№ Legal — Privacy

Privacy Policy

Version 2.0 · Last updated 5 June 2026

Your trust matters to us. This notice explains, in plain terms, what personal information Hair Aesthetics Club collects about you, why we use it, who we share it with, how long we keep it and the rights you have over it — in line with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

Because of the nature of our work — hair restoration, haircuts, skin and aesthetic treatments and training — some of the information we hold is sensitive, including information about your health and photographs of you. We treat that information with particular care, and this notice sets out exactly how.

Quick summary. We use your information to provide our services safely, to manage your bookings and payments, to keep proper records, and — only with your permission — to send you marketing and to use your photographs. We never sell your data. You can ask us to show you, correct or delete your data, and you can withdraw any consent at any time.
On this page
  1. Who we are & how to contact us
  2. The information we collect
  3. How we collect it
  4. How & why we use it (lawful bases)
  5. Health & special category data
  6. Photographs & images
  7. Marketing communications
  8. Cookies & our website
  9. Who we share information with
  10. International data transfers
  11. How long we keep information
  12. How we keep it secure
  13. Your rights
  14. Automated decisions & profiling
  15. Children & age restrictions
  16. CCTV
  17. Changes to this policy
  18. How to complain

1. Who we are & how to contact us

Hair Aesthetics Club ("HAC", "we", "us", "our") is the data controller responsible for your personal data. Hair Aesthetics Club is a trading name of HAC Ltd, a company registered in England and Wales (company number: [to be confirmed]), with its registered office at A6 Moorfield Road, Blakenhall Business Park, Wolverhampton, WV2 4QT.

We are registered with the UK Information Commissioner's Office (ICO) as a data controller (registration number: [to be confirmed]).

For any question about this notice or your data, or to exercise your rights, contact us:

  • By email: info@hacltd.net (please mark it "Data Protection")
  • By phone: +44 7398 626555 or +44 7968 581705
  • By post: Data Protection, Hair Aesthetics Club, A6 Moorfield Road, Blakenhall Business Park, Wolverhampton, WV2 4QT

2. The information we collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Identity & contact data — your name, title, date of birth (where relevant to age-restricted treatments), email address, telephone/WhatsApp number and postal address.
  • Appointment & service data — the services you enquire about or book, your appointment dates, locations and history, consultation notes, the systems or treatments chosen, aftercare details and your preferences.
  • Health & special category data — information relevant to providing treatments safely, such as your hair-loss pattern and scalp condition, skin condition, relevant medical history, medications, allergies and sensitivities, and your suitability for a treatment. See section 5.
  • Photographs & images — before/after and progress photographs taken as part of your treatment record, and (only with your separate consent) images used for our portfolio or marketing. See section 6.
  • Consent & consultation records — the consent forms, assessments and acknowledgements you complete.
  • Payment & transaction data — the amount and date of payments, the plan you are on, and limited payment-method details. Card details are processed securely by our payment provider; we do not store your full card number.
  • Marketing & communications data — your contact preferences and your responses to, and engagement with, our messages.
  • Technical & usage data — when you use our website: your IP address, device and browser type, approximate location, the pages you view and how you arrived, collected through cookies and similar technologies (see section 8).
  • Training Academy data — if you enrol on a course: your professional background, course progress, certification and related payment details.
  • CCTV images — if our studios use CCTV for security (see section 16).

3. How we collect your information

  • Directly from you — when you book or attend a consultation or appointment, complete a consultation, medical or consent form, contact us by phone, email, WhatsApp, social media or our website, make a payment, or sign up to our newsletter.
  • Automatically — when you visit our website, through cookies and similar technologies.
  • From third parties — for example our booking, payment or communications providers, or where you are referred to us with your knowledge.

4. How & why we use your information

We only use your personal data where the law allows us to. The table below sets out what we use your data for and the lawful basis we rely on under Article 6 of the UK GDPR (and, for health and other special category data, the additional condition under Article 9).

