Privacy Policy

Effective date: 1st March 2026
Last updated: 1st March 2026

Thameside Aesthetics (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you use our website, contact us, book an appointment, or receive treatment.

Clinic details
Thameside Aesthetics Address: 204bThames Side, Laleha, Surrey, TW18 2JN
Email: info@thamesideaesthetics.com
Phone: 01784 839834

If you have any questions about this policy or your data, please contact us using the details above.

1. What information we collect

We may collect the following types of personal data:

a) Information you provide to us

  • Name, email address, phone number
  • Enquiry details and messages you send us
  • Appointment details (date/time, services booked)
  • Payment information (handled securely by third-party providers where applicable)
  • Information you provide during consultation and treatment, including:
  • Medical history and health information
  • Consent forms
  • Treatment notes and aftercare information
  • Before-and-after photographs (where applicable)

b) Information we collect automatically (website usage)

  • Device and browser information
  • IP address
  • Pages visited and actions taken on the site
  • Cookie data (see Cookies section)

c) Information from third parties

  • Online booking system providers (appointment data)
  • Payment providers (payment status, transaction confirmations)
  • Website analytics providers (site performance data)

2. How we use your information

We use your personal data to:

  • Respond to enquiries and provide customer support
  • Book and manage appointments
  • Provide consultations and treatments safely
  • Maintain accurate clinical records
  • Send appointment confirmations and reminders
  • Take payment and manage invoices/receipts (where applicable)
  • Improve our website and services
  • Comply with legal and regulatory obligations
  • Manage complaints, incidents, or disputes

3. Lawful bases for processing (UK GDPR)

We process your personal data under one or more of the following lawful bases:

  • Consent – where you have given clear consent (for example, marketing emails, optional photography for marketing)
  • Contract – to provide the services you book or request
  • Legal obligation – where we must comply with the law
  • Vital interests – where processing is necessary to protect someone’s life (rare in this context)
  • Legitimate interests – for running and improving our business, customer service, and website performance (only where this does not override your rights)

Special category data (health information)

Health information is “special category data”. We process it for the purpose of providing safe treatment and maintaining clinical records, typically under:

  • Healthcare/medical purposes (and associated legal bases), and/or
  • Explicit consent where required.

4. Marketing communications

If you opt in, we may send you updates about treatments, news, and offers via email or SMS.

You can unsubscribe at any time using the link in our emails or by contacting us directly.

We do not sell your personal data to third parties.

5. Who we share your information with

We may share your data with trusted third parties only where necessary, including:
Online booking platform providers

  • Payment providers
  • Website hosting and IT providers
  • Analytics tools (such as Google Analytics)
  • Professional advisers (accountant, legal advisers) where necessary
  • Regulators or authorities if required by law

All providers are expected to handle your data securely and in line with applicable data protection laws.

6. How we store and protect your data

We take appropriate security measures to protect your personal data from loss, misuse, unauthorised access, alteration, or disclosure.

Your information may be stored in:

  • Secure digital systems (including booking/CRM systems where applicable)
  • Paper records (stored securely)
  • Encrypted or access-controlled devices/accounts

7. How long we keep your data (retention)

We keep personal data only for as long as necessary to provide services, meet legal obligations, and maintain appropriate records.

Typical retention periods include:

  • Enquiries: 10 years
  • Appointment records: 10 years
  • Clinical/treatment records:10 years (often longer due to clinical and insurance requirements)
  • Marketing preferences: until you unsubscribe or ask us to delete them

If you would like more detail on retention periods, contact us.

8. Your rights

Under UK GDPR, you have rights including:

  • The right to access your personal data
  • The right to correct inaccurate data
  • The right to request deletion (in some circumstances)
  • The right to restrict processing (in some circumstances)
  • The right to object to processing (in some circumstances)
  • The right to data portability (in some circumstances)
  • The right to withdraw consent at any time (where processing is based on consent)
  • To make a request, contact us using the details at the top of this policy.

You also have the right to complain to the Information Commissioner’s Office (ICO) if you believe your data has been handled improperly.

9. Cookies

We use cookies to enhance your experience and ensure our website functions smoothly.

Cookies are small text files stored on your device that help us remember your preferences, understand how visitors use our site, and improve how it performs.

By using our website, you consent to the use of cookies in line with this policy. You can change your cookie settings at any time (see “How to control cookies” below).

What cookies do we use and why?

We may use the following types of cookies:

  • Essential cookies – required for core site functionality, such as security, form submissions, and booking features.
  • Functional cookies – remember your preferences, such as form details or site settings.
  • Analytics cookies – help us understand how visitors use our website so we can improve content and usability (for example, Google Analytics).

We do not knowingly use cookies to sell your data. If we use marketing-related cookies in the future, we will update this policy and provide appropriate choices.

How to control cookies

You can manage or delete cookies via your browser settings. Please note that disabling cookies may affect your experience and some website features may not work as intended.

For information about Google Analytics, you can review Google’s privacy information and opt-out tools via their official resources.

If you would like more details about the cookies we use, please contact us.

10. Social media and embedded content

Our website may include links to social platforms (for example, Instagram) and embedded services such as maps or videos. These third-party services may collect information about your interactions.

Please review the privacy policies of those third parties for more details.

11. Email communications tracking

If we send you emails, we may use basic tracking (such as open and click tracking) to understand engagement and improve communications. You can opt out at any time by unsubscribing.

12. Third-party booking systems

If you book online, your booking will be processed by a third-party booking provider. That provider may act as a separate controller or processor of your data depending on their service. Please refer to the provider’s privacy policy for details.

13. Payments

Payments may be processed securely by third-party payment providers. We do not store full card details on our systems. Payment providers handle your information under their own privacy policies.

14. Policy updates

We may update this Privacy Policy from time to time. Any changes will take effect upon publication on our website. Please check back regularly to stay informed.