Privacy & cookie policy
Last updated: June 2026
This policy explains how Oxy Haus HBOT (“we”, “us”) collects and uses your personal information, and how we use cookies on this website. We are committed to protecting your privacy in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are
Oxy Haus HBOT is a Hyperbaric Oxygen Therapy clinic based at Maldiva Clinic, 7 Clytha Buildings, Constance Street, Newport NP19 7DA. For any privacy questions, or to exercise your data rights, email us at [email protected].
We are the “data controller” for the personal information collected through this website.
2. What information we collect
When you contact us through the form on this site, we collect:
- Your name
- Your email address
- Your phone number (if you choose to provide it)
- The reason for your enquiry and the content of your message
We only ask for what we need to reply to you and arrange a session. Please do not include sensitive medical detail in the form — we can discuss that securely in person or by phone.
3. How we use your information & our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Responding to your enquiry and arranging a session | Consent, and our legitimate interest in responding to enquiries |
| Keeping a record of correspondence | Legitimate interest in running our clinic |
| Understanding how the website is used (analytics) | Consent — only if you accept analytics cookies |
We do not sell your data, and we do not use it for unrelated marketing without your consent.
4. How your form data is processed
When you submit our contact form, your message is delivered to our email inbox using Resend (our email-sending provider) and is then handled by our email provider (Microsoft Outlook). These providers process your data on our behalf as “data processors”.
5. Cookies
A cookie is a small file stored on your device. We keep cookies to a minimum and use a consent banner so analytics cookies are only set if you choose “Accept all”. You can change your choice at any time using the link in the footer.
Essential storage (always on)
| Name | Purpose | Duration |
|---|---|---|
| oxyhaus-consent-v1 | Remembers your cookie choice so we don’t ask again on every visit. Stored in your browser’s local storage, not shared with anyone. | 6 months |
Analytics cookies (only with your consent)
If you accept, we use Google Analytics 4 to understand how visitors use the site (for example, which pages are popular) so we can improve it. IP addresses are anonymised. No analytics cookies are set, and Google Analytics is not loaded, unless and until you accept.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users | 2 years |
| _ga_* | Google Analytics | Maintains session state | 2 years |
You can read more in Google’s privacy policy. If you reject non-essential cookies, none of the above analytics cookies are set.
6. How long we keep your data
We keep enquiry correspondence only as long as needed to deal with your enquiry and for our own records, after which it is deleted. If you become a client, any clinical records are kept separately in line with healthcare record-keeping guidance.
7. Your rights
Under UK GDPR you have the right to:
- Be told how your data is used (this policy)
- Access a copy of the data we hold about you
- Have inaccurate data corrected
- Have your data erased (“right to be forgotten”)
- Restrict or object to processing
- Withdraw consent at any time
To exercise any of these, email [email protected]. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.
8. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when it last changed.
Please review and confirm the retention periods and add a registered business name / ICO registration number if applicable before launch. This template reflects UK GDPR & PECR good practice but is not a substitute for legal advice.