Effective Date 20-11-2025
Brand: Lume Body Co.
Lume Body Co. (“we,” “our,” “us”) provides health and wellness education, bodywork services, training programs, workshops, and related offerings. This Privacy Policy explains how we collect, use, store, and protect personal information across all areas of our brand, including our website, in-person services, booking systems, digital communications, and future product offerings.
By accessing our website, submitting information, or engaging with our services, you agree to this Privacy Policy.
1. Information We Collect
We may collect the following categories of personal information:
1.1 Personal Identification
-
Full name
-
Email address
-
Phone number
1.2 Health-Related Information
Collected through:
-
Paper intake forms
-
GoodNotes digital forms
-
Email
-
Social media DMs
-
Booking notes
These may include: -
Injury descriptions
-
Postural information
-
Training limitations
-
Pain history
-
Relevant medical considerations
1.3 Payment Information
-
Payments via cash
-
Stripe
-
PayPal
-
K Bank
-
Airwallex
We do not store full credit card numbers.
1.4 Automatically Collected Data
-
Cookies
-
IP address
-
Device information
-
Website usage analytics
1.5 Communications
-
Emails
-
Social media direct messages
-
Newsletter sign-ups
-
Booking platform messages
1.6 Minors’ Information
We do not collect personal information from minors.
We only collect parent/guardian information when services relate to a minor.
2. How We Collect Information
We may obtain personal information through:
-
Website forms
-
Booking systems and scheduling software
-
Email communication
-
Social media direct messages
-
Payment processors
-
Paper intake forms
-
GoodNotes digital forms
-
Newsletter platforms (Mailchimp or equivalent)
3. Purposes for Processing Personal Data
We process personal information for the following purposes:
3.1 Service Delivery
-
Booking and managing appointments
-
Providing training, workshops, and bodywork services
-
Assessing health conditions relevant to your treatment
-
Communicating regarding service updates or schedule changes
3.2 Administration
-
Client records and documentation
-
Payment processing
-
Invoicing and receipts
3.3 Business Operations
-
Internal performance analysis
-
Improving service quality
-
Safety and risk management
-
Maintaining client history for continuity of care
3.4 Marketing (Optional)
-
Sending newsletters
-
Announcements of clinics or workshops
You may unsubscribe at any time.
3.5 Legal and Compliance
-
Protecting against fraud or misconduct
-
Meeting regulatory obligations in Thailand, Singapore, or other jurisdictions
4. Legal Basis for Processing (Global + Thailand + Singapore Standards)
4.1 Consent
Used for:
-
Health information
-
Marketing email opt-ins
-
Any optional data provided voluntarily**
4.2 Contractual Necessity
Used for:
-
Bookings
-
Service delivery
-
Payment processing
4.3 Legitimate Interests
Used for:
-
Business improvement
-
Security
-
Record-keeping for continuity of care
4.4 Legal Obligations
Including:
-
Tax compliance
-
Accounting requirements
5. Data Sharing and Third-Party Processors
We share data only when necessary for core business operations:
5.1 Booking & Administration
-
Booking and scheduling software
-
Newsletter platforms (e.g., MailChimp)
5.2 Payment Processing
-
Stripe
-
PayPal
-
K Bank
-
Airwallex
5.3 Internal Staff
Data may be accessed by:
-
Assistants
-
Administrative staff
-
Operational partners
Only on a need-to-know basis.
We do not sell or share data with external marketers or unrelated parties.
6. International Data Transfers
Your information may be stored or processed in:
-
Thailand
-
Singapore
-
Cloud services located globally
We ensure that any transfer follows reasonable security practices consistent with international standards.
7. Data Storage and Retention
7.1 Storage Locations
-
Booking software databases
-
Password-protected devices
-
Cloud platforms (e.g., GoodNotes, email storage)
-
Locked physical filing where paper forms are used
7.2 Retention Period
We retain data only as long as necessary for:
-
Legal compliance
-
Service continuity
-
Accounting and tax obligations
Health-related notes may be stored longer for safety, continuity of care, and legal protection.
You may request deletion unless retention is required by law.
8. Data Security
We implement multiple safeguards:
-
Encrypted communication via payment providers
-
Password-protected digital devices
-
Restricted internal access
-
Protected cloud storage
-
Physical security for paper records
However, no digital transmission is 100% secure. You acknowledge this inherent risk when submitting data.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
-
Request access to your data
-
Request corrections
-
Request deletion (where legally permitted)
-
Withdraw consent for marketing
-
Request how and why your data is processed
To exercise these rights, contact us directly.
10. Children’s Information
We do not knowingly collect personal information from minors.
All services involving minors must be registered under a parent or legal guardian.
11. Changes to This Policy
We may update this Privacy Policy at any time. Updates will be posted on our website with a revised effective date.
12. Contact Information
For data concerns, requests, or questions, contact:
Email: info@betterwithduran.com
Phone: [optional]
Website: [insert website