Skip to main content

Khi Tam Health Hub

Khi Tam Global Privacy Policy

Data protection notice for khitamhealthhub.com, thekhitamtherapyschool.com, chualanhnamthe.com and related Khí Tâm sub-brands and landing pages

Version 1.0 · Effective date: 15 July 2026

1. Introduction

Khi Tam Trading Limited ("Khi Tam", "Khí Tâm", "we", "us", "our") provides complementary wellness therapy, energy-based assessments, therapis-led sessions, and yoga and naturopathy education through khitamhealthhub.com, thekhitamtherapyschool.com, chualanhnamthe.com, and any associated Khí Tâm sub-brand or landing page (together, the "Services").

This Policy explains what personal data we collect from you ("you", "client", "student", "practitioner"), why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights available to you. Because our Services touch on health, wellbeing, and body-state information, we apply the highest applicable standard of care to that data across every jurisdiction in which we operate.

This Policy is written to comply concurrently with four legal frameworks:

  • UK GDPR (Retained Regulation (EU) 2016/679 as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018) together with the Data Protection Act 2018 — our primary framework, because Khi Tam Trading Limited is a company registered in England and Wales.
  • EU GDPR (Regulation (EU) 2016/679), for clients and students located in the European Economic Area.
  • California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.), for California residents.
  • Vietnam's Personal Data Protection Decree, Nghị định 13/2023/NĐ-CP ("PDPD"), effective 1 July 2023, for clients, students, and staff located in Vietnam

Where these frameworks differ, we apply the stricter standard to the relevant data subject. Where a right or safeguard exists under only one framework, we describe it under that framework's section below and, wherever practical, extend it as a courtesy to all users regardless of location.

Khi Tam Trading Limited is a complementary and holistic wellness provider. Our services — including chakra and Five Body assessments, Body State Assessment, energy work, yoga therapy, and naturopathy-informed guidance — are intended to support, complement, and nurture wellbeing. They are not medical diagnosis, medical treatment, cure, or a substitute for regulated healthcare, osteopathy, or clinical psychology. This distinction matters for how we describe our processing purposes throughout this Policy: we process health-adjacent information to personalise complementary wellness support, not to render clinical diagnoses.

Our founder, Master Sridevi Tố Hải (Lê Thị Tố Hải), holds the following credentials: 500-HR RYT, Master in Naturopathy (India), Doctor of Vietnamese Traditional Medicine, and is currently completing an MSc in Psychology. Master Sridevi acts as human-in-the-loop reviewer for any AI-assisted output that touches client wellbeing data, as described in Section 14.

2. Who is the Data Controller

Item Detail
Legal entity (Data Controller) Khi Tam Trading Limited
Registered office 91 Pathfield Road, London SW16 5PA, United Kingdom
Companies House registration number [Companies House: TBC]
ICO registration reference [ICO REG: TBC]
Data Protection contact Tohai.le@khitamtherapy.com
Phone +44 7586 163227
Founder / lead therapist Master Sridevi Tố Hải (Lê Thị Tố Hải)

Khi Tam Trading Limited is the Data Controller for all personal data collected through the Services, in every jurisdiction covered by this Policy. We have not yet appointed a formal Data Protection Officer; this is tracked as an open item in the "Gaps to fill before publishing" section at the end of this document.

We have not yet appointed a separate EU Representative under Art. 27 EU GDPR. If Khi Tam begins actively marketing to, or regularly serving, clients based in the EEA, we will appoint one and update this section. Vietnamese data subjects should also refer to Section 4.4 for the Vietnam-specific processing basis and Ministry of Public Security notification duties that attach to us as the offshore (UK-based) receiver of their data.

3. Data we collect

We collect two broad categories of data: standard personal data, and special category / sensitive personal data connected to your wellbeing.

3.1 Standard personal data

Data Examples Collected when
Identity data Name, date of birth, gender (optional) Registration, booking, enrolment
Contact data Email address, phone number, postal address Registration; address only if you order a physical product or certificate
Account data Login credentials, course progress, order history. Account creation, course platform use
Technical data P address, browser type, device identifiers, session cookies. Automatically, when you browse our sites.
Payment metadata Card type, last four digits, billing name, transaction status Checkout, via Stripe — we never see or store full card numbers.

