This policy explains how we handle your personal data and sensitive health information in compliance with the General Data Protection Regulation (GDPR). By booking a session and completing our health declaration, you provide explicit consent for us to process health-related data to ensure your safety during infrared sauna therapy.
Information We Collect
We collect and process the following categories of data:
Legal Basis for Processing
We process your personal data under the following legal bases:
Your Rights (Including Deletion)
Under GDPR, you have the following rights regarding your data:
Data Retention & Security
We retain your health declaration and booking data for a period necessary to satisfy legal, accounting, or insurance requirements. All data is stored securely within our encrypted third-party platforms (Acuity, Stripe, and PayPal). We do not sell your data.
How to Exercise Your Rights
To request deletion of your data or to exercise any other rights, please contact us at infraredsaunaclub@sunlighten.com, we will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority if you believe your data has been mishandled.