1. Introduction and Statement of Purpose

The British Alliance of Healing Associations (BAHA), registered as a charity in England and Wales (No: 284546), is committed to safeguarding the privacy, confidentiality, and security of all personal data entrusted to us. As a self-regulating umbrella organisation representing Member Associations, individual energy healers, student practitioners, and administrative officials, we process information strictly to maintain the highest standards of the healing profession, administer memberships, facilitate professional training, and secure mandatory block indemnity insurance.

This Privacy Policy operates under the constitutional authority established in Article 18 (Data Protection and Information Governance) of the BAHA Articles of Constitution. It serves as the core operational framework for data management across all BAHA administrative branches, committees, and sub-groups, ensuring compliance with statutory data protection standards.

2. The Data Controller and Operational Continuity

The designated Data Controller for all personal data processed by the Alliance is the BAHA Executive Committee (the Board of Trustees). Correspondence regarding this policy, data access requests, or privacy concerns should be directed in writing to the BAHA Secretary:

Administrative Entity

The British Alliance of Healing Associations (BAHA)

Registered Address

20, The Lings, Bramley, Rotherham, South Yorkshire, S66 1TG

Contact Official

The BAHA Secretary (jointly with the BAHA Chair)

Telephone Contact

07901 715594

Official Email

secretary@britishalliancehealingassociations.com

2.1 Operational and Administrative Continuity Safeguard

To guarantee administrative and operational continuity, and in accordance with official BAHA governing documents which authorise the Executive Committee to access all necessary information to fulfil their administrative, operational, and insurance duties, access to secure BAHA databases, registers, and backup archives is restricted to the Executive Committee as a collective, or designated officers formally authorised by them. This collective access framework ensures the Alliance can perform its statutory, administrative, and public-safeguarding duties uninterrupted under any emergency, vacancy, or change in personnel.

3. Statutory Compliance and Legislative Boundaries

All data collection, storage, transfer, and disposal activities carried out by the Alliance strictly comply with current and upcoming UK and EU data protection legislation. This statutory framework comprises:

  • UK General Data Protection Regulation (UK GDPR): Governing the fundamental principles of lawful, fair, and transparent personal data processing, data minimisation, and individual privacy rights.
  • Data Protection Act 2018 (DPA 2018): The UK's primary data protection statute, supplementing the UK GDPR and establishing rules for processing special category data, enforcing regulatory compliance, and prosecuting breaches.
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR): Governing electronic communications, digital marketing, and consent requirements for newsletters, membership email broadcasts, and public-facing directories.
  • Data Use and Access Act (DUAA): Incorporating the upcoming legal standards for automated digital data exchange, secure verification, cloud storage compliance, and structured regulatory data sharing.
  • Subsequent Re-enactments: Including any subsequent statutory modifications, re-enactments, or updates of data protection or charity legislation as may be introduced or enacted from time to time in the United Kingdom.

4. Categories of Data Processed by the Alliance

BAHA processes distinct categories of personal data depending on the individual's relationship with the Alliance. The scope of processing is kept strictly to what is necessary for administrative, legal, and educational purposes.

4.1 Member Association Records (Rosters)

For the administration of our Member Associations, the Alliance collects and processes the following records submitted annually in digital format by association Secretaries:

  • Full Names, unique registration/membership numbers, and contact details (postal addresses, email addresses, telephone numbers) of all affiliated healers.
  • Practice postcodes, qualifications (e.g., probationer, full healer, tutor), and dates of training completion or registration renewals.
  • Official contact lists, minute extracts, and governance records relating to the office-bearers (Chair, Secretary, Treasurer, and Representatives) of each Member Association.

4.2 Individual, Student, and Transitional Practitioner Records

For healers applying for or admitted into the permanent Individual Healer category, student practising healers, or healers held on temporary administrative safety nets, the Alliance processes:

  • Complete personal contact information, proof of training, and copies of verified professional qualifications.
  • Detailed written justifications for solo practitioner status (proving a valid reason why they cannot join an existing local association).
  • Signed and binding Code of Conduct Declarations, professional indemnity block insurance policy certificates, and direct bank transfer records for annual membership fees.
  • Probationary progress reports, tutor assessments, and student clinical logbooks submitted to the monitoring committee.