What we use it forInformation usedOur lawful basis
Answering your enquiries and giving quotesIdentity, contact, what you're interested inTaking steps at your request before entering a contract; our legitimate interests in responding to you
Managing bookings and providing our servicesIdentity, contact, appointment & service dataPerformance of our contract with you
Assessing suitability & treating you safely, and keeping treatment recordsHealth & special category data, consultation/consent records, photographsPerformance of our contract, plus your explicit consent for special category data (Art 9(2)(a)); where a treatment is provided by a registered healthcare professional, the provision of healthcare (Art 9(2)(h))
Using your photographs for marketing or our portfolioImagesYour explicit consent (separate and freely withdrawable)
Taking payment and preventing fraudPayment & transaction dataPerformance of our contract; legal obligation; our legitimate interests in preventing fraud
Keeping financial & business recordsIdentity, transaction dataCompliance with our legal obligations (tax, accounting)
Service messages — confirmations, reminders, aftercareContact, appointment dataPerformance of our contract; our legitimate interests in running our service well
Marketing — news, offers and tips by email, SMS or WhatsAppContact & marketing preferencesYour consent; or our legitimate interests where you are an existing client and the law permits (the "soft opt-in"). You can opt out at any time
Running, securing & improving our websiteTechnical & usage data, cookiesOur legitimate interests (security and core functionality); your consent for analytics and marketing cookies
Administering the Training AcademyAcademy dataPerformance of our contract with you
Meeting our legal duties and establishing, exercising or defending legal claimsAny relevant dataLegal obligation; our legitimate interests; for special category data, the establishment, exercise or defence of legal claims (Art 9(2)(f))

Where we rely on legitimate interests, we have balanced those interests against your rights and are happy to explain that assessment on request. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. Health & special category data

To provide hair, scalp, skin and aesthetic treatments safely we sometimes need information about your health — for example your scalp or skin condition, relevant medical history, medications, allergies and your suitability for a particular treatment. This is "special category" data and receives extra protection.

We rely on your explicit consent to process this information for your treatment, which you give when you complete our consultation and consent forms. Where a treatment is carried out by, or under the responsibility of, a suitably qualified healthcare professional, we may also process it as necessary for the provision of healthcare. We collect only what we need, restrict access to the team members involved in your care, and store it securely. You can withdraw your consent at any time, although this may mean we are unable to provide certain treatments safely.

6. Photographs & images

With your agreement, we take photographs as part of your treatment record (for example before/after and progress images) so we can plan your treatment and track results. We will only use your images for our portfolio, website or marketing if you give us separate, specific consent to do so. That consent is entirely optional, will never affect the service you receive, and you can withdraw it at any time — after which we will stop using your images going forward (we may be unable to recall materials already printed or published).

7. Marketing communications

We will only send you marketing where you have asked us to, or where you are an existing client and the law allows us to contact you about similar services, in each case with a simple way to opt out. Every marketing email contains an unsubscribe link, and you can opt out at any time by replying STOP to a text, telling a member of our team, or emailing info@hacltd.net. Opting out of marketing will not stop important service messages (such as appointment confirmations and aftercare).

8. Cookies & our website

Our website uses cookies and similar technologies. Strictly necessary cookies make the site work and keep it secure, and do not require your consent. Analytics cookies (which help us understand how the site is used) and any marketing cookies are only set where you have given consent, which you can change or withdraw at any time. You can also control cookies through your browser settings. For full details of the cookies we use, please see our cookie settings or contact us.

9. Who we share your information with

We never sell your personal data. We share it only where necessary, and only with organisations that are required to keep it secure and use it solely on our instructions. These include:

  • Payment providers — to take and process payments securely (for example our card-payment processor).
  • IT, hosting, website & booking providers — who host our website, database and booking system and provide technical support.
  • Communications providers — email, SMS and messaging (including WhatsApp) services we use to contact you. Messages you send us via a third-party platform are also subject to that platform's own privacy terms.
  • Analytics providers — where you have consented to analytics cookies.
  • Professional advisers — such as our accountants, insurers and legal advisers, where needed.
  • Regulators, law enforcement and other authorities — where we are required or permitted by law to disclose information.
  • Purchasers — if we restructure, sell or transfer our business, in which case your data may be shared with the relevant party subject to this notice.

