Privacy Policy

Privacy Policy

Peaceful Pathways Consultancy

Last updated: 24 July 2026

Effective from: 24 July 2026

1. Who I am

This Privacy Policy is issued by Grace Hall trading as Peaceful Pathways Consultancy — a sole trader providing specialist early years sleep and SEND consultancy services. Under UK data protection law, I am the “data controller” of the personal information I collect and use in the course of my work.

Contact details

Name: Grace Hall (trading as Peaceful Pathways Consultancy)

Address: 24 Skylark Way, Barnham, Bognor Regis, PO22 0FA

Email: grace@peacefulpathway.co.uk

Website: www.peacefulpathway.co.uk

ICO registration number: ICO:00014483496

2. What this policy covers

This policy explains what personal information I collect, why I collect it, how I use and protect it, who I share it with, and what rights you have in relation to it. It applies to information collected through my website (www.peacefulpathway.co.uk), through discovery calls and enquiries, and through my work with client families.

Please read it carefully. If anything isn’t clear, or you have questions about how your information is handled, please contact me using the details above.

3. What information I collect

The information I collect depends on how you interact with me. I aim to collect only what I need to provide my services well and to run the business responsibly.

A. Information you give me directly

When you enquire, book a discovery call, or become a client, I collect information including:

  • Your name and contact details (email, phone number, address)

  • Details about your family and household relevant to the work

  • Your child’s name, age, and date of birth

  • Your child’s sleep history, sensory profile, developmental context, and any relevant medical or health information you choose to share

  • Information about your child’s educational setting

  • The content of our conversations — discovery call notes, emails, and WhatsApp messages

  • Marketing preferences and consent records (for example, if you download a guide from my website or opt in to receive occasional emails)

B. Information from third parties (with your consent)

Where relevant to my work with your child, and with your explicit written consent, I may receive information from professionals already involved with your family, including:

  • Reports from occupational therapists, speech and language therapists, paediatricians, portage workers, and other clinicians

  • Education, Health and Care Plans (EHCPs) and other assessment documents

  • Setting observations and reports from nurseries or schools

  • Correspondence with settings or professionals about your child

C. Information collected automatically

When you visit my website, some information is collected automatically — including your IP address, browser type, and how you interact with the site. This is handled via cookies. Please see my Cookie Policy for full details.

D. Payment information

Payments are processed by Stripe, a third-party payment processor. Stripe collects and handles your payment card details directly — I don’t see, store, or hold your card details at any point.

4. Special category data

Some of the information I handle counts as “special category data” under UK GDPR. This includes:

  • Health data — information about medical conditions, diagnoses, and treatments

  • Information about disabilities, developmental differences, and additional needs

  • Occasionally, information about racial or ethnic origin — for example, where cultural sleep practices are relevant

Special category data is subject to additional protections under UK data protection law. I only process this information where you have given me your explicit, informed consent — which I ask for as a separate agreement, distinct from your general consent to my services. You can withdraw this consent at any time by contacting me, though this may affect my ability to continue our work if the information is essential to it.

5. Children’s data

My work centres on early years children (aged 0–5). In practice, this means the children I work with are the primary data subjects, while parents or carers provide the information on their behalf and give consent for its processing.

Key principles

  • The child is the data subject, not the parent — even though the parent provides the information and gives consent.

  • Parental consent provides the legal basis for processing children’s data. Under UK law, parental consent is required for the processing of personal data of children under 13 in an information society services context; since all my clients are 0–5, parental consent always applies.

  • Children’s data is handled with additional care — I collect only what’s necessary for the work, I never use it for marketing, I don’t share it without explicit parental consent, and I delete it on a defined schedule (set out in section 8).

  • Children have their own long-term rights over their data. When your child is old enough to exercise their own data protection rights, they can request access to, correction of, or deletion of information I hold about them — subject to my legal retention obligations.

6. Why I use your information (lawful bases)

Under UK GDPR, I must have a lawful basis for using your personal data. The bases I rely on are:

Contract

Most of what I do with your information is necessary to deliver the services you’ve booked — conducting the discovery call, building the sleep or transition plan, communicating with you throughout the engagement, taking payment, and providing follow-up support.

Consent

I rely on consent for:

  • Marketing communications (you opt in — and can opt out at any time)

  • Downloading resources or guides from my website

  • Processing special category data (see section 4)

  • Communicating with your child’s educational setting or other professionals on your behalf

Legitimate interests

Some administrative work relies on my legitimate interests in running the business efficiently — for example, keeping business records, managing accounts, and improving my services. I balance my interests against your rights, and you can object to this processing at any time.

Legal obligation

Some processing is required by law — for example, keeping financial records for tax purposes, or making a referral where I have a safeguarding concern about a child’s welfare.

7. Who I share your information with

I don’t sell or trade your data. I only share information where it’s necessary to deliver my services, where you’ve given explicit consent, or where I’m legally required to.

Third-party service providers I use to run the business

  • Squarespace — my website hosting platform. If you submit an enquiry through the contact form, that data is temporarily held on Squarespace’s systems before it reaches me.

  • Google (Google Workspace, Google Calendar, Google Meet) — for scheduling discovery calls and hosting them by video.

  • Stripe — for processing payments securely.

  • WhatsApp / Meta — for client communication during active engagements. See the specific note in section 9.


