Privacy Policy

Tatiana Vera Ostara (trading as OstaraSoma)

Last updated: 31 August 2026

1. Who I Am

I am Tatiana Vera Ostara, an independent practitioner operating under the trading name OstaraSoma. I am the data controller for the personal information described in this policy, which means I decide why and how that information is used.

ICO Registration Number: ZC034831
Email: hello@ostarasoma.com


2. What This Policy Covers

This policy explains how I collect, use, store and share personal information when you visit the OstaraSoma website, contact me, book or receive a service, attend a talk or workshop, or deal with me on behalf of an organisation.

It covers Trauma-Informed Somatic Therapy, The Pivot, Talks & Workshops and The Turning.


3. What Personal Information I Collect

Website enquiries and discovery calls

·        Your name and contact details, such as your email address and, where you provide it, your phone number.

·        The contents of your enquiry and any information you choose to include.

·        Information needed to arrange or follow up a discovery call.

1:1 Trauma-Informed Somatic Therapy

If we agree to work together, I may collect information needed to provide and administer the service, including:

·        contact and appointment details;

·        information provided through intake, informed-consent and other onboarding documents;

·        relevant information you choose to share about your circumstances, experiences, wellbeing or health;

·        session notes and administrative records;

·        communications relating to our work together.

Some of this information is likely to be special category personal data under UK data-protection law. This includes information you choose to share yourself about physical or mental health and may, depending on what you choose to share, include other particularly sensitive information such as racial or ethnic origin, religious or philosophical beliefs, sex life or sexual orientation.

The Pivot

For The Pivot, I may collect contact and appointment information, career and employment information, CVs or application material you choose to share, notes relating to our work together, and communications needed to provide the service. If you choose to share health or other sensitive information, that information may also be special category personal data.

Talks, Workshops and The Turning

For talks, workshops and organisational bookings, I may collect business contact details such as name, role, organisation, email address and phone number, together with booking, invoicing, accessibility and event information needed to arrange and deliver the session.

I do not require workshop participants to disclose personal experiences. If a participant voluntarily shares personal or sensitive information with me, I will only use or retain it where there is a clear and lawful reason to do so.

Payments and financial records

Payments are currently made by bank transfer to my NatWest account. When you make a payment, I may receive information connected with the transaction, such as your name, payment reference, amount paid and transaction details. I use this information to identify and reconcile payments, maintain financial records and meet applicable accounting, tax and legal obligations.

I do not collect or store card details through OstaraSoma.

Website and technical information

Framer and other services needed to operate the website may process technical information such as IP address, browser or device information and security or performance data. If I use non-essential analytics, cookies or similar technologies, they will only be used in accordance with the consent requirements that apply. Please see the Cookies Policy for the website's current cookie information.


4. Why I Use Your Information and My Lawful Bases

I only use personal information where I have a lawful reason to do so. The lawful basis depends on why the information is being used.

·        Steps before entering a contract and contract - to respond to a request to work together, arrange a booking, provide a service you have purchased, communicate about that service and administer the working relationship.

·        Legitimate interests - for proportionate business administration, responding to general enquiries, maintaining appropriate business records, securing my systems and managing OstaraSoma, where those interests are not overridden by your rights and interests.

·        Legal obligation - where I need to use or retain information to comply with the law, including applicable tax, accounting, court or regulatory obligations.

·        Consent - where I specifically ask for consent and consent is an appropriate basis for the particular use.

I do not currently use your information to send an OstaraSoma newsletter or unrelated marketing simply because you have enquired about or used a service.


5. Special Category Personal Data

Because somatic therapy may involve information about health and other sensitive aspects of your life, I need an additional legal condition under Article 9 of the UK GDPR as well as an Article 6 lawful basis.

For special category information that is necessary for me to provide 1:1 somatic therapy, I rely on your explicit consent under Article 9(2)(a). My onboarding process asks you to expressly confirm that you consent to the processing of the relevant special category information for the purpose of providing and administering your therapy.

You can withdraw that explicit consent at any time by contacting me. Withdrawal does not make processing that took place before withdrawal unlawful. Because some sensitive information is necessary for me to provide therapy safely and appropriately, withdrawing consent may mean that I can no longer continue to provide that service. I will explain this with you if it arises.

For other uses of special category information, a different Article 9 condition may apply where the law permits or requires it - for example, where processing is necessary to establish, exercise or defend legal claims, to protect vital interests in the limited circumstances recognised by law, or for a specific safeguarding purpose supported by law.

I aim to collect only information that is relevant and reasonably necessary for the purpose, rather than collecting sensitive information simply because it may be interesting or potentially useful.


6. Confidentiality and When Information May Be Shared

Information shared in 1:1 somatic therapy is treated as confidential, subject to the limits explained in your informed consent and practice policies.

There may be circumstances in which I am required or permitted to share information without your consent. These may include where disclosure is required by law or a court order, where a specific safeguarding or legal obligation applies, or where I reasonably believe there is a serious risk of harm to you or another person.

A disclosure is not automatic simply because risk or a safeguarding concern is present. Where disclosure is not legally required, I will consider the circumstances carefully and may consult my supervisor, insurer or another relevant professional. Wherever reasonably possible and appropriate, I will discuss a proposed disclosure with you first. There may be circumstances where doing so would be unsafe, unlawful or could prejudice an investigation.

If information needs to be shared, I aim to disclose only what is reasonably necessary for the purpose.

I undertake regular professional supervision. Client material may be discussed in supervision to support safe and ethical practice, with identifying information minimised wherever reasonably possible.

