Data Controller
Faces Pharmacy LTD
Collected Personal Data
HOW WE COLLECT DATA
XploreU Aesthetics LTD will generally only receive personal data from the individual concerned directly in the course of conducting business. This may be in person, via email, web form or telephone. However, in some cases personal data will be supplied by third parties (for example online booking platforms ) but only when you have specifically booked a service/treatment offered by XploreU aesthetics LTD on a third party platform.
THE DATA WE COLLECT
In the course of our business XploreU aesthetics will collect certain types of personal data which will include:
WHY WE PROCESS YOUR PERSONAL DATA
During the course of our business, we need to process a wide range of personal data and we will only do so in accordance with the law. Some of this is done to fulfil XploreU aesthetics legal obligations including those related to contractual obligations such as those to its insurers. In other cases, we will process data where it is in our legitimate interest except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
XploreU aesthetics believes the following use will fall within the category of legitimate interest:
Given that we need to collect health information and this is classed as a special category of personal data we need to identify a specific condition under Article 9. The condition on which we rely is that processing is necessary for the purposes of providing health care or treatment.
WHO HAS ACCESS TO DATA & WHO WE SHARE IT WITH
Personal information gathered will not be shared with any third party companies for direct marketing. Usually, personal data collected by XploreU aesthetics will remain within the company. Some of the processing is carried by third parties such as website developers, cloud storage providers but is at all times kept securely and only processed with the directions of XploreU aesthetics.
On occasion, we will need to share personal information, to meet our legal obligations or for contractual reasons, with third parties such as banks lawyers, insurers or accountants.
HOW LONG WE KEEP PERSONAL DATA
We are committed to complying with our legal obligation to the retention and deletion of personal information. The type of data and the purpose for collection will determine how long Xplore Aesthetics will retain your data. We will not process your personal information for purposes longer than necessary.
Our insurers require Xplore aesthetics to keep Client records, including medical data, images and treatment data for 10 years from the date of your last treatment following which it will be securely disposed of.
Financial and accounting records will be kept for 6 years from the end of the last company financial year they relate to or longer if the tax return was late or if HMRC requests it.
Your Rights As A Data Subject At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
THIS PRIVACY NOTICE
Xplore aesthetics will update this privacy notice from time to time. Our website will be updated when necessary to reflect the most recent and up to date copy of this notice. Please check with Privacy Policy page occasionally to ensure that you are happy with the changes.
COMPLAINTS
If you believe that we have not complied with our privacy notice you may complain to the Information Commissioner’s office (ICO) although as recommend by the ICO please allow Xploreu aesthetics the opportunity to resolve the matter before involving the regulator.
All queries and complaints in the first instance should be directed by email to Faith Tucker at faith@xploreu.co.uk.
©Copyright. All rights reserved.
We need your consent to load the translations
We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.