3.2 Special category / sensitive personal data

This is data connected to your health, energy state, and body, protected at the highest level under Article 9 UK/EU GDPR and Điều 2, khoản 4 (sensitive personal data) of Nghị định 13/2023/NĐ-CP, and treated as "sensitive personal information" under Cal. Civ. Code §1798.140(ae).

Data Description
Chakra and Five Body assessment results Self-reported responses used to generate your personal energy profile.
ĐBody State Assessment Pain location map, pain intensity, frequency, and character.
Wellbeing scales Self-rated fatigue, sleep quality, energy, and stress levels on a 0-10 scale.
Self-reported history Prior injuries, surgeries, or conditions you choose to disclose.
Session notes (SOAP-format) Notes taken by a licensed therapist during 1-1 sessions at the Health Hub.
>Posture photographs Images captured via PostureScreen, where used.
Biometric scans Foot pressure scans and custom insole measurements, where used.

We only collect special category / sensitive data that you voluntarily provide or that arises directly from a session you have booked. We do not infer or purchase this data from third parties.

4.1 UK GDPR and EU GDPR

Data type Legal basis Reference
Special category (health-adjacent) data Explicit consent, captured via a checkbox before any assessment or session begins. Art. 9(2)(a) UK GDPR / Art. 9(2)(a) EU GDPR
Standard personal data used to deliver a booked service or course Performance of a contract Art. 6(1)(b) UK GDPR / Art. 6(1)(b) EU GDPR
Standard personal data used for site security, fraud prevention, and service improvement Legitimate interest, balanced against your rights. Art. 6(1)(f) UK GDPR / Art. 6(1)(f) EU GDPR
Marketing communications Opt-in consent Art. 6(1)(a) UK GDPR / Art. 6(1)(a) EU GDPR

You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal, per Art. 7(3) UK/EU GDPR.

4.2 California - CCPA/CPRA

We do not "sell" or "share" personal information as those terms are defined in Cal. Civ. Code §1798.140, and we do not maintain "Do Not Sell / Do Not Share" mechanisms for advertising cross-context behavioural tracking beyond the analytics cookies described in Section 11, because we do not currently transact in that manner. If this changes — for example, if we activate Meta or TikTok pixel-based ad audiences noted in Section 6 — we will post a "Do Not Sell or Share My Personal Information" link and update this Policy before doing so.

We provide a notice at collection (this Policy) describing the categories of personal information collected and the purposes of collection, as required by Cal. Civ. Code §1798.100. Sensitive personal information (health-adjacent assessment data, described in Section 3.2) is used only for the limited purposes necessary to deliver the Services you request, consistent with the right to limit use under Cal. Civ. Code §1798.121.

4.3 Vietnam PDPD (Nghị định 13/2023/NĐ-CP)

Consent is the default legal basis for all processing of Vietnamese clients', students', and staff members' personal data, per Điều 11 of the Decree. Consent must be given voluntarily, with full knowledge of the data type, purpose, and recipients, and may be expressed in writing, by voice, by ticking a consent box, by text message, or by an equivalent technical action; silence is never treated as consent.

Because our wellbeing-related data qualifies as sensitive personal data under Điều 2, khoản 4, we separately inform each Vietnamese data subject before processing that the data being collected is sensitive, per Điều 28.

Consent may be withdrawn at any time (Điều 12). Once withdrawn, we and our processors must cease processing the affected data, and we will inform you of any consequences of withdrawal (for example, that we can no longer generate a personalised report)

Special note — Vietnamese staff (4 team members)

The four Vietnam-based Khí Tâm staff members' employment-related personal data is processed under the same PDPD consent framework, plus the limited "processing without consent" exceptions under Điều 17 (for example, contractual necessity for payroll).

