PRIVACY POLICY
A LEGAL DISCLAIMER
Version 2.0 | Effective 28 June 2026 | Next Review: 28 June 2027 | Owner: Registered Manager
Haus of Ästhetik Ltd is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you interact with our website, services, and Subject Access Request processes. This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), CQC Regulation 17 (Good Governance), and the Save Face Code of Practice. It should be read alongside our Terms of Service, Refund & Returns Policy, and Cookie Policy.
POLICY - STATEMENT
1. Data Controller
Haus of Ästhetik Ltd is the data controller for personal data processed through this website, clinical systems, and associated communication channels.
Contact: HausOfAsthetik@icloud.com | 01629 385 318 | 4 Portland Square, Water Street, Bakewell, Derbyshire, DE45 1HA
ICO Registration Number: [To be inserted by Registered Manager]
2. Scope
This Policy applies to: visitors to this website; individuals making enquiries or bookings; patients and service users; individuals submitting Subject Access Requests; and individuals communicating with us via online forms, email, telephone, or website chat. It does not apply to third-party websites linked from our site.
3. Personal Data We Collect
3.1 Identity and Contact Data: Full name, date of birth, postal address, email address, telephone number, and photographic identification where required for verification or safeguarding purposes.
3.2 Health and Special Category Data: Medical history, consultation information, treatment records, clinical notes, consent forms, outcome documentation, and incident records. Processed subject to enhanced safeguards and strict role-based access controls.
3.3 Technical and Usage Data: Anonymised IP address, device type, operating system, browser information, pages visited, referral sources, and interaction patterns.
3.4 Communications Data: Enquiries via website forms, website chat interactions, and email, telephone, or written correspondence.
4. Lawful Bases for Processing
We process personal data under: Article 6(1)(a) Consent; Article 6(1)(b) Contractual necessity; Article 6(1)(c) Legal obligation; Article 6(1)(f) Legitimate interests; Article 9(2)(h) Provision of health or social care. Where consent is relied upon, it may be withdrawn at any time without affecting the lawfulness of prior processing.
5. How We Use Your Data
We use personal data only where there is a clear and lawful purpose, including: responding to enquiries and booking requests; assessing suitability for and delivering clinical care; maintaining accurate clinical and administrative records; fulfilling contractual and payment obligations; meeting legal, regulatory, and professional requirements; managing complaints, incidents, and safeguarding concerns; improving website functionality and accessibility; and responding to Subject Access Requests and other data rights requests.
6. Subject Access Requests
You have the right to request access to personal data we hold about you under Article 15 UK GDPR and the Data Protection Act 2018. Subject Access Requests must be submitted using our dedicated SAR form on this website. Identity must be verified before a request is processed. Statutory response timeframes begin only when a request is validated. Information may lawfully be withheld or redacted to protect third-party rights, safeguarding interests, legal privilege, or to prevent serious harm.
7. Data Retention
Personal data is retained only for as long as necessary: clinical records in line with professional standards, indemnity guidance, and limitation periods (minimum 8 years for adult patients following last treatment); financial and transactional records per HMRC requirements (minimum 6 years); website analytics data anonymised per provider default settings; SAR records retained for audit and accountability purposes. Data no longer required is securely deleted or anonymised.
8. Third-Party Processors, AI Tools, and Analytics
We use trusted third-party systems including: Wix (website hosting, forms, booking infrastructure, payment processing); Twipla Visitor Analytics (anonymised website analytics); Wix AI Chat (automated enquiry assistance); clinical documentation and record-keeping systems; and medical suppliers, pharmacies, laboratories, and distributors involved in prescribing, dispensing, supply, or safety monitoring. Data shared is limited to what is strictly necessary. We do not sell, rent, or monetise personal data.
9. Cookies and Electronic Communications (PECR 2003)
We use cookies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR). Essential cookies are placed without prior consent. Non-essential cookies (analytics, preference, or marketing cookies) are placed only with your prior, informed, freely given consent via our cookie consent banner. Twipla Visitor Analytics collects anonymised data. Users may manage or withdraw cookie consent at any time through browser settings or the cookie banner. A full Cookie Policy is available on this website.
10. Data Security
We implement robust technical and organisational measures including: industry-standard encryption of data in transit and at rest; secure cloud-based storage with layered access controls; role-based access restrictions; strong authentication measures; automatic security updates; and regular access permission reviews. Staff receive training on data protection and information governance. Personal data is stored primarily in UK or EEA-based environments.
11. Children's Data
Our services are primarily intended for adults. Where services are lawfully provided to individuals under 18, we apply enhanced safeguards: age verification, parental or guardian consent, and limitation of data collection to what is strictly necessary. Children's data is never used for marketing purposes.
12. Your Rights Under UK GDPR
Access your personal data (Article 15)
Rectify inaccurate data (Article 16)
Erasure where lawful (Article 17)
Restrict processing (Article 18)
Data portability (Article 20)
Object to processing, including for direct marketing (Article 21)
Not be subject to solely automated decision-making producing significant effects (Article 22)
To exercise any of these rights, contact us using the details in Section 1.
13. Changes to This Policy
We may update this Privacy Policy to reflect legal, regulatory, or operational changes. The current version, with its effective date, will always be available on our website.
14. Governance and Review
This policy is reviewed annually by the Nominated Individual and Registered Manager as part of the clinic governance cycle. Version control and review outcomes are recorded internally.
For any privacy or data protection concerns, please contact:
Haus of Ästhetik Ltd
4 Portland Square, Water Street, Bakewell, Derbyshire, DE45 1HA
Email: HausOfAsthetik@icloud.com
Telephone: 01629 385 318
If you remain dissatisfied, you may lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
