Privacy Policy (UK)

This privacy notice was last updated the 6th of August 2025 and applies to citizens and legal permanent residents of the United Kingdom, European Economic Area and Switzerland.

The Phoenix Foundry (A subsidiary of Herdwick & Goose Limited) 

Registered Company Address: 31 Dashwood Avenue, High Wycombe, Buckinghamshire, HP12 3DZ.

For the purpose of this document “us or we” is used to refer to The Phoenix Foundry. 

In this privacy notice, we explain what we do with the data we obtain about you via your transactions with The Phoenix Foundry (owned by Herdwick & Goose Limited). 

We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy policy.
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes.
  • we first request your explicit consent to process your personal data in cases requiring your consent via our case history process. 
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf.
  • we respect your right to access your personal data or have it corrected or deleted, at your request, as long as it remains in line with our own legal requirements. 

If you have any questions or want to know exactly what data we keep of you, please contact us via contact@thephoenixfoundry.com

Owner and Data Controller

The Phoenix Foundry 

(A subsidiary of Herdwick & Goose Limited)

Owner: Herdwick & Goose Limited 

Director of The Phoenix Foundry: Eleanor Andrews

Website: https://thephoenixfoundry.com

Email: contact@thephoenixfoundry.com

Phone number: +44 (0) 7737608038

Name of Data Controller: Wil Ames

Data controller emailherdwickandgoose@outlook.com

Types of data collected

Among the types of personal data that Herdwick & Goose Limited (or The Phoenix Foundry) collects, by itself or through third parties, there are: email address; first name; last name; date of birth (if under 18); payment info; billing address; various types of data; and website trackers. Complete details on each type of personal data collected are provided in the dedicated sections of this privacy notice or by specific explanation texts displayed prior to the data collection.


Personal data may be freely provided by the user, or, in case of usage data, collected automatically when using The Phoenix Foundry website or that of any of its third-party providers, such as a booking or payment system. Unless specified otherwise, all data requested by us is mandatory and failure to provide this data may make it impossible for us to provide our services. In cases where The Phoenix Foundry specifically states that some data is not mandatory, users are free not to communicate this data without consequences to the availability or the functioning of our service.

Users who are uncertain about which personal data is mandatory are welcome to contact the owner.
Any use of cookies – or of other tracking tools — by Herdwick & Goose Limited (or The Phoenix Foundry) or by the owners of third-party services used by Herdwick & Goose Limited (or the Phoenix Foundry) serves the purpose of providing the service required by the user, in addition to any other purposes described in the present document and in the Cookie Policy found on The Phoenix Foundry website. 

Users are responsible for any third-party personal data obtained, published or shared through The Phoenix Foundry and must review all third-party privacy notices with care. 

Mode and place of processing the Data

Methods of processing

The owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the data.
The data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the owner, in some cases, the data may be accessible to certain types of persons in charge, involved with the operation of The Phoenix Foundry (administration, accounts management etc.) or external parties (such as third-party technical service providers, mail carriers, hosting providers, financial processors, communications systems) appointed, if necessary, as data processors by the owner. The updated list of these parties may be requested from the owner at any time.

Place

Data is processed at the owner’s operating offices and in any other places where the parties involved in the processing are located.

Depending on the user’s location, data transfers may involve transferring the user’s data to a country other than their own, where a third-party provider is based outside the UK. To find out more about the place of processing of such transferred data, users can check the section containing details about the processing of personal data.

Retention time

Unless specified otherwise in this document, personal data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the users’ consent.

The purposes of processing

The data concerning the user is collected to allow the owner to provide its service, comply with legal obligations, respond to enforcement requests, protect its rights and interests (or those of its users or third parties), detect any malicious or fraudulent activity, as well as the following: contacting the user, handling payments, registration and authentication required directly by our third-party providers. Handling finance and accounting, user database management, interaction with data collection platforms and other third parties, Spam and bot protection, handling activities related to productivity and direct communications. 

For specific information about the personal data used for each purpose, the user may refer to the section “Detailed information on the processing of Personal Data”.

