LERÉI

Trust & Privacy

Private by design.

Privacy & Discretion Policy · Effective 19 August 2026 · Last updated 19 August 2026

LERÉI is a private women’s wellness residence built around trust, discretion and thoughtful personal service. We believe you should be able to focus on your wellbeing without wondering who can see your information, why it is being used or where it goes.

This Privacy and Discretion Policy explains how LEREI LTD collects and uses personal information when you visit our website, enquire or apply for membership, become a member, use the LERÉI or Hapana-powered app experience, visit the residence, contact our concierge, attend an event, make a booking, receive a service or otherwise interact with us. It also explains the additional care we take with health-related information and the choices and rights available to you.

1 Who is responsible for your information

LEREI LTD is the controller of personal information handled for LERÉI’s own purposes.

LEREI LTD
Company number 16216802 · Registered in England and Wales
Registered office: 2nd Floor, 171–175 Brompton Road, London, England, SW3 1NF

Privacy enquiries and rights requests may be sent to concierge@lerei.com or by post to the registered office above.

Some practitioners, clinicians and specialist partners may be separately responsible for information you give directly to them. We explain this further in section 9.

2 The information we collect

What we collect depends on your relationship with LERÉI and the services you choose to use.

Identity and contact information

This may include your name, title, date of birth, postal address, email address, telephone number, profile photograph and identifiers linked to your membership or digital account.

Enquiry, application and membership information

This may include information in an enquiry or membership application; membership status, start date and plan; eligibility or application records; membership preferences; communications about your membership; access credentials; and records concerning renewal, freezing, cancellation, suspension or termination. We will not ask for information about protected or particularly private matters unless it is relevant, lawful and proportionate to a defined purpose.

Bookings, attendance and service information

This may include classes, appointments, treatments, consultations, events and experiences requested or attended; waitlists, cancellations and no-shows; check-in and access records; service preferences; and related communications.

Concierge and preference information

Where you choose to tell us, we may record information that helps us provide a considered experience — for example preferred appointment times, communication preferences, dietary preferences, allergies, hospitality preferences, accessibility needs or details relevant to a request made to our concierge. We aim to remember what is useful, not to create an unnecessarily intrusive profile.

Health, fitness and wellbeing information

For some activities or services, we or a practitioner may need information about matters such as injuries, pregnancy, allergies, sensitivities, disabilities, medical conditions, medication, recent procedures, contraindications, fitness goals or other aspects of physical or mental wellbeing.

Information about health is special category personal data and receives additional protection under UK data protection law. We collect it only where there is a defined need and an appropriate legal basis and special-category condition. Where we rely on explicit consent, we will ask for it separately and clearly. Please do not include detailed medical information in a general website form or ordinary concierge message unless we ask for it through an appropriate channel.

Transaction and financial information

This may include membership and purchase history, amounts paid or due, invoices, refunds, payment status, billing address and limited payment-card information. Full card details are generally handled by our payment service provider rather than stored by LERÉI.

App and digital-service information

When you use a LERÉI-branded app, booking journey or member portal powered by Hapana or another supplier, information may include account and profile details, bookings, purchases, membership status, check-ins, device and app information, support interactions, push-notification preferences and information entered into available profile fields. The precise information depends on the functionality enabled by LERÉI. See section 8 for more about Hapana and digital partners.

Website, device and communications information

This may include IP address, browser and device type, operating system, referring page, pages viewed, approximate location inferred from IP, cookie or similar identifiers, interaction data and the date and time of a visit. We also retain correspondence and, where appropriate, a record of telephone or in-person requests. We do not record calls unless we tell you in advance.

Residence access, safety and incident information

This may include access and check-in records, guest records, emergency contacts, lost-property records, accident or incident reports, complaints and relevant security information.

CCTV

CCTV may operate in appropriately selected areas for safety, security, crime prevention and the protection of members, guests, staff and property. It will not be installed in treatment rooms, changing areas, toilets or other spaces where a high degree of privacy is reasonably expected. See section 13.

Photography and recordings

This may include photographs, video or audio captured with appropriate notice or permission at events, classes or brand productions. Identifiable promotional use is not treated as an automatic condition of membership. See section 14.

