Privacy Policy
JP Lagoon Ltd Privacy Notice
Introduction
This Privacy Notice explains how JP Lagoon Ltd collects, uses, stores and protects your personal data when you use our services, contact us, make a booking, attend an appointment, purchase products, complete our forms, visit our premises, or otherwise interact with us.
JP Lagoon Ltd trades as Lagoon and Laguna Aesthetics.
Please read this Privacy Notice carefully. It explains what personal data we collect, why we collect it, how long we keep it, who we may share it with, and the rights you have in relation to your personal data.
Who we are
JP Lagoon Ltd is the data controller for personal data processed through the Lagoon and Laguna Aesthetics brands for the purposes described in this Privacy Notice, except where this notice explains that an independent practitioner is separately responsible for clinical information.
Contact details
JP Lagoon Ltd
139 Alexandra Road
London
SW19 7JY
Email: info@lagoonspa.co.uk
Telephone: 020 8947 2332
For privacy queries, data requests, or complaints about how your personal data is handled, please contact us using the details above.
Important distinction: Lagoon and Laguna Aesthetics
Lagoon
Where you book or receive beauty treatments, services or products under the Lagoon brand, JP Lagoon Ltd is responsible for those services and for the related client records, including consultation forms, treatment notes, treatment photographs where taken, bookings, payments and associated administration.
Lagoon provides beauty and salon services such as nails, waxing, massage, facials, eyelash extensions and related treatments and services, together with retail products and associated customer care. Lagoon does not provide aesthetics treatments.
Laguna Aesthetics
Laguna Aesthetics is a trading name of JP Lagoon Ltd used for the administrative and business-side support of aesthetic services offered from our premises.
JP Lagoon Ltd is responsible for the administrative and business-side processing carried out under the Laguna Aesthetics brand, including enquiries, appointment bookings, client registration, appointment reminders, payment administration, reception and customer service administration, and marketing where consent has been given.
An aesthetics client may complete a client registration form with JP Lagoon Ltd and a separate treatment consultation and clinical consent process with the independent practitioner.
However, where aesthetic treatment is provided under the Laguna Aesthetics brand by an independent practitioner operating from our premises, that practitioner is responsible for their own clinical assessment, treatment decisions, prescribing where applicable, treatment delivery, aftercare, clinical records and clinical photographs.
Where you proceed to consultation or treatment with Dr Saraa Shakir Ali Al-Yasiri, she is responsible for the clinical information she collects and holds as part of her independent clinical practice. This includes consultation records, treatment records, prescribing records where applicable, and clinical photographs connected with treatment.
The personal data we collect
Depending on how you interact with us, we may collect and use the following categories of personal data:
Identity and contact data
- name
- title
- date of birth
- gender
- phone number(s)
- email address
- home address
- emergency contact details
- communication preferences
Booking and client account data
- appointment details and booking history
- services booked or received
- products purchased
- cancellation and no-show history
- customer account details
- loyalty programme information where applicable
- notes relevant to booking administration and customer service
Payment and transaction information
- payment records
- deposits
- refunds
- transaction receipts
- merchant card payment receipts retained as evidence of transactions, which may contain full card number and expiry date on the merchant copy
- and other payment-related information needed for payment administration, fraud prevention, accounting and record-keeping
Consultation and treatment information
For Lagoon treatments, this may include consultation forms, patch test records, treatment notes, relevant health information, treatment photographs where taken with consent or as otherwise lawfully permitted, aftercare records, and feedback relating to treatments.
For independent practitioner Laguna Aesthetics treatments, the treating practitioner is responsible for collecting and controlling clinical consultation and treatment information.
Photographs, video and image data
For Lagoon treatments, photographs or videos taken for treatment, record-keeping, service review, or where otherwise lawfully used are controlled by JP Lagoon Ltd.
For Laguna Aesthetics independent practitioner treatments, clinical photographs or videos connected with consultation or treatment are primarily controlled by the independent practitioner who performed the treatment and/or consultation.
