1. Purpose and scope
This statement applies to personal information handled through the Tip2Toe website, booking system and salon operations. It covers customers, prospective customers, team members and anyone who contacts Tip2Toe.
It supports the customer-facing Privacy Policy. The Privacy Policy explains what people are told about their information; this statement sets out the standards Tip2Toe will follow when handling it.
UK data protection law includes the UK GDPR and the Data Protection Act 2018. Tip2Toe will also consider the Privacy and Electronic Communications Regulations where electronic marketing or optional cookies are used.
2. Our data protection principles
Tip2Toe will handle personal information in line with the seven UK GDPR principles:
Lawfulness, fairness and transparency
Use information lawfully, treat people fairly and explain its use clearly.
Purpose limitation
Collect information for specific purposes and do not reuse it incompatibly.
Data minimisation
Only collect information that is adequate, relevant and necessary.
Accuracy
Take reasonable steps to keep records correct and up to date.
Storage limitation
Keep identifiable information no longer than it is genuinely needed.
Security
Protect information against unauthorised use, loss, damage or disclosure.
Accountability
Be able to demonstrate the decisions, safeguards and checks behind these commitments.
3. Responsibility and accountability
The person or organisation operating Tip2Toe is the data controller for the salon's customer and staff information. It decides why and how that information is used.
- A named data protection lead will oversee this statement, rights requests, incidents, records and staff guidance.
- Managers will approve new uses of personal information before they begin.
- Team members must only use information for their work and must report mistakes or concerns promptly.
- Tip2Toe will maintain proportionate records showing what information is used, why, where it is stored, who receives it and how long it is kept.
Data protection lead: To be confirmed
Contact details: To be confirmed
Statement owner and approver: To be confirmed
4. Lawful use and health information
Before using personal information, Tip2Toe will identify and document an appropriate lawful basis. Expected bases include contract for arranging services, legitimate interests for proportionate business and security needs, legal obligation where records are required by law, and consent where a genuine choice is offered.
Health, allergy, pregnancy, medication, sensitivity, patch-test and treatment-suitability details may be special category data. Tip2Toe will collect only what is necessary for a treatment and will document both an Article 6 lawful basis and an Article 9 condition.
Where explicit consent is used for health information, it will be a clear, specific and separate statement that is recorded and can be withdrawn. Tip2Toe will explain if withdrawing it means a treatment cannot be provided safely.
5. Data protection by design
Privacy and security will be considered at the start of changes to the website, booking system and salon processes, not after a change is released.
- New forms will ask only for information needed for the stated purpose.
- Access will default to the smallest group of staff who need it.
- New suppliers, integrations, analytics, marketing tools and payment features will be reviewed before use.
- A documented risk assessment or data protection impact assessment will be completed where a change is likely to create a high risk to people.
- Customer-facing information and choices will be updated before a materially different use begins.
6. Access and security
The current booking system includes the following safeguards:
- role-based access to staff functions and limited public booking information;
- hashed passwords, protected staff sessions and request-forgery protection;
- request limits intended to reduce automated misuse;
- audit records for relevant staff activity; and
- database backup arrangements to support recovery.
Tip2Toe will also require strong account practices, prompt removal of access when it is no longer needed, secure devices, confidential handling of consultation notes and regular checks that safeguards remain appropriate.
Secure HTTPS transport must be confirmed before this statement is approved for a live customer booking service. No security measure removes all risk, so controls will be reviewed as the service changes.
7. Retention and deletion
Tip2Toe will keep personal information only for as long as there is a documented business, legal, regulatory, insurance or claims reason. There is no single UK GDPR retention period for every type of record.
A retention schedule must set a justified period and disposal method for customer profiles, appointments, consultation and patch-test notes, cancellations, messages, audit records, staff accounts and backups. When a period ends, information will be securely deleted, destroyed or anonymised unless a justified hold applies.
The booking system now provides an admin-only preview and cleanup process for archived customer identity data, appointment notes, stored outbound emails and audit records. It also supports individual erasure requests by anonymising customer identity and free-text information while preserving limited booking facts. Every policy change and cleanup run is audited, and automatic cleanup is disabled until an administrator explicitly approves periods and enables it.
Approval requirement
The final retention periods, any legal or insurance holds, and deletion from backup copies are still to be confirmed. The live cleanup schedule must remain disabled until that review is complete.
8. People’s rights
Depending on the circumstances, people may ask for access, correction, erasure, restriction, portability or object to use of their information. They may withdraw consent where consent is relied upon and have rights concerning automated decisions.
People can submit a request through the Manage My Data form or make one verbally or in writing. Website submissions receive a reference and initial response target, and authorised administrators manage the request in a protected register.
- Requests can be made verbally or in writing and will be passed promptly to the data protection lead.
- Identity will be checked only to the extent reasonably necessary to prevent information being given to the wrong person.
- Requests and decisions will be logged and answered without undue delay, normally within one calendar month.
- A fee will not normally be charged. Any extension, fee or refusal must have a lawful reason and be clearly explained.
Tip2Toe must still confirm its privacy contact address and formally appoint the people responsible for reviewing and responding to requests.
9. Data breaches
A personal data breach includes accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal information. Team members must report suspected breaches immediately rather than trying to resolve them alone.
- Contain the issue, preserve evidence and recover information where possible.
- Record every breach, what happened, its effects and the action taken.
- Assess the likely risk to people's rights and freedoms.
- Notify the Information Commissioner's Office within 72 hours of becoming aware where the legal threshold is met.
- Tell affected people without undue delay where the breach is likely to result in a high risk.
- Review the cause and improve controls after the incident.
A breach register, escalation contacts and response checklist still need to be formally adopted.
10. Suppliers and international transfers
Before another organisation handles personal information for Tip2Toe, it will be checked for appropriate privacy and security arrangements. Where it acts as a processor, a written contract containing the required data protection terms will be put in place.
Tip2Toe will keep a current record of hosting, database, backup, email, messaging, IT support and any future payment providers. Supplier access will be limited to what is needed and reviewed when the arrangement changes or ends.
Personal information will not be transferred outside the UK unless the destination and transfer mechanism have been assessed and appropriate safeguards are in place. The actual suppliers, storage locations and transfer arrangements must be confirmed for the final version.
11. Training, records and review
People with access to personal information will receive practical guidance appropriate to their role, including confidentiality, secure accounts, customer rights, health information, phishing and incident reporting. Training and policy acceptance will be recorded and refreshed when needed.
This statement, the Privacy Policy, processing records, retention schedule, supplier list, rights log and breach register will be reviewed at least annually and whenever the service or law changes materially.
For independent guidance or to raise a concern with the UK regulator, visit the Information Commissioner's Office.