Information about guests and other people

If you provide information about a guest, emergency contact or another person, please provide only what is necessary and, where appropriate, let that person know you have shared it with us. Guests may also be asked to provide information directly when visiting the residence.

3 Where information comes from

We collect personal information:

  • directly from you, including through our website, app, forms, communications and conversations;
  • through your use of the residence, member services and digital services;
  • from someone acting for you, such as an assistant, parent or guardian where applicable, or authorised representative;
  • from a member who names you as a guest or emergency contact;
  • from practitioners or service partners where sharing is necessary, lawful and consistent with what you have been told;
  • from payment, identity, fraud-prevention, booking and technology providers;
  • from publicly available sources, but only where relevant and appropriate; and
  • from cookies and similar technologies, subject to the choices described on this site.

If we obtain information from another source, we will provide privacy information where the law requires it.

4 Why we use information and our lawful bases

We use personal information only where we have a lawful basis. The basis depends on the purpose and context.

PurposeExamples of informationLikely lawful basis
Respond to enquiries and take steps requested before membership or a bookingContact details, correspondence, requested servicesSteps before entering a contract; legitimate interests where appropriate
Assess and administer membership applicationsIdentity, application and correspondenceSteps before entering a contract; legitimate interests in operating a private membership community fairly and securely
Provide and administer membershipAccount, plan, bookings, attendance, concierge requests, feesPerformance of a contract; legitimate interests for proportionate service administration
Arrange and deliver classes, treatments, events and experiencesBooking, preference and relevant suitability informationPerformance of a contract; legitimate interests; consent where appropriate
Personalise member serviceVoluntary preferences and service historyLegitimate interests in providing a consistent service, balanced against your privacy; consent where required
Process payments and maintain business recordsBilling, payment and transaction recordsPerformance of a contract; legal obligation; legitimate interests in financial administration and fraud prevention
Operate the website, app and member portalAccount, device, security and usage informationPerformance of a contract; legitimate interests; consent for non-essential technologies where required
Send service messagesBooking reminders, access information, operational notices and material terms changesPerformance of a contract; legitimate interests
Send news, invitations and offersContact details and marketing choicesConsent where required; otherwise legitimate interests where permitted by law
Protect people, premises and propertyAccess records, CCTV, incident informationLegitimate interests; legal obligation; vital interests in a genuine emergency
Handle concerns, claims and disputesCorrespondence, service, incident and transaction recordsLegitimate interests; legal obligation; establishment, exercise or defence of legal claims where applicable
Meet legal and regulatory dutiesRecords required by tax, company, health and safety or other lawLegal obligation
Improve services and plan operationsFeedback and appropriately minimised usage or booking patternsLegitimate interests; consent where required

Where we rely on legitimate interests, we consider the purpose, necessity and effect on you. You may object to processing based on legitimate interests; see section 19.

5 Health and other special category information

We treat health and other special category information with particular care. For each use, LERÉI must identify both an Article 6 lawful basis for processing personal information and a separate Article 9 condition permitting the use of special category information.

Depending on the service and the relationship between the parties, the relevant condition may be your explicit consent, provision of health care by or under the responsibility of a professional subject to confidentiality, protection of vital interests where you are physically or legally incapable of consenting, or establishment, exercise or defence of legal claims. A condition is used only where its legal requirements are satisfied.

If explicit consent is the condition:

  • the request will identify the relevant type of health information and purpose;
  • it will be separate from marketing and general terms acceptance;
  • you may withdraw it at any time for future processing; and
  • we will explain if we cannot safely provide a requested service without information that is objectively necessary.

We do not use health information to target general marketing or infer vulnerabilities without a separate, specific and lawful basis. We do not ask Hapana or another supplier to make solely automated decisions with legal or similarly significant effects using your health information.

6 Personalisation with boundaries

Personal service depends on context, but discretion depends on restraint. We apply the following principles:

  • record only what is relevant to a service or reasonable member preference;
  • avoid informal or subjective commentary about members;
  • restrict access according to role and need;
  • use health information only for the purpose explained;
  • do not expose one member’s appointments, attendance or preferences to another member;
  • do not disclose membership or attendance publicly without permission or another lawful reason; and
  • review and delete information when it is no longer needed.