Detailed information on the processing of Personal Data

Personal Data is collected for the following purposes and using the following services:

Marketing communications

This type of service allows user data to be utilized for communication purposes. These communications are displayed in the form of emails and other marketing by The Phoenix Foundry, possibly based on user interests. This does not mean that all personal data is used for this purpose, just that which is necessary to communicate with the user. Information and conditions of use are shown below. Some of the services listed below may use trackers to identify ssers or they may use the behavioural retargeting technique, i.e. displaying ads tailored to the User’s interests and behaviour, including those detected outside The Phoenix Foundry. For more information, please check the privacy policies of the relevant third-party service. Services of this kind usually allow users to opt out of such tracking, so this is the responsibility of the user at the time of use. Users may learn how to opt out of interest-based advertising more generally by visiting the relevant opt-out section on each third-party website.

Handling activities related to productivity

This type of service helps the owner to manage tasks, collaboration and, in general, activities related to productivity. In using this type of service, data of users will be processed and may be retained, depending on the purpose of the activity in question. These services may be integrated with a range of third-party services disclosed within this privacy policy to enable the owner to import or export data needed for the relative activity.

Cliniko

Cliniko is a clinic management software that we use to support note taking, diary management and online bookings. Cliniko is based in Melbourne, Australia. Through their service, technical and usage data is collected for the proper functioning of the site, for clinical administration (such as case history taking) and to offer patients the ability to book online. Cliniko is designed to be HIPAA compliant for healthcare organizations, especially for those needing to protect Protected Health Information (PHI)

Personal data processed: Usage data; first name, last name, email address, IP address; device information is held. Alongside clinical and medical data that is relevant to their case and financial data in terms of logging the methods used to pay. Not financial information such as bank account details. 

Legal basis: Data processing is based on legitimate interest as necessary for the medical services we provide; management and maintenance of their website and any data required to book appointments. 
Personal data is deleted once the purpose of the processing has been achieved, unless legal retention obligations apply. 

Place of processing: 

Access to Cliniko’s privacy policy
No data is transferred to third countries.

Handling payments

Unless otherwise specified, Herdwick & Goose Limited processes any payments by credit card, bank transfer or other means via external payment service providers. In general, and unless where otherwise stated, users are requested to provide their payment details and personal information directly to such payment service providers. Herdwick & Goose Limited isn’t involved in the collection and processing of any such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.

PayPal (PayPal Inc.)

PayPal is a payment service provided by PayPal Inc., which allows users to make online payments.

Personal Data processed: email address; first name; last name; payment info.

Legal basis for processing: Contract.

Place of processing: See the PayPal privacy policy – Privacy Policy.

National Westminster Bank plc

When users transfer money directly to our bank account, they will interact with National Westminster. 

National Westminster Bank Plc British banking and financial services company headquartered in Edinburgh, Scotland. 

Personal Data processed: email address; first name; last name; account data, payment info.

User data is kept for the legal basis of processing.

Place of processing: UK –  privacy policy

Direct registration for The Phoenix Foundry blog on WordPress.com

The user registers for our blog by filling out the request form on our WordPress website, they are providing personal data directly to Herdwick & Goose Limited (The Phoenix Foundry)

Personal data processed: email address; first name; last name.

Data is handled in the first instance by WordPress.com and then The Phoenix Foundry. 

WordPress.com collects information to improve its products, personalize user experience, and for marketing purposes, but users have the ability to opt-out of some data collection practices, according to WordPress.com Support. 

Access to WordPress.com’s privacy policy.

Calendly

Calendly: our booking system that also takes payment, via PayPal. 

Calendly is a cloud-based scheduling platform that simplifies appointment booking by allowing practitioners to share their availability and letting others book time slots directly, eliminating the need for back-and-forth emails.

Personal data processed directly: first name, last name, email address. Financial data is handled via PayPal. 

Access to Calendly’s privacy notice

Contacting the User

Mailing list or newsletter (The Phoenix Foundry)

By registering on the mailing list or for the newsletter, the user’s email address will be added to the contact list of those companies we use to provide email marketing. 

Personal Data processed: email address, first name, last name. 

Contact form (The Phoenix Foundry)

By filling in the contact form with their data, the user authorizes Herdwick & Goose Limited (The Phoenix Foundry) to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form. 

Personal Data processed: email address; first name; various types of Data as requested. 

Information on opting out of interest-based advertising

In addition to any opt-out feature provided by any of the services listed in this document, users may learn more on how to generally opt out of interest-based advertising within the dedicated section of the Cookie Policy (found on our website).

Further information about the processing of personal data

Selling goods and services online

The personal data collected are used to provide the user with services or to sell goods, including payment and possible delivery. The personal data collected to complete the payment will go through PayPal, as reported above. Herdwick & Goose Limited performs no direct financial transactions. 

