Privacy Policy
Erika Toth | Well in Midlife
Last updated: 21 July 2026
1. Who We Are
These website (wellinmidlife.com & erikatoth.com) are operated by Erika Toth, trading as "Well in Midlife", based in the United Kingdom. For the purposes of data protection law, we are the "data controller" of the personal data described in this policy.
If you have any questions about this policy or how we handle your personal data, you can contact us at [email protected].
2. What Personal Data We Collect
Depending on how you interact with us, we may collect:
● Contact details, such as your name and email address
● Information you submit through forms, surveys, or opt-ins
● Messages you send us directly
● Technical data such as IP address, browser type, and device information, collected automatically when you visit our site
● Usage data, such as which pages you visit and how you interact with our content
We do not currently sell products or take payments directly through this website. If that changes in future, we will also collect billing information (such as name, billing address, and payment details) needed to process the transaction, and this policy will be updated accordingly.
3. How We Collect Your Data
We collect personal data when you:
● Fill out a form or survey on our website
● Subscribe to our email list or newsletter
● Contact us directly by email or through the site
● Browse our website (via cookies and similar technologies)
4. Why We Process Your Data
We use your personal data to:
● Respond to your enquiries and provide the information you've requested
● Send you marketing emails and newsletters, where you have opted in
● Improve our website and content
● Meet our legal and administrative obligations
You can unsubscribe from marketing emails at any time using the link in any email we send.
5. The Software We Use: SOMBA.io
We use SOMBA.io, a software platform, to manage our website, forms, email marketing, and client communications. SOMBA.io acts as a data processor on our behalf – it processes personal data only according to our instructions, and does not own or control your data.
6. Hosting
SOMBA.io runs on the HighLevel platform (operated by HighLevel Inc., based in the United States of America), which provides the hosting and technical infrastructure for our website and the data we collect.
7. Data Processing Agreement (DPA)
We have a Data Processing Agreement (DPA) in place with our software provider, as required under Article 28 of the GDPR. This agreement sets out how our personal data is processed and protected.
8. International Data Transfers
Because our hosting provider is based in the United States, your personal data may be transferred to and stored in the USA. Where this happens, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), to help protect your data in line with GDPR requirements.
9. How Long We Keep Your Data
We keep your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law. When it's no longer needed, we take steps to delete or anonymise it.
10. Your Rights Under GDPR
If you are located in the UK or EU, you have the right to:
● Access the personal data we hold about you
● Ask us to correct inaccurate data
● Ask us to delete your data
● Object to or restrict how we process your data
● Ask for your data to be transferred to another provider
● Withdraw consent at any time, where we rely on consent to process your data
To exercise any of these rights, please contact us at [email protected].
11. Data Security
We take reasonable steps to protect your personal data from loss, misuse, or unauthorised access. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, along with an updated revision date.
13. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at [email protected].