You may ask us to update or remove a preference note, subject to information we need to retain for legal, safety or contractual reasons.

7 Membership applications

Applying does not guarantee membership. We may use information in an application and relevant communications to assess whether to offer membership and to administer the application process. We will not seek intrusive information unrelated to legitimate membership criteria. LERÉI’s membership and eligibility process is operated consistently with applicable equality and consumer law.

8 Hapana, the LERÉI app and member technology

LERÉI may use Hapana to provide member-account, booking, payment, check-in, communications and app functionality. In the ordinary supplier arrangement, Hapana may process information for LERÉI to provide the configured service. Hapana may also have its own responsibilities for information it uses for independent purposes, as described in the notices shown within its services.

Depending on the features enabled, information passing through Hapana may include identity and contact details, profile information, membership status, bookings, purchases, payment status, check-ins, communication preferences, device information and other fields completed by you or authorised by LERÉI.

LERÉI remains responsible for explaining its own purposes and ensuring that suppliers receive only information appropriate to the service. Where a supplier acts as our processor, our contract requires it to handle information only on documented instructions, apply appropriate security and assist with data-protection obligations.

Hapana’s services may involve international processing. Where a restricted transfer from the United Kingdom occurs, we use an approved transfer mechanism and assess the protection available. See section 17.

9 Practitioners, clinicians and specialist partners

Services at or arranged through LERÉI may be delivered by LERÉI personnel or by independent practitioners, clinicians, therapists, instructors, beauty professionals and other specialists. The privacy relationship can differ:

  • LERÉI as controller: LERÉI decides why and how information is used for membership, access, booking, payment and its own service administration.
  • Supplier processing for LERÉI: a provider handles information only to deliver a service on LERÉI’s instructions.
  • Independent practitioner as controller: a practitioner decides why and how to use information for their professional assessment, advice, treatment and records, under their own legal and professional duties.
  • Joint responsibility: in limited cases, LERÉI and a partner may jointly determine a purpose and means and will allocate responsibilities transparently.

Where an independent practitioner is responsible for clinical or treatment records, their privacy notice applies to those records. LERÉI does not automatically receive their full confidential notes. We may receive information needed to administer the booking, payment and access, and limited information needed for safety, complaints or continuity where lawful and appropriately explained. We aim to make the provider’s identity and status clear before the service.

10 Concierge and communications

Our concierge and membership teams use information to respond to requests, arrange services and maintain an appropriate record of member communications. If a request involves an external provider — for example transport, restaurant, event or specialist booking — we will share the minimum information reasonably needed to fulfil it and tell you where the recipient’s own terms or privacy notice applies.

Email, text and consumer messaging services may not be suitable for detailed health information. We may redirect sensitive conversations to a more appropriate channel. Operational messages — such as booking confirmations, access instructions, safety notices, receipts and material membership updates — are not marketing and may continue even if you opt out of promotional messages.

11 Marketing and invitations

Where permitted, we may send news, invitations, offers and information about LERÉI services. We will obtain consent where required and provide a clear way to opt out in each electronic marketing message. We do not make marketing consent a condition of membership. Marketing choices are separate from necessary service communications.

You can opt out at any time using the unsubscribe link or by contacting concierge@lerei.com. We may keep a minimal suppression record so that we respect your choice. We will not use health information, treatment history or inferred health concerns for direct marketing without your separate explicit consent and a lawful, carefully assessed purpose.

12 Who we share information with

We do not sell member personal information.

Where necessary and proportionate, we may share information with:

  • Hapana and other membership, app, booking and communications providers;
  • payment processors, banks, accountants and fraud-prevention services;
  • website hosting, cloud, IT support, cybersecurity and analytics providers;
  • practitioners, instructors, clinicians and service partners involved in a service you request;
  • concierge suppliers where you ask us to arrange an external service;
  • security, access-control, CCTV and facilities providers;
  • event, photography or production suppliers where appropriately notified;
  • insurers, auditors, lawyers and other professional advisers;
  • a buyer, investor or successor in connection with a genuine corporate transaction, subject to confidentiality and applicable law; and
  • courts, regulators, law enforcement or public authorities where disclosure is required or lawfully justified.

