Privacy Notice September 2018
Beauty Temple {Nottingham) Limited Trading as Beauty Temple
This notice explains what happens when we process your personal information. It covers when and why we collect personal information, how we use it and what we do with it.
The notice covers all salons and divisions within the ‘Beauty Temple (Nottingham) Limited Group’, which trade under the name of ‘Beauty Temple’.
All processing of personal data will be in line with the General Data Protection Regulation (GDPR) and in accordance with general UK legislation.
It is important for you to read this so that you are properly informed and also are aware of your rights under GDPR.
Personal data is any information by which an individual person can be identified. This includes a name, an identification number, address, email address, IP address, photo, date of birth, phone number and images captured by our CCTV cameras. This covers any factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of a person.
Processing includes collection, recording, organising, storage, adapting, retrieval, use, erasure or destruction.
We are committed to keeping your information securely and with respect.
For any information please contact Martin Goodwin of 4 Queen Street Nottingham NG1 2BL
Email: info@beautytemple.co.uk Phone : 0333 313 4003
For independent advice about data protection issues you can contact the Information Commissioner at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Email : casework@ico.org.uk Phone : 0303 123 1113 Website : www.ico.org.uk
1) What Information do we collect?
We only collect information when we need it to provide our services, to promote our services, to maintain our accounts and records and comply with UK law.
For general enquiries by phone or email
- We will have your name and email or telephone number and the nature of your query and our reply
For individual bookings at our Salons
- We will have your name, address email, telephone number and whatever further information necessary for the safe and successful provision of our services. Further information will also be obtained throughout until the service is concluded and will be kept in our records.
For Corporate and other group bookings
- We will request for all the individuals attending their names , addresses, email , telephone number and whatever other information necessary for the provision of the service agreed
- We will request the name and contact details of the person responsible on behalf of the group and the welfare of the individuals attending
- Further information may be requested until the Services are completed. All information is kept with our records
For any Feedback form
- We will have your name and email and the comments provided.
We may ask for written consent to receive marketing materials from us that we believe would be of interest to you.
We also process personal information about our suppliers, employees, independent contractors, advisers and other professional experts.
We sometimes process sensitive classes of, including medical details, for which we will request specific consent from the individual.
2) Who will we share your data with?
We sometimes need to share personal information with other organisations that we work with or who provide services on our behalf. When sharing information we will comply with all aspects of current data protection law.
Your data may be shared with our self-employed Therapists and other expert contractors at the Salons to the extent necessary to provide the agreed service.
For group bookings made through a company or other third party the basic contact data will be shared with the company or third party arranging the services.
Where necessary or required we share information with
- Business associates and other professional advisers
- Financial organisations
- Current, past or prospective employers and employees
- Official bodies
- Suppliers and services providers.
We never share personal information with any other organisation for third party marketing purposes.
Third Parties will also have access to some of your information through your use of our website www.beautytemple.co.uk on a limited basis. These will include Google Analytics and any booking software.
3) The Legal Basis for the Processing
The legal basis for processing shall be:
- The individual has given consent to the processing of their personal information
- The processing is necessary for the performance of a contract to provide a service which the individual is a party or in order to take steps at the request of the individual prior to entering into a contract
- Processing is necessary to comply with our legal obligations
- Processing is necessary for our legitimate interests or those of a third party except where overridden by the interests of the individual especially where a child is involved.
4) Consent and Children
Before any information is collected for a child we will need to obtain the consent from a person holding parental responsibility. A child is a person under 16 years of age.
5) Sensitive Data
- It is necessary to collect basic medical data from all customers to the Salons in order to provide any services
- It may be necessary to collect more detailed medical data if the Customer has mental or physical health issues.
- Medical data is classed as Sensitive Data which also includes data about racial or ethnic origin, religious or philosophical beliefs
- We cannot collect any Sensitive Data without the explicit consent of the individual unless there is an overriding legal or other obligation as provided in Article 9 of GDPR
- The individual will be requested to supply their consent in writing before any Services are provided. This consent can be withdrawn at any time
- If no consent is in place no services can be provided
6) CCTV.
The image of the Customer may be collected at various points in the Salons. This is provided for the security and safety of our Customers as part of our service to them. The Customer will be giving their consent to this when they sign the registration card.
Consent can be withdrawn but then we can no longer provide any Services and the Customer must not enter the Salon premises.
Visible and readable signs on the premises will inform the Customer that they are being recorded. The signs will include details of the organisation operating the system.
CCTV will not be used except in exceptional circumstances in locations where the Customer could expect privacy.
The CCTV images are subject to the same rules as all other Data and the Customer has the same rights.
The CCTV images will only be kept for as long as necessary to meet the purpose of recording them.
7) Security of Processing
We are implementing technical and organisational measures to ensure personal information processed remains secure but absolute security cannot be guaranteed.
8) How long will we keep your data?
Personal data is retained only as long as necessary to comply with statutory retention periods. At the end of those periods the data will be securely deleted provided it is no longer required to fulfil the contract or any legal proceedings.
9) Failure to provide data
Sometimes the provision of personal data by an individual is required by law or failure to provide can result in us being unable to provide the service agreed. If an individual should fail to supply such information we shall not be liable for the consequences of being unable to complete any contract for services.
10) Your rights
We are committed to upholding your rights in respect of your personal data.
- Right of Access
You have a right to ask us what personal information we hold about you and to request a free copy of your information. This is known as a Subject Access Request (SAR). SARs need to be in writing and we ask it is accompanied by proof of your identity and address.
If you want specific information e.g. a particular time frame please clarify this in your written confirmation of consent.
If someone is requesting information on your behalf we shall need your written consent and evidence of ID for both of you.
We have to comply you with the information you request within 30 days although we will endeavour to do so as soon as possible.
- Right to Rectification
You can ask us to rectify your personal data if it is inaccurate or incomplete. Please assist us by informing us of any obvious changes.
- Right to erasure
This is known as the ‘right to be forgotten’. In some circumstances you can ask for your data to be deleted or removed. However we will need to consider each case on its circumstances and it may be that we are obliged to retain the data under our legal and other obligations.
- Right to Withdraw Consent
Where consent forms the basis of processing you have the right to withdraw that consent at any time.
11) Recruitment procedures
We will collect and process the personal data of applicants for the purpose of the processing of the application procedure. The processing may be done electronically.
If the procedure concludes with an employment contract being completed the submitted data will be stored in order to process the employment relationship and comply with legal requirements.
If no employment contract is concluded the applicant’s data and any application documents will be automatically erased three months after notification of the refusal decision provided none of our other legitimate interests are opposed to erasure.
11) Complaints
In the first instance please send any complaints to Martin Goodwin as above. If you are not satisfied with the response then you should contact the Information Commissioner at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Email : casework@ico.org.uk Phone : 0303 123 1113 Website : www.ico.org.uk
12) General
You may not transfer any of you rights under this Privacy Notice to any other person. We may transfer our rights where we reasonably believe your rights will not be affected.
This Notice will be governed by the laws of England.
This Notice will be updated from time to time and a copy of the latest version will be on our website.