Privacy Policy

Francesca Donnelly Health Coaching

Website: http://www.francescadonnelly.com
Last updated: 7th September 2026

Who we are

This website is operated by Francesca Donnelly, trading as Francesca Donnelly Health Coaching (“we”, “us”, “our”), a sole trader providing health and wellbeing coaching and health and wellness copywriting services, based in the United Kingdom.

Francesca Donnelly is the Data Controller responsible for your personal data. You can contact us at:

Email: [email protected]

We are registered with the UK Information Commissioner’s Office (ICO) as a data controller. You can look up our registration on the ICO’s public register by business name.

This notice explains what personal data we collect, why, how we store and protect it, who we share it with, how long we keep it, and what rights you have. It applies to visitors to our website, prospective clients, coaching clients, and copywriting clients.

This notice is written to comply with the UK GDPR and Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), the EU GDPR, and the Swiss Federal Act on Data Protection (FADP), reflecting that clients or prospective clients may be based in the UK, the EU, or Switzerland.

Special category data: how we handle your health information

Because health coaching necessarily involves discussing your health, this website and our services process special category data (health data) about you. This is subject to extra protection under Article 9 of the UK/EU GDPR, and under the Swiss FADP, where it is defined as “sensitive personal data” (Article 5(c)) and requires your express consent to process (Article 6(6)–(7)).

We only process your health data:

  • with your explicit, separately given consent (never bundled into a general “I agree to the terms” checkbox), and
  • where necessary to defend our legal position, in the limited circumstances set out under Retention below.

You can withdraw your consent to health data processing at any time by contacting us at the email address above. Withdrawing consent does not affect the lawfulness of anything we did with your data before you withdrew it.

If you are a signed coaching client, a fuller, separately-consented health data processing clause and session transcription consent form is provided to you directly as part of your Coaching Agreement at intake. This website notice explains the general position; the Coaching Agreement provides the specific, personalised consent record for clients.

What we collect, how, and why

The consent-gated booking process described in Section 1 below applies specifically to health coaching enquiries, since these routinely involve health information. If you’re contacting us about health and wellness copywriting for your brand or business, this doesn’t involve special category data in the same way, and you’d typically reach us via the website contact form (Section 5) or by emailing us directly — both are covered below.

1. Free First Step Call booking (Google Form and Google Calendar)

Booking a Free First Step Call is a two-step process: a Google Form first, then Google Calendar to pick a time. This keeps things simple: we only ever collect your health-related information once you’ve actively agreed to it, separately and specifically.

The Form opens in a new tab from every “Book A Free First Step Call” link, with a link to this Privacy Notice at the top. It asks two mandatory, genuine multiple-choice questions — your consent to us processing health-related information, and your understanding that coaching is non-medical guidance, not treatment. Selecting “No” to either ends the form immediately, with no health information ever requested. Selecting “Yes” to both takes you to a short set of questions — your name, email, and health/wellbeing goals — plus one question about your AI transcription preference. The Form’s confirmation screen then links to our Google Calendar, where you simply confirm a date and time; it doesn’t repeat any health questions.

  • What’s collected: your consent and disclaimer selections; if you consent, your name, email, brief health/wellbeing goals, and your AI transcription preference; separately, your chosen appointment date and time.
  • Why: to establish valid, specific consent before processing any health information, to schedule your call, and to prepare appropriately for our conversation.
  • Legal basis: explicit consent (Article 9(2)(a)) for the health-related answers, given via a genuine, unbundled multiple-choice question before any such information is requested; contract/pre-contract steps (Article 6(1)(b)) for your name, email, and appointment details.
  • Where it’s stored: the form and its response data are held within our Google Workspace Business Standard account (see “Where your data is stored” below) — the same secured, business-only environment used for all other client data, not a personal account.

2. Coaching Agreement and health intake at the start of coaching

If you decide to become a client, you complete a Client Health Profile Intake Form, sent and returned via email, and sign a Coaching Agreement which contains its own, separately-consented sections for health data processing and session recording/transcription. This is more detailed than the Free First Step Call questions, because it directly shapes your coaching programme.

