Key Aspects affecting H&Co Clients
Right to Access
Part of the expanded rights of data subjects outlined by the GDPR is the right for data subjects to obtain from the data controller confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electronic format. This change is a dramatic shift to data transparency and empowerment of data subjects.
Right to be Forgotten
Also known as Data Erasure, the right to be forgotten entitles the data subject to have the data controller erase his/her personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data. The conditions for erasure, as outlined in article 17, include the data no longer being relevant to original purposes for processing, or a data subjects withdrawing consent. It should also be noted that this right requires controllers to compare the subjects’ rights to “the public interest in the availability of the data” when considering such requests.
GDPR introduces data portability – the right for a data subject to receive the personal data concerning them, which they have previously provided in a ‘commonly use and machine readable format‘ and have the right to transmit that data to another controller.
More information on GDPR can be found at https://www.eugdpr.org
We keep records for a number of reasons in various formats which are explained in more detail below.
The systems we use that store client data
Our salon software which also operates our online booking system may contain your information if you have booked an appointment with us by telephone or online. We started our business with client records from Portobello salon which we bought the client goodwill for so in some cases if you have ever visited Portobello salon we may also have you listed on our booking system. Our Salon system/software is web based and is secured with 128bit encryption.
(IF YOU NO LONGER WISH TO BE INCLUDED IN OUR BOOKING SYSTEM SALON SOFTWARE PLEASE USE THE FORM BELOW.)
Our website has a number of forms that have been used in various competitions and registering for offers. If you have ever completed a form on our website your information will be held in the list of entries which are held securely on our web server using SSL 128bit encryption.
(IF YOU WOULD LIKE YOUR DETAILS REMOVED FROM STORED WEB FORM ENTRIES PLEASE COMPLETE THE FORM BELOW)
Our Email Marketing system ‘Mailchimp’ may have a record of your name if you are a current or previous client, if you have filled out a web based form and possibly if you were a former client of Portobello salon.
(ALL EMAILS HAVE AN UNSUBSCRIBE OPTION IN THE FOOTER, PLEASE CLICK THIS IF YOU NO LONGER WISH TO RECEIVE EMAILS FROM US OR COMPLETE THE FORM BELOW)
Our SMS/Text Marketing System may have a record of your first name if you if you are a current or previous client, if you have filled out a web based form and possibly if you were a former client of Portobello salon.
(TO REMOVE YOURSELF FROM OUR SMS SYSTEM PLEASE REPLY TO ANY OF OUR TEXT’S WITH THE WORD “STOP” & YOU WILL BE AUTOMATICALLY REMOVED. ALTERNATIVELY COMPLETE THE FORM BELOW)
Our smartphone app will contain your information if you have downloaded the app and registered.
(IF YOU NO LONGER WISH TO BE INCLUDED IN OUR SMARTPHONE APP PLEASE UNINSTALL THE APP FROM YOUR PHONE COMPLETE THE FORM BELOW)
CCTV: We have CCTV in our salon for security reasons. The CCTV is set to record outside of working hours.
The Information each system holds
|Your Name||Your Email||Your Mobile Number||Your address||Your Date of Birth||Skin Test Information||Colour Consultation data||Colour Notes|
|Online Booking System |
|Smartphone App (only if you have registered)||Yes||Yes||Yes||No||Yes||No||No||No|
|Email Marketing System||Possibly||Possibly||No||Possibly||No||No||No||No|
|SMS / Text marketing System||Possibly||No||Possibly||No||No||No||No||No|
|Website form entries||Possibly||Possibly||Possibly||Possibly||Possibly||Possibly||Possibly||No|
What we use your data for
Name: We use your name for our appointment system so we know who is visiting each day. Your name is also used to personalise messages sent from our booking system, website, email marketing system and SMS/Text based marketing system.
Email Address: Email addresses are used in our booking system to send appointment confirmations and to send emails to you regarding appointments.. In addition we use email addresses in our website to send confirmations of forms that have been completed and in our email marketing system to send offers and newsletters.
Mobile Phone Number: Our software system may hold your mobile phone number so that the system can send you reminder messages 24 hours before your appointment and also so we can contact you should we need to discuss your appointment. Your mobile number (if we hold it) may also be held within our sms/text messaging system to send text based promotions and/or offers.
Home Phone number: We may hold your home phone number in our booking system only if you do not have a mobile number of if you have not given us your mobile number. Your home number if we hold it would only be used to contact you about your appointment
Your Address: We may hold your address if you have previously completed a webform that requested your address or if you completed a competition card that requested yoru address. We would use your address to send, special offers if appropriate
Your Date of Birth: If you have downloaded and registered using our smartphone app you will have added your date of birth. The system uses this information to send you a birthday message on your birthday with a special offer.
Colour Notes: Our software/booking system may hold colour notes specific to you so that when you next come in for your colour we have a record of what was used previously.
Colour Consultations: Colour consultations are undertaken online, this information is held on our secure webserver and is used to ensure we have a record of the consultation and what was discussed including evidence of patch test if applicable.
Requesting your data to be removed
Should you wish to have some or all of your data removed from our systems please complete the form below. Your request will be actioned within 14 days and this entry itself will also be deleted once actioned.