Privacy Policy
The Village Edit ("we", "us", "our") is committed to protecting your personal data. This policy explains how we collect, use, store, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
The Village Edit is a hair and beauty salon located on High Street, Wimbledon Village, London. We are the data controller for the personal data described in this policy. We operate solely within the United Kingdom.
For data protection enquiries, contact us at hello@thevillageedit.co.uk.
We have not appointed a Data Protection Officer as we are a small business that does not process personal data on a large scale. All data protection queries should be directed to the email address above.
2. Data We Collect
We collect the following types of personal data:
- Contact details — name, email address, phone number, submitted via our contact form or Olivia chat assistant
- Booking and appointment data — processed and stored via Fresha, our booking platform (governed by Fresha's Privacy Policy)
- Health and allergy information — disclosed by you before treatment (e.g. allergies for hair colour services, medical conditions for pedicure services). This is special category data under UK GDPR and is processed on the basis of your explicit consent and our legitimate interest in your health and safety
- Treatment notes and preferences — recorded to personalise your experience and ensure continuity of care
- Patch test records — results from skin tests required before hair colour services, stored for your safety
- Website analytics data — collected via Google Analytics 4 (pseudonymised browsing behaviour, only with your consent)
- Session recording data — collected via Microsoft Clarity (pseudonymised clicks, scrolls, and page interactions, only with your consent)
- Chat messages — submitted to Olivia, our AI chat assistant, to help answer your questions and recommend services
3. Lawful Basis for Processing
Under UK GDPR Article 6, we process your data on the following lawful bases:
- Contract — processing booking data to perform our services (Fresha)
- Legitimate interest — responding to contact form enquiries, maintaining treatment notes for continuity of care, ensuring health and safety (allergy/medical screening)
- Consent — analytics cookies (Google Analytics 4), session recordings (Microsoft Clarity), marketing communications (if you opt in)
- Legal obligation — retaining records as required by health and safety regulations
4. How We Use Your Data
- To respond to enquiries and booking requests
- To perform and personalise your salon services
- To conduct allergy screening and maintain patch test records for your safety
- To retain treatment notes so we can provide consistent care across appointments
- To improve our website and services
- To send service-related communications (appointment confirmations, reminders). We do not send marketing communications unless you provide explicit consent
5. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — ask us to delete your data (where there is no legal requirement to retain it)
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — request your data in a portable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at hello@thevillageedit.co.uk. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). Visit ico.org.uk or call 0303 123 1113.
6. Data Retention
- Contact form submissions — retained for 24 months, then deleted
- Booking and appointment data — retained by Fresha as required by their platform policies
- Treatment notes and preferences — retained for 36 months to ensure continuity of care. You may request deletion at any time
- Patch test records — retained for 36 months for your safety
- Health and allergy information — retained for the duration of your client relationship plus 12 months
- Analytics data — retained per Google and Microsoft standard policies
- Chat messages (Olivia) — session data is temporary and not retained long-term
7. Third-Party Services
We share data with the following third-party processors, each operating under their own privacy policies:
- Fresha — booking, payments, and client management (Privacy Policy)
- Google Analytics 4 — website analytics, pseudonymised data (Privacy Policy)
- Microsoft Clarity — session recordings, pseudonymised data (Privacy Policy)
- Cloudflare — content delivery and security. Cloudflare may process IP addresses and traffic data to protect our website (Privacy Policy)
- Cookiebot — cookie consent management (Privacy Policy)
- Sentry — error tracking for website stability (Privacy Policy)
We do not sell your personal data to any third party.
8. Olivia Chat Assistant
Olivia is our AI-powered chat assistant, available on every page of our website. When you use Olivia, the messages you submit are processed to provide helpful responses about our services. Chat sessions are temporary. We may use aggregated, non-identifiable chat data to improve our services. For full details on how Olivia handles your data, contact us at the email address above.
9. Children's Data
Our website and online services are not directed at children under 16. We do not knowingly collect personal data from anyone under 16 years of age. If you believe a child's data has been submitted to us, please contact us and we will delete it promptly.
10. Data Breach
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected individuals without undue delay. Where required, we will also notify the ICO within 72 hours of becoming aware of the breach.
11. Cookies
We use cookies for essential website functionality, analytics, and session recordings. Non-essential cookies are only set after you provide consent via our cookie banner. For full details, see our Cookie Policy.
12. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. We encourage you to review this page periodically.
13. Contact
For any data protection queries or to exercise your rights: hello@thevillageedit.co.uk