5. Purposes of processing

We use your personal data only for the following purposes:

  • Generating your individual wellbeing report (e.g. "Personal Energy Report") from assessment answers you provide.
  • Recommending therapy sessions, courses, or practices that may complement your stated goals
  • Supporting 1-1 sessions between you and a licensed therapist, including secure session note-keeping
  • Issuing and verifying certificates for the 200-hour and 300-hour therapy school programmes
  • Communicating with you about orders, bookings, and enrolments you have made
  • Sending newsletters or promotional content, but only if you have opted in, and always with an unsubscribe option
  • Operating, securing, and improving our websites and booking systems
  • Meeting our legal and tax record-keeping obligations (for example, UK HMRC invoice retention)

We do not:

  • Sell personal data to any third party
  • Share health-adjacent data with advertising partners such as Google or Meta
  • Use your personal data to train third-party AI models
  • Share your data with insurers, employers, or any party outside the delivery of your own Services, except where legally compelled

6.Who sees your data — internal roles and processors

6.1 Internal roles

Role Data accessed Reason
Master Sridevi Tố Hải (Founder, lead therapist) Full access where clinically or operationally relevant Service oversight and human-in-the-loop review of AI outputs
Licensed therapists Assessment results and Body State data of their own clients TDelivering 1-1 sessions
Teaching assistants Course progress and certificate data Supporting learners and issuing certification
Vietnam-based staff (4 members Role-limited access (e.g. admin, customer support, course coordination Day-to-day operations

6.2 External processors and sub-processors

Vendor Purpose Data shared Location Safeguard
Neon (Postgres) Database hosting All categories, encrypted at rest eu-west-2 (London, UK) UK GDPR adequacy + AWS Standard Contractual Clauses
Stripe Payment processing Payment metadata only (no full card numbers) USA UK International Data Transfer Addendum + EU SCCs; PCI-DSS Level 1 certified
Resend Transactional email delivery Email address and message content USA SCCs + Data Processing Agreement
Google Workspace Business email Email address and content EU + USA Google Data Processing Addendum + SCCs
Mailchimp Email marketing. Email address and stated preferences USA UK Addendum + SCCs
Vercel Website hosting IP address, session data USA + EU regions Standard Contractual Clauses (SCCs).
LearnWorlds Course platform ("Đạo Sư") Enrolment and progress data EU (Cyprus HQ) GDPR Data Processing Agreement (DPA).
Meta / TikTok (planned, not yet active) Marketing audiences Ad audience identifiers USA UK Addendum + SCCs
Anthropic (Claude API) "Y Sư" and "Nội Sư" AI support tools CRedacted prompts only, no direct identifiers where avoidable USA Zero data retention API terms + Data Processing Agreement
OpenAI (GPT-4o API) "Đạo Sư" and "Kế Toán Sư" AI support tools Non-health text only USA Zero data retention API terms + Data Processing Agreement

Every processor listed above operates under a signed Data Processing Agreement and is contractually bound to use your data only for the purpose we specify, to apply appropriate security, and to delete data on our instruction.

7. Technical and organisational security measures

We apply the following safeguards across all Services:

  • Encryption in transit: TLS 1.3 for all website and API connections.
  • Encryption at rest: AES-256 encryption on our Neon Postgres database.
  • Access control: Role-based access limited to staff who need the data for their function, protected by two-factor authentication.
  • Audit logging: All access to special category / sensitive data is logged
  • Backups: Encrypted daily backups, retained for 30 days.
  • Password handling: All account passwords are hashed using bcrypt; we never store passwords in plain text.
  • AI data minimisation: Where AI tools (Section 14) process client information, prompts are redacted of direct identifiers wherever the underlying task allows it.
  • Vendor due diligence: All processors listed in Section 6.2 are contractually required to maintain security measures at least equivalent to our own.

8. Data retention

Data Retention period Basis
Assessment results and Body State Assessment data 7 years from last interaction Aligned with NHS clinical record-keeping standard
1-1 session notes (SOAP format) 7 years from last session UK complementary-health industry norm
Certificates issued (200H/300H) 10 years, then anonymised Supports ongoing public verification of qualifications
Financial invoices and payment records 7 years HMRC record-keeping requirement (UK)
Marketing consent and email preferences Until you unsubscribe Tied to the consent that permits processing
Consultation audio recordings (where taken) 30 days, then anonymised Minimisation of special category data
Non-essential cookies 13 months ICO cookie guidance

If you exercise your right to erasure, we will complete deletion within 30 days for UK/EU requests, unless a legal retention obligation applies (for example, HMRC invoice records). For Vietnamese data subjects, deletion following a valid request or consent withdrawal is completed within 72 hours, per Điều 12 and Điều 16 of Nghị định 13/2023/NĐ-CP, except where a documented legal exception applies.

