Last Updated: June 19, 2026
Introduction
This privacy policy explains how aura-heath collects, uses, stores, and protects personal information provided by clients and website visitors. We are committed to maintaining the confidentiality and security of your data in accordance with applicable data protection legislation.
Information We Collect
We may collect the following types of personal information:
- Name, email address, and contact details provided through enquiry forms
- Financial information disclosed during consultations for the purpose of providing advice
- Communication records, including emails and meeting notes
- Technical data such as IP addresses, browser type, and device information when you visit our website
- Cookie data as described in our Cookies Policy
How We Use Your Information
Personal information is collected and processed for specific, legitimate purposes:
- To provide financial management services and advice as requested
- To communicate with you regarding your enquiries and appointments
- To maintain records required for regulatory compliance
- To improve our website functionality and user experience
- To send relevant information about our services, where you have consented to receive such communications
Legal Basis for Processing
We process personal data under one or more of the following legal bases:
- Contractual necessity: Processing is necessary to fulfill our services agreement with you
- Legitimate interests: We have a legitimate business interest in processing your data to operate our practice effectively
- Legal obligation: We are required to retain certain information for regulatory and tax purposes
- Consent: Where you have explicitly agreed to specific processing activities
Data Sharing and Disclosure
We do not sell or rent personal information to third parties. Your data may be shared only in the following circumstances:
- With professional service providers who assist in delivering our services, under strict confidentiality agreements
- Where required by law or regulatory authorities
- To protect our legal rights or the safety of individuals
- With your explicit consent for specific purposes
Data Security
We implement appropriate technical and organizational measures to protect personal information against unauthorized access, loss, or alteration. These measures include:
- Secure data storage with encryption
- Access controls limiting who can view your information
- Regular security assessments and updates
- Staff training on data protection requirements
Data Retention
Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected. Financial advice records are maintained for a minimum of seven years in accordance with professional standards and regulatory requirements. Website enquiry data is typically retained for two years unless deletion is requested sooner.
Your Rights
Under data protection law, you have the following rights:
- Right of access: Request a copy of the personal information we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal information in certain circumstances
- Right to restrict processing: Request limitation on how we use your data
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to processing based on legitimate interests or for direct marketing
To exercise any of these rights, please contact us at [email protected]
Changes to This Policy
We may update this privacy policy periodically to reflect changes in our practices or legal requirements. The date of the most recent revision will be indicated at the top of this page. Continued use of our services following any changes constitutes acceptance of the updated policy.
Contact Information
If you have questions about this privacy policy or how your personal information is handled, please contact us:
Email: [email protected]
Address: 47 West George Street, Glasgow, G2 1BP, United Kingdom
Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.