  • What’s collected: fuller health history, lifestyle information, and coaching goals.
  • Why: to design and deliver your coaching programme safely and appropriately.
  • Legal basis: explicit consent (Article 9(2)(a)), given specifically and separately within the Coaching Agreement, plus contract (Article 6(1)(b)) for the coaching service itself.
  • Where it’s stored: securely within Google Workspace (Google Drive), in your individual client file.

3. Coaching sessions (Google Meet, transcription, and AI-generated summaries)

Coaching sessions take place over Google Meet. Your explicit, separately given consent for session transcription is captured in advance, as part of your Coaching Agreement and intake consent form — if you have not given this consent, transcription is never activated for your sessions. Sessions are transcribed using Google Meet’s native transcription feature, and Gemini AI (operating under our Google Workspace Business Standard account) is used to generate a written summary of the session.

  • What’s collected: a full written transcript of the session and an AI-generated summary.
  • Why: to allow us to be more present during your session rather than writing everything down, and to keep an accurate, thorough record for continuity of your coaching.
  • Legal basis: explicit consent (Article 9(2)(a)).
  • How this data flows: the raw transcript is reviewed and then permanently deleted within 3 months of the session. Only the distilled written summary is kept, and it is retained in your client file for 7 years (see “How long we keep your data” below).
  • AI training safeguard: our Google Workspace configuration contractually prohibits Google from using any transcript, summary, or prompt to train public AI models, and blocks human review of this content. This is secured through our Data Processing Addendum (DPA) with Google.

Session notes, coaching tools, and post-session emails

Whether or not you consent to transcription, we make our own written notes during and after each session. These may include the goal you have set, where things stand now, the options we explore together, the action you decide to take and how we will follow up on it, along with observations from our conversation and points for me to follow up before your next session.

Where we complete a coaching tool or exercise together during a session, the completed tool, along with any notes added to it, is stored in your client file in the same way.

After each session we will normally send you a short email confirming the goal you have set for the period until we next meet, and the date and time of your next appointment. Where we have completed a coaching tool, we will offer to email you a copy. Anything we email you is sent to the address you have given us; once it arrives it sits in your inbox and is outside our control. Please tell us if you would prefer not to receive material containing health information by email, and we will agree another way of sharing it.

  • What’s collected: written session notes and completed coaching tools, which contain health information.
  • Why: to deliver your coaching, track your progress, and keep an accurate professional record.
  • Legal basis: explicit consent (Article 9(2)(a)) for the health information itself; contract (Article 6(1)(b)) generally.
  • Retention: kept in your client file for 7 years (see “How long we keep your data” below).

4. Contact between sessions (WhatsApp, email)

Between sessions, we may correspond with existing clients over WhatsApp (text messages only — we do not use WhatsApp for calls, and chat backup to any cloud service is switched off) and email (Google Workspace).

  • What’s collected: message content, which may include health-related updates.
  • Why: to support you between sessions.
  • Legal basis: explicit consent (Article 9(2)(a)) where health information is discussed; contract (Article 6(1)(b)) generally.
  • Retention: WhatsApp is used as a communication channel, not a permanent record. Anything relevant to your coaching is briefly logged in your client file (the same way a phone call would be noted), and the WhatsApp conversation thread itself is deleted within 3 months of your coaching relationship ending. If you contact us via WhatsApp before becoming a client, we delete that conversation after 3 months of no further contact.

5. Website contact form and direct email enquiries

Our website’s contact form, provided by Jetpack, allows visitors to send us a message. Submissions are stored in the WordPress dashboard as well as sent to us by email. This is also the main route for health and wellness copywriting enquiries, alongside emailing us directly at the address given in “Who we are” above — both are treated the same way.

  • What’s collected: name, email, and whatever message content you choose to include.
  • Why: to respond to your enquiry.
  • Legal basis: legitimate interest in responding to enquiries directed at us (Article 6(1)(f)), or contract/pre-contract steps where relevant.
  • Where it’s stored: WordPress.com (Automattic, US) for contact form submissions; our email inbox (Google Workspace) for both contact form notifications and any direct emails.

6. Newsletter sign-up (footer and exit-intent popup)

If you sign up to our newsletter, we collect your email address via MailerLite, an EU-based (Lithuania) email marketing platform. Sign-up uses double opt-in — you must confirm your subscription before you’re added to our list.

