Privacy Policy

Last updated: Thursday, 27th November 2025.

1. Introduction

Welcome to Circadian Healing Ltd’s Privacy Policy.

We respect your privacy and are committed to protecting your personal data. This privacy policy will explain how we look after your personal data when you visit our website or purchase our products (including our lighting products), and will inform you of your privacy rights and how the law protects you.

This policy contains important information about who we are, how and why we collect, store, use and share your personal information, and explains your rights in relation to your personal information.

Circadian Healing Ltd complies with the UK General Data Protection Regulation (UK-GDPR), the Data Protection Act 2018, and, where applicable, the EU GDPR.

By providing us with your data, you warrant that you are over 13 years of age.

2. Important Information and Who We Are

Controller

Circadian Healing Ltd (“we”, “us”, or “our”) is the controller and responsible for your personal data.

Company details:

Circadian Healing Ltd
Company No: 16307291
Registered Office: 12 Queen’s Terrace, London, NW8 6DF
Email: team@inrhythm.earth

If you have questions about this privacy policy or would like to exercise your legal rights, please contact us using the details above.

Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection: www.ico.org.uk.

We would, however, appreciate the chance to resolve your concerns first.

Your Duty to Inform Us of Changes

Please keep us informed if your personal data changes during your relationship with us.

Third-party Links

Our website may include links to third-party websites, plug-ins and applications. We do not control these third-party websites and are not responsible for their privacy statements.

3. The Data We Collect About You

“Personal data” means any information that can identify you.

We may collect, use, store and transfer the following categories of personal data:

Identity Data

Includes first name, last name, and username.

(We do not require date of birth or gender unless explicitly provided.)

Contact Data

Billing address, delivery address, email address, telephone number.

Financial Data

Payment card details (processed securely via our payment providers; we do not store full card details).

Transaction Data

Details of products/services purchased from us.

Technical Data

IP address, browser type/version, time zone setting, operating system and device information.

Profile Data

Account details, order history, preferences, feedback, survey responses.

Usage Data

How you use our website, products and services.

Marketing & Communications Data

Your marketing preferences and communication preferences.

Aggregated Data

We may collect aggregated statistical data which does not identify you.

Sensitive Data

We do not routinely collect special category (sensitive) data.

However, if you voluntarily provide health-related information (for example, when booking a free consultation or describing your sleep challenges), we may process this data only with your explicit consent, and only for the purpose of delivering the requested service.

You may withdraw your consent at any time by emailing us at team@inrhythm.earth.

4. How We Collect Your Personal Data

We collect personal data through:

Direct interactions

When you:

  • purchase a product

  • contact us

  • fill out a form

  • book a consultation

  • subscribe to emails

  • provide feedback or reviews

Automated technologies

We automatically collect Technical Data through cookies and similar technologies.

Third-party providers

Including analytics providers (e.g., Google Analytics), payment processors (e.g., PayPal, Stripe), and fulfilment partners.

5. How We Use Your Personal Data

We will only use your personal data where permitted by law. The main purposes include:

  • Performing a contract with you (processing orders, deliveries, customer service)

  • Our legitimate business interests (improving our products, marketing insights, operating our website)

  • Complying with legal obligations

  • Sending marketing communications where you have consented

Below is a simplified explanation of how we use your data:

6. Marketing Communications

We may send you marketing emails if:

  • you have opted in, OR

  • you purchased from us and have not opted out.

We will only contact you via WhatsApp or SMS where you have explicitly opted in for those channels.

You can opt out at any time using the link in any marketing email or by emailing team@inrhythm.earth.

We will never share your data with third parties for their own marketing unless you provide express opt-in consent.

7. Disclosures of Your Personal Data

We may share your data with:

  • Service providers (IT, hosting, analytics, fulfilment, logistics, payment processors)

  • Professional advisers

  • Regulators and HMRC

  • Parties involved in a business sale or restructure

All third parties are required to treat your data securely and lawfully.

8. International Transfers

We may transfer data outside the UK/EEA where:

  • necessary to deliver your order

  • our service providers are located abroad

  • you are based outside the UK/EEA

We ensure appropriate safeguards (e.g., adequacy decisions or approved contractual clauses)

9. Data Security

We implement security measures to protect your data from loss, misuse, unauthorised access, alteration or disclosure.
Only staff and partners with a business need-to-know may access your data.

We have processes to respond to any suspected data breach.

10. Data Retention

We keep your personal data only as long as necessary for legal, accounting or business purposes.

  • Customer data is retained for 6 years for tax and legal purposes.

  • Non-customer data is retained for up to 3 years after last interaction.

  • Consultation notes (if containing health information) are stored only with consent and deleted on request.

  • Aggregated or anonymised data may be kept indefinitely.

You may request deletion at any time (see your rights below).

11. Your Legal Rights

You have the right to:

  • Request access to your data

  • Request correction

  • Request deletion

  • Object to processing

  • Restrict processing

  • Request transfer of your data

  • Withdraw consent at any time

To exercise any of these rights, please email team@inrhythm.earth.

There is no fee unless your request is excessive.

12. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will post the new version on our website.