Each of these providers has its own privacy policy governing how they handle data. Where you’d like to review those, links are provided on their respective websites.

Others I may share information with

  • Your child’s educational setting or other professionals — only with your explicit written consent, on a case-by-case basis, for the specific purpose agreed. I never share information with settings or professionals without asking you first.

  • Safeguarding authorities — where I have a genuine safeguarding concern about a child’s welfare. I am required by professional and legal duties to follow standard safeguarding procedures in these circumstances.

  • HMRC and other regulatory bodies — where required by law (for example, for tax records or in response to a lawful information request).

Who I don’t share your information with

  • Other clients or families

  • Marketing partners or data brokers

  • Any third party for commercial gain

8. How long I keep your information

I keep personal information only as long as necessary for the purpose it was collected, and in line with my legal obligations. The specific periods are:

  • Discovery call notes (where the family doesn’t proceed to work with me): 6 months from the date of the discovery call.

  • Active client information (during our engagement): held throughout the engagement.

  • Closed client information (after our engagement ends): 6 years. This aligns with HMRC’s requirement for retention of business records and is the standard professional retention period.

  • Marketing consent records: held for the duration of your consent, plus 12 months after withdrawal (for audit purposes).

  • Email marketing list: until you unsubscribe.

  • Lead magnet download records: 12 months, unless you’ve also opted in to ongoing communications.

After the retention period ends, I either securely delete the information or anonymise it so it can no longer be linked to you or your child.

9. A specific note about WhatsApp

For client communication during active engagements, I use WhatsApp Messenger or WhatsApp Business. Messages exchanged via WhatsApp are stored on Meta’s servers and handled according to Meta’s own privacy policy. Where you communicate with me via WhatsApp, you should be aware that Meta processes that communication data.

If you would prefer not to use WhatsApp for our communication, email is available as an alternative — please let me know at the start of our work together and I’ll adapt accordingly.

10. International data transfers

Some of the third-party providers I use (Google, Meta, Stripe) may process your data outside the UK, including in the United States and the European Union. Where they do, they rely on legal safeguards such as UK adequacy decisions, the UK International Data Transfer Agreement, or the UK Extension to the EU-US Data Privacy Framework to ensure your data continues to be protected to UK standards.

11. How I keep your information secure

I take reasonable and appropriate steps to protect the personal information I hold. This includes:

  • Storing electronic information on secured, password-protected systems

  • Using reputable, GDPR-compliant service providers

  • Keeping physical records (where any exist) in secure locations

  • Limiting access to information to what’s necessary for the work

  • Reviewing my security practices regularly

No system is entirely risk-free. If a data breach ever occurred that put your rights at risk, I would notify you and the Information Commissioner’s Office in line with UK GDPR requirements.

12. Your rights

Under UK GDPR, you have a number of rights in relation to your personal information. These include:

  • The right of access — you can request a copy of the personal data I hold about you or your child.

  • The right of rectification — you can ask me to correct information that’s inaccurate or incomplete.

  • The right of erasure — you can ask me to delete your data (the “right to be forgotten”), subject to any legal retention obligations.

  • The right to restrict processing — you can ask me to pause processing while a request is being resolved.

  • The right to data portability — you can ask to receive your data in a structured, machine-readable format.

  • The right to object — to processing based on legitimate interests, or to direct marketing.

  • The right to withdraw consent — at any time, where consent is the lawful basis for processing.

To exercise any of these rights, please contact me using the details in section 1. I aim to respond to all requests within one calendar month. There is no charge unless a request is clearly excessive or repetitive, in which case I’ll explain any fee before proceeding.

13. How to raise a concern or make a complaint

If you’re unhappy with how I’ve handled your personal data, please raise it with me first. I want to know if something has gone wrong so I can put it right.

Complaining directly to me

You can raise a complaint by any of the following routes:

  • By email, using the address in section 1

  • By letter, sent to the address in section 1

  • Via my website contact form

I will acknowledge your complaint within 30 days and investigate it without undue delay. I will keep you informed about the progress and outcome. This is a legal right under section 164A of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025).

Complaining to the Information Commissioner’s Office

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at any time — you don’t need to raise the issue with me first, though I would appreciate the chance to try to resolve it directly.

The ICO can be contacted at:

  • Website: www.ico.org.uk

  • Helpline: 0303 123 1113

  • Postal address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

14. Cookies

This website uses cookies to help it function properly and, where you consent, to help me understand how visitors use the site. Full details of what cookies are used, why, and how you can manage your preferences are set out in my Cookie Policy, available on the website.

15. Changes to this policy

I review this Privacy Policy at least once a year to make sure it stays accurate and current. Where I make significant changes, I’ll update the “Last updated” date at the top of this policy and, where I hold your email address and you’ve opted in to communications, I’ll let you know by email.

16. How to contact me

If you have any questions about this Privacy Policy, or about how your personal information is handled, please get in touch:

Grace Hall, Peaceful Pathways Consultancy

24 Skylark Way, Barnham, Bognor Regis, PO22 0FA

grace@peacefulpathway.co.uk

ICO registration number: ICO:00014483496

Privacy Policy for Peaceful Pathways Consultancy. Compliant with UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), and the Privacy and Electronic Communications Regulations.