General Data Protection Regulation (GDPR) Compliance
The EU General Data Protection Regulation (GDPR) is effective from May 2018 gives all EU citizens more rights and protections for their personal data, to minimise the possibility of theft and fraud.
These regulations include provisions for the following areas:
- The right to be informed: Companies must publish a privacy notice, in addition to explaining transparently how they use this personal data.
- The right of access: Individuals will have the right to demand details of any of their data that a company may hold. This information must be provided within one month of request at no charge to the individual.
- The right to rectification: If a person’s data is incorrect or incomplete, he or she has the right to have it corrected. If the company that holds the information has passed any of that information to third parties. The company must inform the third party of the correction and inform the person which third parties have their personal data.
- The right to be forgotten: A person may request the removal of his or her personal data in specific circumstances.
- The right to restrict processing: Under certain circumstances, an individual can block the processing of his or her personal data.
- The right to data portability: A person can access their data for their own use anywhere they prefer.
- The right to object: A person can object to the use of their personal data for most purposes.
UniSkin Aesthetics Privacy & GDPR Policy
1.0 Our core principles regarding user privacy and data protection
- User privacy and data protection are inviolable human rights
- We have a duty of care to people contained within our data
- Data is a liability: it should only be collected and processed when absolutely necessary
- We despise spam in all its forms
- We will never sell, rent or otherwise distribute or make public any personal information
2.0 Relevant Legislation
Alongside our business and internal computer systems, this UniSkin Aesthetics website is designed to comply with the following national and international legislation with regards to data protection and user privacy:
- UK Data Protection Act 1988 (DPA)
- EU Data Protection Directive 1995 (DPD)
- EU General Data Protection Regulation 2018 (GDPR)
This site’s compliance with the above legislation, all elements of which are stringent in nature, means that this site is likely compliant with the data protection and user privacy legislation set out by many other countries and territories as well. If you are unsure about whether this site is compliant with your own country of residences’ specific data protection and user privacy legislation you should contact our data protection officer (details of whom can be found in section 9.0 below) for clarification.
3.0 Personal information that this website collects and why we collect it
This website collects and uses personal information for the following reasons:
3.1 Site visitation tracking
Like most websites, this site uses Google Analytics (GA) to track user interaction.
We use this data to determine the number of people using our site, to better understand how they find and use our web pages and to track their journey through the website.
Although GA records data such as your approximate geographical location, device, internet browser and operating system, none of this information personally identifies you to us.
GA also records your computer’s IP address which could be used to personally identify you but Google do not grant us access to this. We consider Google to be a third party data processor (see section 6.0 below).
Disabling cookies on your internet browser will stop GA from tracking any part of your visit to pages within this website.
3.2 Email links
Should you choose to contact us using an email email@example.com, none of the data that you supply will be stored by this website or passed to/be processed only by any of the third party data processors defined in section 6.0 below.
Instead the data will be collated into an email and sent to us over the Simple Mail Transfer Protocol (SMTP). Our SMTP servers are protected by TLS (sometimes known as SSL) meaning that the email content is encrypted using SHA-2, 256-bit cryptography before being sent across the internet. The email content is then decrypted by our local computers and devices.
3.3 Contact forms
Should you choose to contact us using the contact form on our Contact us page the email address that you submit to us will be stored in our www.uniskin.co.uk website platform in the ‘Contacts’ database, which we use contacting you. We consider www.uniskin.co.uk to be a third party data processor (see section 6.0 below). The email address that you submit will be stored within this website’s own database but not in any of our internal computer systems.
Your email address will remain within the www.uniskin.co.uk ‘Contacts’ database on our website for as long as we continue to use the www.uniskin.co.uk platform or until you specifically request removal from the list.
You can do this by unsubscribing using the unsubscribe links contained in any email newsletters that we send you or by requesting removal via email. When requesting removal via email, please send your email to us using the email account that you used on the contact us form.
