Privacy Policy
Last updated: 2026.09.07.
This Privacy Policy explains how Sarah Graffi (“the Business”) handles personal information in connection with this website and the appointment booking services provided.
The Business respects the privacy of its clients and aims to handle personal information in a transparent, secure, and responsible manner.
1. Data Controller
The data controller responsible for personal data processed in connection with the services is:
SARAH GRAFFI INTEGRATIVE NUTRITION HEALTH COACH
sarahgraffi@gmail.com
http://www.sarahgraffi.com
For any questions regarding the processing of personal data, the Business can be contacted using the email address above.
2. Personal Data Collected
This website does not contain a contact form and does not directly require visitors to provide personal information. Clients who wish to book an appointment will be redirected to a third-party appointment booking platform operated by Reservio.
When making an appointment, the booking platform may request personal information such as:
- name;
- email address;
- phone number;
- other information necessary to arrange and manage the appointment.
The third-party booking provider may process this information in accordance with its own privacy policy and terms of service. Clients are encouraged to review the provider’s privacy policy.
3. Purposes of Processing
Personal data relating to appointments is processed only for purposes connected with providing and managing the services, including:
- scheduling and confirming appointments;
- communicating with clients regarding appointments;
- responding to appointment-related questions;
- rescheduling or cancelling appointments;
- maintaining appropriate business and administrative records; and
- complying with applicable legal, tax, accounting, and other legal obligations.
The Business does not sell or rent clients’ personal data and does not use appointment information for unrelated purposes.
Personal data will not be used for marketing purposes unless there is an appropriate lawful basis for doing so and, where required, the client’s consent has been obtained.
4. Legal Basis for Processing
Depending on the circumstances, personal data may be processed on one or more of the following legal bases under the General Data Protection Regulation (GDPR):
- processing is necessary to take steps at the client’s request and/or to perform a contract with the client;
- processing is necessary to comply with a legal obligation;
- processing is necessary for the legitimate interests of the Business, provided that those interests are not overridden by the rights and freedoms of the individual; or
- the individual has provided consent where consent is required by applicable law.
Where consent is used as the legal basis for processing, consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Third-Party Appointment Booking Provider
Appointments are arranged through Reservio, which is a separate third-party service provider. When a client uses the booking system, personal data is processed by both the booking provider and, where applicable, the Business. The booking provider may process personal information in accordance with its own privacy policy and applicable data protection obligations.
The booking provider’s privacy policy can be found here:
www.reservio.com/privacy-policy
Clients are encouraged to review this policy to understand how their information is handled by the booking provider.
6. Sharing of Personal Data
The Business does not sell, rent, or otherwise commercially trade clients’ personal data.