Our privacy Policy

What does this notice cover?

Our privacy policy details the way in which we use your personal data, how we collect it, and how the data is stored. It also explains your rights concerning the data.

What is personal data?

Personal data is defined as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’ by the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”)

In simple terms, personal data is information that can be used to identify you. Personal information can be details such as name, and gender, but it also applies to more abstract data, such as IP address and location data.

What are your rights?

The right to know about how we gather/use/store your data. This privacy policy offers this information, but please contact us if there is anything else that you would like to know.

The right to obtain access to the data that we hold in relation to you. You can request this data.

The right to data rectification. If you wish to correct personal data, you can request rectification.

The right to be forgotten. You have the right to have any personal data permanently removed.

The right to restrict the use of your data.

The right to data portability, which can be achieved in the form of a data request.

More detailed information on your rights can be found at the ICO website.

Why we collect information about you

Dermaesthetics & MG Aesthetics hold clinical information about you to ensure practitioners have a complete and continuous record about your past, current and future treatment. Your records may be written down, or held on a computer.

To identify who you are we need your:



Date of birth

In some cases we may require your NHS number.

Information is held solely for the purpose of your health and wellbeing and will only be shared with practitioners and agencies involved in your treatment and care.

If you have agreed we will use your data to send you email and text messages for marketing and promotional reasons.

How do we use your personal data?

We have a responsibility to use your data lawfully and ethically. The primary use of your data is to provide you with a service. The information below provides more information:

Supplying our services and products. We require certain information to enable us to provide services and enter into a contract with you.

Providing a bespoke service, enabled by the personal information.

Communication. We may need to communicate with you via phone, email, or SMS for the purposed of providing service.

Supplying you with marketing information (only in the case where you an opted-in to this service)

Assessing your progress and tailoring our service throughout the duration of a course of treatments.

With your explicit permission, we may use your data to inform you about special offers. You can opt-out of these communications at any time. We will never sell your data.

How long will we keep your personal data?

Your personal data will be kept for 3 years from the last point which in which we interact. You can request that we remove all alter your information at any time.

How and where do we store or transfer your personal data?

Your data is securely stored in the UK and is protected by the GDPR regulations.

Do we share your personal data?

Without your permission, we will not share your personal data with any external entity unless we are explicitly required to do so by law.

How can you access your personal data?

If you want to know what personal data we have about you, you can ask us for details of that personal data and a copy of it. This is known as a “Data access request”.

We will respond to your subject access request within 14 days and, in any case, not more than one month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time.