Privacy Policy
Last updated: August 2026
Who we are
Sullio Technologies Ltd is a software-as-a-service platform for self-care and wellness professionals. We operate at sullio.co.uk and are registered in Scotland, United Kingdom. If you have any questions about this policy, contact us at johnmmailey@gmail.com.
Who controls your data
Two different kinds of people use Sullio, and the answer is different for each.
- If you run a venue: we are the data controller for your own account — your sign-up details, your subscription, and how you use the platform.
- If you booked an appointment with a venue: that venue is the data controller for your booking and contact details. We are their data processor — we hold and handle that information on their instructions to run their booking system, and we never use it for our own purposes, sell it, or market to you off our own back.
In practice this means a venue's client list belongs to the venue, not to us. Venue owners can download everything we hold for them at any time, including after they stop paying — see your data. If you booked an appointment and want your details corrected or removed, ask the venue you booked with; you can also contact us at johnmmailey@gmail.com and we will pass it on to them.
What data we collect
We collect the following categories of personal data:
- Account data: name, email address, phone number provided at sign-up or booking.
- Booking data: appointment details, service selections, booking history and notes.
- Payment data: Stripe processes all card payments on our behalf — we do not store card numbers, CVV codes or full payment details on our servers. We store transaction references and amounts.
- Profile images: venue and staff photos uploaded via Cloudinary, a GDPR-compliant image hosting provider.
- Session data: an authentication cookie stored in your browser when you sign in.
- Usage data: pages visited, actions taken within the platform, to improve the service.
Legal basis for processing
Under UK GDPR, we rely on the following legal bases:
- Contract performance: processing necessary to provide the Sullio service you have subscribed to or booked through.
- Legitimate interests: improving the platform, preventing fraud, and maintaining security — where these interests are not overridden by your rights.
- Legal obligation: retaining financial records as required by HMRC and UK law.
Third-party processors
- Stripe: payment processing. Stripe is PCI-DSS Level 1 certified and processes card data under their own privacy policy.
- Cloudinary: image hosting and transformation for venue, staff and marketing images.
- Neon: the database the platform runs on. All account, booking and contact data is stored here.
- Vercel: hosting. Serves every page and runs our scheduled jobs; request logs pass through it.
- Resend: email delivery — booking confirmations, reminders, and any marketing a venue sends.
- Upstash: short-lived counters used to rate-limit sign-in and booking attempts. These are keyed on IP address and, for booking limits, email address, and expire automatically.
- Meta (Facebook/Instagram): only where a venue has connected its own social accounts, to publish posts on its behalf.
We do not sell your personal data to third parties, use it for advertising, or share it beyond what is required to operate the platform.
Data retention
- Financial records (payment transactions, invoices): retained for 7 years as required by HMRC.
- Bookings that were completed or cancelled: kept for as long as the venue's account is open, and deleted on request.
- Abandoned bookings (started at checkout but never paid for): deleted 90 days after the attempt. We keep a daily count of how many were abandoned, which contains nothing about any individual.
- Contact records with no bookings and no marketing consent: deleted after 120 days. A contact who has opted in to marketing is kept until they unsubscribe.
- Session cookie: 24 hours from signing in, or immediately when you sign out.
Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure: request deletion of your data where there is no legal basis for continued retention.
- Right to data portability: receive your data in a machine-readable format.
- Right to restriction: ask us to pause processing of your data in certain circumstances.
- Right to object: object to processing based on legitimate interests.
To exercise any of these rights, email johnmmailey@gmail.com. We will respond within 30 days.
Cookies
We use a session cookie for authentication and Stripe.js sets cookies required for payment fraud detection. We do not use advertising or tracking cookies. See our Cookie Policy for full details.
Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy
We may update this policy from time to time. We will notify registered users by email of any material changes. Continued use of Sullio after the effective date constitutes acceptance of the revised policy.