4.3 Educational, Training Manuals, and Supply Records

As part of BAHA's core educational operations, the Alliance supplies official training manuals, student record of training handbooks, codes of conduct booklets, certificates, and relevant educational resources to Member Associations, tutors, and student healers. For this purpose, we process:

  • Billing, delivery, and contact coordinates for Member Associations, local tutors, and ordering individuals.
  • Historical records of manuals, handbooks, and booklets supplied, including dates of purchase, dispatch records, and invoice tracking to ensure financial auditing and curriculum compliance.

5. The Special Category Health Data Boundary

A critical legal and operational distinction is made regarding sensitive 'special category' data, specifically health and clinical records. BAHA's stance is defined by two strict principles:

Principle 1: No Permanent Clinical Storage. Under normal operating conditions, BAHA does not collect, see, process, or permanently store client treatment files, case notes, medical history charts, or patient consent forms. All such clinical records remain the exclusive property of, and are stored by, the individual practising healer or their local clinic in strict accordance with the retention guidelines in the BAHA Code of Conduct and Standards.
Principle 2: Mandatory Temporary Investigative and Custodial Access. In the event of an official complaint, a reported breach of the Code of Conduct, or a temporary custodianship takeover of an association in administrative crisis, the BAHA Executive Committee and the formally appointed Disciplinary Committee (DC) possess the absolute constitutional right under Article 18(c) to request, inspect, and temporarily process relevant client files, treatment notes, and administrative databases. This processing is strictly necessary to protect the public, enforce professional discipline, and maintain the integrity of the Alliance. All such sensitive records are held under the highest security, restricted strictly to authorised panel members, and are securely destroyed or returned to the parent body immediately upon the final resolution of the case.

Lawful Basis for Special Category Processing: Under UK GDPR Article 9(2)(g) and Schedule 1 of the Data Protection Act 2018, BAHA's lawful basis for temporarily processing special category health data during active disciplinary cases is Substantial Public Interest for the purposes of public protection, safeguarding, and maintaining the ethical self-regulation of a national healing profession.

6. The Lawful Bases for General Processing

To process non-sensitive personal data, BAHA relies on the following defined lawful bases under Article 6 of the UK GDPR:

UK GDPR Lawful Basis

What It Applies To

Specific Operational Purpose

Contractual Necessity
(Article 6.1.b)

Processing lists, fees, and registers for Member Associations and solo individual healers.

To administer the affiliation contract, verify qualifications, maintain active rosters, and manage the official application pipeline under monitoring committee oversight.

Legitimate Interests
(Article 6.1.f)

Co-ordinating lists with the BAHA-approved insurance broker and distributing administrative bulletins.

To secure professional indemnity block insurance cover for all practising healers, protecting both the healer and the public from liability.

Legal Obligation
(Article 6.1.c)

Financial accounts, Trustee declarations, and statutory filings with relevant charity regulators.

To comply with relevant charity legislation, auditing guidelines, and financial reporting requirements as a registered charity.

Consent
(Article 6.1.a)

Distributing the official digital BAHA newsletter or listing a healer's clinic details on the website.

To promote the practice of energy healing to the public and share updates, with members retaining the absolute right to opt out or withdraw consent at any time.

7. How We Share and Disclose Personal Data

BAHA operates under a strict non-disclosure regime. We never sell, lease, commercialise, or trade personal data to any third party. Personal information is only shared under the following restricted and contractually secure conditions:

  • To the BAHA-Approved Insurance Broker: Roster registers, qualifications, and unique reference codes are transferred securely to administer the mandatory professional indemnity block insurance policy. This transfer is managed strictly in compliance with relevant financial and data protection rules.
  • To Statutory and Charity Regulators: We may disclose Trustee details, governance correspondence, or active disciplinary status where strictly required by statutory charity law, public accountability, or direct regulatory orders of competent jurisdiction.
  • To Public Directories (with Consent): Healers' contact information, clinic locations, and modalities are published on our public web directory solely where the individual healer has provided express, written opt-in consent to facilitate public client bookings.

