Entity: Richard Reid Enterprises (IOM) Limited, trading as Pinnacle Wellbeing Services (“Pinnacle”, “we”, “us”, “our”)
Pinnacle Wellbeing Services (“we”, “our”, “us”) is committed to protecting the privacy, dignity, and personal data of our clients, executive participants, website visitors, partners, and affiliates.
This Privacy Policy explains how we collect, process, store, and safeguard your personal and sensitive data in accordance with the Isle of Man Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. The Data We Collect
Depending on how you interact with us (e.g., as an executive coaching client, therapy client, corporate sponsor, or website visitor), we may collect and process:
Identity & Contact Data: Name, business address, email address, telephone number, job title, and employer details.
Special Category (Clinical/Health) Data: Psychological assessments, therapy session notes, mental health histories, occupational wellbeing reports, and related health information provided during clinical or coaching engagements.
Financial & Transaction Data: Billing addresses, invoice history, payment records, and retainer details.
Technical & Usage Data: IP address, browser type, device information, and website usage statistics collected via cookies.
2. Lawful Bases for Processing
We process personal data only when authorized by law under Article 6 and Article 9 of the UK GDPR / IoM DPA 2018:
Contractual Necessity (Art. 6(1)(b)): To deliver agreed coaching, training, or consultancy services under our Service Agreements.
Legitimate Interests (Art. 6(1)(f)): For business operations, client relationship management, service quality audits, and website security.
Provision of Health or Social Care (Art. 9(2)(h)): To provide professional psychological assessment, therapy, and clinical support under strict ethical and professional standards.
Explicit Consent (Art. 9(2)(a)): Where required for specific sensitive data sharing or specialized coaching initiatives.
3. Special Category Data and Confidentiality
Psychological notes and clinical therapy records are classified as Special Category Data.
Therapeutic Privilege: Session content and clinical assessments remain strictly confidential between the practitioner and the client/participant.
Corporate Boundaries: Corporate client sponsors are never provided with individual therapy notes, session content, or personal clinical diagnoses without the explicit, written consent of the participant, except where mandated by law or emergency safeguarding protocols.
4. Disclosure of Your Information
We treat your engagement with us with the utmost discretion. We may disclose your personal information to third parties only if we are under a duty to disclose or share your data to comply with any legal obligation (e.g., risk of severe harm to self or others, or by court order). We do not share your clinical data with your corporate employer or sponsor without your explicit written authorisation.
5. Data Retention and Erasure
We do not hold personal data longer than necessary:
Clinical & Psychological Records: Retained for 7 years following your last session or contract completion to satisfy professional body standards and professional indemnity requirements.
Administrative, Financial & Corporate Records: Retained for 6 years post-contract termination in compliance with statutory tax and accounting laws.
Marketing & Inquiry Records: Retained until you opt out or request erasure.
6. Your Statutory Rights
Under applicable data protection laws, you have the following rights:
Right of Access (Subject Access Request – SAR): You have the right to request a copy of your personal data held by Pinnacle. The initial copy is provided free of charge. Subsequent or duplicate copies may incur a reasonable administrative fee based on processing costs.
Right to Rectification: You may request correction of inaccurate or incomplete data.
Right to Erasure (“Right to be Forgotten”): You may request deletion of your data, subject to statutory record-keeping exemptions (such as our 7-year clinical retention obligation).
Right to Restrict or Object to Processing: You may object to direct marketing or restrict processing under specific legal conditions.
Requests will be fulfilled within one calendar month of identity verification.
To exercise any of these rights, please complete our Data Subject Rights Request Form and email our Data Protection Officer at info@richard-reid-enterprises.com and CC info@pinnaclewellbeingservices.com
7. Cookies and Digital Tracking (PECR Compliance)
Our website uses cookies and similar tracking technologies:
Essential Cookies: Required for basic website operation, security, and page navigation (do not require consent).
Analytics & Performance Cookies: Used only with your explicit consent (via our website cookie banner) to analyze traffic and improve user experience. You may modify your cookie preferences at any time in your browser settings.
8. Data Security and Incidents
We maintain enterprise-grade security controls including AES-256 bit encryption at rest, TLS 1.3 encryption in transit, multi-factor authentication (MFA), and strict access controls.
We maintain a robust Incident Response Framework to contain, investigate, and remediate any potential security threats. In the event of a personal data breach that is likely to pose a risk to your rights and freedoms, we are committed to notifying the relevant supervisory authority (such as the Isle of Man Information Commissioner or the UK Information Commissioner’s Office(ICO)) within 72 hours of discovery, in accordance with applicable data protection laws.
Direct Client Notification: If a data breach occurs that poses a high risk to your personal privacy, confidentiality, or rights, we will notify you directly and without undue delay via secure, direct communication channels. Our notification will outline:
The nature of the security incident and the specific data involved.
The immediate containment and remedial actions taken by our security team.
Recommended steps you can take to protect your accounts (if applicable).
Direct contact details for our Data Protection Officer (DPO) for ongoing updates.
Reporting Suspected Breaches or Security Concerns: If you suspect that your personal data has been compromised, or if you identify a potential security vulnerability, unauthorized access, or misdirected communication, please report it immediately by sending a completed Client Inquiry and Resolution Form to our Data Protection Officer at info@richard-reid-enterprises.com or call +44 7360 275141. All external security reports are triaged immediately upon receipt.
9. Contact Details and Regulatory Complaints
If you have questions, concerns, or wish to exercise your data protection rights, please contact:
Data Protection Officer (DPO)
Pinnacle Wellbeing Services
18 Bowling Green Road, Castletown, Isle of Man IM9 1EB
Email: info@richard-reid-enterprises.com
CC: info@pinnaclewellbeingservices.com
If you remain unsatisfied with our response, you have the right to lodge a complaint with your supervisory authority:
Isle of Man Information Commissioner: www.inforights.im
UK Information Commissioner’s Office (ICO): www.ico.org.uk
PPD Review Date:
Written on: 1st August 2025
Last Updated: 29 September 2026
Next Review Date: 28 September 2027