Privacy & Cookie Policy

Last updated: April 2026  ·  The Food Phoenix (thefoodphoenix.com)  ·  Operated by Dr Catriona Walsh

The short version: We don't sell your data. We don't share it with advertisers. We use Google Analytics to understand how people find and use this site, and we only activate it after you give us permission. That's it.

1. Who We Are

This website is operated by Dr Catriona Walsh, trading as The Food Phoenix, a nutrition and lifestyle coaching service.

Contact:
Email: admin@thefoodphoenix.co.uk
Website: www.thefoodphoenix.com
Address: 235 Cavehill Road, Belfast BT15 5BQ, Northern Ireland, United Kingdom

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), Dr Catriona Walsh is the data controller for personal data collected through this website.

2. What Data We Collect and Why

2a. Analytics Data (Google Analytics)

We use Google Analytics 4 (GA4) to understand how visitors find and use this website — which pages are most helpful, where people come from, and whether the site is working properly. This helps us improve the content and experience we offer.

We only activate Google Analytics after you give explicit consent via the cookie banner. If you decline, GA does not load and no cookies are set.

What Google Analytics collects:

  • Pages visited and time spent on each page
  • How you arrived at the site (e.g. search engine, social media, direct)
  • General geographic location (country/city level — not precise location)
  • Browser type and device type
  • Anonymised IP address (we have configured GA4 to anonymise IP addresses — your full IP is never stored)

What Google Analytics does not collect: your name, email address, or any information that directly identifies you as an individual.

Data is processed by Google LLC. For more information, see Google's Privacy Policy.

Legal basis: Consent (Article 6(1)(a) UK GDPR / EU GDPR).
You may withdraw consent at any time using the Cookie Settings link.

2b. Contact Form / Enquiry Data

If you fill in a contact or enquiry form on this website, we collect the information you submit — typically your name, email address, and the details of your enquiry. We use this solely to respond to you.

Legal basis: Legitimate interests (Article 6(1)(f) UK GDPR) — responding to enquiries you have initiated.

We do not add you to any mailing list without your explicit agreement.

2c. Email Newsletter

We operate two separate email newsletters:

The Food Phoenix Newsletter (marketing emails, programme updates, and health content) is managed through VBOUT, an email marketing platform. If you subscribe via our website or a lead magnet, your name and email address are stored in VBOUT and used solely to send you the content you signed up for. You can unsubscribe at any time via the link in any email. See VBOUT's Privacy Policy for details of how they handle that data.

The Food Phoenix Substack (long-form articles and updates) is hosted at thefoodphoenix.substack.com. Substack processes your email address and subscription data independently. See Substack's Privacy Policy for details.

Legal basis: Consent — you actively choose to subscribe to either or both newsletters. Subscribing to one does not subscribe you to the other.

2d. Coaching Programme Data

If you become a coaching client, we collect and process additional personal information as necessary to deliver the programme — including health history, dietary records, and relevant lifestyle information you share with us. This information is handled with the utmost care and confidentiality.

Legal basis: Contract (Article 6(1)(b) UK GDPR) — necessary to provide the service you have engaged us for, and where relevant, explicit consent for any processing of health-related data (Article 9(2)(a) UK GDPR).

Client data is never shared with third parties except where strictly necessary to deliver the service (e.g., a dietary analysis app), and never sold or used for marketing.

2e. Surveys & Research

We occasionally run surveys — for example, research into patient experiences of gadolinium toxicity, interest surveys for new products or tools, and similar initiatives. Surveys are conducted with minimal collection of identifying information.

Surveys are typically hosted on Google Forms or similar platforms. Please note that while we do not ask for your name in most surveys, Google's servers may log your IP address as standard web traffic when you access a form. We do not see or store your IP address in the survey responses themselves.

Survey responses are used for the purpose stated at the top of each survey (such as research publication, service development, or product planning). A brief consent statement and explanation of use is included at the start of every survey.

