Privacy Policy

Information on our privacy policy

Data Controller
Vivien Mills

Collected Personal Data 

1. Introduction

Beauty Xposure is committed to protecting the personal information of our clients, job applicants, suppliers and website visitors. This privacy policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and your rights under UK data protection law.

2. Who we are and how to contact us
•     Data controller: Beauty Xposure / Vivien Mills
•     Trading as: Beauty Xposure / bX Skin Care.
•     Address: 2 French's Yard, Ware, Herts SG12 9HP
•     Data protection lead: Vivien Mills.
•     Contact email: info@beautyxposure.co.uk
•     Contact telephone: 01920 745210

WHAT INFORMATION DO WE COLLECT?

3. Personal data we collect
We may collect the following types of personal data, depending on the service or interaction:
•     Identity and contact: name; address; email; phone number.
•     Appointment and transaction data: booking details; treatment history; receipts; payment references.
•     Health and medical information: allergies; medical conditions; pregnancy status; medications where relevant to safe treatment.
•     Marketing preferences: consent for email/SMS/telephone marketing; communication preferences.
•     Device and website data: IP address; cookies and similar tracking when you use our website.
•     Staff and supplier data: CVs; references; payroll and invoicing details.
 

4. Lawful bases for processing
We process personal data only when we have a lawful basis, including:
•     Performance of a contract when you book and receive treatments.
•     Legal compliance for record-keeping and tax or health and safety obligations.
•     Consent where we ask you to opt in for marketing or for the processing of certain health information.
•     Legitimate interests such as preventing fraud, improving services, and maintaining client relationships, balanced against your rights and freedoms.

5. How we use your personal data
We use personal data to:
•     Provide and manage appointments, treatments and aftercare.
•     Process payments and refunds and prevent fraud.
•     Communicate confirmations, reminders, updates and follow-up care.
•     Manage client safety and clinical records for safe treatment.
•     Send marketing only where you have given consent or where we have a legitimate interest and you have not objected.
•     Respond to enquiries, complaints and legal requests.
•     Maintain employment and supplier records.

6. Sharing and third parties
We may share personal data with:
•     Payment processors for card transactions.
•     Cloud or practice management system providers that host appointment and clinical records.
•     HM Revenue & Customs and other statutory bodies when required by law.
•     Professional advisers such as accountants or legal advisers when necessary.
We will not sell personal data to third parties.

7. International transfers
We will not be sharing clients data.

8. Data retention
We retain personal data only as long as necessary for the purposes set out above or to comply with legal, regulatory and professional obligations. Typical retention examples:
•     Client appointment and clinical records: 4 years
•     Financial records: 6 years
•     Marketing consents: until you withdraw consent.

9. Your rights
You have rights in relation to your personal data, including:
•     Right to access the personal data we hold about you.
•     Right to rectification of inaccurate data.
•     Right to erasure in certain circumstances.
•     Right to restriction of processing in some situations.
•     Right to object to direct marketing or processing based on legitimate interests.
•     Right to data portability where applicable.
To exercise any right, contact us at the details in section 2. If you remain unhappy you may contact the Information Commissioner’s Office.

10. Cookies and tracking
We use cookies on our website to improve functionality and analytics. You can control cookie preferences via your browser settings or our cookie banner where provided.

11. Security
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption where appropriate and staff training.

12. Changes to this policy
We will update this policy when our practices change. The latest policy will be published on our website and the revision date will appear at the top.

13. Effective date
This policy is effective from 19/10/2025 last revised


HOW CAN YOU CONTACT US ABOUT THIS POLICY?     

If you have questions or comments about this policy, you may email us at info@beautyxposure.co.uk

or write to us at:  Beauty Xposure (bX Skin Health), 2 Frenchs Yard, Amwell End, Ware, Herts. SG12 9HP

MAKE THE MOVE TO LOOKING AFTER YOU!

Telephone: 01920 745210
E-mail: info@beautyxposure.co.uk
Address: bX Skin Care, 2, French's Yard, Amwell End, Ware, Herts. SG12 9HP

Legal NoticePrivacy Policy
© Copyright. All rights reserved. 

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.