10. International data transfers

Some of our providers are based outside the United Kingdom, which may mean your personal data is transferred internationally. Whenever we do this, we make sure an appropriate safeguard recognised under UK data protection law is in place — for example transfer to a country the UK has deemed to provide adequate protection, an International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), or another lawful transfer mechanism. You can ask us for more detail about the safeguards that apply.

11. How long we keep your information

We keep your personal data only for as long as we need it for the purposes set out in this notice, including to meet legal, accounting, insurance and regulatory requirements, and to handle any complaint or claim. Our typical retention periods are:

Type of informationHow long we keep it
Client treatment & consultation records, including health data, consent forms and treatment-record photographsFor the duration of your relationship with us and for at least 7 years after your last treatment — or longer where needed to deal with a complaint or claim, or where required by our insurers or by law. Where you were under 18 at the time, until your 25th birthday.
Booking & appointment recordsIn line with your treatment records (up to 7 years).
Payment & financial records6 years from the end of the relevant financial year (tax & company law).
Marketing images (used with your consent)Until you withdraw your consent.
Marketing preferencesUntil you opt out or object, plus a minimal record so we can honour your choice.
Enquiries that do not lead to a bookingUp to 12 months.
Website logs & analyticsUp to 24 months.
CCTV footage (if used)Usually around 30 days, unless retained for a specific incident.

When we no longer need your data, we securely delete or anonymise it.

12. How we keep your information secure

We take the security of your data seriously and use appropriate technical and organisational measures to protect it against loss, misuse and unauthorised access — including access controls, encryption of data in transit, secure storage, staff confidentiality obligations and limiting access to those who need it. No method of storage or transmission is completely secure, but we work to protect your data and have procedures to deal with any suspected breach. Where the law requires, we will notify the ICO, and you, of a personal data breach.

13. Your data protection rights

Under UK data protection law you have the following rights, which you can exercise free of charge by contacting us (see section 1):

  • Access — to be told whether we hold your data and to receive a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to ask us to delete your data in certain circumstances ("right to be forgotten").
  • Restriction — to ask us to limit how we use your data in certain circumstances.
  • Portability — to receive certain data in a portable format, or have it sent to another provider.
  • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Withdraw consent — where we rely on your consent, to withdraw it at any time.
  • Rights regarding automated decisions — see section 14.

We will respond within one month. We may need to verify your identity, and in limited cases the law allows us to refuse or charge for a manifestly unfounded or excessive request — we will always explain our decision.

14. Automated decision-making & profiling

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. If this ever changes, we will update this notice and tell you about your rights.

15. Children & age restrictions

Our services and website are intended for adults. Certain treatments are subject to legal age limits — in particular, we do not provide Botox (botulinum toxin) or cosmetic filler treatments to anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

16. CCTV

Where our studios operate CCTV, it is used for the safety and security of our clients, staff and premises, on the basis of our legitimate interests. Signage is displayed where CCTV is in use, footage is held securely for a limited period and accessed only where necessary (for example to investigate an incident or where required by law).

17. Changes to this policy

We may update this notice from time to time to reflect changes in our services or the law. The current version, with its date, is always available on this page. Where changes are significant, we will take reasonable steps to bring them to your attention.

18. How to complain

If you have a concern about how we handle your personal data, please contact us first (section 1) so we can try to put it right. You also have the right to complain to the UK supervisory authority:

  • Information Commissioner's Office (ICO)
  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Sedgley studio
9 Dudley Street, Sedgley, DY3 1SA

Wolverhampton — registered office & HQ
A6 Moorfield Road, Blakenhall Business Park, Wolverhampton, WV2 4QT
West Midlands, England