PRIVACY POLICY

1. Introduction

This Privacy Policy details how we, YUV Beauty UK Limited of Suite 109, Clerkenwell Workshops, 27-31 Clerkenwell Close, London EC1R 0AT  and our group companies collect, use and process personal data.

If you have any questions on this Privacy Policy or otherwise relating to how we process your personal data you can contact us at info@yuv.co

This Privacy Policy affects your legal rights and obligations so please read it carefully. If you do not agree to be bound by this Privacy Policy, please do not provide your personal data to us.  

We may update this Privacy Policy from time to time at our discretion and in particular to reflect any changes in applicable laws. If we do so, and the changes substantially affect your rights or obligations, we shall notify you if we have your email address. Otherwise, you are responsible for regularly reviewing this Privacy Policy so that you are aware of any changes to it.

We are either the controller of the personal data provided to us for the purposes of applicable data protection legislation.

If you provide personal data to us directly, we are the controller of that personal data which means we determine how we collect, use and process that personal data (subject of course to applicable laws).

If a stylist who uses our YUV colour device provides your personal data to us, in particular  to register you on our YUV colour system, then  we process that personal data only on the instructions of that stylist and are therefore the processor of that personal data. You should also therefore review the privacy policy of the stylist to see how they process your personal data.  

Please contact us if you are unsure of the identity of  the stylist who has collected your personal data.

2. Whose personal data do we collect?

By personal data we mean identifiable information about you. Generally, this is likely to include information such as names, email address, correspondence address and your IP address if you access our website.  

We may collect, use, store and transfer different kinds of personal data:

  • Contact Data includes data such as your email address, telephone number, geographical address and billing address

  • Identity Data includes data such as first name, last name, date of birth and hair colour;

  • Financial Data includes details you provide to us so that we can process your payments;

  • Technical Data includes data such as internet protocol (IP) address, your login data, browser type and version, cookies, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website and any communications we may send to you.

  • Usage Data includes information about how you use our website such as  information about your visit to our website, including the full Uniform Resource Locators (URL) clickstream to and through, pages you viewed or searches you made, page response times, download errors, length of visit, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.

  • Marketing Data includes your preferences in receiving marketing from us.

  • Health Data includes data about allergies or other reactions to hair colour.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as it does not directly or indirectly identity you.  However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we will treat the combined data as personal data which will be used in accordance with this Privacy Policy.

Information you provide to us

If you are a stylist and you upload your client’s personal data to the YUV colour system,  you must have the lawful right to do so and in particular you must have their consent to share Health Data with us.

Information we automatically collect about you

When you use our website, we may automatically collect and store information about your Technical Data and Usage Data for the purposes of research and analysis.

Some of this information is collected using cookies and similar tracking technologies. If you want to find out more about the types of cookies we use, why, and how you can control them, please see our Cookies Policy for the website in question.

Information we receive from others

We may receive personal data about you from our security service partners, and our payment providers  if they choose to provide it to us for any reason.  

If we reasonably believe that any of the personal data you have provided to us is inaccurate, we may receive further personal data from third parties, confirming or otherwise, your identity.

3. Legal basis for processing your personal data

We will only use your personal data where we have a lawful basis to do so.  The lawful purposes that we rely on under this Privacy Policy are:  

  • consent (where you choose to provide it);

  • performance of our contract with you;

  • compliance with legal requirements; and

  • legitimate interests.    When we refer to legitimate interests we mean our legitimate business interests in the normal running of our business which do not materially impact your rights, freedom or interests.

If you wish to purchase a YUV colour device and colour products from us, we shall use your personal data to provide the YUV colour device and colour products in accordance with our applicable terms and conditions.

We may from time to time need to use your personal data to comply with any legal obligations, demands or requirements, for example, as part of anti-money laundering processes or to protect a third party’s rights, property, or safety.    

We may also use your personal data for our legitimate interests including to improve our services and in connection with, or during negotiations of, any merger, sale of assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or into another company; to deal with any customer services you require; for audit purposes and to contact you about changes to this Privacy Policy.

4. Who do we share your data with?

For our legitimate interests, we may share your personal data with our service providers, sub-contractors and agents that we may appoint to perform functions on our behalf and in accordance with our instructions, including IT service providers, payment providers, accountants, auditors and lawyers.    

We shall provide our service providers, sub-contractors and agents only with such of your personal data as they need to provide the service for us and if we stop using their services, we shall request that they delete your personal data or make it anonymous within their systems.

If we need to use your personal data to comply with any legal obligations, demands or requirements, for example, as part of anti-money laundering processes or to protect a third party’s rights, property, or safety then in doing so, we may share your personal data with third party authorities and regulatory organisations and agencies.

If we choose to merge, sell assets, consolidate or restructure, finance, or sell of all or a portion of our business by or into another company then the new owners may use your personal data in the same way that we do as set out in this Privacy Policy.

5. Where we hold and process your personal data

Some or all of your personal data may be stored or transferred outside of the United Kingdom for any reason, including for example, if our email server is located in a country outside the United Kingdom or if any of our service providers are based outside of the United Kingdom.

Where your personal data is transferred outside the United Kingdom, it will only be transferred to countries that have been identified as providing adequate protection for personal data or to a third party where we have approved transfer mechanisms in place to protect your personal data.

6. Security

We shall process your personal data in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.  In particular, access is restricted to employees who need to know your personal data, and we use appropriate password protection and appropriate strong encryption electronic measures within our electronic data management systems.

However, unfortunately, because of the nature of electronic storage,  we cannot promise that your personal data or any other data you provide to us will always remain secure.   If there is a security breach, we will do all that we can as soon as we can to stop the breach and minimise the loss of any data.

7. Marketing

You may consent to receive marketing email messages from us about our business and/or we may send to you marketing email message for our legitimate business interests.  You can choose to no longer receive marketing emails from us by contacting us or clicking unsubscribe from a marketing email.  Please note that it may take us a few days to update our records to reflect your request.

If you ask us to remove you from our marketing list, we shall keep a record of your name and email address to ensure that we do not send to you marketing information.

8. Your rights

You have a number of rights under applicable data protection legislation. Some of these rights are complex, and not all of the details have been included below. Further information can be found here

  • Right of access:  You have the right to obtain from us a copy of the personal data that we hold for you.

  • Right to rectification: You can require us to correct errors in the personal data that we process for you if it is inaccurate, incomplete or out of date.

  • Right to portability: You can request that we transfer your personal data to another service provider if you initially provided consent for us to use the personal data or where we used the personal data to perform a contract with you.

  • Right to restriction of processing:  In certain circumstances, you have the right to require that we restrict the processing of your personal information if you believe our processing impacts on your fundamental rights and freedoms.  However, we may demonstrate that we have legitimate grounds to process your personal data not withstanding your rights and freedoms.

  • Right to be forgotten: You also have the right at any time to require that we delete the personal data that we hold for you, where it is no longer necessary for us to hold it.  However, whilst we respect your right to be forgotten, we may still retain your personal data in accordance with applicable laws and when we respond to your request we shall notify you of any specific legal reasons that we have to retain your personal data.

  • Right to stop receiving marketing information: You can ask us to stop sending you information about our services, but please note we shall continue to contact you in relation to any matters relating to about any services or goods you have purchased from us or may purchase in the future.

We reserve the right to charge an administrative fee if your request in relation to your rights is manifestly unfounded or excessive.

If you have any complaints in relation to this Privacy Policy or otherwise in relation to our processing of your personal data, please tell us. We shall review and investigate your complaint and try to get back to you within a reasonable time.  You can also contact the Information Commissioner, see www.ico.org.uk or if you are based outside of the United Kingdom, please contact your local regulatory authority.

9. Retention of personal data

We may also be required to retain personal data for a particular period of time to comply with legal, auditory or statutory requirements, including requirements of HMRC in respect of financial documents and in order to deal with any dispute you might raise.  To determine the appropriate retention period for personal data, we consider the type of the personal data, the potential risk of harm from unauthorized use or disclosure of the  personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means.

Where we have no legal basis for continuing to process your personal data, we shall either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.For the avoidance of doubt, we may use anonymous data, such as usage data for research or statistical purposes indefinitely without further notice to you.

10. General

We may also be required to retain personal data for a particular period of time to comply with legal, auditory or statutory requirements, including requirements of HMRC in respect of financial documents and in order to deal with any dispute you might raise.  To determine the appropriate retention period for personal data, we consider the type of the personal data, the potential risk of harm from unauthorized use or disclosure of the  personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means.

Where we have no legal basis for continuing to process your personal data, we shall either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.For the avoidance of doubt, we may use anonymous data, such as usage data for research or statistical purposes indefinitely without further notice to you.

YUV Beauty 27-31 Clerkenwell Close Suite 109 London, UK EC1R 0AT | Company Registration number: 13687265. Registered in England and Wales.