Privacy Policy
Last updated: Thursday, 27th November 2025.
1. Introduction
Welcome to Circadian Healing Ltd’s Privacy Policy.
We respect your privacy and are committed to protecting your personal data. This privacy policy will explain how we look after your personal data when you visit our website or purchase our products (including our lighting products), and will inform you of your privacy rights and how the law protects you.
This policy contains important information about who we are, how and why we collect, store, use and share your personal information, and explains your rights in relation to your personal information.
Circadian Healing Ltd complies with the UK General Data Protection Regulation (UK-GDPR), the Data Protection Act 2018, and, where applicable, the EU GDPR.
By providing us with your data, you warrant that you are over 13 years of age.
2. Important Information and Who We Are
Controller
Circadian Healing Ltd (“we”, “us”, or “our”) is the controller and responsible for your personal data.
Company details:
Circadian Healing Ltd
Company No: 16307291
Registered Office: 12 Queen’s Terrace, London, NW8 6DF
Email: team@inrhythm.earth
If you have questions about this privacy policy or would like to exercise your legal rights, please contact us using the details above.
Complaints
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection: www.ico.org.uk.
We would, however, appreciate the chance to resolve your concerns first.
Your Duty to Inform Us of Changes
Please keep us informed if your personal data changes during your relationship with us.
Third-party Links
Our website may include links to third-party websites, plug-ins and applications. We do not control these third-party websites and are not responsible for their privacy statements.
3. The Data We Collect About You
“Personal data” means any information that can identify you.
We may collect, use, store and transfer the following categories of personal data:
Identity Data
Includes first name, last name, and username.
(We do not require date of birth or gender unless explicitly provided.)
Contact Data
Billing address, delivery address, email address, telephone number.
Financial Data
Payment card details (processed securely via our payment providers; we do not store full card details).
Transaction Data
Details of products/services purchased from us.
Technical Data
IP address, browser type/version, time zone setting, operating system and device information.
Profile Data
Account details, order history, preferences, feedback, survey responses.
Usage Data
How you use our website, products and services.
Marketing & Communications Data
Your marketing preferences and communication preferences.
Aggregated Data
We may collect aggregated statistical data which does not identify you.
Sensitive Data
We do not routinely collect special category (sensitive) data.
However, if you voluntarily provide health-related information (for example, when booking a free consultation or describing your sleep challenges), we may process this data only with your explicit consent, and only for the purpose of delivering the requested service.
You may withdraw your consent at any time by emailing us at team@inrhythm.earth.
4. How We Collect Your Personal Data
We collect personal data through:
Direct interactions
When you:
purchase a product
contact us
fill out a form
book a consultation
subscribe to emails
provide feedback or reviews
Automated technologies
We automatically collect Technical Data through cookies and similar technologies.
Third-party providers
Including analytics providers (e.g., Google Analytics), payment processors (e.g., PayPal, Stripe), and fulfilment partners.
5. How We Use Your Personal Data
We will only use your personal data where permitted by law. The main purposes include:
Performing a contract with you (processing orders, deliveries, customer service)
Our legitimate business interests (improving our products, marketing insights, operating our website)
Complying with legal obligations
Sending marketing communications where you have consented
Below is a simplified explanation of how we use your data:
6. Marketing Communications
We may send you marketing emails if:
you have opted in, OR
you purchased from us and have not opted out.
We will only contact you via WhatsApp or SMS where you have explicitly opted in for those channels.
You can opt out at any time using the link in any marketing email or by emailing team@inrhythm.earth.
We will never share your data with third parties for their own marketing unless you provide express opt-in consent.
7. Disclosures of Your Personal Data
We may share your data with:
Service providers (IT, hosting, analytics, fulfilment, logistics, payment processors)
Professional advisers
Regulators and HMRC
Parties involved in a business sale or restructure
All third parties are required to treat your data securely and lawfully.
8. International Transfers
We may transfer data outside the UK/EEA where:
necessary to deliver your order
our service providers are located abroad
you are based outside the UK/EEA
We ensure appropriate safeguards (e.g., adequacy decisions or approved contractual clauses)
9. Data Security
We implement security measures to protect your data from loss, misuse, unauthorised access, alteration or disclosure.
Only staff and partners with a business need-to-know may access your data.
We have processes to respond to any suspected data breach.
10. Data Retention
We keep your personal data only as long as necessary for legal, accounting or business purposes.
Customer data is retained for 6 years for tax and legal purposes.
Non-customer data is retained for up to 3 years after last interaction.
Consultation notes (if containing health information) are stored only with consent and deleted on request.
Aggregated or anonymised data may be kept indefinitely.
You may request deletion at any time (see your rights below).
11. Your Legal Rights
You have the right to:
Request access to your data
Request correction
Request deletion
Object to processing
Restrict processing
Request transfer of your data
Withdraw consent at any time
To exercise any of these rights, please email team@inrhythm.earth.
There is no fee unless your request is excessive.
12. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will post the new version on our website.