Legal basis: Consent — by submitting a survey, you agree to the use described. Where surveys involve health data, explicit consent is obtained within the survey form.

2f. Session Notes & AI Transcription

Coaching sessions take place on Google Meet. We do not routinely record sessions as audio or video. Notes are taken during sessions, and — with your explicit written consent obtained before your first session — we also use Google Gemini AI (built into Google Meet) to automatically generate a transcript and session notes after each call. This allows us to remain fully present during the session rather than typing notes throughout.

AI-generated transcripts are stored within our Google Workspace account (EU-based) and are not shared with any third party. You may withdraw consent for AI transcription at any time by emailing us at admin@thefoodphoenix.co.uk.

If we do not receive your written consent before the first session, we will not activate Gemini transcription. Manual notes will still be taken.

Legal basis: Explicit consent (Article 9(2)(a) UK GDPR) — required before AI transcription is activated.

3. Cookies

What is a cookie?

A cookie is a small text file stored on your device by a website you visit. They're widely used to make websites work, remember your preferences, and gather usage information.

Cookies we use

CookiePurposeDurationProvider
tfp_cookie_consentRemembers your cookie choice (accepted/declined) so we don't ask every visit12 monthsThe Food Phoenix (localStorage)
tfp_cookie_consent_dateRecords when you gave consent, so we can ask again after 12 months as required by law12 monthsThe Food Phoenix (localStorage)
_gaGoogle Analytics — distinguishes unique users for traffic analysis12 monthsGoogle LLC (only if accepted)
_ga_*Google Analytics — maintains session state for traffic analysis12 monthsGoogle LLC (only if accepted)
__cf_bm and relatedCloudflare Bot Fight Mode — distinguishes legitimate visitors from automated bot traffic to protect the website from abuse. Strictly necessary for security.30 minutes (session)Cloudflare, Inc. (strictly necessary — set automatically)

Note on our consent storage: We use your browser's localStorage (not a cookie) to store your consent choice. This is a small piece of data stored locally on your device that is not transmitted to our servers.

Security cookies

We use Cloudflare to protect this website against malicious bots and security threats. Cloudflare may set a strictly necessary security cookie (__cf_bm and related) on your browser to distinguish legitimate visitors from automated traffic. This processing is carried out on the basis of our legitimate interests in maintaining a secure website (Article 6(1)(f) UK GDPR). Cloudflare does not use this data for advertising or tracking. For more information, see Cloudflare's Privacy Policy.

Because these cookies are strictly necessary for security, they are set automatically and cannot be disabled without affecting the basic operation of the site.

Video content

Some pages on this site link to video content hosted on Adilo (BigCommand). The video player is hosted on Adilo's own platform at adilo.bigcommand.com. When you click through to watch a video, your browser connects to Adilo's servers, which may process your IP address and device information in accordance with BigCommand's Privacy Policy and Cookie Policy. We do not embed Adilo video players directly on this site — you choose whether to navigate to Adilo's platform.

Some pages may also reference YouTube content. Where YouTube videos appear, we use YouTube's privacy-enhanced mode (youtube-nocookie.com), which means YouTube does not set any cookies unless you actually press play. If you play a video, YouTube may set its own cookies — see Google's Privacy Policy for details.

Managing your cookie choices

You can change your cookie preferences at any time by clicking Cookie Settings. This will clear your existing choice and reload the cookie banner.

You can also delete cookies directly through your browser settings. Note that doing so won't automatically prevent Google Analytics from loading on future visits if you previously accepted — use Cookie Settings for that.