Where a client gives separate consent for marketing use of aesthetics photographs or videos, copies of relevant images or videos may be shared with JP Lagoon Ltd for the marketing of Laguna Aesthetics.
In limited circumstances, copies of aesthetics treatment photographs or videos may also be shared with JP Lagoon Ltd for legitimate business purposes such as monitoring treatment standards, investigating complaints, dealing with insurance matters, legal claims, safeguarding concerns, or compliance-related issues.
Marketing or promotional use of identifiable photographs or videos will only take place where appropriate consent or another lawful basis applies.
CCTV
CCTV footage from our premises for safety, security, crime prevention and incident investigation.
Communications and enquiry data
- emails
- text messages
- telephone call information
- website contact messages
- social media messages sent to us
- booking notes or messages submitted through our online booking system or app
- and other communications you send to us in connection with enquiries, appointments, products or services
Recruitment data
If you apply for a job with us, we may collect CV and application information, contact details, employment history, interview notes, and right to work and related recruitment records.
Special category data
Some treatments require us to collect more sensitive personal data, including health information. This is known as special category data.
For Lagoon services, we may collect health information where this is necessary to assess suitability for a treatment, carry out treatments safely, identify possible contraindications, provide appropriate aftercare, maintain an accurate treatment record, and protect your health and wellbeing.
For independent practitioner aesthetic treatments conducted under the Laguna Aesthetics brand, the independent practitioner is responsible for the collection and use of special category clinical data in connection with consultation and treatment.
How we collect your personal data
We collect personal data from you when you make an enquiry, book an appointment, complete a registration form or consultation form, purchase products or services, contact us by phone, email, text, website form, social media or in person, attend our premises, provide feedback, reviews, photographs, video or other information to us, or apply for a role with us.
We may collect information through Phorest salon software, our website, email and messaging systems, telephone calls, paper records, CCTV systems, in-person conversations with staff, and images, video or related consent forms supplied to us by you or, where relevant, by an independent practitioner in accordance with client consent and applicable legal obligations.
How we use your personal data
To provide products, services and appointments
- registering you as a client
- booking, confirming, changing or cancelling appointments
- supplying products and services you request
- keeping treatment and service records where we are responsible for them
- taking payments, deposits and issuing refunds
- and providing aftercare information and customer service support
To communicate with you
- responding to enquiries
- sending booking confirmations and reminders
- contacting you about cancellations, changes or service issues
- and responding to feedback, complaints or follow-up queries
To run our business and maintain records
- customer account management
- internal administration
- staff planning and operational management
- maintaining business records
- preventing duplicate records and correcting errors
- monitoring service quality
- and analysing business performance and customer usage trends
For safety, security and fraud prevention
- operating CCTV
- preventing crime and unauthorised activity
- protecting customers, staff and property
- and handling incidents, insurance matters and legal claims
For marketing, where permitted
sending offers, promotions, service updates, news and related marketing communications where you have consented or where we are otherwise lawfully permitted to do so; administering loyalty programmes and associated communications where applicable; and using photographs or videos for the marketing of Lagoon or Laguna Aesthetics where appropriate consent or another lawful basis applies
For legal and regulatory purposes
- complying with legal obligations
- responding to lawful requests from regulators, insurers, courts, law enforcement or government bodies
- establishing, exercising or defending legal claims
- and complying with tax, accounting, consumer protection and local authority requirements where applicable
For recruitment
- processing job applications
- contacting applicants
- assessing suitability for roles
- and keeping recruitment records
Our lawful bases for processing
Under UK data protection law, we must have a lawful basis for using your personal data. Depending on the circumstances, we rely on one or more of the following: contract, legitimate interests, legal obligation, and consent.
Where we process special category data, such as health information, we also rely on an appropriate additional condition under data protection law.
Appointment communications and marketing
Appointment and service communications
We may use your contact details to send you appointment confirmations, appointment reminders, booking changes or cancellation messages, customer service communications, and post-appointment administrative communications. These are service-related communications and are separate from marketing.
