Privacy Policy
Effective Date: 15 June 2026
Introduction
Thrive and Bloom Nutrition is a private paediatric dietetic practice operated by Sophie Wootten in Cardiff, Wales. We are committed to protecting the privacy and confidentiality of the children and families we support. This policy explains how we collect, use, store, and protect your personal information in accordance with UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Information We Collect
We may collect and process the following information:
Parent or guardian contact details
Child’s personal, medical, and developmental information
Feeding, nutritional, allergy, and growth history
Clinical notes and consultation records
Information from GPs and other healthcare professionals involved in care
Appointment, communication, and payment records
How We Collect Information
Information is usually collected directly from parents or guardians when you:
Contact us via our website or email;
Complete intake forms, food diaries, or clinical questionnaires;
Book appointments through our online scheduling system;
Attend virtual or telephone consultations; or
Communicate with us by email, telephone, or professional social media channels.
With your explicit permission, we may also receive relevant medical information from GPs, paediatricians, or other healthcare professionals involved in your child’s care.
How We Use Your Information
We use personal information to:
Provide expert dietetic assessment, advice, and clinical treatment;
Maintain accurate, professional clinical records;
Communicate regarding appointments, invoicing, and ongoing care;
Liaise with relevant healthcare professionals regarding your child's treatment;
Process secure payments and invoices;
Meet our statutory legal, professional (HCPC), and safeguarding obligations; and
Send educational or marketing communications where explicit consent has been provided.
We do not sell or lease personal information to third parties.
Lawful Basis for Processing
Under the UK GDPR, we rely on the following lawful bases to process your data:
Performance of a Contract: To deliver the dietetic services or packages you have purchased.
Provision of Healthcare: To provide individualised healthcare and dietetic assessments. Health information is strictly treated as Special Category Data under Article 9 of the UK GDPR.
Compliance with Legal Obligations: To satisfy statutory clinical record-keeping and safeguarding rules.
Consent: For any marketing communications, which can be withdrawn at any time.
Information Sharing
We treat all personal information with strict clinical confidentiality. Data is only shared with third parties under the following circumstances:
Multidisciplinary Care: Shared with your child’s GP, health visitor, or paediatrician where clinically appropriate and agreed upon.
Trusted Processors: We utilize secure, professional third-party software platforms to run our practice, including Google Workspace for our encrypted business email, calendar scheduling, and secure digital document storage. We also use trusted third-party providers to securely process card payments and manage clinic bookings.
Legal Disclosures: Information may be disclosed without consent if required by a court of law, or if a consultation raises an immediate child safeguarding concern or risk of serious harm.
Virtual Consultations
Where consultations are delivered remotely by video or telephone, we take all reasonable steps to ensure consultations remain secure, end-to-end encrypted, and private. However, no electronic system over the internet can be guaranteed to be 100% secure.
Data Storage and Security
Personal information is stored securely using password-protected, two-factor authenticated, and encrypted digital systems within our Google Workspace environment and associated clinical systems. Appropriate technical measures are in place to protect your family's information from unauthorised access, loss, or misuse.
Some of our secure cloud service providers process or store data outside the UK (such as in the United States). Where this occurs, we ensure that appropriate safeguards are in place—such as Standard Contractual Clauses (SCCs) or valid international data-sharing frameworks—to ensure your data remains protected to UK GDPR standards.
Retention of Records
Clinical records are retained in strict accordance with UK healthcare and professional retention guidelines. Records relating to children and minors must legally be securely retained until the child’s 25th birthday (or 26th birthday if they were 17 years old at the conclusion of their treatment). After this statutory period, records are permanently and securely destroyed.
Your Rights
Under UK data protection law, you hold the following statutory rights regarding your data:
The right to request access to your or your child's personal and clinical information;
The right to request correction of inaccurate or incomplete information;
The right to request erasure of your data (please note this does not apply to medical records that we are legally mandated to retain for clinical safety);
The right to restrict or object to certain data processing methods;
The right to instantly withdraw consent for any marketing or newsletter communications; and
The right to lodge a formal complaint with the Information Commissioner’s Office (ICO).
Cookies and Website Analytics
Our website uses basic cookies and analytics tools to track website performance and improve user experience. You can manage, block, or delete cookie preferences at any time directly through your web browser settings.
Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in data law or clinical guidelines. The latest version, complete with its effective date, will always be publicly accessible in our website footer.
Contact Details
Data Controller: Sophie Wootten
Business: Thrive and Bloom Nutrition
Location: Cardiff, Wales
Email: hello@thriveandbloomnutrition.org
If you have concerns about how your information is handled, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
Information Commissioner’s Office (ICO)
Legal Notice
Thrive and Bloom Nutrition is a registered trade mark with the United Kingdom Intellectual Property Office under Trade Mark No. UK00004293519. All rights reserved.