Privacy
Privacy
What is held about business contacts, families and parents, why it is held, who sees it, and what you may ask at any time.
1Who is responsible
ANGKOR QUANTUM FENG SHUI & HEALING, trading as The Grand Years, is responsible for the information described on this page. Privacy questions, requests, complaints and formal notices go to [email protected].
The Grand Years is established outside the United Kingdom. Before any continuing UK outreach route is activated, the practice records whether a UK representative is required and, if so, publishes that representative’s name and contact details here.
2What this covers
This notice covers this site; individual business introductions; enquiries and discovery-call bookings; the letters families and parents write; the arrangement and delivery of a membership; session and correspondence records; invoicing; objections; and the minimum records needed to prevent unwanted contact. Service providers also operate under their own privacy terms, but that does not remove the practice’s responsibility for choosing and supervising them.
3What is held
For an individual business introduction, the practice may hold a person’s name, employer, public professional role, corporate work contact, the exact public professional source and access date, a short relevant excerpt, the message and its evidence record, delivery or reply status, and any objection or contact preference. It does not use inferred family circumstances, wealth, private social content, health, diagnosis, disability, treatment, bereavement, crisis or vulnerability as outreach signals.
A letter about a parent is personal by nature, and some of it may concern health or wellbeing. For the service itself, the practice may hold what a family or parent chooses to write; the session record; Jonathan’s notes and correspondence; the contact details needed to reply; billing identity and country, separated from health-adjacent information; booking records; and ordinary security and technical logs. Full card numbers, security codes and bank credentials are not held by the practice.
4Where it comes from
Service information comes mostly from the family or parent directly, with booking and payment status from the relevant provider. Business-contact information may come from an official company website, another approved public professional source, a referral or an approved business-contact provider. The first business introduction identifies the source or explains it as specifically as reasonably possible and links to this notice. A public source does not remove anyone’s privacy rights. Where you write to us about your mother, you are giving us information about another adult — please tell her that you have, and share only what is relevant to the work.
5What is relevant, and what is not
Please send what bears on the work and no more. A complete medical history is not wanted and is not needed. Business-contact research is limited to relevant professional facts and excludes private-family and sensitive information. Never send passwords, card details, bank credentials or copies of identity documents; nothing here requires them.
6Why it is held
Information is used to respond to enquiries; decide whether one restrained business introduction is relevant; prepare and human-review that introduction; honour objections; arrange discovery calls; understand a parent; arrange, deliver and record the work; correspond with the family and parent; raise invoices and keep required accounts; maintain security; prevent misuse; and comply with law.
Where UK data-protection law applies, the proposed basis for a named employee at a verified limited company or limited liability partnership is legitimate interests, supported by a purpose, necessity and balancing assessment before contact. Contract steps and performance support service administration; explicit consent or another valid legal condition is used for health or other special-category information where required; legal obligation supports required accounting and compliance records. Consent is not used to disguise an unsolicited business introduction where it has not been given.
7Business introductions, objections and suppression
The practice may send a small number of individually researched introductions to named people at verified corporate work addresses. It does not contact sole traders, personal addresses or people selected through health, family-vulnerability or other sensitive information under this route. It does not use open pixels, hidden click tracking, bought bulk lists, false familiarity or automated follow-up in the controlled pilot.
You have an absolute right to object to direct marketing. Reply “no”, use the visible opt-out in the message, or write to [email protected]. The contact stops immediately. The practice keeps only the minimum suppression record needed to prevent another contact, including after re-import or across another trading name. Personal information is not sold, rented or traded.
8Between the two of you
Confidentiality runs both ways and it is absolute. Nothing she confides reaches the person paying. Nothing the payer writes reaches her. Where she is glad for news to travel, exactly that travels and nothing more. This is the promise the practice is least willing to bend, and it survives the ending of a membership.
9Who else sees it
Only the people and services needed for the relevant purpose see information. Depending on the route actually enabled, these may include the website host and security provider; Supabase for the protected control-plane database; Google Workspace, Gmail and Google Cloud Pub/Sub for email and reply events; OpenAI for minimised, structured drafting and review; Calendly when someone chooses to book; a payment provider; an accountant; and, where necessary, a solicitor or privacy adviser. Each receives only what its role requires. The current controlled outreach route does not use Smartlead or Anthropic.
