In compliance with UK GDPR, Data Protection Act 2018, and PECR Regulations
At Sorbon Spa and Beauty Limited, we are fully committed to protecting your privacy and personal data. As a London-based business, we adhere strictly to all UK data protection laws to ensure your information remains secure and confidential.
Information We Collect
We collect and process the following personal data to provide our services:
Personal Identification:
- Full name
- Contact details (email, phone number, address)
- Date of birth (for age-restricted treatments)
Service Information:
- Appointment history and preferences
- Treatment records and notes
- Skin type/allergy information (for safe treatment delivery)
Payment Details:
- Card information (processed securely via PCI-compliant systems)
- Transaction history
- Gift card/voucher details
Lawful Basis for Processing
We process your data under the following legal bases:
- Contractual necessity (for appointment bookings and service delivery)
- Legal obligation (for health and safety records)
- Consent (for marketing communications)
How We Use Your Data
Your information enables us to:
- Book, confirm, and remind you of appointments
- Personalize treatments based on your history and preferences
- Process payments securely
- Send service updates and offers (only with your explicit consent)
- Maintain treatment records as required by UK health regulations
Data Retention Periods
We retain your personal data only as long as necessary:
- Appointment records: 7 years (in line with UK insurance requirements)
- Financial transactions: 6 years (for HMRC compliance)
- Marketing preferences: Until withdrawal of consent
Your Data Rights
Under UK data protection law, you have the right to:
- Request access to your personal data
- Correct inaccurate information
- Request deletion of your data (subject to legal requirements)
- Restrict or object to data processing
- Withdraw consent for marketing
- Request data portability
To exercise these rights, please contact our Data Protection Officer at:
Email: privacy@sorbonspa.co.uk
Post: Sorbon Spa and Beauty Limited, [Your London Address]
Data Security Measures
We implement robust security protocols including:
- Encrypted data storage
- Restricted staff access to personal data
- Regular security audits
- Secure destruction of paper records