1. CATEGORIES OF DATA

Apsara Health & Flow will process your personal data, including:

Data collected automatically.
The computer systems and applications dedicated to the operation of this website collect certain data during normal operation (the transmission of which is inherent in the use of internet communication protocols), which may be associated with identifiable users. This data includes IP addresses, domain names of computers used by users, URI (Uniform Resource Identifier) addresses of requested resources, the time of request, the method used to submit the request to the server, the size of the response file, numerical codes indicating the status of the server’s response (success, error, etc.), and other parameters related to the user’s operating system, browser, and IT environment. This data is processed only for the time strictly necessary to obtain anonymous statistical information on the use of the site and to ensure its proper functioning. Providing such data is mandatory as it is directly related to the web browsing experience.

Cookies.
All information regarding the use of cookies on the Apsara Health & Flow website is available in the dedicated [cookie policy].


2. SOURCE OF PERSONAL DATA

The personal data held by Apsara Health & Flow is collected directly from the data subject.

Personal Data.
Personal data is collected through the use of contact information published online by the data controller. Every time you visit https://apsarahealthflow.com, we collect general, anonymous data on visitors’ geographic origin and IT systems. These data are stored securely and accessed only by the Apsara Health & Flow team.

We collect personal data for the purpose of:

  • enabling communication with our team;

  • creating a reference database accessible exclusively by authorised Apsara Health & Flow personnel.


3. DATA CONTROLLER

The Data Controller is Anna Paola Crespi Linklater, with registered office at
6 Blantyre Terrace, Edinburgh, United Kingdom
Email: annapcrespi@apsarahealthflow.com


4. PURPOSE AND LEGAL BASIS FOR DATA PROCESSING

The legal basis for processing your data is your voluntary, informed, and explicit choice to provide your personal information to the Data Controller via the contact channels published on https://apsarahealthflow.com, for the purpose of responding to your inquiries or requests for information.


5. METHODS OF DATA PROCESSING

Your personal data will be processed in accordance with current legislation and the confidentiality principles guiding the Data Controller’s activity. The data may be processed using digital, paper-based, or other suitable means, ensuring compliance with appropriate security measures as outlined in Article 5(1)(f) of the UK GDPR.


6. DATA RECIPIENTS

Your data may be shared, within the limits of the stated purposes, with partners, consultants, or private companies appointed as Data Processors by the Data Controller, or to comply with legal obligations or your specific requests. Your data will not be publicly disclosed. Data Processors and authorised staff are identified in the internal Privacy Documentation, which is reviewed regularly.


7. INTERNATIONAL DATA TRANSFER

Your personal data will not be transferred outside the United Kingdom. Should data transfers outside the UK become necessary, they will be carried out in compliance with UK GDPR provisions and with appropriate safeguards.


8. DATA DISCLOSURE AND PROFILING

Your data will not be disclosed or used for profiling purposes.


9. DATA RETENTION PERIOD

Collected data will be stored only for as long as necessary to achieve the purposes for which it was collected, or as required by applicable laws (“storage limitation principle”, Article 5 UK GDPR). Periodic reviews are conducted to ensure data is not retained longer than needed.


10. DATA SUBJECT RIGHTS

As a data subject, you may at any time:

  • request access to your data;

  • request correction or deletion;

  • request restriction or object to processing;

  • request data portability;

  • withdraw your consent (where applicable).

You can exercise your rights by contacting the Data Controller at:
annapcrespi@apsarahealthflow.com

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
https://ico.org.uk


11. CONSENT REQUIREMENTS

Providing your personal data is not mandatory while browsing our website.


12. SECURITY OF PERSONAL DATA

Apsara Health & Flow confirms that all personal data is collected and processed lawfully, fairly, and for specific, explicit, and legitimate purposes. The organisation is committed to adopting appropriate and preventative security measures to safeguard the confidentiality, integrity, availability, and completeness of your data.

Data is processed both digitally and in paper format for the time necessary to achieve the specified purposes. Specific technical and organisational measures are in place to prevent accidental loss, unauthorised access, misuse, or other unlawful forms of processing.

Apsara Health & Flow is not responsible for any false or inaccurate information sent by users to the address annapcrespi@apsarahealthflow.com (e.g., incorrect email addresses or payment data), nor for information provided fraudulently by third parties.


13. ACCESS, MODIFICATION, AND DELETION OF DATA

In accordance with UK GDPR, the data subject may request at any time:

  • confirmation of the existence of their data;

  • communication of the data in intelligible form;

  • updating, correction, integration, deletion, or transformation;

  • restriction or blocking of data processed unlawfully.

Requests should be made via email to:
Anna Paola Crespi-Linklater — annapcrespi@apsarahealthflow.com