Privacy Policy

Effective Date: 1st September 2025

This Privacy Policy explains how we at Infinity Hair Loss Clinic collect, use, and protect your personal data, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Information We Collect

We may collect and process the following information:

  • Personal Information: Name, email, phone number, and appointment details.

  • Payment Details: Collected securely via Stripe through Acuity Scheduling.

  • Billing Authorisation: If you choose to proceed with a treatment plan, we may process further payments with your prior consent.

  • Website Analytics: Basic usage data (IP address, browser type) collected via Squarespace.

2. Lawful Basis for Processing Data

We process your data under the following lawful bases:

  • Consent: When you provide your information to book a consultation.

  • Contract: To fulfil your service appointment and related communications.

  • Legitimate Interest: To improve our services and respond to inquiries.

3. How We Use Your Information

  • Manage bookings and consultations

  • Communicate with you (confirmations, reminders, follow-ups)

  • Process secure payments

  • Respond to support queries

  • Improve our services and website experience

We never sell or share your data for marketing purposes.

4. Data Retention

We retain your data only as long as necessary to fulfil the purpose it was collected for — typically up to 6 years for accounting and tax purposes, unless you request it be deleted sooner (where legally permissible).

5. Your Data Protection Rights (under UK GDPR)

You have the right to:

  • Access your personal data

  • Request corrections

  • Request deletion

  • Object to or restrict processing

  • Withdraw consent at any time

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

To exercise these rights, click here to email us.

6. Data Security

We use secure systems and restrict access to your data to authorised staff only. All payments are processed through secure platforms (Stripe and Acuity Scheduling).

7. Cookies

Our site may use cookies to enhance functionality and performance. You can adjust cookie preferences in your browser settings.

8. Third-Party Providers

We use trusted providers to deliver our services:

  • Squarespace – website and booking interface

  • Acuity Scheduling – appointment and invoicing system

  • Stripe – secure payment processing

These providers comply with UK GDPR and maintain their own privacy policies.

9. Medical & Health Information

As part of your consultation, you will be asked to complete a paper-based pre-consultation form. This form may include questions about:

  • Your current health status

  • Any medications you are taking

  • Relevant medical history

This information is necessary to assess your suitability for our treatments and to ensure your safety.
We collect and process this data under Article 9(2)(h) of the UK GDPR — "the provision of health or social care" — and with your explicit consent.

Your form will be:

  • Stored securely, in accordance with UK GDPR

  • Accessed only by trained staff involved in your care

  • Not shared with any third parties unless required by law (e.g. safeguarding concerns)

You have the right to withdraw your consent at any time, though this may affect your eligibility to proceed with treatment.

10. Contact Us

If you have questions or concerns about your data or this policy, please:
Click here to email us
www.infinityhairlossclinic.co.uk