01
Who we are
ONE EIGHT is a trading name of The Beauty Bar by MLS Limited, a company registered in England and Wales (company number 14921396). Our registered office is 83 Upper St John Street, Lichfield, England, WS14 9DT. Our treatment room is at Porchways House, 83 Upper St John Street, Lichfield, Staffordshire, WS14 9DT.
We decide how your personal information is used. That makes us its “controller” under UK data protection law. For anything about your information, email [email protected] or call 07393 739427.
02
At a glance
- We collect only what we need to arrange and carry out your treatments safely.
- Health details from your consultation form are used only to keep your treatment safe, and only with your consent.
- We never sell your information, and we don’t send marketing messages.
- A photo of your treatment goes online only with your permission.
- You can ask to see, correct or delete your information at any time.
03
What we collect and why
The law only lets us use your information when we have a lawful reason, called a “lawful basis”. The last column gives ours, from Articles 6 and 9 of the UK GDPR.
| When | What we collect | Why | Lawful basis |
|---|---|---|---|
| You get in touch (website form, phone, text, WhatsApp, Instagram, Messenger or email) | Your name, phone number, email address, Instagram username if you use it, the treatments and times you’re interested in, and anything you tell us | To reply and arrange your appointment | Steps you’ve asked us to take before booking (Art 6(1)(b)) |
| You book and have treatments | Your name and contact details, appointment history, treatment notes and patch-test records | To book and carry out your treatments | Our agreement with you (Art 6(1)(b)) |
| You fill in a consultation form | Health information you give us, for example allergies or previous reactions | To check a treatment is safe for you, and how to carry it out | Our agreement with you, plus your explicit consent for health information (Art 9(2)(a)). We keep it afterwards in case of a legal claim (Art 9(2)(f)). |
| You pay | The amount, the date and how you paid. SumUp handles card payments, and we don’t receive your full card details. | To take payment and keep company accounts | Our agreement with you, and our legal duty to keep accounts (Art 6(1)(c)) |
| You agree to a photo | Photos of your finished treatment | To show our work on Instagram and this website | Your consent (Art 6(1)(a)) |
| You visit this website | With your permission: how you use the site (Google Analytics; see our Cookie Policy). Without cookies: page-view counts (Cloudflare). Technical data such as your IP address, to deliver the site and block spam. | To understand how the site is used, and to keep it working and secure | Your consent for Google Analytics (Art 6(1)(a)). Our legitimate interest in running a secure, working website for the rest (Art 6(1)(f)). |
- When
- You get in touch (website form, phone, text, WhatsApp, Instagram, Messenger or email)
- What we collect
- Your name, phone number, email address, Instagram username if you use it, the treatments and times you’re interested in, and anything you tell us
- Why
- To reply and arrange your appointment
- Lawful basis
- Steps you’ve asked us to take before booking (Art 6(1)(b))
- When
- You book and have treatments
- What we collect
- Your name and contact details, appointment history, treatment notes and patch-test records
- Why
- To book and carry out your treatments
- Lawful basis
- Our agreement with you (Art 6(1)(b))
- When
- You fill in a consultation form
- What we collect
- Health information you give us, for example allergies or previous reactions
- Why
- To check a treatment is safe for you, and how to carry it out
- Lawful basis
- Our agreement with you, plus your explicit consent for health information (Art 9(2)(a)). We keep it afterwards in case of a legal claim (Art 9(2)(f)).
- When
- You pay
- What we collect
- The amount, the date and how you paid. SumUp handles card payments, and we don’t receive your full card details.
- Why
- To take payment and keep company accounts
- Lawful basis
- Our agreement with you, and our legal duty to keep accounts (Art 6(1)(c))
- When
- You agree to a photo
- What we collect
- Photos of your finished treatment
- Why
- To show our work on Instagram and this website
- Lawful basis
- Your consent (Art 6(1)(a))
- When
- You visit this website
- What we collect
- With your permission: how you use the site (Google Analytics; see our Cookie Policy). Without cookies: page-view counts (Cloudflare). Technical data such as your IP address, to deliver the site and block spam.
- Why
- To understand how the site is used, and to keep it working and secure
- Lawful basis
- Your consent for Google Analytics (Art 6(1)(a)). Our legitimate interest in running a secure, working website for the rest (Art 6(1)(f)).
04
Health information and patch tests
Some treatments are only safe if we know about allergies, skin or eye conditions, medication or previous reactions. You tell us on a paper consultation form, and you sign or tick to agree to us using that information.
- We use it only to decide whether a treatment is safe for you, and how to carry it out.
- We don’t share it with anyone.
- Consultation forms and patch-test records are kept only on paper, locked away. They are never put in our booking system.
- You can withdraw your consent at any time by telling Megan. We may then be unable to carry out treatments that need it.
05
Photographs
We may photograph your finished treatment to show our work on Instagram and this website. We only do this with your permission, which we ask for by message or with a tick on your consultation form, so there is a record of it. Saying no makes no difference to your treatment.
You can change your mind at any time by messaging or emailing us. We will then take the photo down from our website and Instagram. We can’t recall copies that other people have already shared or saved.
06
Messaging apps
If you message us on WhatsApp, Instagram or Facebook Messenger, Meta, the company that runs those apps, also handles your messages under its own privacy policy. Texts and calls go through our mobile network, and emails through Microsoft (see who we share it with). Messages are kept on Megan’s phone and in the apps themselves.
