LEGALPrivacy Policy
Last updated: August 2026
Who we are
The Berry Collective ("we", "us", "our") is a wellbeing and creative business operating from Blossom Yurt at Howgills Hideaway, Lowgill, Kendal LA8 0BT, United Kingdom.
We are the data controller for the personal information described in this policy. That means we are responsible for deciding how and why your information is used.
For any question about this policy, or about the information we hold on you, contact us at hello@theberrycollective.co.uk.
This policy explains what we collect, why we collect it, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What information we collect
We only collect what we need in order to reply to you, take a booking, send you something you asked for, or run our website. Depending on how you interact with us, that may include:
Information you give us directly
Contact details, such as your name, email address and, if you provide it, your phone number.
Enquiry details, meaning the content of your message and which service or event you are interested in.
Booking details, such as the event you have booked, the number of places, and any dietary requirements, access needs or health information you choose to tell us about.
Newsletter preferences, if you sign up to hear from us.
Information collected automatically
Technical and usage data, such as your IP address, browser type, device type, the pages you visited, how long you stayed and which website referred you.
Cookies and similar technologies. These are covered in detail in our Cookie Policy.
Health information
Some of what we offer involves physical activity, heat and cold exposure. If you tell us about a health condition, injury, pregnancy or medication so that we can keep you safe or adapt a session, that counts as special category data under UK GDPR. We treat it with extra care, use it only for your safety and wellbeing during the activity, share it with no one outside our team unless there is a medical emergency, and delete it once it is no longer needed.
You are never obliged to give us health information, but please be aware that without it we may not be able to let you take part in certain activities, particularly sauna and cold water sessions.
How we collect it
When you complete a contact or enquiry form on this website.
When you email, message or telephone us.
When you book an event through our booking provider, TryBooking.
When you subscribe to our newsletter.
When you buy a print or product from our shop.
Automatically, through cookies and analytics, when you browse the website.
Who we share it with
We use a small number of trusted service providers to run our business. They process information on our instructions and are not permitted to use it for their own purposes.
Squarespace: Hosts this website, delivers our contact forms and stores form submissions, provides built in analytics, and runs our shop
TryBooking: Takes event bookings and payments on our behalf
Google Analytics: Tells us anonymously how the website is used, only if you accept analytics cookies
Our email provider: Sends our newsletter and stores subscriber details
Howgills Hideaway: Provides accommodation for retreats, so we pass on the guest names needed for your stay
When you follow a link from our website to our Etsy shop, you leave our website and Etsy's own privacy policy applies to anything you do there. The same is true of our social media pages.
We may also disclose information where we are required to do so by law, or where it is necessary to protect someone's safety.
Information sent outside the UK
Some of our providers are based outside the United Kingdom, or store data on servers outside it. Where information is transferred internationally, we rely on safeguards approved under UK data protection law, such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission's standard contractual clauses, or a finding of adequacy for the country concerned.
How long we keep it
Enquiries that do not become bookings: up to 12 months, then deleted.
Booking and customer records: 7 years from the end of the tax year they relate to, because HMRC requires financial records to be kept.
Health information: deleted shortly after the activity it related to, unless it forms part of an incident record.
Newsletter subscriptions: until you unsubscribe, and we remove subscribers who have not engaged for a long period.
Analytics data: in line with the retention period set in Google Analytics, which is currently 14 months.
Your rights
Under UK GDPR you have the right to:
Be informed about how we use your information, which is the purpose of this policy.
Access a copy of the personal information we hold about you.
Rectification, meaning correction of anything inaccurate or incomplete.
Erasure, sometimes called the right to be forgotten, where there is no good reason for us to keep it.
Restrict processing while a concern is being resolved.
Data portability, meaning a copy in a machine readable format.
Object to processing based on our legitimate interests.
Withdraw consent at any time, where we relied on consent.
To exercise any of these, email hello@theberrycollective.co.uk. We will respond within one month. There is no charge, and we may ask you to confirm your identity first so that we do not release your information to the wrong person.
Marketing and unsubscribing
We only send marketing emails to people who have asked for them, or who have bought from us and have not opted out. Every email includes an unsubscribe link, and you can also simply reply and ask us to stop. We act on unsubscribe requests promptly.
Cookies
We use cookies to make the website work and, with your permission, to understand how it is used. Full details of every cookie, and how to change your choice at any time, are in our Cookie Policy.
Keeping your information safe
We take reasonable and appropriate steps to protect your information, including secure hosting over an encrypted connection, access limited to those who need it, strong and unique passwords with two factor authentication where available, and choosing established providers who take security seriously. No transmission over the internet can be guaranteed completely secure, but we take our responsibility here seriously and will notify you and the Information Commissioner's Office where we are required to do so following a breach.
Changes to this policy
We may update this policy from time to time to reflect changes to our services or to the law. The date at the top of the page shows when it was last revised. Where a change is significant, we will make that clear on the website.