  • What’s collected: your name, email address, and your subscription/consent status.
  • Why: to send you our newsletter and updates.
  • Legal basis: consent (Article 6(1)(a)).
  • Your control: you can unsubscribe at any time using the link in every email.

7. Social media (Instagram and LinkedIn)

We maintain a presence on Instagram and LinkedIn. We use direct messages on these platforms only to direct people to book a Free First Step Call or to visit our website — never to discuss or collect health information.

If you send us health-related information through a social media direct message without us having asked for it, we will not continue that conversation on the platform. We will not retain or act on the content of that message beyond replying to redirect you to book a call or to email us through a secure channel. If you go on to become a client, only a brief, necessary note (not the original message) is carried into your proper client file.

Please be aware that Instagram (Meta) and LinkedIn are separately responsible, as controllers in their own right, for how they handle any message you send through their platforms — this notice only covers what we do with that information once received.

8. Testimonials

We display testimonials from past clients on our website. We only publish a testimonial where the client has given specific, written consent to that testimonial being published, including where it references any aspect of their health journey. We follow this same consent process for every testimonial we publish, including any collected in future.

9. Cookies and website analytics

See “Cookies” section below.

10. Payment

We do not collect or store any client card or bank details. Payment for coaching packages is made by direct bank transfer to our business account (via Wise, a UK-regulated payments provider) — we do not process or retain any client banking information as part of this.

Where your data is stored, and who processes it

We use a small number of specific, named service providers (“processors”) to run our business. We do not sell, rent, or share your personal data for marketing purposes with any third party. The table below sets out every processor that may handle your personal data, and why.

ProcessorWhat it processesWhere it’s basedTransfer safeguard
Google Workspace (Business Standard) — including Google Forms, Google Calendar, Google Meet, Gemini AI, Google Drive, GmailConsent and intake data (Free First Step Call booking form), booking and appointment data, session transcripts and AI summaries, client files, email correspondenceUS-headquartered (Google LLC); UK/EU data flowsGoogle’s Data Processing Addendum (DPA) and Standard Contractual Clauses (SCCs), accepted on our account
WordPress.com (Automattic, Inc.)Website hosting, contact form submissions, site backups (via native WordPress.com real-time backups)US-headquarteredAutomattic’s Data Processing Addendum and SCCs
MailerLiteNewsletter sign-up, email address, subscription statusLithuania (EU)N/A — data remains within the EU
ComplianzRecords of cookie consent choices made by website visitorsProvided via WordPress.com plugin infrastructureConsent-log data only; see Cookies section
WhatsApp (Meta)Text messages exchanged with clients and prospective clientsIreland/US (Meta Platforms)Meta’s standard data transfer safeguards for WhatsApp Business

Disclosure required by law: We may share your personal data, including health information where necessary, if required to do so by law, to comply with a court order or other legal process, or where lawfully requested by a regulatory or law enforcement body (such as the ICO). In the rare event of a genuine, serious risk to someone’s safety or life, we may also share relevant information with an emergency service or other appropriate authority. Where this involves health data, we rely on Article 9(2)(c) (protecting someone’s vital interests) or Article 9(2)(g) (substantial public interest) of the UK/EU GDPR, alongside our general legal obligation under Article 6(1)(c).

Canva is used only for designing marketing and website graphics, and no personal or client data is ever entered into it — it is not listed above as it does not process personal data on our behalf.

International transfers

Some of our processors (Google Workspace, WordPress.com) are US-headquartered companies, meaning your personal data may be transferred to and processed in the United States as part of their infrastructure. Where this happens, we rely on the UK International Data Transfer Addendum / Standard Contractual Clauses and, where applicable, the equivalent EU Standard Contractual Clauses, which these providers have in place, as the legal transfer mechanism. This means your data continues to receive a level of protection equivalent to that required under UK GDPR, EU GDPR, and Swiss FADP, regardless of where it is processed.

We do not otherwise transfer your data outside the UK, EU, or Switzerland.

How long we keep your data

We only keep personal data for as long as necessary, and no longer.