8. Database Security and Encryption Standards

In transitioning from historical physical cabinets ('under lock and key') to modern electronic operations, the Alliance enforces digital security protocols across all systems:

  • Database Encryption: All digital databases, spreadsheet registers, and application files held by the Alliance are stored in secure, encrypted cloud servers or secure digital vaults protected by AES-256 encryption.
  • Password Protection and Multi-Factor Access: All administrative access to BAHA systems requires complex, frequently rotated passwords and multi-factor authentication (MFA). Permitted access is restricted to the Executive Committee as a collective and designated authorised officers.
  • Physical Security: Where physical records must be temporarily held (e.g. printed application forms or paper evidence during active disciplinary hearings), they must be kept in locked security cabinets, with access strictly restricted to the Executive Committee, Disciplinary Committee, or designated representatives.
  • Transit Security: Any transfer of membership registers or financial records (e.g. between Member Association Secretaries and the BAHA Secretary) is recommended to occur over secure, encrypted email or password-protected transfer portals. Excel documents containing rosters should ideally be password-encrypted in transit.

9. Data Retention and Secure Destruction

Personal data is only retained for as long as is necessary to fulfill the specific administrative, legal, or auditing purposes for which it was collected. Our retention schedules are strictly defined:

  • Administrative and Membership Registers: Active healer registers, unique membership IDs, and qualification records are retained for the duration of the practitioner's active affiliation. Lapsed records are archived and retained for a maximum of 7 years after resignation or disaffiliation to defend potential liability or insurance claims.
  • Corporate, Financial, and Board Governance: Trustee minutes, AGM records, annual returns, and audit trails must be retained for a minimum period of 7 years to satisfy the requirements of relevant charity regulators, taxation authorities, and statutory bodies.
  • Active Disciplinary and Investigation Files: All official administrative records of a case (including complaints, correspondence, minutes, and final decision notices) shall be retained securely by the Alliance for a standard legal protection period of 7 years to satisfy regulatory audits, compliance reporting, and legal defence. However, any raw clinical client records, treatment files, or sensitive medical notes temporarily acquired during an investigation or custodial takeover shall be securely destroyed or returned immediately upon the formal resolution of the case and the expiration of the appeal window, in accordance with our data minimisation principles.
  • Educational Booklets and Supply Order Records: Billing details and delivery tracking for official training manuals, record of training handbooks, and certificates are retained for 7 years for financial audit, inventory control, and curriculum verification.

10. Your Statutory Data Rights

Under the UK GDPR and the Data Protection Act 2018, every affiliated healer, trustee, and client whose data is processed by BAHA has the following statutory rights. These rights may be exercised by contacting the BAHA Secretary in writing:

  • The Right to be Informed: The right to receive clear, transparent, and easily understandable information about how we process your personal data (fulfilled through this public policy).
  • The Right of Access (Subject Access Request): The right to obtain a copy of all personal data held about you by the Alliance. BAHA will respond to all valid Subject Access Requests (SARs) free of charge within one calendar month.
  • The Right to Rectification: The right to have inaccurate or incomplete personal information corrected or updated without delay.
  • The Right to Erasure ('Right to be Forgotten'): The right to request the deletion or removal of your personal data where there is no overriding legal, insurance, or disciplinary justification for its continued processing.
  • The Right to Restrict Processing: The right to 'block' or suppress the processing of your personal data under certain conditions, such as during an active dispute over accuracy.
  • The Right to Object: The right to object to processing based on legitimate interests or direct marketing (including immediately opting out of the BAHA newsletter).

11. Privacy Policy Amendments and Review

The BAHA Executive Committee retains absolute authority to update, amend, and publish this Privacy Policy from time to time. To ensure continued compliance with statutory data protection standards and operational alignment, this policy shall be reviewed regularly.

Any updates will be published immediately on the BAHA website, which serves as the active master copy. Where material changes are made to how we collect, process, or share personal data, the Alliance will highlight these changes on the website and, where appropriate, notify Member Association Secretaries. We encourage all members, practising healers, and affiliates to review this policy periodically to remain informed of our data protection standards.

Any healer who believes that BAHA has processed their personal data unlawfully or failed to uphold their statutory rights has the formal right to lodge a complaint with the UK's independent data regulator, the Information Commissioner's Office (ICO). However, we respectfully request that you contact the BAHA Secretary first so that we may work to resolve any administrative concerns or disputes immediately and amicably.

Last updated August 2026