9. Your rights, by jurisdiction

9.1 UK GDPR and EU GDPR — 8 rights

Right What it means
Right to be informed Know what data we collect and why (this Policy)
Right of access Request a copy of the personal data we hold about you
Right to rectification Ask us to correct inaccurate or incomplete data
Right to erasure Ask us to delete your data ("right to be forgotten")
Right to restrict processing Ask us to pause processing of your data
Right to data portability Receive your data in a portable format (e.g. JSON/CSV)
Right to object Object to processing based on legitimate interest or direct marketing
Rights related to automated decision-making Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, without human review

Response time: 30 days (Art. 12(3) UK/EU GDPR), extendable by two further months for complex requests, with notice to you.

9.2 California CCPA/CPRA — 5 rights

Right Statutory reference What it means
Right to know Cal. Civ. Code §1798.100, §1798.110 Know the categories and specific pieces of personal information collected, and the purposes of collection
Right to delete Cal. Civ. Code §1798.105 Request deletion of personal information we hold
Right to correct Cal. Civ. Code §1798.106 Request correction of inaccurate personal information
Right to opt out of sale/sharing Cal. Civ. Code §1798.120 Opt out of any sale or sharing of personal information (not currently applicable — we do not sell or share)
Right to non-discrimination Cal. Civ. Code §1798.125 We will not penalise you for exercising any of the above rights

California residents additionally have the right to limit the use of sensitive personal information under Cal. Civ. Code §1798.121; because we already limit use of your wellbeing data to the purposes necessary to deliver the Services, no separate opt-out mechanism is required, but you may still contact us to confirm this limitation in writing. Response time: 45 days, extendable once by a further 45 days with notice (Cal. Civ. Code §1798.130).

9.3 Vietnam PDPD — 11 rights

Right Article
Right to be informed Điều 9(1)
Right to consent Điều 9(2)
Right to access / view / edit data Điều 9(3)
Right to withdraw consent Điều 9(4)
Right to delete data Điều 9(5)
Right to restrict processing Điều 9(6)
Right to be provided with data Điều 9(7)
Right to object to processing Điều 9(8)
Right to complain, denounce, or initiate lawsuits Điều 9(9)
Right to claim damages Điều 9(10)
Right to self-defence Điều 9(11)

Response time: 72 hours for data provision, deletion, and processing-restriction requests (Điều 14, Điều 16); consent withdrawal takes effect immediately upon our acknowledgement (Điều 12)

10. How to exercise your rights

Send an email to Tohai.le@khitamtherapy.com with the subject line "Data Subject Request", stating which right you wish to exercise and the Service(s) you have used. We may ask you to verify your identity before processing the request, to protect your data from unauthorised disclosure

There is no charge for a standard request. We may charge a reasonable administrative fee only for manifestly unfounded, excessive, or repetitive requests, consistent with Art. 12(5) UK/EU GDPR. If you are not satisfied with our response, you may escalate to the relevant supervisory authority listed in Section 17.

We use three categories of cookies, described in full in our separate Cookie Policy:

Category Purpose Can you disable it?
Strictly necessary Login sessions, shopping cart, securit No — the site will not function correctly without these
Analytics Anonymised visit counting and usage patterns Yes, via the cookie banner
Marketing Not currently used for any visitor who has not opted in Not applicable until activated

Non-essential cookies are retained for a maximum of 13 months, in line with ICO guidance, a er which consent must be refreshed. California visitors may decline analytics cookies via the cookie banner at any time; this is treated as an opt-out request even though it does not currently correspond to a "sale" or "share" under the CCPA/CPRA.

12. International data transfers

Our primary data storage is in the United Kingdom, on Neon's eu-west-2 (London) region. Certain processors listed in Section 6.2 are based in the United States or elsewhere outside the UK/EEA. Every such transfer is protected by one or more of the following safeguards, consistent with Articles 44-49 UK/EU GDPR:

  • UK International Data Transfer Addendum
  • EU Standard Contractual Clauses (SCCs)
  • Additional technical safeguards such as encryption and access restriction

For Vietnamese data subjects, any transfer of personal data outside Vietnam — including transfer to our UK servers and US-based processors — is subject to Điều 25 of Nghị định 13/2023/NĐ-CP. We prepare and maintain a cross-border transfer impact assessment dossier and submit it to the Ministry of Public Security (Department of Cybersecurity and High-Tech Crime Prevention) within 60 days of the relevant processing commencing, and notify the Ministry upon completion of each transfer, as required by that Article.

