Overview
BROW ABILITY
Last Updated March 2025
Overview
​
Business: Brow Ability & Salon Ability
GDPR: General Data Protection Regulation
Responsible Person: Nicole Foster
Register of Systems: A register of all systems or contexts in which personal data is processed by the company
Privacy Statement
Brow Ability & Salon Ability recognises that personal privacy is an important issue and therefore adheres to the privacy policies in line with UK legislation.
Any personal information gathered through the website or through paperwork signed at the clinic will be used only for insurance and medical purposes. We hereby declare that we do not sell, license or trade your personal information to third parties. We also declare that we do not distribute your personal information to marketing companies or other such organisations.
The pages of this website use cookies for security purposes. These cookies are not used to capture or store personal information for any purpose other than to authenticate the user and are deleted as soon as a session is terminated. Information about the pages visited by logged-in users is stored for statistical analysis purposes, but individual usage patterns are not monitored.
Finally, we maintain logs of the website’s server activity. These log files include the IP address of every computer used to access the Brow Ability & Salon Ability website. The log files are solely used to analyse website usage.
To exercise any of your privacy rights, or if you have any questions or concerns regarding this Privacy Notice or the data processing practices outlined herein, please contact us as follows:
By email at: contact@browability.com
Data Protection Policy
The Company is committed to processing data in accordance with its responsibilities under the GDPR.
Article 5 of the GDPR requires that personal data shall be:
-
Processed lawfully, fairly and in a transparent manner in relation to individuals
-
Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
-
Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
-
Accurate and, where necessary, kept up to date
-
Kept in a form which permits identification of data subjects for no longer than is necessary
-
Processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage
How we get the personal information and why we have it:
Most of the personal information we process is provided to us directly by you for one of the following reasons:
-
You are attending for a treatment
-
You are an employee, or worker, or otherwise engaged with the company
-
You are attending as a student for a training course
How we collect data:
-
CCTV (video) within the premises
-
Consent forms and medical history forms for treatments
-
Other forms if applicable
​
We use the information you provide to:
-
Ensure the safety of our customers
-
Carry out thorough consultations prior to treatments
-
Obtain formal consent before providing treatments
-
Assess medical history to enable our practitioners to advise appropriately
Why we use CCTV on the premises:
-
For the safety of our customers and staff
-
Due to the nature of certain treatments and potential risks involved
-
For crime prevention
-
Because of the nature of the business (education, training, invasive treatments)
-
For the protection of our company
We inform staff and clients of CCTV through:
-
Data protection policy on our website
-
Verbal communication when required
​
Important Information
At Brow Ability & Salon Ability, we take the privacy of our customers and staff very seriously. We are committed to having the right processes in place and ensuring that everyone who interacts with our company understands that we respect and protect your personal data at all times.
Your Data Protection Rights
Under data protection law, you have rights including:
-
Right of access – You can request copies of your personal data.
-
Right to rectification – You can request corrections to inaccurate or incomplete data.
-
Right to erasure – You can request deletion of your data in certain circumstances.
-
Right to restrict processing – You can request limited use of your data in certain circumstances.
-
Right to object to processing – You can object to how we use your data in some cases.
-
Right to data portability – You can request your data be transferred to another organisation or directly to you in specific cases.
You are not required to pay any charge for exercising your rights. If you make a request, we will respond within one month.
Please contact us using the details above to make any data-related requests.
Accuracy
The Company shall take reasonable steps to ensure personal data is accurate. Where necessary, steps shall be taken to keep personal data up to date for the lawful basis on which it is processed.
Storing of Data
To ensure that personal data is retained no longer than necessary, the company has an annual archiving review process. This determines what data must be retained, for how long, and for what purpose.
Storage Location: 112 Hollyhedge Road, B71 3AH
Security
We ensure that all personal data is stored securely, using up-to-date software and locked filing systems. Access is limited to authorised personnel only. When data is deleted, it is done securely to ensure it cannot be recovered.
How to Complain
If you have concerns about our use of your personal information, you can make a complaint to us via our website contact page.
If you remain dissatisfied, you can also contact the Information Commissioner’s Office (ICO):
ICO Contact Details:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: www.ico.org.uk