1. Introduction
At Glowra, we believe that transparency is the foundation of luxury service. This Privacy Policy outlines how we collect, use, and safeguard your personal information when you interact with our aesthetic boutique and digital platforms.
By using our services, you entrust us with your personal details and medical history relevant to treatments. We treat this data with the same meticulous care we apply to our clinical procedures.
This policy applies to all information collected through our website, booking system, and in-clinic consultations. Please read it carefully before booking an appointment or submitting any personal details.
2. Data We Collect
We collect information that allows us to provide a bespoke and safe aesthetic experience:
- Identity information: name, date of birth, and contact details for appointment management
- Health history: relevant medical background to ensure treatment safety and efficacy
- Visual records: before and after photography to monitor your aesthetic journey (with explicit consent)
- Transaction data: billing information processed through our secure, encrypted gateways
- Communication preferences: how and when you prefer to receive updates from us
All health-related data is classified as sensitive and handled under enhanced security protocols in accordance with UK GDPR regulations.
3. How We Use Your Information
Your information is used solely to provide and improve our services:
Personalized Consultations
We use your profile to curate specific treatment plans that align with your skin goals and physical health, ensuring every appointment is tailored to you.
Appointment Communications
Sending reminders, follow-up care instructions, and post-treatment guidance via your preferred contact method.
Service Refinement
Analyzing anonymized, aggregated data to improve our treatment offerings and clinical protocols. No individually identifiable information is used for this purpose.
We will never sell, rent, or share your personal data with third parties for their marketing purposes.
4. Data Protection
We utilize enterprise-grade encryption and restricted physical access to ensure your records remain private. Our security measures include:
- 256-bit SSL encryption for all data in transit
- Encrypted at-rest storage for all sensitive records
- Role-based access control limiting staff access to relevant data only
- Regular third-party security audits
- Secure physical file storage with access logging
In the unlikely event of a data breach, we will notify affected clients and the relevant regulatory authority within 72 hours, as required by UK GDPR.
6. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right to access: request a copy of all data we hold about you
- Right to rectification: correct any inaccurate or incomplete information
- Right to erasure: request deletion of your data in certain circumstances
- Right to restriction: limit how we process your data
- Right to portability: receive your data in a structured, machine-readable format
- Right to object: opt out of certain types of processing, including marketing
To exercise any of these rights, contact our Privacy Officer at hello@glowra.com. We will respond within 30 days.