Skip to main content

If you’re a UK nutrition business owner, there comes a point where you realise you’re not just doing nutrition anymore…

You’re running a proper business. With clients, payments, a website, forms, email marketing, maybe even digital products.

And then the questions start:

  • “Do I need T&Cs?”
  • “What’s the difference between a privacy policy and website terms of use?”
  • “What about cookies?”
  • “If I collect sensitive health info… Do I need to get consent?”
  • “What insurance do I actually need?”

I see these questions all the time (especially from newer business owners).

Quick note before we start: I’m not a lawyer and this post is not legal advice. I’m sharing what I’ve learned through CPD and conversations with solicitors, plus the key themes I’ve seen come up again and again with clients. If you’re unsure, it’s always worth getting proper legal advice for your specific setup.

This post simply gives you an overview of the core documents to consider and why they matter.

Client T&Cs (your “this is how we work together” document)

Your client T&Cs (or contract) is one of the most important documents in your whole business. It should be available before someone pays (or at the point of booking/signing up).

It helps with:

✅ Clarity (what they’re buying, what happens next, refunds/cancellations)
✅ Boundaries (how to contact you, response times, rescheduling)
✅ Protection (fewer misunderstandings, fewer payment issues)

Think:

  • What you’re providing (and what you’re not providing)
  • How payment works (and what happens if payment is late)
  • How sessions are booked, moved, or cancelled
  • Refunds and cancellations (including “cooling-off” rules for some purchases)
  • What happens if you or the client needs to pause/end early
  • A simple “limits” section (you can’t guarantee outcomes, and you’re not responsible for things outside your control)

Privacy notice/policy (your “what I do with your data” page)

If you collect any personal details (names, emails, enquiry forms, bookings, intake forms), you need a clear privacy notice.

This usually lives in your website footer and anywhere you collect data (contact forms, landing pages).

In simple terms, your privacy policy should explain:

  • What information you collect
  • Why you collect it
  • Where it’s stored (and how you keep it safe)
  • Who you share it with (e.g., booking system, email platform, payment provider)
  • How long you keep it
  • How someone can ask to see, correct, or delete their info

Website terms of use (your “using this website means…” page)

Website terms are not always a strict “must-have”, in that you won’t be fined if you don’t have them, but they’re a really helpful layer of protection.

They usually cover:

  • A website disclaimer (information is general and not personalised advice)
  • A reminder that you own your website content (and what people can/can’t do with it)
  • Basic rules for how people use the site

This is especially important if you publish blogs, freebies, resources, or training.

Cookies policy + cookie consent (the pop-up most people ignore… but you still need)

If your website uses tracking tools (like analytics, pixels, or embedded content), you likely use non-essential cookies, and you need:

  1. A cookies policy (what cookies are used + why)
  2. A cookie consent tool (so people can accept/reject/manage)

This is usually the cookie pop-up that appears when someone first lands on your site. 

Sometimes cookie info is added at the end of a privacy policy, but your cookie pop-up still needs to link clearly to wherever the full cookie details live.

Product T&Cs for digital products

If you sell digital products, it’s worth having product-specific T&Cs.

Why? Because you want to be super clear on things like:

  • What they get access to (and for how long)
  • Refund rules (digital products often have different expectations)
  • Sharing/logins (especially for courses/memberships)
  • Your content ownership (so your work doesn’t get reposted or resold)

GDPR basics (especially when you collect health information)

Most business owners collect personal information in some way and if you’re working in nutrition, you’re almost certainly handling sensitive personal information (like health history, medications, test results). 

So GDPR isn’t optional.

Here’s some practical steps to cover the basics:

  • Register with the ICO
  • Have a clear privacy policy on your website
  • Have a clear internal plan for how you handle client data (even if it’s simple)
  • Add a data section in your client T&Cs (or a separate data statement)
  • Use opt-in consent for email marketing (don’t auto-add people just because they downloaded a freebie)
  • Get clear & specific consent when collecting health info (e.g., on your onboarding form)

If a contractor handles personal data (even an admin VA helping with email marketing), then you will need a Data Processing Agreement (DPA) in place. 

Insurance (the boring bit that you’ll be grateful for if anything goes wrong)

The right insurance gives you a safety net – and in health and wellness, it’s an important one.

Here are the most common types mentioned for nutrition businesses:

  • Professional indemnity insurance

Helps protect you if someone claims they were harmed (or financially impacted) by your advice or service. The British Dietetic Association is the most common one but there are other providers that may be able to offer similar coverage. 

  • Public liability insurance

More relevant if you see clients in person, run events, hire rooms, or have anyone on your premises. If you’re fully remote, it may be less relevant (but check your own setup).

  • Employers’ liability insurance

If you employ staff, this is typically essential. It can also come into play depending on how your team is set up (employee vs contractor; sole trader vs ltd company), so it’s worth checking with an insurance provider who understands small healthcare businesses.

“Do I have to write all this myself?”

You can, but you don’t have to. And I also don’t recommend that you do. 

There are template options available for documents like:

  1. Client T&Cs – specifically for dietitians/nutritionists
  2. Privacy policy
  3. Website terms of use
  4. Cookie policy
  5. Digital product T&Cs

Templates are a great starting point, especially if you’re in the early stages and want something solid in place – just make sure you customise them to match how your business actually works. Drop me an email at nevine@thriveonlineservices.co.uk if you need any recommendations of where to purchase them.

Action Plan

If you want a low-overwhelm action plan, start here:

  1. Add or update client T&Cs/contract
  2. Add a privacy policy link to your footer + forms
  3. Check your website has cookie consent + cookie info
  4. Add website terms (especially if you blog/share freebies)
  5. Make sure your onboarding form includes clear consent for health info
  6. Review your insurance (PI, public liability, employers liability if relevant)
     

I’m not a lawyer, and this post isn’t legal advice – it’s general education based on CPD and solicitor discussions, shared because I know how often these questions pop up with my own clients. If you want tailored advice for your exact business model, please speak to a qualified legal professional.

It’s things like this that feel small at first, but gradually eat at your own time to sort out. This is just one of many things I support clients with to manage their business so they can focus on supporting clients, business growth and having a better work/life balance.

If you want to build a business that feels simpler to run, then book a free enquiry call with me to see how I can support you. You don’t have to figure it all out alone.

This website uses cookies and asks your personal data to enhance your browsing experience. View our cookie policy We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).