Privacy Policy
Last updated: 3/7/2026
Your privacy matters a lot to me. This policy explains what personal information I collect, why I collect it, how it is used, and the choices you have about your information.
As a clinical herbalist, I sometimes collect sensitive health information to provide safe and appropriate care. I only collect information that is relevant to the services I provide and I treat it with appropriate care and confidentiality.
If you have any questions about this policy or how your information is handled, please contact:
Email: cora.inkster@pm.me
Website: corainkster.co.uk
Address: [pending]
Who I am
Cora Inkster Herbal is the data controller for the personal information collected through this website and during consultations.
I am a sole trader based in Scotland and a qualified clinical herbalist. I am a member of the National Institute of Medical Herbalists (NIMH) and hold appropriate professional indemnity and liability insurance.
ICO registration number: [pending]
Information I collect
The information I collect depends on whether you are making an enquiry, booking a consultation, or purchasing products.
Information you provide
You may choose to provide information including:
Name
Pronouns
Email address
Telephone number
Postal address
Date of birth
GP or primary healthcare provider details
Health concerns
Medical history
Current and previous medications or supplements
Pregnancy or breastfeeding status
Allergies
Other information you choose to share
Any correspondence you send to me
Most questions on the consultation intake form are optional. Providing additional information helps me make safe and appropriate recommendations but is not required unless it is essential for your care.
Consultation records
If you become a client, I will create clinical notes relating to your consultations and recommendations.
These notes may include information about:
Symptoms
Medical history
Lifestyle factors
Herbal recommendations
Follow-up observations
Clinical reasoning
Communications relating to your care
Orders and payments
If you purchase products or herbal prescriptions, I may collect information necessary to:
Process payments
Prepare prescriptions
Deliver orders
Respond to customer enquiries
Payment card details are processed securely by third-party payment providers. I do not store your full payment card details.
Website information
When you visit the website, certain technical information may be collected automatically through cookies and similar technologies.
Please see the Cookie Policy for more information.
Why I collect your information
I collect personal information to:
Provide clinical herbal consultations
Make personalised herbal recommendations
Prepare bespoke herbal prescriptions
Process orders and payments
Deliver products
Respond to enquiries
Keep appropriate clinical records
Meet professional, ethical and legal obligations
Improve the website and services
Send newsletters where you have chosen to subscribe
Legal basis for processing
Under the UK GDPR, I rely on different legal bases depending on the information being processed.
These include:
Performance of a contract (such as providing consultations or fulfilling orders)
Compliance with legal obligations
Legitimate interests in operating and improving the business
Your consent, where required (for example, marketing communications)
Because consultation records may include health information, they are treated as special category personal data. This information is processed only where permitted under applicable data protection law, including for the provision of health care and the management of healthcare services.
Consent to treatment
Before an initial consultation, you will be asked to complete a consultation form and provide informed consent.
Following your consultation, I will usually provide recommendations by email. You are free to accept or decline these recommendations.
Recommendations are offered as professional clinical advice and do not oblige you to purchase herbal medicines or other products.
GP and healthcare provider information
You may choose whether to provide details of your GP or primary healthcare provider.
I will not routinely contact your GP.
If I believe communication with your healthcare provider would benefit your care, I will normally seek your permission before making contact.
In exceptional circumstances where there is a serious concern for your safety or the safety of others, I may contact an appropriate healthcare professional or authority without prior consent where required or permitted by law or professional obligations.
Sharing your information
I never sell your personal information.
Your information may be shared only where necessary with trusted service providers who help me operate my business.
These may include:
Squarespace (website hosting and online shop)
Acuity Scheduling (appointment booking)
Stripe and Squarespace Payments (payment processing)
Royal Mail or Parcelforce (delivery services)
Flodesk (email newsletters if you have subscribed)
These providers process information only as necessary to provide their services and are responsible for protecting the information they receive.
Your information may also be disclosed if required by law, court order, professional obligations, or to protect someone's vital interests.
