Sullio logoSullio

Privacy Policy

Last updated: May 2026

Who we are

Sullio Ltd is a software-as-a-service platform for self-care and wellness professionals. We operate at sullio.co.uk and are registered in Scotland, United Kingdom. If you have any questions about this policy, contact us at privacy@sullio.co.uk.

What data we collect

We collect the following categories of personal data:

  • Account data: name, email address, phone number provided at sign-up or booking.
  • Booking data: appointment details, service selections, booking history and notes.
  • Payment data: Stripe processes all card payments on our behalf — we do not store card numbers, CVV codes or full payment details on our servers. We store transaction references and amounts.
  • Profile images: venue and staff photos uploaded via Cloudinary, a GDPR-compliant image hosting provider.
  • Session data: an authentication cookie stored in your browser when you sign in.
  • Usage data: pages visited, actions taken within the platform, to improve the service.

Legal basis for processing

Under UK GDPR, we rely on the following legal bases:

  • Contract performance: processing necessary to provide the Sullio service you have subscribed to or booked through.
  • Legitimate interests: improving the platform, preventing fraud, and maintaining security — where these interests are not overridden by your rights.
  • Legal obligation: retaining financial records as required by HMRC and UK law.

Third-party processors

  • Stripe: payment processing. Stripe is PCI-DSS Level 1 certified and processes card data under their own privacy policy.
  • Cloudinary: image hosting and transformation. Cloudinary is GDPR-compliant and stores data in EU-region infrastructure.

We do not sell your personal data to third parties, use it for advertising, or share it beyond what is required to operate the platform.

Data retention

  • Financial records (payment transactions, invoices): retained for 7 years as required by HMRC.
  • Account and booking data: retained until you request deletion of your account.
  • Session cookies: expire when you close your browser or sign out.

Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data where there is no legal basis for continued retention.
  • Right to data portability: receive your data in a machine-readable format.
  • Right to restriction: ask us to pause processing of your data in certain circumstances.
  • Right to object: object to processing based on legitimate interests.

To exercise any of these rights, email privacy@sullio.co.uk. We will respond within 30 days.

Cookies

We use a session cookie for authentication and Stripe.js sets cookies required for payment fraud detection. We do not use advertising or tracking cookies. See our Cookie Policy for full details.

Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Changes to this policy

We may update this policy from time to time. We will notify registered users by email of any material changes. Continued use of Sullio after the effective date constitutes acceptance of the revised policy.