Privacy notice
This privacy notice explains how Severn Clinical Canine Massage Therapy handles your personal data when you use this website. It is written to be honest, short, and specific.
Who is responsible for your data
Joanne Rawlings, trading as Severn Clinical Canine Massage Therapy, is the data controller for the personal data described below.
- Service address: 34 The Woodlands, Ryall, Upton Upon Severn, WR8 0PQ
- Email: jo@severnclinicalcaninemassage.co.uk
- ICO registration number: ZC161633
This website is operated on Joanne's behalf by The Code Abides Limited (Company No. 13307220, registered office 9-11 Vittoria Street, Birmingham, B1 3ND), under a written processor agreement. The Code Abides Limited is a processor in the UK GDPR sense — they hold the website on Joanne's instructions; they do not make their own decisions about your data.
What we collect
If you use the contact form on this site, we collect the information you choose to provide:
- Your name (required).
- Your email address (required, so we can reply to you).
- Your phone number (optional, if you'd prefer a call back).
- Your message (required).
When you submit the form, we also receive your IP address (used only to validate that you are not a bot, then discarded) and your browser's User-Agent string (recorded as part of a security audit log so we can investigate misuse of the form).
We do not use cookies that require your consent. The contact form uses a security challenge service (Cloudflare Turnstile) that sets a small number of strictly-necessary security cookies on challenges.cloudflare.com only during an active challenge — these are named and explained in the “Cookies” section below.
What we use it for, and the legal basis
| What | Why | Legal basis (UK GDPR Article 6) |
|---|---|---|
| Reading and responding to your enquiry | So Joanne can reply to you and arrange a treatment if appropriate | Article 6(1)(b) — necessary for steps before entering a contract; or Article 6(1)(f) — legitimate interests in responding to general correspondence |
| Bot-mitigation on the contact form | So genuine enquiries reach Joanne and aren't lost in spam | Article 6(1)(f) — legitimate interests in protecting the contact channel |
| Audit log of submissions (hashed IP, User-Agent, outcome — no message content) | So we can detect attack patterns on the form | Article 6(1)(f) — legitimate interests in security forensics |
How long we keep it
- Your message stays in Joanne's mailbox until she deletes it. As a general rule, enquiries that don't lead to a booking are deleted within twelve months; enquiries that lead to a booking become part of Joanne's client records and are kept for as long as is appropriate for clinical record-keeping.
- The audit log (hashed IP, User-Agent, outcome) is kept for twelve months and then deleted.
- Resend (our email delivery service) keeps a copy of the email-sending logs for thirty days, then deletes them.
- Application Insights (our infrastructure monitoring) keeps request metadata for thirty to ninety days, then deletes it.
- Cloudflare Turnstile does not retain personal data after the challenge is completed.
Subprocessors
Your message is processed by the following services on our behalf:
| Service | What they do | Where | Transfer mechanism |
|---|---|---|---|
| Microsoft Azure (UK South) | Hosts the website, runs the contact-form endpoint, and stores the security audit log | London | Intra-UK — no transfer mechanism required |
| Apple (iCloud) | Hosts Joanne's mailbox at jo@severnclinicalcaninemassage.co.uk via Apple's iCloud Custom Email Domain feature | Ireland — Joanne's iCloud contract is with Apple Distribution International Ltd, Cork | UK–EEA adequacy — no additional transfer mechanism required |
| Resend (Plus Five Five, Inc.) | Delivers the email from the contact form to Joanne's mailbox | United States storage; EU region for sending | EU-US Data Privacy Framework with UK Extension (primary); EU Standard Contractual Clauses + UK International Data Transfer Addendum (fallback) |
| Cloudflare, Inc. | Bot-mitigation on the contact form. Cloudflare acts as a processor for the bot-mitigation service we use, and separately as an independent controller for improving its own bot-detection capability | United States parent; UK or EU edge for our visitors | EU-US Data Privacy Framework with UK Extension, Participant ID 5666 (primary); EU SCCs + UK IDTA (fallback) |
| GitHub (Microsoft) | Source-code repository for the website (does not see your data) | United States | Not a processor of visitor data |
| The Code Abides Limited | Operates the website on Joanne's behalf as processor | United Kingdom | Intra-UK — no transfer mechanism required |
Cloudflare's dual role (processor for the service Joanne uses; independent controller for its own product improvement) is unusual enough to call out explicitly. The data Cloudflare uses for its own purposes is the same transient signals it processes for ours — no additional data is collected.
Your data and people outside the UK
Two of the subprocessors above are based in the United States: Resend and Cloudflare. When your data reaches them, it is protected by the UK Extension to the EU-US Data Privacy Framework, which has been the UK Government's approved mechanism for personal-data transfers to certified US recipients since 2023. As a backup mechanism, our contracts with both include EU Standard Contractual Clauses and the UK International Data Transfer Addendum — these activate automatically if the primary framework is ever set aside.
Joanne's mailbox works differently. Her iCloud subscription is held with Apple Distribution International Ltd in Cork, Ireland, so a message arriving in her inbox travels from the UK to Ireland. The UK Government recognises the EEA, including Ireland, as providing an adequate level of data protection, so no additional safeguard is needed for that step. Anything Apple does with the data after that — including moving it within its own group — is Apple's responsibility under its own arrangements, not something Joanne directs.
Cookies
This site does not use cookies that require your consent.
The Cloudflare Turnstile widget on the contact form may set the following cookies on challenges.cloudflare.com during an active security challenge. These are strictly-necessary security cookies under PECR Regulation 6(4) — they do not require your consent because they are necessary to deliver the security feature you've engaged with.
| Cookie | Domain | Lifetime | Purpose |
|---|---|---|---|
cf_chl_rc_i | challenges.cloudflare.com | Session | Challenge state |
cf_chl_rc_ni | challenges.cloudflare.com | Session | Challenge state |
cf_chl_rc_m | challenges.cloudflare.com | Session | Challenge state |
__cf_bm | challenges.cloudflare.com | ~30 minutes | Bot-management |
We do not run analytics. We do not run advertising. We do not run third-party scripts that set cookies on our domain.
Your rights
Under UK GDPR you have the right to:
- Know what data we hold about you (right of access).
- Correct data we hold about you (right of rectification).
- Have it deleted (right of erasure, also called the “right to be forgotten”).
- Restrict how we use it.
- Object to our use of it where we rely on legitimate interests as the legal basis.
- Move it elsewhere (right of portability, where applicable).
- Complain to the Information Commissioner's Office if you think we've handled your data unfairly. The ICO's contact details are at ico.org.uk.
To exercise any of these rights, email Joanne at jo@severnclinicalcaninemassage.co.uk. We'll respond within one calendar month. If we need slightly longer for a complex request we'll tell you why, but we expect most requests to be answered straight away.
Changes to this notice
If we materially change how we handle your data, we'll update this notice and change the “last updated” date at the top. Significant changes will also be highlighted on this page for at least 60 days.