Further Information for Users

Legal basis of processing

The owner may process personal data relating to users if one of the following applies:

  • Users have given their consent for one or more specific purposes.
  • provision of data is necessary for the performance of an agreement with the user and/or for any pre-contractual obligations thereof;
  • processing is necessary for compliance with a legal obligation to which the owner is subject;
  • processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the owner;
  • processing is necessary for the purposes of the legitimate interests pursued by the owner or by a third party.

In any case, the owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract between the patient (user) and the practitioner. 

Further information about retention time

Unless specified otherwise in this document, personal data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the users’ consent.

Therefore:

  • Personal data collected for purposes related to the performance of a contract between the owner and the sser shall be retained until such contract has been fully performed.
  • Personal data collected for the purposes of the owner’s legitimate interests shall be retained as long as needed to fulfil such purposes. users may find specific information regarding the legitimate interests pursued by the owner within the relevant sections of this document or by contacting the owner.

The owner may be allowed to retain personal data for a longer period whenever the user has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the owner may be obliged to retain personal aata for a longer period whenever required to fulfil a legal obligation or upon order of an authority, such as the General Osteopathic Council. 

Once the retention period expires, personal data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

The rights of users based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their data processed by the owner.

In particular, users have the right to do the following, to the extent permitted by law:

  • Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their personal data.
  • Object to processing of their data. Users have the right to object to the processing of their data if the processing is carried out on a legal basis other than consent.
  • Access their Data. Users have the right to learn if data is being processed by the owner, obtain disclosure regarding certain aspects of the processing and obtain a copy of the data undergoing processing.
  • Verify and seek rectification. Users have the right to verify the accuracy of their data and ask for it to be updated or corrected.
  • Restrict the processing of their Data. Users have the right to restrict the processing of their data. In this case, the owner will not process their data for any purpose other than storing it.
  • Have their Personal Data deleted or otherwise removed. Users have the right to obtain the erasure of their data from the owner if it is legal to do so.
  • Receive their data and have it transferred to another controller. Users have the right to receive their data in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
  • Lodge a complaint. Users have the right to bring a claim before a competent data protection authority.

Users must know that, should their personal data be processed for direct marketing purposes, they can object to that processing at any time, free of charge and without providing any justification. Where the user objects to processing for direct marketing purposes, the personal data will no longer be processed for such purposes. To learn whether the owner is processing personal data for direct marketing purposes, users may refer to the relevant sections of this document or email us on contact@thephoenixfoundry.com

How to exercise these rights

Any requests to exercise user rights can be directed to the owner by email via contact@thephoenixfoundry.com

or the contact details provided in this document. Such requests are free of charge and will be answered by the owner as early as possible and always within one month, providing users with the information required by law. Any rectification or erasure of personal data or restriction of processing will be communicated by the owner to the recipient unless this proves impossible or involves disproportionate effort. At the users’ request, the owner will inform them about those limitations. 

Additional information about Data collection and processing

Legal action

The user’s personal data may be used for legal purposes by the owner in Court or in the stages leading to possible legal action arising from improper use of our services or any related products.
The user declares to be aware that the owner may be required to reveal personal data upon request of public authorities. In the health care setting this may be related to safety of an adult or child. 

Additional information about User’s Personal Data

In addition to the information contained in this privacy policy, Herdwick & Goose Limited (The Phoenix Foundry) may provide the user with additional and contextual information concerning services or the collection and processing of personal data upon request.

Information not contained in this policy

More details concerning the collection or processing of Personal Data may be requested from the owner at any time. Please see the contact information at the beginning of this document.

Changes to this privacy policy

The owner reserves the right to make changes to this privacy policy at any time by notifying its users on this page and possibly by email as far as is technically and legally feasible – sending a notice to users via any contact information available to the owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed on the basis of the user’s consent, the owner shall collect new consent from the user, where required.

Complianz | The Privacy Suite for WordPress

Our website uses the Privacy Suite for WordPress from Complianz to collect records of consent. For this functionality your IP address is anonymized and stored in our database. For more information, see the Complianz Privacy Statement.

Really Simple SSL

Really Simple SSL and Really Simple SSL add-ons do not process any personal identifiable information, so the GDPR does not apply to these plugins or usage of these plugins on your website. You can find our privacy policy here.