1. INTRODUCTION

This privacy policy notice is served by:

Sassy Brow & Skin Clinic
191 Scargreen Avenue
L11 3BA Liverpool, UK
www: http://sassyskinbrowclinic.co.uk
tel. 01512715581
e-mail: contact@sassybrowskinclinic.co.uk

The purpose of this policy is to explain to you how our business control, process, handle and protect your personal information through our services and while you browse or use our website.

Policy key definitions:

  • “I”, “our”, “us”, or “we” refer to the business: Sassy Brow & Skin Clinic
  • “you”, “your”, “the user” “the client” refer to the person(s) using our services including browsing or using our website.
  • GDPR means General Data Protection Act
  • Cookies mean small files stored on a users computer or device
2. DATA COLLECTED
WHAT DATA DO WE COLLECT

• Personal identification data
• Contact information
• Information about client’s health
• Online identifiers including cookie identifiers

HOW DO WE COLLECT YOUR DATA

You directly provide us with most of the data we collect. We collect data and process data when you:

• Register online or make a booking for any of our products or services
• Complete a Client Consultation Form
• Use or view our website via your browser’s cookies
• Google Analytics

HOW DO WE USE YOUR DATA

By collecting your data we can:

  • Verification/identification of the user during website usage;
  • Providing Technical Assistance;
  • Sending updates to our users with important information to inform about news/changes;
  • Checking the accounts’ activity in order to prevent fraudulent transactions and ensure the security
  • over our customers’ personal information;
  • Customize the website to make your experience more personal and engaging;
  • Guarantee overall performance and administrative functions run smoothly.
  • Process your booking and manage your client’s account
  • Phone and/or email you about your booking
  • Email you with special offers on products and services we think you might like
  • Provide you and our other customers quality services and products

When we process your booking, it may send your data to, and also use the resulting information from, credit reference agencies to prevent fraudulent purchases.

DATA STORAGE LOCATION

We are UK based company and operate web servers hosted in UK. Our hosting provider 1&1 IONOS Ltd. (” 1&1 IONOS”), comply with all relevant data protection legislation ensuring that your data is securely stored and GDPR compliant. For more information on 1&1 IONOS Ltd. (” 1&1 IONOS”) privacy policy, please see here.

MARKETING

We would like to send you information about products and services of ours that we think you might like. If you have agreed to receive marketing, you may always opt out at a later date.

You have the right at any time to stop us from contacting you for marketing purposes or giving your data to other members of our business. If you no longer wish to be contacted for marketing purposes, please contact us.

REGISTRATION DATA

If you register on our website, we store your chosen username and your email address and any additional personal information added to your user profile. You can see, edit, or delete your personal information at any time (except changing your username). Website administrators can also see and edit this information.

COMMENTS

When you leave comments on the website we collect the data shown in the comments form, and also the IP address and browser user agent string to help spam detection.

CONTACT FORM

Information submitted through the contact form on our site is sent to our company email, hosted by 1&1 IONOS Ltd. (” 1&1 IONOS”). For more information on 1&1 IONOS Ltd. (” 1&1 IONOS”) privacy policy, please see here.

These submissions are only kept for customer service purposes they are never used for marketing purposes or shared with third parties.

GOOGLE ANALYTICS

We use Google Analytics on our site for anonymous reporting of site usage. So, no personalized data is stored. If you would like to opt-out of Google Analytics monitoring your behavior on our website please use this link: Google Analytics Opt-out.

3. EMBEDDED CONTENT

Pages on this site may include embedded content, like YouTube videos, for example. Embedded content from other websites behaves in the exact same way as if you visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged-in to that website. Below you can find a list of the services we use:

FACEBOOK

The Facebook page plugin is used to display our Facebook timeline on our site. Facebook has its own cookie and privacy policies over which we have no control. There is no installation of cookies from Facebook and your IP is not sent to a Facebook server until you consent to it. See their privacy policy here: Facebook Privacy Policy .

TWITTER

We use the Twitter API to display our tweets timeline on our site. Twitter has its own cookie and privacy policies over which we have no control. Your IP is not sent to a Twitter server until you consent to it. See their privacy policy here: Twitter Privacy Policy .

YOUTUBE

We use YouTube videos embedded on our site. YouTube has its own cookie and privacy policies over which we have no control. There is no installation of cookies from YouTube and your IP is not sent to a YouTube server until you consent to it. See their privacy policy here: YouTube Privacy Policy.

CONSENT CHOICE

We provide you with the choice to accept this or not, we prompt consent boxes for all embedded content, and no data is transferred before you consented to it.

