Advanced Aesthetic & Skin Clinic

City Skin Lab
Loading menu...

Privacy Policy

Your privacy is important to us. Learn how we protect your personal information.

Last updated: 5 August 2025

1. Introduction

City Skin Lab ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, book appointments, or use our services. We comply with the General Data Protection Regulation (GDPR) and UK data protection laws.

2. Information We Collect

Personal Information

  • Name, address, phone number, and email address
  • Date of birth and age
  • Medical history and health information relevant to treatments
  • Treatment preferences and consultation notes
  • Payment information (processed securely by third-party providers)
  • Photos (before/after treatment photos with your consent)

Website Usage Information

  • IP address and browser information
  • Pages visited and time spent on our website
  • Cookies and similar tracking technologies
  • Referral sources and search terms

3. How We Use Your Information

We use your personal information for the following purposes:

  • Treatment Provision: To provide medical aesthetic treatments and consultations
  • Appointment Management: To schedule, confirm, and manage your appointments
  • Medical Records: To maintain accurate medical records as required by law
  • Communication: To contact you about appointments, aftercare, and follow-ups
  • Marketing: To send promotional materials (with your consent)
  • Website Improvement: To analyze website usage and improve our services
  • Legal Compliance: To comply with legal and regulatory requirements

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract: Processing necessary for treatment provision and appointment management
  • Consent: Marketing communications and photography (you can withdraw consent anytime)
  • Legal Obligation: Medical record keeping and regulatory compliance
  • Legitimate Interest: Website analytics and service improvement

5. Information Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Healthcare Professionals: Other medical practitioners involved in your care
  • Service Providers: Third-party companies that help us operate our business (payment processors, appointment systems)
  • Legal Authorities: When required by law or to protect our legal rights
  • Emergency Situations: To protect your vital interests or those of others

All third parties are contractually obligated to protect your information and use it only for specified purposes.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Secure servers and encrypted data transmission
  • Access controls and staff training
  • Regular security assessments and updates
  • Secure physical storage of paper records
  • Professional indemnity and cyber liability insurance

7. Data Retention

We retain your personal information for the following periods:

  • Medical Records: 8 years after your last treatment (as required by medical regulations)
  • Marketing Data: Until you unsubscribe or withdraw consent
  • Website Analytics: 26 months maximum
  • Financial Records: 7 years for tax and accounting purposes

8. Your Rights

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete information
  • Erasure: Request deletion of your data (subject to legal requirements)
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for marketing or photography

To exercise these rights, please contact us using the information provided below.

9. Cookies and Tracking

Our website uses cookies to:

  • Remember your preferences and settings
  • Analyze website traffic and usage patterns
  • Improve website functionality and user experience
  • Provide relevant content and advertisements

You can control cookies through your browser settings. Disabling cookies may affect website functionality.

10. International Transfers

Your personal data is primarily processed within the UK. If we transfer data internationally, we ensure appropriate safeguards are in place, such as adequacy decisions or standard contractual clauses approved by the European Commission.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on our website with a new effective date.

12. Contact Information

For questions about this Privacy Policy or to exercise your rights, contact us:

City Skin Lab

9 Devonshire Square

City of London, England EC2M 4WY

Phone: 020 8036 3759

Email: bookings@cityskinlab.com

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data appropriately.