Privacy Policy

Privacy Policy

Next Level Nutrition Ltd Last updated: August 2026

1. Who we are

Next Level Nutrition Ltd (“we”, “us”, “our”) provides 1:1 nutrition coaching services. This policy explains what personal information we collect about you, why we collect it, what we do with it and what rights you have over it.

We are the data controller for the information described in this policy.

Contact details

We are registered with the Isle of Man Information Commissioner as a data controller. You can search the public register at www.inforights.im.

We do not have a Data Protection Officer. We are not required to appoint one. Any question about your personal information should go to hello@nextlevelnutrition.me.

2. The law we work to

We handle your personal information in line with Isle of Man data protection law. That means the Data Protection Act 2018, the Data Protection (Application of GDPR) Order 2018 and the GDPR and LED Implementing Regulations 2018, together referred to here as the Applied GDPR. We also follow the Unsolicited Communications Regulations 2005, which govern marketing by email, text and phone.

3. Information we collect

3.1 When you enquire or book a call

Through the contact forms on our website, or through the TidyCal booking page, or by email, phone, text or WhatsApp:

3.2 When you become a client

To coach you properly we collect a broader and more sensitive set of information:

Health information is “special category data” under the Applied GDPR and gets extra protection. Section 4 explains the legal basis we rely on for it.

3.3 When you sign up to our email list

3.4 When you use our website

4. Why we use your information and our legal basis

We must have a lawful basis under Article 6 of the Applied GDPR for everything we do with your personal information. Where health information is involved we also need a condition under Article 9.

What we doInformation usedArticle 6 basis
Respond to your enquiry and arrange a strategy callContact details, your messageConsent, given when you tick the consent box on the form. Also steps taken at your request before entering a contract
Deliver coaching, including check-ins, calls and WhatsApp supportAll client information listed at 3.2Performance of a contract with you
Take payment and chase unpaid invoicesContact and payment recordsPerformance of a contract with you
Keep accounting and tax recordsTransaction recordsLegal obligation
Send you marketing emails, offers and programme launchesName, email, engagement dataConsent, which you can withdraw at any time
Keep records to defend a complaint, claim or insurance issueClient records and coaching notesLegitimate interests, being our interest in protecting the business against legal claims
Improve the website and understand how it is usedWebsite usage dataConsent for non-essential cookies. Legitimate interests for essential site operation and security
Share client feedback or testimonialsYour name, comments, before and after photosConsent, given separately in writing each time

Health and other special category information

We rely on your explicit consent under Article 9(2)(a) of the Applied GDPR to collect and use health information about you.

You give that consent when you sign your coaching agreement and complete your intake questionnaire. It is separate from your agreement to the contract itself, it is written down, and it is specific about what we are collecting and why.

You can withdraw it at any time by emailing hello@nextlevelnutrition.me. If you withdraw it, we can no longer coach you, because we cannot give safe or useful nutrition advice without it. Withdrawing consent does not affect anything we did lawfully before you withdrew it, and it does not automatically delete records we are required to keep for tax or legal claim purposes. See section 6.

We are not a regulated healthcare provider and we do not rely on the healthcare or medical diagnosis conditions in Article 9(2)(h).

5. Who we share your information with

We do not sell your information. We do not share it for anyone else’s marketing.

We use the following service providers, who process personal information on our behalf under written contracts that meet Article 28 of the Applied GDPR:

ProviderWhat it doesWhere data is processed
20iWebsite hosting and the storage of contact form submissionsUnited Kingdom
ActiveCampaignEmail marketing, automations and contact recordsUnited States
TidyCalStrategy call bookingsUnited States
WhatsApp (Meta Platforms)Daily client messaging supportGlobal
Google (Workspace, Maps, [Analytics])Email, file storage, embedded map, website analyticsGlobal
StripePayment processingGlobal
Evolution AccountingAccounts and tax filingIsle of Man

We may also share information where we are legally required to, for example with a court, a regulator, our insurers or our professional advisers, or where there is a serious and immediate risk to someone’s safety.

Messaging apps. WhatsApp messages are encrypted in transit between us, but Meta still processes information about your account and your use of the service under its own terms. If you would rather not discuss health matters over WhatsApp, tell us and we will use email instead.

6. How long we keep your information

RecordRetention period
Enquiries that do not become clients12 months from last contact
Client records, including health information and coaching notes7 years from the end of the coaching relationship
Financial and transaction records7 years, to meet Isle of Man tax and company law requirements
Email marketing recordsUntil you unsubscribe, plus a suppression record kept indefinitely so we do not email you again by mistake
Website analytics data[PERIOD, e.g. 14 months]

The 7 year period for client records reflects the time limits for bringing a contractual or negligence claim, and the requirements of our professional indemnity insurer. Once a period ends we securely delete or anonymise the information.

7. Sending information outside the Isle of Man

Several of our providers are based in the United States or process data globally. When your information is transferred outside the Isle of Man to a country without an adequacy decision, we make sure one of the safeguards in Chapter V of the Applied GDPR is in place. In practice that means the standard contractual clauses built into our contracts with those providers, supported by their own technical and organisational security measures.

You can ask us for details of the safeguards that apply to any specific transfer.

8. Your rights

Under the Applied GDPR you have the right to:

To exercise any of these, email hello@nextlevelnutrition.me. We will respond within one month. That can be extended by two further months for complex requests, and we will tell you if that happens. There is no charge unless a request is manifestly unfounded or excessive.

We may ask you to confirm your identity before we release information.

9. Cookies

Our website uses cookies and similar technologies. Cookies are small text files stored on your device.

We use:

The Isle of Man’s Unsolicited Communications Regulations 2005 do not yet include the specific cookie consent requirements found in UK and EU law. The Isle of Man Information Commissioner regards compliance with those requirements as good practice, and because many of our visitors are in the UK, we follow the higher standard. You will be asked to accept or reject non-essential cookies when you first visit, and you can change your choice at any time via [COOKIE SETTINGS LINK].

You can also block or delete cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site working.

10. Marketing

We will only send you marketing emails if you have opted in.

Every marketing email includes an unsubscribe link. Click it and you are removed straight away. You can also email hello@nextlevelnutrition.me at any time.

Unsubscribing from marketing does not stop the service emails we need to send you as a client, for example your check-in reminders, call bookings and invoices.

11. Security

We protect your information with measures appropriate to the risk, including encrypted storage, multi factor authentication on our accounts, access restricted to Angela Clucas alone, encrypted transmission via HTTPS across the website, and written data processing agreements with every supplier who handles your data.

No transmission of information over the internet is completely secure. If we suffer a personal data breach that poses a risk to you, we will report it to the Isle of Man Information Commissioner within 72 hours and tell you directly where the risk to your rights and freedoms is high.

12. Children

Our services are for adults. We do not knowingly collect information about anyone under 18. If you believe a child has given us their information, contact us and we will delete it.

13. Links to other websites

Our website links to other sites, including our Facebook and Instagram pages and our TidyCal booking page. We are not responsible for their privacy practices. Read their policies before giving them your information.

14. Changes to this policy

We review this policy at least once a year. When we make significant changes we will post a notice on the website. The date at the top shows when it was last updated.

15. Complaints

If you are unhappy with how we have handled your personal information, contact us first at hello@nextlevelnutrition.me and we will try to put it right.

You also have the right to complain to the independent supervisory authority for the Isle of Man:

Isle of Man Information Commissioner P.O. Box 69 Douglas Isle of Man IM99 1EQ

Telephone: +44 (0)1624 693260 Email: ask@inforights.im Website: www.inforights.im