Marketing
Where required, we will ask for your consent before sending marketing by email or SMS. Marketing may include promotions, special offers, updates about services or products, business news, and loyalty or event-related communications.
You can opt out of marketing at any time by using the unsubscribe option in the communication, or by contacting us directly.
Marketing use of photographs and video
Where photographs or video are to be used for marketing or promotional purposes and the client is identifiable, we will seek appropriate consent or rely on another lawful basis where permitted.
For Laguna Aesthetics, marketing use of aesthetics images or video may be based on a separate consent obtained in connection with the independent practitioner treatment process, and copies of the relevant consented material may then be shared with JP Lagoon Ltd for the purpose of marketing Laguna Aesthetics.
Photographs and video
Lagoon photographs and video
For treatments provided by Lagoon, photographs or video may sometimes be taken for treatment records, monitoring results, safety and service review, internal training or quality assurance where appropriate, and marketing or promotional use, where you have given appropriate consent or another lawful basis applies.
Where identifiable photographs or video are used for marketing or promotional purposes, we will seek appropriate permission before use unless another lawful basis clearly applies.
Laguna Aesthetics independent practitioner treatments
Where photographs or video are taken as part of consultation or treatment by an independent practitioner, those materials form part of that practitioner’s clinical record and remain under the primary control of the independent practitioner who performed the treatment and/or consultation.
If a client separately agrees to the marketing use of aesthetics images or video, copies of relevant materials and associated consent information may also be provided to JP Lagoon Ltd for marketing use in relation to Laguna Aesthetics.
In limited circumstances, copies of relevant materials may also be shared with JP Lagoon Ltd for legitimate business purposes including the monitoring of treatment standards, complaints handling, insurance matters, safeguarding, legal claims or compliance-related review. Such sharing does not transfer clinical responsibility to JP Lagoon Ltd or make JP Lagoon Ltd the controller of the practitioner’s underlying clinical record.
Payment and card transaction information
We process payment information in order to take payment for products and services, administer deposits and refunds, maintain accounting and transaction records, and help prevent fraud.
In-salon and telephone card payments made directly to JP Lagoon Ltd are processed through secure merchant card terminals and recognised payment providers.
- When one of these card payments is made, two paper card receipts are produced by the card terminal: a customer copy, which shows truncated card data only
- and a merchant copy, which shows the full card number and expiry date
JP Lagoon Ltd retains a single merchant copy as evidence of the transaction for legitimate business purposes, including payment verification, responding to chargebacks, dealing with payment queries or disputes, fraud prevention, accounting, legal, insurance, and record-keeping purposes.
Merchant card receipts are stored securely with restricted access in a locked facility and are retained for 6 years, unless they need to be kept longer in connection with an active dispute, investigation, insurance matter or legal claim.
For online or app bookings and deposits processed through Phorest and its payment providers, JP Lagoon Ltd does not handle or store the full payment card data used for the transaction. Through the Phorest system, authorised staff may have access only to limited card information, such as truncated card details and expiry date, where this is shown for customer service and account administration purposes.
We do not use card payment information or merchant card receipts for marketing purposes.
CCTV
We operate CCTV at our premises for crime prevention, customer and staff safety, security of premises and property, incident review and investigation, and insurance and legal purposes.
CCTV footage is processed in accordance with applicable data protection law and is only accessed where there is a legitimate need to do so.
Routine CCTV footage is normally retained for up to 60 days, after which it is automatically overwritten or deleted. Where footage is required for the investigation of an incident, complaint, insurance matter, safeguarding concern, legal claim or law-enforcement request, relevant footage may be retained for longer for as long as reasonably necessary for that purpose.
Who we share your personal data with
We do not sell or rent your personal data.
We may share personal data where necessary with service providers and processors, professional advisers, regulators and authorities, and relevant parties in business transfers, subject to appropriate safeguards.
Where relevant to booking administration, complaints handling, safeguarding, insurance, legal compliance, marketing administration based on client consent, or appointment administration, limited information may be shared between JP Lagoon Ltd and an independent practitioner operating from our premises, in line with the roles each party is responsible for.