3.4 Email newsletter
If you choose to join our regular newsletter mailings (which is sent via email), the email address that you submit to us will be stored in our www.uniskin.co.uk website platform in the ‘Shout Out’ database, which we use for our email marketing. We consider www.uniskin.co.uk to be a third party data processor (see section 6.0 below). The email address that you submit will be stored within this website’s own database but not in any of our internal computer systems.
Your email address will remain within the www.uniskin.co.uk‘ Shout Out’ database on our website for as long as we continue to use the www.uniskin.co.uk platform for email marketing or until you specifically request removal from the list.
You can do this by unsubscribing using the unsubscribe links contained in any email newsletters that we send you or by requesting removal via email. When requesting removal via email, please send your email to us using the email account that is subscribed to the mailing list.
If you are under 16 years of age you MUST obtain parental consent before joining our email newsletter.
While your email address remains within the www.uniskin.co.uk ‘Shout Out’ database, you will receive occasional newsletter-style emails from us.
4.0 How we store your personal information
As detailed in section 3.2 above, if you submit a comment to a News post published on this website, some personal information will be stored within this website’s database.
If you have made a purchase from this website, then your details (not including any financial details) are stored in our www.uniskin.co.uk ‘Engage’ database in order that we can fulfil your order(s) and also to refer back to your email and/or postal details in order that we may track any orders you have queries on. Any financial information is not stored or used by us as all our transactions are made within the PayPal platform which does not retain any financial information once the transaction has been processed.
These are the only occasions where personal data will be stored on this website. This data is currently stored in an identifiable fashion; a limitation of the content management system that this website is built on (www,uniskin.co.uk). In the near future we aim to change the storage of this data to a pseudonymous fashion meaning that the data would require additional processing using a separately stored ‘key’ before it could be used to identify an individual.
Pseudonymisation is a recent requirement of the GDPR which many web application developers are currently working to fully implement. We are committed to keeping it as a high priority and will implement it on this website as soon as we are able to.
5.0 About this website’s server
This website is hosted in data centers in the United States and Europe. From time to time, we may transfer hosting from one location to another. Notwithstanding the above, the www,uniskin.co.uk.com platform complies with the EU-US Privacy Shield Framework and the Swiss-US privacy shield framework as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information transferred from the European Union to the United States, and therefore adheres to the Privacy Shield Principles. www,uniskin.co.uk.com guarantees that the platform will be compliant with the new regulation from May 2018.
All traffic (transferral of files) between this website and your browser is encrypted and delivered over HTTPS.
6.0 Our third party data processors
We use two third parties to process personal data on our behalf. The third parties we use are PayPal and www,uniskin.co.uk.
PayPal process payments for any products/services purchased from our website. Neither we nor PayPal retain any financial information you may submit as part of the purchasing process. PayPal monitor every transaction, 24/7 to prevent fraud, email phishing and identity theft. Every transaction is heavily guarded behind PayPal’s advanced encryption. If something appears suspicious, their dedicated team of security specialists will identify suspicious activity and help protect you from fraudulent transactions. PayPal, www.uniskin.co.uk or UniSkin Aesthetics will never ask for any sensitive information.
Your data as mentioned below is encrypted before transmission to prevent misuse of the transmitted data by third parties. SSL (Secure Socket Layer) is a security technology which guarantees that your personal data, including credit card information, login data and payment method, are securely transferred via the Internet. The data is encrypted so that is only readable by the PayPal payment system.
Your data which is encrypted, is as follows:
- personal data (address data, telephone number, etc.)
- login data (username and password)
- all methods of payment selected, credit card and bank account
www.uniskin.co.uk provide the Customer Engagement platform we use to manage and fulfil your orders. No personal financial information is ever taken or stored in this system as during the process, everything is transferred out to PayPal so that neither UniSkin Aesthetics nor www.uniskin.co.uk has access to your financial information.