Service providers receive only the information reasonably needed for their role and are subject to appropriate contractual and confidentiality protections where they act for us.

13 CCTV and access monitoring

CCTV and access records may be used for safety, security, crime prevention, incident investigation and protection of people and property. Signage will identify monitored areas and give a contact route. Footage is accessed only by authorised people and disclosed only where justified — for example to investigate an incident, respond to a lawful request or protect legal rights. We do not use CCTV for promotional content or routine member profiling.

Recordings are retained for a limited period unless an incident, claim, investigation or legal requirement justifies preserving a relevant extract for longer.

14 Photography, filming and social media

Members and guests may reasonably expect discretion at the residence. LERÉI does not treat identifiable promotional photography or filming as automatically permitted because someone is a member, guest or event attendee.

Where LERÉI plans photography or filming, we will provide appropriate notice and, where required, obtain permission. We will offer a practical way to avoid being included where reasonably possible. Close-up testimonials, interviews and other featured promotional uses require a separate release or other clearly documented legal basis.

Members and guests must respect the privacy of others and follow residence rules on personal photography, filming, livestreaming and social-media posts. Permission from LERÉI does not replace the need to respect the rights of any identifiable person. Security footage is governed by section 13 and is not repurposed for marketing.

15 Children and age restrictions

LERÉI’s membership is intended for adults. Guest and event age rules may vary and will be stated at booking. We do not knowingly collect children’s information through general website or marketing journeys except where needed to administer an expressly permitted guest, event or safeguarding arrangement and with appropriate information and authority.

16 How long we keep information

We retain information only for as long as reasonably necessary for the purpose collected, including membership and service delivery and legal, tax, accounting, safety, insurance and dispute requirements.

Retention depends on the record. For example, an unsuccessful initial enquiry will generally be kept for less time than an active membership, transaction, signed treatment form, incident report or record relevant to a legal claim. CCTV ordinarily has a short rolling retention unless footage is preserved for a specific reason. When information is no longer needed, we delete or anonymise it securely.

You may ask about the retention period applying to a particular record by contacting concierge@lerei.com.

17 International transfers

Some technology and service providers may process information outside the United Kingdom. Where UK law restricts a transfer, we use an approved safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with a transfer risk assessment where required. You may contact us for more information about the safeguards relevant to your information.

18 Security

We use organisational and technical measures designed to protect information against unauthorised access, loss, misuse, alteration or disclosure. Measures are proportionate to the nature and sensitivity of the information and include role-based access, supplier controls, staff confidentiality, secure configuration and incident procedures.

No system is completely secure. If a personal-data breach creates a legal notification duty, we will notify the Information Commissioner and affected individuals as required.

19 Your rights

Depending on the circumstances, UK data protection law may give you the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • receive certain information in a portable format;
  • withdraw consent at any time where processing relies on consent; and
  • ask for safeguards relating to solely automated decisions that produce legal or similarly significant effects.

These rights are not absolute. We may need to retain or continue using information where the law permits or requires it. Withdrawing consent does not make earlier processing unlawful.

To exercise a right, contact concierge@lerei.com. We may ask for proportionate information to verify identity. We will respond without undue delay and normally within one month; the law permits extensions in some circumstances.

20 Questions and complaints

Please contact us first if you have a concern about how we use personal information, by email to concierge@lerei.com or by post to our registered office. We will acknowledge and investigate data-protection complaints in line with applicable legal requirements.

You may also complain to the UK Information Commissioner’s Office (ICO):

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

You may contact the ICO at any time, although it will often be useful to give us an opportunity to address the issue first.

21 Changes to this policy

We may update this policy to reflect changes to our services, suppliers, legal obligations or practices. The latest version will appear here with its effective date. If a change materially affects how we use existing information, we will provide additional notice where appropriate.

Return to LERÉI

LEREI LTD · Registered in England and Wales · Company No. 16216802
Registered office: 2nd Floor, 171–175 Brompton Road, London, England, SW3 1NF
© 2026 LEREI LTD. All rights reserved.