AESTHETICS LOUNGE ACADEMY LTD
Last Updated December 2020
Overview
Company: Aesthetics Lounge Academy LTD
GDPR: General Data Protection Regulation
Responsible Person: Emily Abbassi
Register of Systems: a register of all systems or contexts in which personal data is processed by the company
How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you for one of the following reasons:
You are attending for a treatment
You are an employee for the company
you are attending as a student for a training course
How we collect data
CCTV (Video/Audio) Within the premises
Consent forms and medical history forms for treatments
Other forms if applicable
We use the information that you have given us in order to
Ensure thorough safety of our customers
In order to carry out thorough consultations prior to treatments
In order to receive your formal consent prior to treatment
Assess medical history so that our practitioners can advise accordingly
Why do we feel it is necessary to install CCTV (Audio/Video) within the premises:
Safety of our customers
Due to the nature of certain treatments & risks potentially involved
Crime Prevention
Due the nature of the business (Education, Training, Invasive treatments)
Safety of our staff
Protection of our Company
Some methods we use to make our customers/Staff aware of CCTV:
Notices situated around the premises
Dat protection policy on our website
Consent forms completed with all staff
Verbally if required
Important Information
Here at Aesthetics Lounge Academy Ltd, we take privacy of our customers and our staff very seriously and whilst ensuring that we have the correct processes in place for the company and our customers, its very important to us that our customers and staff are aware that we as a company respect your privacy and do everything we can in order to minimise the impact on this.
Your data protection rights
Under data protection law, you have rights including:
Your right of access- You have the right to ask us for copies of your personal information.
Your right to rectification- You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure- You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing- You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing- You have the the right to object to the processing of your personal information in certain circumstances.
Your right to data portability- You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us using the contact details above to make any form of request
Accuracy
The Company shall take reasonable steps to ensure personal data is accurate.
Where necessary for the lawful basis on which data is processed, steps shall be put in place to ensure that personal data is kept up to date.
Storing of Data
To ensure that personal data is kept for no longer than necessary, The Company shall put in place an archiving policy for each area in which personal data is processed and review this process annually.
The archiving policy shall consider what data should/must be retained, for how long, and why.
Storage location: 22 unit 6, Hatherton Court, Hatherton Street, Walsall, WS4 2LA
Security
The Company shall ensure that personal data is stored securely using software that is kept-up-to-date and also in lockable filing storage.
Access to personal data shall be limited to personnel who need access and appropriate security should be in place to avoid unauthorised sharing of information.
When personal data is deleted this should be done safely such that the data is irrecoverable.
Data protection principles
The Company is committed to processing data in accordance with its responsibilities under the GDPR.
Article 5 of the GDPR requires that personal data shall be:
processed lawfully, fairly and in a transparent manner in relation to individuals.
collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals; and
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.”
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us using the contact form on our website.
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk