Privacy & data protection

Privacy notice

This notice explains how Catherine Moore, trading as Iterum & Grá, handles your personal data under the UK GDPR and the Data Protection Act 2018.

Last updated: 16 August 2026

Who is the data controller

Catherine Moore, trading as Iterum & Grá, a therapy and Reiki practice based in Norfolk, United Kingdom, is the data controller for personal data collected through this website. You can reach the practice at any time through the contact form or by email at info@iterumandgra.com.

ICO registration number: ZA309952.

What personal data is collected

Through this website, only the information you choose to send in the enquiry form is collected: your first and last name, email address, telephone number (if you provide one), the content of your message, and a record that you agreed to this privacy notice together with the date and time of that agreement.

Please do not include detailed health information or clinical history in the enquiry form. A secure route for that information is agreed with you before any session begins. Clinical notes for people who go on to become clients are held separately from this website and are covered by the separate client privacy information given to you at assessment.

Why it is used and the lawful basis

Enquiry data is used solely to reply to you, arrange sessions and keep an accurate record of enquiries. The lawful basis is your consent (UK GDPR Article 6(1)(a)), given by ticking the consent box on the enquiry form. You can withdraw consent at any time, which will not affect the lawfulness of processing before withdrawal.

Your details are never sold, never used for marketing lists, and never shared with third parties for their own purposes.

Where your data is stored — UK data residency

Enquiries submitted through this website are stored in an encrypted PostgreSQL database hosted in the London (eu-west-2) region of Amazon Web Services in the United Kingdom. Data is encrypted in transit (TLS) and at rest. The website itself is served over HTTPS from a global content delivery network; the pages it serves contain no personal data.

Because the database is UK-hosted, no international transfer of your enquiry data takes place in the ordinary course of business. If a technical support provider ever needed access from outside the UK, that access would be governed by the UK International Data Transfer Addendum or an adequacy decision.

How long it is kept

Enquiries that do not become bookings are deleted within 24 months. Where you go on to become a client, contact details are transferred into your clinical record and retained in line with professional guidance for therapy records, then securely destroyed. You may ask for your enquiry to be deleted sooner at any time.

Cookies and tracking

This website sets no advertising cookies, no analytics cookies and no third-party tracking or profiling. Because no non-essential cookies are used, no cookie consent banner is required under the Privacy and Electronic Communications Regulations. Fonts are loaded from Google Fonts, which receives your IP address purely to deliver the font files.

Booking and payments

Sessions are arranged personally by email or telephone after you enquire; the “book a session” links on this site lead to the enquiry form and do not send your details to any external booking platform. No card details are collected or stored on this website.

Your rights

Under UK GDPR you have the right to be informed, to access a copy of your data, to rectification, to erasure, to restrict processing, to data portability, to object, and to withdraw consent. Requests are answered within one calendar month and free of charge.

To exercise any right, use the contact form or email info@iterumandgra.com. If you are unhappy with the response, you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

Security and breaches

Access to enquiry data is restricted to Catherine Moore through an authenticated administrative interface; the public website can submit an enquiry but cannot read any stored enquiry. Any personal data breach likely to pose a risk to your rights will be reported to the ICO within 72 hours and, where the risk is high, to you directly.

Changes to this notice

This notice may be updated as the practice changes. The date at the top of the page shows when it was last revised.