Privacy policy

The General Data Protection Law (‘GDPR’) has now come into effect in the UK giving you more control over your personal data, and greater transparency around how it is used. At Crown Hair Replacement Ltd we are committed to keeping personal data of our clients safe and secure. We have updated our Privacy Policy to explain these changes to give you more information about how we collect, use, and store your personal data. Please review this information below.

Who is responsible for your personal data:

Crown Hair Replacement Ltd, a company registered in England and Wales (Registration number 10639947) is registered as a data controller in the United Kingdom for the purposes of the Data Protection Act 1998 or any subsequent UK legislation resulting from EU General Data Protection Regulations (GDPR). We are a recruitment agency and recruitment business as defined in the Employment Agencies and Employment Businesses Regulations 2003.

We are registered with the Information Commissioners Office (‘ICO’) under registration number A8723723 and you can view more information about our registration online here.

Information We May Collect:

  • Identification Data – First name, last name, title, date of birth and gender
  • Your Personal Contact Data – Home address, email address and telephone numbers
  • Your Health Data – Any information we require about your health, and in particular in relation to your hair that arises from one of our consultations with you, including any treatment or other services that you may receive from us
  • Your Financial Data – Bank account and payment card details
  • Transaction Data – Details about payments to and from you and other details of products and services you have purchased from us
  • Technical Data – Internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this site
  • Usage Data – Information about how you use our Site, products, and services
  • Marketing and Communications Data – Your preferences in receiving marketing from us and our third parties and your communication preferences

Why We Will Use Your Data:

  • Consent – When you have provided your affirmation consent, which you may revoke at any time, such as by signing up to our mailing list
  • Legal Obligation – If necessary to comply with a legal obligation and to comply with our obligations under the Crown Hair Replacement Ltd Policy Terms of Use
  • ContractThe processing is necessary for a contract we have with you (for example, to process and deliver our services to you and to manage our relationship with you), or because you have asked us to take specific steps before entering into a contract
  • Vital Interests – The processing is necessary to protect someone’s life
  • Legitimate Interests – The processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your Personal Data for our legitimate interests. We do not use your Personal Data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law

We rely on the following legitimate interests when processing your Personal Data:

  • To manage our business and comply with our obligations to our clients, staff and suppliers;
  • To protect our proprietary and commercially sensitive information; and
  • To administer and maintain our website.

We also need to satisfy specific conditions for using your health data.  We rely upon the following ground in this regard:

  • Express Consent – You expressly consent to the processing of Personal Data concerning your health to allow us to deliver our services to you.

Click here to find out more on the Information Commissioner’s Office website about the types of lawful basis that we will rely on to process your Personal Data.

Generally, we do not rely on consent as a legal basis for processing your Personal Data other than as described below. However, where we do ask for your consent (for example in processing data relating to your health) we will do so to comply with the principle that any processing must be lawful and transparent.

Information Sharing and Disclosure:

We may have to share your Personal Data with the parties below in order to provide our services to you. We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law, and when they are processing Personal Data on our behalf we do not allow our third-party service providers to use your Personal Data for their own purposes and only permit them to process your Personal Data for specified purposes and in accordance with our instructions and in accordance with the law. Examples of our third parties include

  • Third Parties who you authorise to provide services to you; and
  • Professional advisors including financial services who may provide finance to you in relation to payment of any treatment.

Information from other sources:

Social buttons on pages of our website you will see ‘social buttons’ for Linkedin, Instagram and Facebook. In order to implement these buttons and connect them to the relevant social networks and external sites, there are scripts from domains outside of Crown Hair Replacement Ltd. You should be aware that these sites may collect information about what you are doing on the internet, including on Crown Hair Replacement Ltd website. So, if you click on any of these buttons, these sites will be registering that action and may use that information. In some cases, these sites will be registering the fact that you are visiting Crown Hair Replacement Ltd and the specific pages you are on, even if you don’t click on the button while you are logged into their sites. You should check the respective privacy policies of each of these sites to see exactly how they use your information and to find out how to opt out, or delete, such information if you wish.

Data Retention:

We retain your personal information for as long as necessary to provide you with services and as described in our Privacy Policy. However, we may also be required to retain this information to comply with our legal and regulatory obligations, to resolve disputes, and to enforce our agreements. Your data is stored on both electronic and paper records which is within a controlled access area and regularly inspected to mitigate the risk of any unauthorised access to physical records.

Your Rights:

Access. You have the right to request access and receive a copy of the personal information we hold about you by contacting us using the contact information below. You also have rights to request to change, restrict our use of, or delete your personal information. Absent exceptional circumstances (like where we are required to store data for legal reasons) we will generally delete your personal information upon request unless we have compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.

Use of Cookies:

We use cookies to gather information about your computer for our services and to provide statistical information regarding the use of our website. Such information will not identify you personally – it is statistical data about our visitors and their use of our website. This statistical data does not identify any personal details whatsoever. We may also gather information about your general Internet use by using a cookie file. Where used, these cookies are downloaded to your computer automatically. This cookie file is stored on the hard drive of your computer, as cookies contain information that is transferred to your computer’s hard drive. They help us to improve our website and the service that we provide to you. All computers have the ability to decline cookies. This can be done by activating the setting on your browser, which enables you to decline the cookies. Please note that should you choose to decline cookies, you may be unable to access particular parts of our website.

How to Contact Us:

You may request details of personal information that we hold about you under the Data Protection Act 1998. If you would like a copy of the information held on you please write to us at Crown Hair Replacement Ltd at 72 Merthyr Road, Whitchurch, Cardiff, CF14 1DJ. If you believe that any information we are holding on you is incorrect or incomplete, or you have any questions or concerns, please email us as soon as possible at and we will promptly correct any information found to be incorrect