What www.uniskin.co.uk do to ensure data protection to all our customers:
- uniskin.co.uk employ full-time security consultants, dedicated to the security of our customer information.
- www,uniskin.co.uk signup and login services are completed through a secure server (HTTPS/SSL).
- uniskin.co.uk uses cryptography hash functions to protect your information. Your password is stored as a hash digest and, in the event of a security breach, your original password cannot be recovered from ours or www.uniskin.co.uk servers.
- uniskin.co.uk is certified under the EU-US Privacy Shield Framework and the Swiss-US privacy Shield Framework as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, and therefore adheres to the Privacy Shield Principles.
PayPal and www.uniskin.co.uk have been carefully chosen and all of them comply with the legislation set out in section 2.0.
Two of the following third parties are based in the USA and one is based in the Republic of Ireland and all are EU-U.S Privacy Shield compliant.
7.0 Data breaches
We will report any unlawful data breach of this website’s database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.
8.0 Social Media Platforms
Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are custom to the terms and conditions as well as the privacy policies held with each social media platform respectively.
Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution in regard to their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.
This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.
9.0 Shortened Links On Social Media
This website and its owners through their social media platform accounts may share web links to relevant web pages. By default some social media platforms shorten lengthy url’s (web addresses).
Users are advised to take caution and good judgement before clicking any shortened url’s published on social media platforms by this website and its owners. Despite the best efforts to ensure only genuine url’s are published many social media platforms are prone to spam and hacking and therefore this website and its owners cannot be held liable for any damages or implications caused by visiting any shortened links.
10.0 Links To Other Websites
In addition, if you linked to our website from a third party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.
11.0 16 And Under
We are concerned to protect the privacy of children aged 16 or under. If you are aged 16 or under‚ please get your parent/guardian’s permission beforehand whenever you provide us with personal information.
12.0 Transferring Your Information Outside of Europe
As part of the services offered to you through this website, the information which you provide to us may be transferred to countries outside the European Union (“EU”). By way of example, this may happen if any of our servers are from time to time located in a country outside of the EU. These countries may not have similar data protection laws to the UK. By submitting your personal data, you’re agreeing to this transfer, storing or processing. If we transfer your information outside of the EU in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy.
If you use our services while you are outside the EU, your information may be transferred outside the EU in order to provide you with those services.
We keep this Policy under regular review. This Policy was last updated in May 2018.
Instead, we recommend that you check this page occasionally for any policy changes. Specific policy changes and updates are mentioned in the change log below.
UniSkin ("UniSkin") operates UniSkin.co.uk and may operate other websites. It is UniSkin policy to respect your privacy regarding any information we may collect while operating our websites.
Like most website operators, UniSkin collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. UniSkin purpose in collecting non-personally identifying information is to better understand how UniSkin visitors use its website. From time to time, UniSkin may release non-personally-identifying information in the aggregate, e.g., by publishing a report on trends in the usage of its website.
UniSkin also collects potentially personally-identifying information like Internet Protocol (IP) addresses for logged in users and for users leaving comments on UniSkin.co.uk blogs/sites. UniSkin only discloses logged in user and commenter IP addresses under the same circumstances that it uses and discloses personally-identifying information as described below, except that commenter IP addresses and email addresses are visible and disclosed to the administrators of the blog/site where the comment was left.
Gathering of Personally-Identifying Information
Certain visitors to UniSkin websites choose to interact with UniSkin in ways that require UniSkin to gather personally-identifying information. The amount and type of information that UniSkin gathers depends on the nature of the interaction. For example, we ask visitors who sign up at UniSkin.co.uk to provide a username and email address. Those who engage in transactions with UniSkin are asked to provide additional information, including as necessary the personal and financial information required to process those transactions. In each case, UniSkin collects such information only insofar as is necessary or appropriate to fulfill the purpose of the visitor's interaction with UniSkin. UniSkin does not disclose personally-identifying information other than as described below. And visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain website-related activities.
