates to This Policy

This Privacy Policy may be updated from time to time to reflect changes in legal requirements or business practices.

The latest version will always be published on the website with an updated effective date.


14. Contact

For any questions about this Privacy Policy or how personal data is handled, please contact:

Tal Badehi
Sage Leaf Clinic
18 Devonshire Row
London EC2M 4RH
United Kingdom

Email: tal@sageleafclinic.co.uk