DataRetention periodLegal basis for the period
Coaching client records (Coaching Agreement, intake forms, session notes, completed coaching tools, session summaries)7 years from the end of your coaching relationshipRequired under our professional indemnity insurance (Westminster Global), aligned with the UK’s 6-year limitation period for legal claims plus a buffer; justified under the “establishment, exercise or defence of legal claims” exception (Article 9(2)(f) / Article 17(3)(e))
Raw session transcriptsDeleted within 3 months of the sessionData minimisation — only the distilled summary is needed long-term
Free First Step Call intake data (name, email, health/wellbeing goals), where you do not go on to become a client7 yearsAlthough no contract exists, a prospective client could still bring a claim relating to advice given during the call; this retention is justified under Article 9(2)(f) (defence of legal claims), combined with the explicit consent you give at the point of booking, per our professional indemnity insurance requirements
Records of a declined consent (Free First Step Call booking form)Not applicable — no health information is collected in this caseIf you decline consent or the scope-of-practice disclaimer on the booking form, only the fact of that decision is recorded; this is not special category data and carries no separate retention obligation beyond normal record-keeping
WhatsApp message threadsDeleted within 3 months of your coaching relationship ending (or 3 months of no further contact, if you never became a client)Data minimisation — relevant content is logged in your client file instead
Newsletter subscriber data (MailerLite)Until you unsubscribeConsent-based; you may withdraw at any time
Website contact form submissionsDeleted once your enquiry is resolved, unless you go on to become a clientData minimisation

We periodically review data that has passed its retention period to ensure it is properly deleted rather than retained indefinitely by default.

Cookies

We use a small number of cookies, and manage them using Complianz, a cookie consent tool that shows a consent banner to every visitor and technically blocks non-essential cookies until you make a choice.

Necessary/Functional cookies: these keep the website working correctly, including remembering the cookie choice you make. They don’t track you and can’t be switched off.

Statistics cookies: we use Google Analytics to understand how visitors use our website — for example, which pages are most helpful, and how people move through the site. Google Analytics only runs after you actively consent via the banner; if you decline or don’t respond, it does not load, and your visit is not tracked. No personal or health information is ever collected through Google Analytics.

We do not use any advertising, retargeting, or marketing cookies — no Meta Pixel, no Google Ads remarketing, no LinkedIn Insight Tag, and no equivalent tools. There is no “Marketing” cookie category on this site because nothing of that kind is present.

Fonts: the typefaces used on this website are served either directly from our own server or via WordPress.com’s own delivery infrastructure. No connection is made to Google’s font servers, and no visitor data is shared with Google as a result of font loading.

Third-party embeds: our newsletter sign-up popup is provided by MailerLite, our email marketing platform (see “What we collect” above). This is the only embedded third-party content on the site; we do not use embedded social media feeds, maps, or video players elsewhere.

You can change your cookie preferences at any time using the cookie preferences icon on the site, or by clearing your browser’s cookies for this website.

Your rights

Under UK GDPR, EU GDPR, and the Swiss FADP, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Erasure (“right to be forgotten”), subject to our legal retention obligations described above
  • Restrict how we process your data in certain circumstances
  • Object to processing based on legitimate interests
  • Data portability, where processing is based on consent or contract and carried out by automated means
  • Withdraw consent at any time, where processing is based on consent (this will not affect processing carried out before withdrawal)

To exercise any of these rights, contact us at [email protected].  We will respond to your request within one month of receipt, in line with our obligations under Article 12(3) of the UK/EU GDPR. In some cases, this period may be extended by a further two months where a request is particularly complex — if so, we’ll let you know within the first month and explain why.

Complaints

If you have any concern about how we have handled your personal data, please contact us directly first, at [email protected], so we can try to resolve it. We will acknowledge your complaint within 30 days and work with you to address it as quickly as possible.

If you remain unsatisfied with our response, you have the right to lodge a complaint with:

  • The UK Information Commissioner’s Office (ICO)ico.org.uk or 0303 123 1113, if you are based in the UK; or
  • Your local EU data protection supervisory authority, if you are based in the EU; or
  • The Swiss Federal Data Protection and Information Commissioner (FDPIC)edoeb.admin.ch, if you are based in Switzerland.

Changes to this notice

We keep this privacy notice under regular review and will update it as our business, tools, or the law change. This notice was last reviewed on the date shown at the top of this page.