UniSkin may collect statistics about the behavior of visitors to its websites. UniSkin may display this information publicly or provide it to others. However, UniSkin does not disclose personally-identifying information other than as described below.
Protection of Certain Personally-Identifying Information
UniSkin discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors and affiliated organizations that (i) need to know that information in order to process it on UniSkin behalf or to provide services available at UniSkin websites, and (ii) that have agreed not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using UniSkin websites, you consent to the transfer of such information to them. UniSkin will not rent or sell potentially personally-identifying and personally-identifying information to anyone. Other than to its employees, contractors and affiliated organizations, as described above, UniSkin discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when UniSkin believes in good faith that disclosure is reasonably necessary to protect the property or rights of UniSkin, third parties or the public at large. If you are a registered user of an UniSkin website and have supplied your email address, UniSkin may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what's going on with UniSkin and our products. If you send us a request (for example via email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users. UniSkin takes all measures reasonably necessary to protect against the unauthorized access, use, alteration or destruction of potentially personally-identifying and personally-identifying information.
If UniSkin, or substantially all of its assets, were acquired, or in the unlikely event that UniSkin goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of UniSkin may continue to use your personal information as set forth in this policy.
Our policy: In addition to your legal rights, we also allow you to return goods if you simply change your mind. Please return the unused goods to us with the original till receipt within 14 days and we will offer you an exchange or a credit note.
How to Return an Item:
1. Review the entire Return Policy below.
2. Obtain authorization to return your item by emailing firstname.lastname@example.org
3. Include all parts, pieces, printed materials, promotional items and accessories, along with the product’s original packaging.
4. Include a copy of your packing slip and return authorization received from us via email.
5. Mail your return within 14 days of purchase to the address provided in your return authorisation.
6. Allow 2 weeks for your return to be processed.
Products are eligible for a refund if you decide you don’t want the item, it didn’t meet your expectations or if you have had an adverse skin reaction.
You will be responsible for the return mailing/shipping costs.
If you paid with a gift certificate, store credit, and/or Reward Points along with a credit card, the gift certificate, store credit and/or Reward Points will first be refunded, then your credit card will be refunded.
Prior authorisation is required on all returns. Any returns sent to us without a return authorisation number written on the outside of the package cannot be accepted.
Returned items are subject to inspection by UniSkin staff. All parts, pieces, printed materials, promotional items, accessories and any original product packaging must be returned. Returned products may not be altered, used or damaged.
Multiple return requests for the same products are subject to review by UniSkin. We reserve the right to deny multiple refunds on products purchased and returned more than once.
Returns that do not meet the return policy criteria will not qualify for a refund and may be returned at the customer’s expense or destroyed upon request.
We are not responsible for return packages that may be lost or damaged in transit. It is recommended that you choose a method of shipping with tracking and insurance.
If you have any questions, feel free to contact our customer service representatives via e-mail at email@example.com
Non-Surgical Terms and Conditions
- All patients are required to provide contact details; including address, telephone and email in order to secure an appointment.
- All clients will complete a Medical history form at their first appointment, this is necessary to inform the consultation and treatment planning process.
- All information will be treated as confidential and protected in accordance with Data Protection legislation
- Patient information will not be shared with third parties without written permissions and you will not receive unsolicited information from us.
- You may choose to remove yourself from our mailing list at any time, by unsubscribing.
New Patient – Telephone Consultation
Whilst telephone consultations are discouraged, we acknowledge some circumstances when this service may be helpful; particularly for our patients who will be travelling long distance. New patients, seeking advice from a practitioner in a telephone discussion, require a diary appointment of 30 minutes. Patients must call the clinic at the time agreed.
- You will be sent appointment reminders the day before your appointment, either by text or email.
- Please provide as much notice as possible, if you need to cancel or reschedule your appointment, so that we may make best use of our appointment diary.
- When diaries are particularly busy, we may take a nominal deposit, of (£ 50) refundable on attendance, to mitigate missed appointments.