Security Policy
At Spa Utopia, protecting the security of our clients’ personal and confidential information is a core priority. We take reasonable and appropriate measures to safeguard information against unauthorized access, use, disclosure, alteration, or destruction.
This Security Policy outlines the practices and controls we use to protect information collected through our website, booking systems, in-spa services, and related communications.
Information We Protect
We apply security safeguards to protect personal information, including contact details, appointment information, payment-related data, and any health or service-related information provided to us in the course of delivering spa and wellness services.
Administrative Safeguards
We maintain internal policies and procedures designed to protect information and limit access to authorized personnel only. These measures include employee confidentiality obligations, role-based access controls, and ongoing review of our privacy and security practices.
Physical Safeguards
Physical security measures are used to protect information stored at our locations. These include secured offices, restricted access areas, and locked storage for physical records containing personal information.
Technical Safeguards
We use reasonable technical safeguards to protect electronic information, including password protection, secure user authentication, encryption where appropriate, firewalls, and monitored systems to reduce the risk of unauthorized access.
Third-Party Service Providers
Where we use third-party service providers to support our operations, such as booking platforms, payment processors, or IT services, we require that they implement security measures that are comparable to our own and appropriate to the sensitivity of the information they handle.
Payment Security
Payment transactions are processed through secure third-party payment providers. Spa Utopia does not store full credit card numbers on its systems. Payment providers are responsible for maintaining compliance with applicable payment security standards.
Data Retention and Disposal
Personal information is retained only for as long as necessary to fulfill business, legal, or regulatory purposes. When information is no longer required, it is securely destroyed or permanently deleted using appropriate methods.
Monitoring and Improvements
We regularly review and update our security practices to reflect changes in technology, business operations, and emerging security risks. While no system can be guaranteed to be completely secure, we continuously work to maintain reasonable and appropriate safeguards.
Your Role in Security
Clients are encouraged to take steps to protect their own information when using online services, including safeguarding login credentials and notifying us immediately of any suspected unauthorized access related to their interactions with Spa Utopia.
Questions or Concerns
If you have questions or concerns regarding our security practices, you may contact us using the details below.
Contact Information
Email: privacy@360healthandwellness.ca
Mail: The 360 Degrees Health & Wellness Company #206 – 10183 152A Street
Surrey, BC V3R 4H6
Attention: Privacy Officer