GDPR Privacy Policy
Last Updated: 02/12/2025
Data Controller: Renova Hair Limited
Registered Address: 28a Main Street, Garforth, Leeds, LS25 1AA
Contact Email: info@renovahair.co.uk
Telephone: 0113 467 6219
1. Introduction
This Privacy Policy explains how Renova Hair collects, uses, stores, and protects your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are committed to safeguarding your personal information and ensuring transparency about how it is processed.
2. What Personal Data We Collect
We may collect and process the following categories of personal data:
2.1 Identity & Contact Information
-
Full name
-
Address
-
Email address
-
Phone number
-
Date of birth
2.2 Medical & Health Information
-
Medical history relevant to trichology or hair loss
-
Lifestyle information
-
Appointment notes
-
Photographs for clinical assessment
(This is special category data and is processed under strict GDPR conditions.)
2.3 Transaction Information
-
Payment details
-
Appointment bookings
-
Purchase history
2.4 Technical Data
-
IP address
-
Browser type
-
Usage data from our website
-
Cookies (see section 10)
2.5 Marketing Preferences
-
Communication preferences
-
Consent records
3. How We Use Your Personal Data
We use your data for the following purposes:
-
To provide trichology consultations and treatment
-
To assess medical suitability for procedures
-
To maintain accurate clinical records
-
To manage appointments and follow-ups
-
To process payments
-
To send reminders, service updates, or aftercare information
-
To send marketing communications only with your explicit consent
-
To maintain business operations and comply with legal obligations
4. Legal Basis for Processing
We rely on the following lawful bases:
-
Consent – for marketing, photographs, and specific medical information
-
Contract – to provide treatments or services you request
-
Legal obligation – for financial record keeping
-
Vital interests – safety and risk management
-
Legitimate interests – improving services, communication records
-
Special category data – processed under Article 9(2)(h) for healthcare purposes
5. How We Store & Protect Your Data
We take appropriate technical and organisational measures to secure your information:
-
Encrypted digital systems
-
Secure clinical records
-
Restricted staff access
-
Password-protected devices
-
Regular data protection training
-
Secure disposal of physical documents
6. Data Sharing
We do not sell your personal data.
We may share information with:
-
Medical professionals (only with your consent)
-
Payment processors
-
Insurance providers (if relevant)
-
IT system providers (secure & GDPR-compliant)
-
Law enforcement authorities (only when required by law)
All third parties are bound by data processing agreements ensuring GDPR compliance.
7. Data Retention
We retain your data only for as long as necessary:
-
Medical records: 7 years after final appointment (or longer for minors)
-
Financial records: 6 years (legal requirement)
-
Marketing data: until you withdraw consent
-
General enquiries: up to 12 months
After this period, data is securely deleted or anonymised.
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
-
Right to access – request a copy of your data
-
Right to rectification – correct inaccuracies
-
Right to erasure – request deletion (“right to be forgotten”)
-
Right to restrict processing
-
Right to data portability
-
Right to object
-
Right to withdraw consent at any time
-
Right not to be subject to automated decision-making
To exercise your rights, email info@renovahair.co.uk.
9. Photography & Case Studies
We will never use your images in marketing without your explicit written consent.
Clinical images used for assessment are stored securely and only accessible to authorised staff.
10. Cookies
Our website uses cookies to:
-
Enable site functionality
-
Analyse user behaviour
-
Improve user experience
A cookie banner allows you to accept, reject, or customise your preferences. For details, refer to our Cookie Policy.
11. Marketing Communications
We will only send marketing emails or SMS messages if you have provided clear, opt-in consent.
You may opt out at any time by clicking “unsubscribe” or contacting us directly.
12. Complaints
If you are unhappy with how we handle your data, please contact us first.
You also have the right to complain to the ICO:
Information Commissioner’s Office (ICO)
www.ico.org.uk
13. Changes to This Privacy Policy
We may update this policy occasionally. The latest version will always appear on our website with the updated date.