International Transfers
Several service providers mentioned above (including Squarespace, Stripe, Acuity Scheduling, and Flodesk) operate globally and may transfer or store data outside the UK. Where personal data is transferred internationally, particularly to countries without an adequacy decision by the UK Information Commissioner's Office, I implement appropriate safeguards including:
Standard Contractual Clauses approved by the UK ICO
Careful review of provider privacy policies and sub-processor agreements
Preference for providers offering UK/EU data residency options where available
These measures ensure your personal information receives consistent protection regardless of where it is processed.
Clinical records
Clinical records are kept separately from identifying information wherever reasonably practicable.
Consultation records are recorded using patient reference codes rather than names.
Identifying information is stored separately using an end-to-end encrypted service.
Clinical records are retained for approximately 7 years after your last consultation unless a longer retention period is required by law, insurance requirements, or professional obligations.
After this period, identifying information is completely removed. Anonymised clinical information may be retained for educational, research or practice development purposes.
Keeping your information secure
I take appropriate technical and organisational measures to protect your personal information from unauthorised access, loss, misuse or disclosure. These include:
Encrypted storage for files containing identifiable client information
End-to-end encrypted communication channels for sharing clinical recommendations by email
Strong password management using a dedicated password manager with unique credentials for all accounts
Two-factor authentication enabled on all applicable services
Automatic screen locking on devices accessing client information
Restricted physical access to papers and devices at my premises
Regular software updates and antivirus protection on all devices
Secure backup procedures with encrypted copies maintained separately
Session timeout settings on booking and practice management systems
Although every reasonable effort is made to protect your information, no method of electronic storage or transmission can be guaranteed to be completely secure.
Data Breach Notification
In the unlikely event of a personal data breach affecting your information (such as unauthorised access, accidental loss, or unauthorised disclosure) I will take steps to mitigate any potential harm.
If the breach is likely to result in a high risk to your rights and freedoms, I will notify you directly without undue delay.
Your notification will include:
A description of the nature of the breach
The categories of personal information concerned
Likely consequences of the breach
Measures taken or proposed to address the breach and mitigate adverse effects
I am also legally required to report certain types of data breaches to the Information Commissioner's Office within 72 hours of becoming aware of them.
Marketing
If you subscribe to the newsletter, your email address will be processed through Flodesk.
You will only receive marketing emails if you have chosen to opt in.
You can unsubscribe at any time using the link included in every email or by contacting me directly.
Cookies
This website uses cookies to operate properly and, where you choose to allow them, to improve your browsing experience.
Further information is available in the Cookie Policy.
Children's privacy
Consultations are generally intended for adults aged 18 and over.
Children may attend consultations when accompanied by a parent, legal guardian or other appropriate adult who is responsible for providing consent where required.
Information relating to child clients is handled with the same level of confidentiality and care as adult records.
Your rights
Under UK GDPR and relevant Scottish healthcare regulations, you have the following rights regarding your personal and health information:
Depending on the circumstances, you have the right to:
Request access to your personal information.
Request correction of inaccurate information.
Request deletion of information where applicable.
Request restriction of processing.
Object to certain types of processing.
Withdraw consent where processing is based on consent.
Request a copy of your information in a portable format where applicable.
Important Note on Retention Periods: As a registered member of the National Institute of Medical Herbalists, I am bound by professional standards requiring retention of clinical records for a minimum period (generally seven years after last consultation for adult patients, longer for minors until age 25–28). During this period, requests for full deletion cannot be accommodated for documentation that forms part of your clinical care record. Identifiable information will be removed once anonymisation is possible while still meeting retention obligations.
If you are located outside the UK, additional rights under your local data protection legislation may also apply. Please contact me to discuss how these interact with my practice obligations.
Complaints
To exercise these rights, email cora.inkster@pm.me with ‘Access Request' in the subject line. I will respond within one month as required by UK GDPR.
You also have the right to make a complaint to the Information Commissioner's Office (ICO) if you feel your data protection rights have been infringed.
The ICO complaints page can be found at:
https://ico.org.uk/make-a-complaint/
Changes to this policy
This Privacy Policy may be updated from time to time to reflect changes in legal requirements, technology or the way the practice operates.
The latest version will always be published on this website with the revision date shown at the top of the page.