Legal
Privacy Policy
Last updated: 22 June 2026
1. Who is the data controller?
Chicay Hair, an independent hairstyling service based in Lewisham, SE13, London, United Kingdom, is the data controller for personal data collected through chicay.co.uk. You can reach us at info@chicay.co.uk.
2. What data we collect
- Booking details — name, email address, phone number, the service you choose, the date and time of your appointment, and any notes you add.
- Payment reference — we receive bank-transfer confirmations matching the reference shown on your booking. We do not store card numbers; we never see them.
- Account data — if you create an account, your email, an encrypted password hash and authentication metadata, managed by our auth provider.
- Site usage — anonymous, aggregated counts of which buttons are clicked and which pages are visited, plus standard server log data (IP address, browser, request time) kept briefly for security.
- Communications — copies of emails or messages you send us.
3. Why we use it and the legal basis
- To manage your booking (contract, UK GDPR Art. 6(1)(b)) — confirming, rescheduling, cancelling and reminding you of appointments.
- To run the business (legitimate interests, Art. 6(1)(f)) — keeping the Site available, preventing fraud and abuse, basic analytics to improve services.
- To comply with the law (Art. 6(1)(c)) — accounting and tax records.
- Marketing (consent, Art. 6(1)(a)) — only if you opt in. You can withdraw at any time using the link in any marketing email.
4. Who we share data with
We do not sell your personal data. We share it only with trusted processors who help us run the service:
- Hosting & database — our application platform stores bookings, account data and site content on our behalf in EU/UK data centres.
- Email delivery — used to send booking confirmations, reminders and reset emails.
- Bank — our UK bank receives deposit transfers and shares the reference for reconciliation.
- Professional advisers & authorities — accountants, lawyers, or regulators where the law requires.
Each processor is bound by a written contract to handle your data only on our instructions.
5. International transfers
Where a processor stores data outside the UK, we rely on an adequacy decision or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses to keep your data protected to UK standards.
6. How long we keep it
- Active booking records: while you remain a customer.
- Accounting records (including payment references): 6 years from the end of the relevant tax year, as required by HMRC.
- Account data: until you ask us to delete it or after 24 months of inactivity, whichever comes first.
- Server logs: up to 30 days.
- Marketing consent: until you withdraw it.
7. Your rights
Under UK GDPR you have the right to:
- Be told how your data is used (this notice).
- Request a copy of the data we hold about you.
- Have inaccurate data corrected.
- Ask us to delete data we no longer need.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw any consent you have given.
To exercise any of these rights, email info@chicay.co.uk. We usually reply within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
8. How we keep your data safe
We use HTTPS, access controls, password hashing, role-based admin permissions, audit logs and database row-level security to protect your data. No system is perfect — please use a strong, unique password if you create an account.
9. Cookies & tracking
We use a small number of cookies and similar technologies. See our Cookie Policy for the full list and how to control them.
10. Children
The Site is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
11. Changes to this notice
We may update this Privacy Policy from time to time. The "Last updated" date at the top shows when. If we make significant changes we will tell you by email or a notice on the Site.
12. Contact
Questions or requests? Email info@chicay.co.uk.
