Home / Privacy Policy
Privacy Policy
How we handle your personal information, including booking and payment data.
This Privacy Policy explains how Divino Comercio Ltd ("Divino", "we", "us") collects, uses and protects personal information collected through this website and in the course of providing our services. Divino Comercio Ltd is the data controller for the purposes of UK data protection law. We are registered in England & Wales, company number 15623775, with registered office at Regus, Oxford House, 12–20 Oxford Street, Newbury, Berkshire, RG14 1JB.
1. Information we collect
We collect only what we need to respond to you and provide our services:
- Enquiry details, your name, email address, organisation and the content of any message you send us.
- Booking details, the information you provide when scheduling a consultation, such as your name, email, time-zone and any notes about your enquiry.
- Payment information, when you pay for a session, payment is processed by our payment provider (Stripe). We receive confirmation of payment and limited transaction details; we do not receive or store your full card number.
- Technical data, limited information your browser sends when embedded scheduling or payment tools load (see our Cookie Policy).
2. How we use it
We use your information to respond to enquiries, arrange and deliver consultations and advisory services, take and reconcile payment, keep proper business and accounting records, and meet our legal obligations.
3. Lawful bases
We rely on the following lawful bases under UK GDPR: your consent (for example, when you contact us); performance of a contract (to deliver a session or engagement you have booked); and our legitimate interests in responding to enquiries and operating the practice. Where we process payment data, this is also necessary for the performance of our contract with you and to comply with legal and accounting obligations.
4. Sharing your information
We do not sell your information. We share it only with trusted service providers who help us operate the practice, acting on our instructions, including:
- Cal.com, our scheduling provider, used to manage bookings.
- Stripe, our payment provider, used to process session fees securely.
- Our email, hosting and professional advisers, where necessary.
We may also disclose information where we are required to do so by law. Some providers may process data outside the UK; where they do, appropriate safeguards (such as UK-approved transfer mechanisms) are in place.
5. Retention
We keep enquiry and client information only for as long as necessary for the purposes set out above, and to meet our legal, tax and accounting obligations. When information is no longer needed, we delete or anonymise it.
6. Your rights
Under UK data protection law you have the right to access the personal information we hold about you, to ask us to correct or erase it, to object to or restrict its use, and to data portability. To exercise any of these rights, email info@divinouk.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
7. Security
We take appropriate technical and organisational measures to protect your information. Payment is handled by Stripe, a PCI-DSS compliant provider, and card details are never stored on our systems.
8. Changes to this policy
We may update this policy from time to time. The current version is always published on this page, with the date it was last updated shown above.