4. How Long We Keep Your Data

  • Analytics data: Processed by Google according to your retention settings in GA4 (we have set this to 14 months in line with standard practice).
  • Contact enquiries: Retained for as long as reasonably necessary to resolve your enquiry, typically no longer than 2 years.
  • Newsletter subscriptions: Until you unsubscribe.
  • Coaching client records: Retained for 8 years after the end of the coaching relationship. This follows NHS guidance for health-related records and reflects the nature of the health information we handle. You may request earlier deletion; we will comply unless a legal obligation to retain the data applies.
  • Financial and billing records: Retained for 7 years in accordance with HMRC requirements.
  • Anonymised data (such as aggregated survey findings, anonymised case study patterns, or testimonials from which all identifying information has been removed): retained indefinitely, as anonymised data falls outside the scope of UK GDPR.

5. Who We Share Your Data With

We do not sell your data. We do not share it with advertisers.

We may share data with third-party service providers solely to operate this website and deliver our services. All third parties are contractually required to handle your data in accordance with applicable data protection law.

Client & programme platforms

  • FuseBase — secure client portal used to store coaching programme materials and client records. FuseBase operates at HIPAA-compliant level. Only coaching clients have access to their own data within this platform.
  • Nutritics / Libro — dietary analysis app used optionally within coaching programmes. Nutritics acts as a separate data processor for any food diary data you choose to log.

Communications & call platforms

  • Google LLC — Google Analytics (only if you consent), Google Workspace (email and document storage), and Google Meet (video consultations for coaching clients). Google Meet may use AI transcription (Google Gemini) to generate session notes — this is only activated with your explicit prior consent. Google is certified under the EU-US Data Privacy Framework.

Email marketing

  • VBOUT — email marketing platform (only if you subscribe to our newsletter or download a free resource).
  • Substack — newsletter hosting (only if you subscribe via Substack).

Client report & document delivery

  • Gamma (Gamma Technologies) — a US-based platform used to create client health reports and programme documents. Documents are delivered either as downloaded files attached to email, or — where file size requires — uploaded to Google Drive and shared via a secure link. Gamma may also be used for documents delivered as part of email nurture sequences or programme materials. Gamma's servers may log basic access data (such as IP address and timestamp) when a link is opened. See Gamma's Privacy Policy.

AI writing assistance

We occasionally use AI writing tools — including Anthropic Claude and Google Gemini — to assist in drafting client health reports and correspondence with healthcare professionals. Before any information is submitted to an AI tool, it is fully anonymised: names, dates of birth, addresses, and any other directly identifying details are removed. Only anonymised health and lifestyle information is processed in this way. The resulting draft is then reviewed, personalised, and approved by Dr Catriona Walsh before being shared with any client or third party. Clients are sent a copy of any correspondence drafted on their behalf for review and approval before it is sent.

AI tools are used solely as writing aids — they do not make clinical decisions, access your records directly, or receive any information that could identify you as an individual. If you would prefer that AI tools are not used in preparing your reports or correspondence, please let us know. We will always respect this preference; please be aware that reports prepared without AI assistance may be shorter and less detailed in their presentation.

Workflow automation

  • Pabbly Connect — a workflow automation tool that may be used to pass data between platforms (for example, connecting a sign-up form to our email marketing list). Where personal data flows through Pabbly, it acts as a data processor. Pabbly Connect is subject to its own Privacy Policy. We will update this section as specific automations are implemented.

Peer consultation & professional development

We may occasionally discuss fully anonymised case information with a peer consultant or professional advisor for quality assurance and continuing professional development purposes. No identifying information is shared in these contexts.

Website & technical

  • Grigora — our website hosting platform.
  • Cloudflare — website security and bot protection. Cloudflare processes visitor IP addresses and browser data to identify and block malicious automated traffic. This is a strictly necessary security function. Cloudflare is headquartered in the United States and is certified under the EU-US Data Privacy Framework. See Cloudflare's Privacy Policy.

Professional advisors

  • Lawyers, accountants, or insurers — only if required for compliance or legal purposes, and only to the extent necessary.

We may disclose your data if required to do so by law or in response to valid legal process.

6. International Data Transfers

Some of our service providers (including Google, VBOUT, and FuseBase) are based in the United States. Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), or participation in recognised data transfer frameworks such as the EU-US Data Privacy Framework.