We separately maintain a Data Protection Impact Assessment dossier for our processing of sensitive personal data generally, and submit it to the Ministry of Public Security within 60 days of commencing such processing, per Điều 24 of the Decree.

13. Children and minors

Our Services are intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18 without appropriate consent. A parental consent workflow for users under 18 has not yet been launched; until it is, under-18 users should not use the Services, and any parent or guardian who discovers that their child has provided data to us should contact Tohai.le@khitamtherapy.com so that we can delete it promptly.

For Vietnamese data subjects specifically, any future processing of a child's personal data will require the child's own consent once they are 7 years of age or older, in addition to parental or guardian consent, per Điều 20 of Nghị định 13/2023/NĐ-CP.

14. Automated decision-making and AI processing

Khi Tam uses AI-assisted tools internally, referred to as "Y Sư" and "Nội Sư" (built on the Anthropic Claude API) and "Đạo Sư" and "Kế Toán Sư" (built on OpenAI's GPT-4o API), to help dra personalised wellbeing suggestions, respond to student questions, and support administrative tasks. These tools:

  • Receive redacted inputs wherever the task allows, to minimise exposure of directly identifying information.
  • Operate under zero-data-retention API terms with both Anthropic and OpenAI, and are covered by Data Processing Agreements (see Section 6.2).
  • Never make a final clinical, therapeutic, or enrolment decision without human review.

Master Sridevi Tố Hải, or a licensed therapist under her supervision, remains the human-in the-loop for any output that could affect your wellbeing recommendations, course results, or certification. We do not make any decision based solely on automated processing that produces legal effects or similarly significant effects concerning you, consistent with Art. 22 UK/EU GDPR.

15. Public Certificate Registry

thekhitamtherapyschool.com/verify allows the public to confirm that a named individual has completed a 200-hour or 300-hour programme. We display a student's chosen display name and programme title on this registry only where the student has given explicit, separately recorded opt-in consent, logged in our internal time by emailing consent_ledger. You may withdraw this consent at any Tohai.le@khitamtherapy.com, and we will remove your listing within the timelines described in Section 8 and Section 9.

16. Changes to this Policy

We may update this Policy as our Services, vendors, or legal obligations change. Material changes will be notified to you by email at least 30 days before they take effect. The current version is always available at khitamhealthhub.com/privacy, and prior versions are retained in our version history (Section 18).

17. Contact us and supervisory authorities

  • Data Controller: Khi Tam Trading Limited
  • Address: 91 Pathfield Road, London SW16 5PA, United Kingdom
  • Email: Tohai.le@khitamtherapy.com
  • Phone: +44 7586 163227

If you are not satisfied with how we have handled your personal data, you may complain to the relevant supervisory authority for your jurisdiction:

Jurisdiction Authority Contact
United Kingdom Information Commissioner's Office (ICO ico.org.uk
0303 123 1113
European Union / EEA) Your local Data Protection Authority (e.g. CNIL in France, or your country's equivalent) edpb.europa.eu
California, USA California Attorney General's Office / California Privacy Protection Agency oag.ca.gov
cppa.ca.gov
Vietnam Ministry of Public Security, Department of Cybersecurity and High-Tech Crime Prevention (Bộ Công an, Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao) bocongan.gov.vn

18. Effective date and version history

Version Effective date Summary of changes
1.0 2026-07-15 Initial global policy covering UK GDPR, EU GDPR, California CCPA/CPRA and Vietnam PDPD (Nghị định 13/2023/NĐ-CP).

This Policy governs khitamhealthhub.com, thekhitamtherapyschool.com, chualanhnamthe.com and any associated Khí Tâm sub-brand or landing page. A separate Vietnamese-language version will be published alongside this English version; where the two differ in interpretation, the version applicable to the data subject's jurisdiction of residence governs

v1.0 · Effective 2026-07-15 · Khi Tam Trading Limited