Orchard Sauna Privacy Policy

Last updated: 12/20/2025

This Privacy Policy explains how Orchard Sauna collects and uses your personal data.
It also explains your rights under the GDPR and Irish data protection law.

By using our website or booking a session, you agree to this policy.


1. Who we are

Orchard Sauna
Castleblaney, Co. Monaghan, Ireland

Email: [your contact email]
Phone: [your phone number, if any]

For data protection law, Orchard Sauna is the “data controller” for the personal data we collect about you.


2. What this policy covers

This policy applies when you:

It does not cover third-party websites or services we link to (for example, booking or payment providers). They have their own privacy policies.


3. What personal data we collect

We only collect what we need to run the business and provide our services.

We may collect:

Identity and contact details

Booking and purchase information

Payment information

Health information (special category data)

We only ask for this when it is relevant to your safe use of the sauna and ice bath.

Communication and feedback

Website and technical data

This may be collected through cookies or similar tools, depending on how the site is set up.


4. How we collect your data

We collect personal data:


5. Why we use your data and legal bases

Under GDPR we must have a legal reason (“legal basis”) to use your data.
We use your data for the following purposes:

To manage bookings and provide our services

Legal basis:

To keep you and others safe

Legal basis:

You can withdraw this consent at any time (see Section 11).
If you do, it may affect how or whether you can safely use our services.

To communicate with you

Legal basis:

Direct marketing (if we ever send it)

Legal basis:

You can unsubscribe at any time by using the link in the email or contacting us.

To run and improve our website

Legal basis:

To meet legal and tax obligations

Legal basis:


6. Special category data (health information)

Health information is “special category” data under GDPR.
We only process it when:

You can ask us not to record health details; however, this may mean we cannot provide some or all services if we believe it would be unsafe.

We do not use your health data for marketing.


7. Cookies and website tracking

Our website may use cookies or similar technologies to:

If we use non-essential or analytics cookies, we will:

You can change your browser settings to block cookies, but some parts of the site may not work properly if you do.


8. Who we share your data with

We do not sell your personal data.

We may share your data with trusted third parties who help us run the business, such as:

These third parties act as data processors in most cases and can only use your data as instructed by us. We have agreements in place with them where required by law.


9. International transfers

Some of our service providers may be based outside the European Economic Area (EEA), for example large online booking, payment or email services.

If your personal data is transferred outside the EEA, we will ensure that:

You can contact us if you want more information about international transfers and safeguards.


10. How long we keep your data

We keep personal data only for as long as needed for the purposes described in this policy, and to meet legal and tax requirements.

As a guide:

We may keep anonymised information (which no longer identifies you) for statistics or planning.


11. Your data protection rights

Under GDPR, you have several rights about your personal data.

You can:

  1. Access your data
    Ask us for a copy of the personal data we hold about you.
  2. Rectify your data
    Ask us to correct inaccurate or incomplete data.
  3. Erase your data (“right to be forgotten”)
    Ask us to delete your data where we no longer need it, you withdraw consent, or you successfully object to processing.
    We may not be able to delete data we must keep for legal reasons.
  4. Restrict processing
    Ask us to limit how we use your data in certain situations (for example, while we check its accuracy).
  5. Data portability
    Ask us to give you certain data in a structured, commonly used format, or transfer it to another provider, where the processing is based on consent or contract and done by automated means.
  6. Object to processing
    Object to processing based on our legitimate interests, including profiling, and we will stop unless we have strong lawful reasons to continue.
    You can always object to direct marketing.
  7. Withdraw consent
    Where we rely on consent (for example, health information and marketing), you can withdraw it at any time.
    This does not affect past processing already carried out, but it may affect how we provide services going forward.

To exercise any of these rights, contact us at:
Email: [your contact email]
We may need to verify your identity before we act on your request.


12. Complaints

If you are unhappy with how we use your personal data, please contact us first.
We will try to resolve the issue.

You also have the right to make a complaint to the Data Protection Commission (DPC) in Ireland.

Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland

Website: dataprotection.ie Homepage | Data Protection Commission+1


13. Security

We take appropriate technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, disclosure, alteration and destruction.

No system is 100% secure. But we aim to keep access to your data limited to people who need it and to reduce risk as far as reasonably possible.


14. Changes to this policy

We may update this Privacy Policy from time to time.
The latest version will always be on our website with the “last updated” date at the top.

If we make major changes, we may also notify you by email or through the website.