Group workshops are not confidential in the same way as 1:1 therapy. I cannot guarantee what another participant may do with information someone chooses to share in a group.


7. Services I Use to Run OstaraSoma

I use a limited number of third-party services to operate OstaraSoma. Depending on the service and the circumstances, a provider may process information on my behalf or act as a separate controller for some of its own activities.

·        Framer - website hosting and website functionality.

·        Calendly - appointment scheduling.

·        Google Meet - online video sessions.

·        Google Drive - storage of PDFs, client documents and working records.

·        Microsoft Outlook - email and communications.

·        NatWest - business banking and bank-transfer payments.

I may also use professional advisers or service providers where reasonably necessary, such as an accountant, insurer, solicitor or IT support provider. I only share information that is reasonably necessary for the relevant purpose.

I do not sell personal information or share client or enquiry information with third parties for their own unrelated advertising.


8. International Transfers

Some of the technology providers I use are international organisations, so personal information may be processed or accessed outside the UK.

Google LLC states that it participates in the UK Extension to the EU-US Data Privacy Framework for relevant transfers from the UK. Microsoft Corporation also states that it participates in the UK Extension. Calendly states that it participates in the UK Extension and also provides contractual transfer safeguards, including the UK Addendum to the Standard Contractual Clauses. Framer B.V. is established in the Netherlands and its data-processing terms provide for recognised transfer mechanisms, including adequacy arrangements and the UK Addendum where required for onward transfers.

Where I make or permit a restricted transfer of personal information outside the UK, I rely on an applicable UK adequacy regulation or another recognised safeguard. Where the UK Extension to the EU-US Data Privacy Framework is relied upon, the relevant US recipient must have active certification covering the type of information transferred. I keep these arrangements under review because providers, sub-processors and legal mechanisms can change.

Where special category information is transferred, I take account of the additional requirements that apply to sensitive information.


9. Security

I take reasonable technical and organisational steps to protect personal information. These include password-protected accounts, access controls and limiting access to information to what is needed for the relevant purpose.

I use cloud services to store and communicate information, including Google Drive and Microsoft Outlook. No method of electronic storage or communication can be guaranteed to be completely secure.

If I become aware of a personal-data breach, I will assess it and take the steps required by data-protection law, including notifying the ICO and affected individuals where the applicable legal thresholds are met.


10. How Long I Keep Information

I keep personal information only for as long as I can justify for the purpose for which it is held. My standard retention periods are:

·        General enquiries where no working relationship begins: normally up to 12 months after the last meaningful contact, unless there is a reason to keep the correspondence for longer.

·        Discovery-call information where no service begins: normally up to 12 months after the call or last meaningful contact.

·        1:1 somatic therapy intake information, consent records, session notes and related client records: normally 6 years after our work ends. This period is intended to allow appropriate continuity, professional accountability and the handling of possible complaints or legal claims. Records may be deleted earlier where there is no continuing reason to retain them, or retained longer where there is a specific legal, insurance, safeguarding or claims-related reason.

·        The Pivot client records and material needed to evidence the service provided: normally 6 years after the working relationship ends, unless a shorter period is appropriate for material that is no longer needed.

·        Organisational booking agreements, invoices and core records relating to Talks & Workshops or The Turning: normally 6 years after the booking or end of the contractual relationship, where needed for business administration or possible contractual claims.

·        Accessibility or sensitive participant information provided for a particular workshop or event: deleted as soon as it is no longer needed for the event or any necessary follow-up, unless there is a lawful reason to retain it.

·        Financial and tax records: kept for at least the period required by HMRC. For a self-employed person, this is generally at least 5 years after the 31 January Self Assessment submission deadline for the relevant tax year.

At the end of a retention period, I delete or anonymise information unless there is a clear and lawful reason to keep it for longer. I review retention where circumstances change or where an individual makes a relevant request.


11. Your Data-Protection Rights

Depending on the circumstances and the lawful basis being used, you may have rights including:

·        the right to be informed about how your information is used;

·        the right to request access to your personal information;

·        the right to ask for inaccurate information to be corrected;

·        the right to ask for information to be erased in certain circumstances;

·        the right to ask for processing to be restricted in certain circumstances;

·        the right to object to certain processing, including some processing based on legitimate interests;

·        the right to data portability where the legal conditions for that right apply;

·        the right to withdraw consent at any time where consent is relied upon.

These rights are not absolute and do not all apply to every type of processing. If I cannot comply with a request, I will explain why where the law requires me to do so.

To exercise a right or ask a data-protection question, email hello@ostarasoma.com.


12. Your Right to Object

Where I rely on legitimate interests to process your personal information, you have the right to object to that processing in certain circumstances. If you object, I will consider your request and stop the processing unless I can demonstrate a lawful reason to continue that overrides the objection, or the information is needed for legal claims.


13. Complaints to the ICO

If you have concerns about how I use your personal information, I would welcome the opportunity to address them first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator.

ICO website: ico.org.uk


14. Cookies

The OstaraSoma Cookies Policy explains the cookies and similar technologies used on the website. Cookies that are strictly necessary for the website can be used without consent where the legal exemption applies. Non-essential cookies or analytics will not be set before the required consent has been obtained.


15. Changes to This Policy

I may update this Privacy Policy when my services, systems or legal obligations change. The latest version will be published on the OstaraSoma website with its last-updated date. Where a change materially affects how existing client information is used, I will take reasonable steps to bring it to the attention of the people affected where appropriate.


16. Contact

Tatiana Vera Ostara
OstaraSoma
Email: hello@ostarasoma.com
ICO Registration Number: ZC034831