08
Sending information outside the UK
Some of these services store or handle information outside the UK. When they do, UK law requires a safeguard so your information stays protected to the same standard.
| Service | Where | Safeguard |
|---|---|---|
| Microsoft 365 (email) | Microsoft’s data centres, which may be outside the UK, for example for support | Microsoft’s data protection terms, including the UK transfer agreement (IDTA) and the UK-US data bridge |
| Cloudflare (website) | Its worldwide network, including the US | Cloudflare’s data protection terms: standard contractual clauses with the UK Addendum |
| Google Analytics | Collected on servers in the UK or Europe, then possibly handled in other countries, including the US | The UK-US data bridge, with standard contractual clauses as a fallback |
| SumUp (card payments) | The European Economic Area | UK adequacy regulations, which recognise the EEA’s protection as equal to the UK’s |
| The US | WhatsApp’s UK data transfer terms: standard contractual clauses with the UK Addendum | |
| Instagram and Messenger | The US | Meta handles these messages under its own privacy policy |
| Salon Iris (booking system) | May be the US, where DaySmart Software runs Salon Iris’s system | Salon Iris Ltd arranges this with DaySmart. We are confirming the safeguard it uses with Salon Iris, and will update this policy. |
- Service
- Microsoft 365 (email)
- Where
- Microsoft’s data centres, which may be outside the UK, for example for support
- Safeguard
- Microsoft’s data protection terms, including the UK transfer agreement (IDTA) and the UK-US data bridge
- Service
- Cloudflare (website)
- Where
- Its worldwide network, including the US
- Safeguard
- Cloudflare’s data protection terms: standard contractual clauses with the UK Addendum
- Service
- Google Analytics
- Where
- Collected on servers in the UK or Europe, then possibly handled in other countries, including the US
- Safeguard
- The UK-US data bridge, with standard contractual clauses as a fallback
- Service
- SumUp (card payments)
- Where
- The European Economic Area
- Safeguard
- UK adequacy regulations, which recognise the EEA’s protection as equal to the UK’s
- Service
- Where
- The US
- Safeguard
- WhatsApp’s UK data transfer terms: standard contractual clauses with the UK Addendum
- Service
- Instagram and Messenger
- Where
- The US
- Safeguard
- Meta handles these messages under its own privacy policy
- Service
- Salon Iris (booking system)
- Where
- May be the US, where DaySmart Software runs Salon Iris’s system
- Safeguard
- Salon Iris Ltd arranges this with DaySmart. We are confirming the safeguard it uses with Salon Iris, and will update this policy.
09
How long we keep it
We keep information only as long as we need it, then delete or shred it.
| Information | How long we keep it |
|---|---|
| Consultation forms, patch-test records and treatment notes | 6 years after your last appointment. For clients under 18, until their 24th birthday if that is later. |
| Messages with clients | The same as treatment records |
| Enquiries that don’t lead to a booking | 12 months |
| Payment and accounting records | 6 years |
| Complaints | 3 years after the complaint is closed |
| Photos online | Until you withdraw your permission, or we take them down |
| Google Analytics data | 2 months, after which Google deletes it automatically |
| Website spam check | Your IP address, held only as a scrambled code, is deleted after one hour |
- Information
- Consultation forms, patch-test records and treatment notes
- How long we keep it
- 6 years after your last appointment. For clients under 18, until their 24th birthday if that is later.
- Information
- Messages with clients
- How long we keep it
- The same as treatment records
- Information
- Enquiries that don’t lead to a booking
- How long we keep it
- 12 months
- Information
- Payment and accounting records
- How long we keep it
- 6 years
- Information
- Complaints
- How long we keep it
- 3 years after the complaint is closed
- Information
- Photos online
- How long we keep it
- Until you withdraw your permission, or we take them down
- Information
- Google Analytics data
- How long we keep it
- 2 months, after which Google deletes it automatically
- Information
- Website spam check
- How long we keep it
- Your IP address, held only as a scrambled code, is deleted after one hour
10
Keeping it secure
- Paper records are kept locked away.
- Only Megan can see consultation forms and treatment notes. Appointment details in the shared booking system can also be seen by Pure Beauty.
- Our email and booking system are business accounts protected by passwords.
- If something goes wrong with your information and it puts you at high risk, we will tell you.
11
Your rights
You can ask us to:
- give you a copy of the information we hold about you;
- correct anything that’s wrong or incomplete;
- delete your information;
- limit how we use it;
- stop using it where we rely on our legitimate interests;
- give it to you, or to another business, in a format a computer can read.
Where we rely on your consent (health information, photos and Google Analytics), you can withdraw it at any time. That doesn’t affect anything we did before.
To ask, email [email protected] or tell Megan. It’s free. We reply within one month. If a request is complex, we may need up to two more months, and we’ll tell you why. We may ask you to confirm who you are first.
Some rights have limits. For example, we may need to keep treatment records in case of a legal claim, or payment records for our accounts, even if you ask us to delete them. If so, we’ll explain.
12
Complaints
If you’re unhappy with how we’ve handled your information, please tell us first at [email protected], so we can try to put it right. We’ll acknowledge your complaint within 30 days, usually much sooner. Then we’ll look into it and tell you the outcome.
You can also complain to the UK regulator, the Information Commission (known as the ICO), at any time. You don’t have to come to us first.
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113 (Monday to Friday, 9am to 5pm)
- Post: Information Commission’s Office, 4th Floor, No.3 Circle Square, 5 Hawkshaw Street, Manchester M1 7BL
13
Changes to this policy
We’ll update this page whenever something changes, and change the date at the top.