7. Your Rights

Under UK GDPR (and EU GDPR where applicable), you have the following rights in relation to your personal data:

  • Right of access — to request a copy of the data we hold about you.
  • Right to rectification — to ask us to correct inaccurate data.
  • Right to erasure — to ask us to delete your data (subject to any legal obligations to retain it, such as the 8-year health records retention period).
  • Right to restrict processing — to ask us to limit how we use your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, commonly used format.
  • Right to object — to object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at admin@thefoodphoenix.co.uk. We will respond within one calendar month.

If you are unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint  ·  0303 123 1113

If you are in the EU, you may also contact your national data protection authority. We encourage you to contact us first so we can try to resolve any concerns directly.

8. Data Security

We take the security of your personal data seriously. Measures in place include password protection, encryption where possible, access controls, and use of platforms with appropriate security certifications. Only Dr Catriona Walsh has access to client records — we do not employ staff with access to client data.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by law.

9. Confidentiality & Safeguarding

All information you share within our coaching relationship is treated as strictly confidential. We will not disclose your personal information to any third party without your explicit consent, except in the following limited circumstances where we are legally or ethically required to do so:

  • Risk to life: If we have serious and credible concern that you or another person is at immediate risk of significant harm or death, we may be required to disclose relevant information to appropriate emergency services or authorities without your prior consent.
  • Child protection: If information comes to our attention that raises a genuine concern about the safety or welfare of a child or young person (under 18), we have a legal and ethical duty to report this to the appropriate statutory authorities (such as social services or police), regardless of your wishes. This obligation overrides our normal duty of confidentiality.
  • Legal requirement: If we are required to disclose information by a court order or other valid legal process.

In any of the above situations, we will disclose only the minimum information necessary and, wherever possible, we will inform you that a disclosure has been made or is being considered — unless doing so would increase the risk of harm to you or another person.

10. Medical Disclaimer

The content on this website is provided for informational and educational purposes only. It does not constitute medical advice, diagnosis, or treatment. Dr Catriona Walsh operates exclusively as a nutrition and lifestyle coach and does not practise medicine through this website or service.

Always consult a qualified medical professional before making changes to your diet, supplements, or lifestyle, particularly if you have a diagnosed medical condition.

11. Children's Privacy

Our services are primarily directed at adults. We do not knowingly collect personal data from anyone under the age of 13 without parental or guardian consent. Where we work with clients under 18, all communications and records are managed through the relevant parent or legal guardian. If you believe a child has provided us with personal data without appropriate consent, please contact us and we will address it promptly.

12. Links to Other Websites

This website may contain links to external sites (such as research papers, partner organisations, or social media). We are not responsible for the privacy practices of those sites and encourage you to read their own policies.

13. Changes to This Policy

We may update this policy from time to time. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review it periodically. Where changes materially affect how we handle your data, we will take reasonable steps to notify active clients directly.

14. Contact Us

Questions, concerns, or data requests — please get in touch:

Dr Catriona Walsh — The Food Phoenix
Email: admin@thefoodphoenix.co.uk
Website: www.thefoodphoenix.com
Address: 235 Cavehill Road, Belfast BT15 5BQ, Northern Ireland, United Kingdom

This policy was last reviewed and updated in April 2026.

Medical Disclaimer

The information provided on this website is for educational and informational purposes only. It is not intended as a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition. Never disregard professional medical advice or delay in seeking it because of something you have read on this website.

Dr Catriona Walsh provides nutrition and lifestyle coaching services. While she is a former consultant paediatrician, the services offered through this website do not constitute medical practice and are not a replacement for appropriate medical care. If you think you may have a medical emergency, call your doctor or emergency services immediately.

The testimonials and case studies presented represent individual experiences and results. Individual results may vary. No guarantee of specific results is made or implied.

© 2025 The Food Phoenix. All rights reserved.

Follow me: