Scroll to top

Privacy Policy

Privacy Policy

The Secret Space is committed to complying with the General Data Protection Regulation and the Data Protection Act 2018. Looking after the personal information you share with us is very important, and we want you to be confident that your personal data is kept safely and securely and to understand how we use it to offer you a better and more personalised experience.We have published this notice to help you understand:– how and why The Secret Space collect information from you– who The Secret Space share your information with, why and on what basis– what your rights areIf we make changes to this notice we will update you on our website and by sending you an email notification. You will be deemed to have accepted the terms of the Privacy Policy on your first use of Our Site following the alterations. We recommend that you check this page regularly to keep up-to-date.This policy was last updated on the 25th of May, 2018.

Definitions and Interpretation

In this Policy, the following terms shall have the following meanings:

Our Locations include


The Secret Space Mind Body booking portal at

Constant Contact email marketing at

The Secret Space 105 Fore Street Hertford SG14 1AS

Our Site

Refers to


Means The Secret Space, Mind Body or Constant Contact  account required to access and/or use certain areas and features of Our Locations

Personal Data

Any and all data that relates to an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data that you give to us via any of our Locations.

We, Us ,Our

Means The Secret Space registered in England under Charity number 1167219 – Company Reg No 9161978 whose registered address is 105 Fore Street Hertford SG14 1AS.

When do we collect your personal data?

– When you create an account at any of Our Locations

– When you purchase a product at any of Our Locations

– When you book a service at any of Our Locations

– When you visit our centres to attend a class

– When you redeem a gift card at any of Our Locations

– When you engage with us on social media

– When you contact us by any means with queries, complaints or to send us your CV for a job application

– When you enter prize draws or competitions

– When you choose to complete any feedback requests or surveys we send you

What data do we collect and how do we use it?

Depending upon your use of Our Locations, We may collect some or all of the following personal and non-personal data

Data Protection says that we are allowed to collect and use your personal data only where we have a proper reason to do so. The law says we must have one or more of these reasons:

Contract – your personal information is processed in order to fulfill a contractual arrangement e.g. to place an order or book a class.

Consent – where you agree to us using your information in this way e.g. for storing your payment card details.

Legitimate Interests – this means the interests of The Secret Space in managing our business to allow us to provide you with the best products and service in the most secure and appropriate way

Legal Obligation – where there is statutory or other legal requirement to share the information e.g. when we have to share your information for law enforcement purposes.


What we store Our Reasons (Legal Basis) What we use the data for
Name, date of birth, email, telephone number, For your security, we’ll also keep an encrypted record of your login password. Fulfilling a contract We need this information as a minimum in order to process your orders and bookings
Email Consent Supplying you with email Marketing communications that you have opted into to keep you informed of special offers, promotions and new events
Email Legitimate Interests Notifying you about enhancements to our services, such as changes to pricing and schedules or new services
Contacting you to request feedback and undertake customer satisfaction surveys
Email Fulfilling a contract Sending you payment invoices by email
Date of Birth Legitimate interest For health and safety reasons under 14s cannot practice yoga, (unless in a child specific class), Between the ages of 14 and 16 you can practice if accompanied by an adult
Your gender and how you heard about The Secret Space Legitimate interest Personalising and tailoring your experience with The Secret Space. Developing products and services that attract and retain customers. Improving customer interaction with our sites
If you purchase one of our services or make a booking: your purchased / booked services, receipts Fulfilling a contract We also use information about services bought and volumes, to help us with planning, demand forecasting, management of information and research
Time and date of your check-ins for any bookings
Legitimate interest To help us with planning and handling our customer contact efficiently and effectively
Details of your interactions with us through, Our Locations. For example, we collect notes from our conversations with you, details of any complaints or comments you make, and how and when you contact us. Legitimate interest Keeping our records up to date, handling our customer contact efficiently and effectively
Health information and emergency contact Legitimate interest To enable us to assess your suitability for the services and safeguard your health
Details of your visits to our websites including IP address, web browser and version, operating system, and which website referred you to ours. Legitimate interest Improving customer experience and interaction with our sites.

Third party services and how we share your data

We The Secret Space contract with third parties to supply products and services to you on our behalf. In some cases, the third parties may require access to some or all of your data. Where any of your data is required for such a purpose, we will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights, our obligations, and the obligations of the third party under the law. In certain circumstances, we may be legally required to share certain data held by us, which may include your personal data, for example, where we are involved in legal proceedings, where we are complying with legal requirements, a court order, or a governmental authority.

We use the following third party data processors who are based outside the EU, but who are protected by the Privacy Shield, which allows them to store EU data on US soil with the GDPR.

MINDBODY Online, California USA – we use Mind Body online for web scheduling, registration, order processing and online payments. Details of MINDBODY’s compliance with GDPR and EU regulations can be viewed here.

Constant Contact – we use Constant Contact to email newsletters to keep you informed of upcoming events and special promotions. Details of their compliance to GDPR and EU regulations can be viewed here.

Google, California USA – We may compile statistics about the use of Our Locations using Google Analytics including data on traffic, usage patterns, user numbers, sales, and other information. All such data will be anonymised and will not include any personally identifying data, or any anonymised data that can be combined with other data and used to identify you. We may from time to time share such data with third parties such as prospective investors, affiliates, partners, and advertisers. Data will only be shared and used within the bounds of the law.

Where do we store your data?

Your data will be stored in the UK and any third party data storage is protected via The Privacy Shield which allows MINDBODY Online and Constant Contact to store EU data on US soil with the GDPR.

How long we keep your information

If we collect your personal information, the length of time we retain it is determined by a number of factors including the purpose for which we use that information and our obligations under other laws.

We may need your personal information to establish, bring or defend legal claims. For this purpose, we will always retain your personal information for 7 years after the date it is no longer needed by us for any of the purposes listed under ‘What data do we collect and how do we use it’.

– the law requires us to hold your personal information for a longer period, or delete it sooner;

– you exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law;

– we bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible; or

– in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.

Your rights

You have the following rights under the GDPR, which this Policy and Our use of personal data have been designed to uphold:

Your right to access – You have the right to request information about the personal data we hold on you at any time.

Your right to portability – Whenever we process your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Your right to rectification – You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed. If you have a Secret Space or Mind Body account you can edit your personal data under your account and membership pages.

Your right to erasure – You have the right to erase any personal data processed by Us at any time except for the following situations:

– you have an ongoing matter with Customer Service

– you have an unsettled debt with Us, regardless of the payment method

– if you are suspected or have misused our services within the last four years

– your debt has been sold to a third party within the last three years or one year for deceased customers

– if you have made any purchase, we will keep your personal data in connection to your transaction for book-keeping purposes

– we bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible

– in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.

Your right to object to processing based on legitimate interest

You have the right to object to processing of your personal data that is based on Our legitimate interest. We will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.

If you have any cause for complaint about Our use of your personal data, please contact Us at in the first instance in order that we can investigate thoroughly. Should you find the response unsatisfactory, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office, by calling 0303 123 1113.

For further information about your rights, please contact the Information Commissioner’s Office or your local Citizens Advice Bureau.

Our use of cookies

Cookies are small encrypted text files that are stored on your device by a website. We use cookies to enhance your shopping experience and to analyse our traffic. We don’t store personal information in the cookies we create, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

By continuing to browse our site, you consent to our placing cookies on your computer (unless you have chosen to disable them via your browser). Certain features of Our Site depend on Cookies to function. Cookie Law deems these Cookies to be “strictly necessary”. Your consent will not be sought to place these Cookies. You may still block these Cookies by changing your internet browser’s settings but please be aware that Our Site may not work properly if you do so.

The following first party Cookies may be placed on your computer or device:

These cookies enable the function of Google Analytics. This software helps us collect and analyse visitor information such as browser usage, new visitor numbers, response to marketing activity and shopping times. That information helps us to improve the website and your shopping experience, and to make our marketing campaigns more relevant.

The data stored by these cookies can be seen only by the relevant teams at The Secret Space and Google and never shows any confidential information.

Name of Cookie Purpose Strictly Necessary
_ga is used to distinguish users and has an expiration of 2-years. No
_gid _gid is used to distinguish users and has an expiration of 24-hours. No
_gat _gat is used to throttle requests and has an expiration of 1-minutes. No

Third party Cookies may be placed on your computer or device by the following companies however these are not within our control:

– Social Sharing (Facebook, twitter and Google+) uses cookies to allow for customer engagement on social media platforms

– Doubleclick is used for placing adverts and marketing on third party websites

– Youtube is used to provide video social media and content

You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. If you’d like to learn more about cookies in general and how to manage them please visit

Information about the Secret Space

Our Locations are owned and operated by The Secret Space 105 Fore Street Hertford SG14 1AS. The Secret Space is a registered charity in England & Wales (1167219). Company Registration Number is 9161978. (England & Wales).

Should you have any questions about this policy please write to us at