Privacy Statement
1. Introduction
This Privacy Statement explains how RenuYou (“we”, “us”, “our”) processes personal data and fulfils its data protection responsibilities under UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR).
This statement applies to all personal data processed by our staff in the course of our business activities. It is provided for information purposes and does not form part of any contract or condition of using our services.
2. Data Controller
For the purposes of data protection law, RenuYou is the data controller where we determine the purposes and means of processing personal data.
Responsibility for data protection compliance sits with the Privacy Manager (PM), who can be contacted using the details at the end of this statement.
3. Personal Data We Process
The personal data we process is limited to what is necessary and may include:
-
Names
-
Contact details (such as email address, telephone number, postal address)
-
Information provided in enquiries or correspondence
-
Information required to deliver our services or meet legal obligations
If you do not provide the personal data we request, we may be unable to respond to your enquiry or fulfil our obligations to you.
4. Confidentiality and Security
We operate a strict duty of confidentiality. All staff treat personal data with respect and in confidence, and access is limited to those who need it to perform their role.
We expect the same level of confidentiality from any third parties we share personal data with.
Appropriate organisational and technical measures are in place to protect personal data and company information. All processing takes place on-site, with routine backups performed on UK-based servers.
5. Lawful Bases for Processing
We process personal data only where a lawful basis applies, including:
-
Legitimate interests – to respond to enquiries and maintain contact following service or product delivery
-
Legal obligation – to comply with statutory requirements, including HMRC obligations
-
Contract – where processing is necessary for the performance of a contract with you or to take steps prior to entering into a contract
-
Consent – where processing is for a specific, defined purpose and consent is obtained in advance
Where processing is based on consent, you may withdraw that consent at any time by contacting the Privacy Manager.
All processing is carried out in accordance with the data protection principles set out in UK data protection legislation.
6. Sharing Personal Data
We only share personal data where necessary and may do so with:
-
HM Revenue & Customs (HMRC) for accounting and tax purposes
-
IT support providers operating under a data processing agreement
-
Solicitors appointed by RenuYou, where required
-
Accountants appointed by RenuYou for financial processing and record-keeping
-
Contractors providing outsourced services, subject to appropriate data processing agreements
We do not sell personal data.
7. Data Retention
We follow a documented retention schedule to determine how long personal data is held:
-
General enquiries that do not result in a quotation or sale are retained for 1 year after last contact
-
Pre-contract and quotation data is retained for the duration of the activity plus 7 years after last contact
-
Minimal contact details may be stored indefinitely, subject to erasure requests
-
Financial records and invoices are retained for 6 years after the end of the relevant tax year
-
Exceptional cases may require data to be retained beyond these periods where there is a legal obligation or legitimate interest
At the end of the applicable retention period, personal data will be securely deleted, destroyed, or rendered inaccessible. We allow up to 3 months to complete this process.
8. Cookies
Our website uses cookies and similar technologies. Cookies that are not strictly necessary for the operation of the website will only be used with your consent.
Further details are provided in our Cookie Policy.
9. Your Rights
Under UK GDPR, you have rights in relation to your personal data, including:
-
The right to be informed about how your data is processed
-
The right of access (via a Data Subject Access Request)
-
The right to rectification
-
The right to erasure
-
The right to restrict processing in certain circumstances
-
The right to data portability (where applicable)
-
The right to object to processing
-
Rights relating to automated decision-making and profiling (we do not use these techniques)
Further information is available on the Information Commissioner’s Office (ICO) website:
IcoHome
10. Raising Concerns or Exercising Your Rights
To raise a concern, exercise your rights, or ask questions about how we process personal data, please contact the Privacy Manager using the details below.
We may need to verify your identity before responding. You also have the right to raise concerns directly with the ICO, although we welcome the opportunity to address any issues first.
11. Contact Details
Company name: RenuYou
Contact name: Claire Beesly
Email address: renuyouskinclinic@gmail.com