Information is disclosed beyond those roles only where the law requires it or where it is genuinely necessary to protect someone from serious harm. A current provider and transfer summary, together with available information about safeguards, may be requested from the privacy contact.
10Where it is held
The practice operates from Cambodia and its users and providers may be in the United Kingdom, United States, European Union, Singapore or another provider location. Before making a transfer restricted by applicable law, the practice identifies the parties and purpose, checks whether adequacy rules apply and, where they do not, records the applicable contractual safeguard and data-protection test or other lawful route. A restricted transfer is not made merely because it is small. Information about an applicable safeguard and how to obtain a copy may be requested from the privacy contact.
11How long it is kept
An outreach candidate who is not selected is kept for no more than 90 days. A contacted business prospect’s minimum evidence, message and interaction record is kept for up to 24 months after the last meaningful interaction, unless a shorter period or law requires otherwise. Reply content is removed when no longer needed for human handling. An objection is kept as a minimal suppression proof for as long as needed to honour it. Rejected sensitive material is not retained as a targeting record.
Service records are kept while a membership runs. Afterwards, family and parent letters, session records, Jonathan’s notes and correspondence are normally kept for two years; invoices and accounting records for three years or longer where law requires; and ordinary technical records for twelve months. An enquiry that never becomes a membership is deleted rather than kept indefinitely. Backups may retain a protected copy for up to 30 additional days. Records are then deleted or irreversibly de-identified, subject to a lawful hold needed for a dispute, security matter or legal obligation.
12Security
Access is limited by role and environment; production and testing are separated; credentials are kept in protected secret storage; health-adjacent notes are kept apart from invoicing and outreach records; administrative actions are restricted and audited; message renders, objections, replies and sending limits are checked deterministically. No email, message or storage system can be promised to be perfectly secure. Suspected incidents are contained, investigated and notified where applicable law requires. If you think something has been exposed, say so at once.
13Cookies and analytics
This site uses only what is strictly necessary to serve the pages and keep them secure. There are no analytics cookies, no advertising cookies, no cross-site trackers and no social-media pixels. If any of that ever changes, this page is updated first and consent asked for where the law requires it.
14Service letters and optional communications
When you enquire, book or arrange a membership, your email address is used to reply and to send the necessary booking, service, billing, safety and legal communications. Optional newsletters or general promotional letters are separate from the controlled business-introduction route, are not assumed from an enquiry or membership, and include a clear way to stop.
15Accounts and testimonials
No family’s words, no parent’s account and no identifying detail is ever published without separate permission asked for and given in writing. Agreeing to a membership grants no permission to publish anything. Permission can be limited, anonymised, or withdrawn for future use.
16Artificial intelligence
Private family letters, session records, health information, photographs and practitioner notes are not intentionally submitted to a public artificial-intelligence model for training, fine-tuning or model development. For business introductions, the practice may provide the OpenAI API with minimised public professional information for structured research, drafting and quality review. The exact source and output are retained only within the stated limits. A human reviews every pilot message. A model cannot approve or send a message, override an objection, reserve sending capacity or restart a sequence, and no solely automated decision produces legal or similarly significant effects.
17Adults and decision-making capacity
The service and this website are intended for adults. Where an older parent cannot make a particular decision, the practice requires the family to identify the lawful authority or other valid basis relied on before information is used for the service. The parent’s dignity, confidentiality and rights remain. The outreach engine never uses a person’s capacity, diagnosis or vulnerability as a signal.
18What you may ask, at any time
Depending on the law that applies, you may ask for access to personal information about you, correction, deletion, restriction, objection or a portable copy, and may withdraw a consent you gave. Write and ask; identity may need confirming first, and where a response would reveal protected information about another person, that part may be withheld.
Your right to object to direct marketing is absolute. It is brought to your attention separately in every business introduction and takes effect immediately.
If UK data-protection law applies and you are not satisfied with the response, you may complain to the Information Commissioner’s Office. Its current contact details are at ico.org.uk/make-a-complaint. You may also complain to another competent data-protection authority where the law gives you that right.
19Changes, and how to reach us
Version 2.0, effective 4 August 2026. Where something material changes for a family, member or business contact already affected, they are told rather than left to notice where law requires. Questions, objections and requests go to [email protected].