Data processors
We use third-party providers to support parts of our business. These may include providers such as Phorest salon software for appointment scheduling, client record administration, customer relationship management, and marketing support functions.
We use a CCTV system based on HIK-Connect and may access footage through the HIK-Connect app. Our CCTV service provider is Polaris Fire & Electrical Ltd, Suite A, 3rd Floor, The Clock House, Barking, Essex.
International transfers
Some of our service providers may process personal data outside the UK or EEA. Where this happens, we will take appropriate steps to ensure that personal data is protected by using appropriate safeguards where required.
How long we keep your personal data
We keep personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, tax, insurance, regulatory, safeguarding, complaint-handling and record-keeping requirements.
Our standard retention periods currently include: Lagoon salon treatment records: 7 years; Laguna Aesthetics client registration and administrative records held by JP Lagoon Ltd: 7 years; complaint and insurance records: 7 years; merchant card receipts: 6 years; unsuccessful recruitment records: up to 12 months after the end of the recruitment process, unless a longer period is justified; and routine CCTV footage: up to 60 days, unless required for an incident, investigation, insurance matter, safeguarding concern, legal claim or law-enforcement purpose, in which case relevant footage may be retained for longer for as long as reasonably necessary.
Retention periods may vary depending on the type of information and the reason it was collected. In deciding how long to keep personal data, we take into account the nature of the information, the purpose for which it was collected, legal and regulatory requirements, tax and accounting obligations, insurance requirements, limitation periods for legal claims, safeguarding and complaint considerations, and operational necessity.
Consequences of not providing your personal data
If you do not provide certain information we reasonably require, we may not be able to register you as a client, book or manage your appointments, provide requested products or services, carry out a treatment safely, comply with legal or regulatory requirements, take payment or manage your account properly, or respond appropriately to queries, complaints or aftercare issues.
Children’s data
Lagoon may, in limited circumstances, provide certain treatments or services to clients under the age of 16, such as age-appropriate beauty treatments.
Where this applies, consultation and consent documentation may need to be completed by a parent or legal guardian; we may collect the child’s name, date of birth and limited health information where needed for the treatment; and we request that contact details recorded on the file are those of the parent or legal guardian, not the child, unless there is a clear reason otherwise.
We do not knowingly collect personal data directly from children where we are not permitted to do so.
Laguna Aesthetics does not provide treatments to clients under the age of 16.
How we keep your personal data secure
We take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage.
These measures may include secure software systems and restricted user access, passwords, PIN protection and access controls, secure storage of paper records, restricted access to consultation records, treatment records and payment-related records, secure handling of merchant card receipts, CCTV access controls, staff training and confidentiality obligations, secure disposal or destruction of records when no longer required, and the use of service providers who are expected to maintain appropriate security standards.
Where personal data is processed through third-party systems such as salon management, payment or communications platforms, we seek to ensure that appropriate contractual and security arrangements are in place.
Your rights
Subject to applicable law, you may have the right to be informed about how your personal data is used, request access to your personal data, request correction of inaccurate or incomplete personal data, request erasure of personal data in certain circumstances, request restriction of processing in certain circumstances, object to processing based on legitimate interests, object to direct marketing, request transfer of your personal data where applicable, and withdraw consent where processing is based on consent.
These rights are not absolute and may be subject to legal exceptions.
If you wish to exercise any of your rights, please contact us using the details set out in this Privacy Notice.
Complaints
If you have any concerns about how we use your personal data, please contact us first and we will try to resolve the issue.
You also have the right to make a complaint to the Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.
Contact us
If you have any questions about this Privacy Notice or about how JP Lagoon Ltd handles your personal data, please contact: JP Lagoon Ltd, 139 Alexandra Road, London, SW19 7JY. Email: info@lagoonspa.co.uk. Telephone: 020 8947 2332.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in law, regulation, our services, our business operations, or how we handle personal data.
The latest version of this Privacy Notice will be made available through our forms, systems, website or on request.