PRIVACY POLICY
Privacy Policy
Last Updated: 10.02.2025
1. Introduction
Welcome to Natasha Berresford Skin ("we," "us," "our"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website ([Insert Website URL]), book treatments, or engage with our services.
By using our website and services, you consent to the practices described in this policy. If you do not agree, please refrain from using our services.
2. Information We Collect
We collect and process different types of personal data, including but not limited to:
2.1 Information You Provide Directly
-
Booking & Account Information: When you book a treatment via Ovatu, register on our website, or contact us, we may collect your name, email address, phone number, and appointment details.
-
Health Information: If you complete a consultation form or disclose health conditions relevant to your treatments, we may collect medical history, allergies, and skin concerns.
-
Payment Information: Payments are processed securely via Ovatu or third-party payment providers; we do not store your card details.
2.2 Information Collected Automatically
-
Website Usage Data: We may collect technical data such as IP address, browser type, device details, and pages visited through cookies and analytics tools.
-
Cookies & Tracking Technologies: Our website uses cookies to enhance user experience and track website traffic (see Section 7).
3. How We Use Your Information
We use your personal data for the following purposes:
-
Providing Services: To schedule and manage appointments, deliver treatments, and provide customer support.
-
Legal & Compliance: To maintain records for tax, legal, and insurance purposes.
-
Marketing (With Consent): To send promotions, newsletters, and service updates. You can opt out at any time.
-
Improving Our Website: To analyze usage patterns and enhance our website’s functionality.
4. Use of Ovatu for Bookings
We use Ovatu as our third-party booking system. When you book an appointment through Ovatu, your personal data (such as name, email, phone number, and booking details) is processed in accordance with Ovatu’s Privacy Policy.
-
Ovatu’s Commitment to Data Protection
-
Ovatu is GDPR-compliant and takes necessary security measures to protect your data.
-
Your data is stored securely within Ovatu’s system.
-
Ovatu may process payments through its integrated payment processors. We do not store or have direct access to your payment details.
For more details, you can review Ovatu’s Privacy Policy.
5. Legal Basis for Processing Personal Data
We process personal data under the following legal grounds:
-
Contractual Necessity: When processing data to fulfill treatment bookings.
-
Legal Obligations: For regulatory compliance and record-keeping.
-
Legitimate Interest: To improve services, prevent fraud, and ensure security.
-
Consent: For marketing communications and storing medical history (where applicable).
6. Sharing Your Data
We do not sell or rent your personal data. However, we may share data with:
-
Service Providers:
-
Ovatu for bookings.
-
Payment processors for secure transactions.
-
IT and website service providers for security and maintenance.
-
Legal & Regulatory Bodies: When required by law or for fraud prevention.
-
Marketing Platforms (With Consent): If you opt into promotional emails or SMS marketing.
All third parties are required to process your data securely and in compliance with UK GDPR.
7. Data Security & Retention
We implement strict security measures to protect your data from unauthorized access, alteration, or loss. Personal data is retained only for as long as necessary:
-
Client records: Retained for up to 7 years in compliance with industry regulations.
-
Marketing data: Retained until you withdraw consent.
8. Cookies & Tracking Technologies
We use cookies to enhance your website experience. You can manage cookie preferences in your browser settings. Our Cookie Policy explains this in more detail.
9. Your Data Rights
Under UK GDPR, you have the right to:
-
Access: Request a copy of your personal data.
-
Correction: Request amendments to inaccurate information.
-
Deletion ("Right to Be Forgotten"): Request deletion of your data (subject to legal retention requirements).
-
Restriction: Request limited processing of your data.
-
Objection: Withdraw consent for marketing communications.
-
Data Portability: Request data transfer to another provider where applicable.
To exercise these rights, please contact us at info@natashaberresford.skin.
10. International Data Transfers
We store data in the UK. If we transfer data outside the UK/EU, we ensure adequate protection via UK GDPR-approved safeguards (e.g., Standard Contractual Clauses).
11. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for their privacy policies or practices.
12. Updates to This Policy
We may update this Privacy Policy periodically. Please review this page for changes.
13. Contact Us
For any privacy concerns or data requests, contact:
📧 Email: info@natashaberresford.skin
If you are unsatisfied with our response, you can lodge a complaint with the Information Commissioner’s Office (ICO): www.ico.org.uk.