BOOKSESH.COM Privacy Policy
Version: 1.0 Effective date: 27 November 2025 Document owner: BOOKSESH.COM
BOOKSESH.COM (“BOOKSESH.COM”, “we”, “us”, “our”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this policy carefully. By using our platform, you confirm that you have read and understood how we handle your personal data.
1. Who We Are
Data Controller: Conceptcubes Ltd (trading as BOOKSESH.COM) Company number: 09751872 Registered address: Studio 231 Oxgate House Oxgate Lane, London, England, NW2 7FT Contact for data matters: booksesh.com/contact-us/
BOOKSESH.COM operates an online marketplace and SaaS platform that connects customers with independent wellness and wellbeing practitioners. We are registered with the Information Commissioner’s Office (ICO) under registration number C1939164
2. What Data We Collect
2.1 Account and profile data
When you create an account, we collect: name, email address, phone number, and account preferences. Practitioners additionally provide business name, service descriptions, and professional information.
2.2 Booking data
When you make or accept a booking, we collect: session type, date, time, practitioner details, and any information you voluntarily provide relating to your booking.
2.3 Payment data
We collect the information needed to process payments, including billing details. Full payment card data is processed directly by our regulated payment service provider and is not stored on our systems.
2.4 Communications
We retain records of messages sent through our platform, support requests, and communications with our AI assistant.
2.5 Technical data
We automatically collect IP address, browser type, device information, pages visited, and usage patterns when you use our platform. We use cookies in accordance with our Cookie Policy.
2.6 Marketing preferences
If you opt in to marketing communications, we retain your preference and contact information for that purpose.
2.7 Verification data
We collect information provided during our practitioner verification process, including email verification records and documentation submitted as part of insurance or credential verification.
2.8 AI assistant interaction data
If you use our AI chat assistant, we may retain anonymised records of interactions to improve the service. Where interactions can be linked to your account, this data is handled in accordance with this policy.
3. Special Category Data
Some of the services listed on BOOKSESH.COM relate to health, wellbeing, and wellness. Depending on the service you book and information you provide, we may process data that constitutes special category data under UK GDPR Article 9 — specifically, data that reveals or infers health-related information.
We process such data only where:
- You have given explicit consent for us to do so; or
- Processing is necessary for reasons of preventive or occupational medicine, medical diagnosis, or provision of health or social care, subject to appropriate safeguards; or
- Another Article 9 condition applies.
We take additional care with this category of data, including strict access controls and data minimisation practices. We do not share health-inferred data with third parties for marketing or profiling purposes.
If you do not wish to provide health-related information, you are not required to do so. However, some practitioners may require relevant information to assess suitability for their services.
4. How We Use Your Data
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account | Contract (UK GDPR Article 6(1)(b)) |
| Processing bookings and payments | Contract (Article 6(1)(b)) |
| Preventing fraud and securing the platform | Legitimate interests (Article 6(1)(f)) |
| Communicating with you about your account or bookings | Contract (Article 6(1)(b)) |
| Sending marketing communications (with your consent) | Consent (Article 6(1)(a)) |
| Improving our platform and services | Legitimate interests (Article 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Article 6(1)(c)) |
| Operating our AI chat assistant | Legitimate interests (Article 6(1)(f)) |
| Practitioner verification and trust and safety | Legitimate interests (Article 6(1)(f)) |
| Processing special category (health-related) data | Explicit consent (Article 9(2)(a)) |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review.
AI intent scoring: Our AI assistant uses algorithmic signals to assess the relevance and intent of chat conversations. This affects how conversations are prioritised and escalated but does not affect your rights, contractual terms, or access to services.
5. Who We Share Your Data With
We do not sell your personal data. We share data only in the following circumstances:
5.1 Practitioners
When you make a booking, relevant booking details are shared with the practitioner you are booking with. Practitioners who receive your data are independent data controllers responsible for their own data handling.
5.2 Payment processor
Payment data is shared with our regulated third-party payment service provider to process transactions. This provider is bound by its own regulatory obligations and data protection standards.
5.3 Service providers
We use carefully selected third-party providers for services including email delivery, cloud hosting, customer support, and AI processing. These providers act as data processors and are bound by data processing agreements that require them to handle your data only on our instructions and in accordance with UK GDPR.
5.4 Legal and regulatory requirements
We may disclose data where required by law, court order, or regulatory authority.
5.5 Business transfers
If BOOKSESH.COM is acquired, merged, or subject to a restructure, your data may be transferred as part of that transaction. We will notify you if this occurs.
6. International Transfers
Some of our service providers may process data outside the UK. Where this occurs, we ensure that appropriate safeguards are in place — including the UK International Data Transfer Agreement (IDTA) or equivalent — in accordance with UK GDPR Chapter V.
7. How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Account data | Until account deletion, plus 2 years |
| Booking records | 7 years (legal/financial compliance) |
| Payment records | 7 years (HMRC requirements) |
| AI chat interactions | 12 months, then anonymised |
| Marketing preferences | Until you withdraw consent |
| Verification records | Duration of practitioner relationship plus 2 years |
| Technical/log data | 12 months |
We review retention periods periodically and will update this policy if they change.
8. Your Rights
Under UK GDPR, you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — request deletion of your data (subject to legal retention obligations)
- Right to restriction — ask us to restrict how we use your data in certain circumstances
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
- Rights related to automated decision-making — not to be subject to solely automated decisions with significant effects
To exercise any of these rights, contact us via our contact form at booksesh.com/contact-us/. We will respond within one calendar month.
9. Cookies
We use cookies and similar technologies to operate our platform, remember your preferences, and understand how our platform is used. For full details of the cookies we use and how to manage them, please see our Cookie Policy, available at booksesh.com/legal/cookies.
10. Children
Our platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a child, please contact us via our contact form at booksesh.com/contact-us/ and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice on our platform at least 14 days before the change takes effect. The version number and effective date at the top of this document will always reflect the current version.
12. Contact and Complaints
For any questions about this policy or how we handle your data:
Contact: booksesh.com/contact-us/ Post: Studio 231 Oxgate House Oxgate Lane, London, England, NW2 7FT
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
We would always prefer the opportunity to address your concern directly first.
BOOKSESH.COM is a trading name of Conceptcubes Ltd — Registered in England and Wales — Company number 09751872 Privacy Policy Version 1.0 — Effective 27 November 2025