Privacy Policy
Privacy Policy for Elish Nails and Beauty
Effective Date: 29/09/2025
At Elish Nails and Beauty we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you visit our website or use our services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
⸻
1. Information We Collect
We may collect and process the following personal data:
• Identity Data: name, date of birth (if provided).
• Contact Data: email address, phone number, and address.
• Booking Data: appointment details, service preferences.
• Health Data: allergies or medical conditions (only where relevant to the services you request).
• Payment Data: payment card details (processed securely by our payment provider, not stored by us).
• Technical Data: IP address, browser type, and cookies when using our website.
⸻
2. Lawful Basis for Processing
We process your personal data under the following lawful bases:
• Contract: to provide the services you book with us.
• Consent: where you have explicitly given consent (e.g., to receive marketing emails).
• Legal Obligation: to comply with financial, tax, or legal requirements.
• Legitimate Interests: to improve our services, manage appointments, and ensure business operations.
⸻
3. How We Use Your Information
Your data may be used to:
• Confirm and manage bookings
• Provide our nail and beauty services safely
• Send reminders, updates, or offers (with your consent)
• Process payments securely
• Improve our website and customer experience
⸻
4. Data Sharing
• We do not sell your personal information.
• Data may be shared with trusted third-party providers such as booking platforms, payment processors, or IT support services.
• Health information is treated as special category data and will only be used where necessary to protect your wellbeing.
• We may disclose information if required by law or regulatory authorities.
⸻
5. Data Retention
We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including legal, accounting, or reporting requirements.
• Basic customer records: kept for up to 6 years (for tax/legal purposes).
• Health/consultation forms: retained for 3 years after your last visit (or longer if required by insurance providers).
⸻
6. Your Data Rights
Under UK GDPR, you have the right to:
• Access the personal data we hold about you
• Request correction of inaccurate or incomplete data
• Request deletion of your data (where legally permitted)
• Object to or restrict processing of your data
• Request transfer of your data to another provider
• Withdraw consent at any time (for marketing or optional data use)
To exercise your rights, please contact us using the details below.
⸻
7. Cookies & Website Use
Our website may use cookies to enhance your browsing experience. You can adjust your browser settings to refuse cookies.