The checkboxes below show you all embeds you have consented to so far. You can opt-out any time by un-checking them and clicking the update button.

  • YouTube
  • Facebook
  • Twitter
4. COOKIES

This site uses cookies – small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences, store information for things like shopping carts, and provide anonymized tracking data to third party applications like Google Analytics. Cookies generally exist to make your browsing experience better. However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the help section of your browser.

NECESSARY COOKIES (ALL SITE VISITORS)
  • cfduid: Is used for our CDN CloudFlare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. See more information on privacy here: CloudFlare Privacy Policy.
  • PHPSESSID: To identify your unique session on the website.
NECESSARY COOKIES (ADDITIONAL FOR LOGGED IN CUSTOMERS)
  • wp-auth: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
  • wordpress_logged_in_{hash}: Used by WordPress to authenticate logged-in visitors, password authentication and user verification.
  • wordpress_test_cookie Used by WordPress to ensure cookies are working correctly.
  • wp-settings-[UID]: WordPress sets a few wp-settings-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
  • wp-settings-[UID]:WordPress also sets a few wp-settings-{time}-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface.
5. WHO HAS ACCESS TO YOUR DATA

If you are not a registered client for our site, there is no personal information we can retain or view regarding yourself.

If you are a client with a registered account, your personal information can be accessed by:

  • Our system administrators.
  • Our supporters when they (in order to provide support) need to get the information about the client accounts and access.
6. THIRD PARTY ACCESS TO YOUR DATA

We don’t share your data with third-parties in a way as to reveal any of your personal information like email, name, etc. The only exceptions to that rule are for partners we have to share limited data with in order to provide the services you expect from us. Please see below:

ENVATO PTY LTD

For the purpose of validating and getting your purchase information regarding licenses for the Avada theme, we send your provided tokens and purchase keys to Envato Pty Ltd and use the response from their API to register your validated support data. See the Envato privacy policy here: Envato Privacy Policy.

TICKSY

Ticksy provides the support ticketing platform we use to handle support requests. The data they receive is limited to the data you explicitly provide and consent to being set when you create a support ticket. Ticksy adheres to the EU/US “Privacy Shield” and you can see their privacy policy here: Ticksy Privacy Policy.

7. HOW LONG WE RETAIN YOUR DATA

We securely keep your personal data collected by registration form at our business address for up to 2 years. Once this time period has expired, we will erase your data by deleting your data from our database and destroy any paper documents with your data provided.

When you submit a comment, its metadata is retained until (if) you tell us to remove it. We use this data so that we can recognize you and approve your comments automatically instead of holding them for moderation.

If you register on our website, we also store the personal information you provide in your user profile. You can see, edit, or delete your personal information at any time (except changing your username). Website administrators can also see and edit that information.

8. YOUR DATA RIGHTS

We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

The right to access – You have the right to request us for copies of your personal data. We may charge you a small fee for this service.

The right to rectification – You have the right to request that us correct any information you believe is inaccurate. You also have the right to request us to complete the information you believe is incomplete.

The right to erasure – You have the right to request that we erase your personal data, under certain conditions.

The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.

The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.

The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at our email contact@sassybrowskinclinic.co.uk.

GDPR RIGHTS

Your privacy is critically important to us. Going forward with the GDPR we aim to support the GDPR standard. We permit residents of the European Union to use its Service. Therefore, it is our intention to comply with the European General Data Protection Regulation. For more details please see here: EU GDPR Information Portal.

9. THIRD PARTY WEBSITES

We may post links to third party websites on this website. These third party websites are not screened for privacy or security compliance by Sassy Brow & Skin Clinic and you release us from any liability for the conduct of these third party websites.

All social media sharing links, either displayed as text links or social media icons do not connect you to any of the associated third parties, unless you explicitly click on them.

Please be aware that this Privacy Policy, and any other policies in place, in addition to any amendments, does not create rights enforceable by third parties or require disclosure of any personal information relating to members of the Service or Site. We bears no responsibility for the information collected or used by any advertiser or third party website. Please review the privacy policy and terms of service for each site you visit through third party links.

10. RELEASE OF YOUR DATA FOR LEGAL PURPOSES

At times it may become necessary or desirable to Sassy Brow & Skin Clinic, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, we may elect to notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.

Any passing on of personal data for legal purposes will only be done in compliance with laws of the country you reside in.

11. AMENDMENTS

We may amend this Privacy Policy from time to time. When we amend this Privacy Policy, we will update this page accordingly and require you to accept the amendments in order to be permitted to continue using our services.