Alchemy & i Group Client Privacy Notice

Effective date: 1st Jan 2026

1. About this privacy notice

Alchemy & i Group takes the privacy and security of its clients, visitors and prospective clients seriously.

This notice explains how we collect, use, store and share your personal information when you:

  • visit one of our salons, spas or clinics;
  • book or receive a service or treatment;
  • use our website or online booking system;
  • contact our reservations or client-care teams;
  • purchase a product, gift card or membership;
  • attend an event or promotion;
  • interact with us through email, telephone, text, WhatsApp or social media; or
  • visit premises where CCTV is operating.

This notice applies to businesses operating under the Alchemy & i, Cecily, and other associated Alchemy & i Group trading names.

It does not cover personal information relating to employees, workers, contractors or job applicants, which is dealt with under separate privacy information.

2. Who we are

Alchemy & i Group is the umbrella name used for a group of related businesses under common ownership. These businesses operate hair salons, beauty salons, spas, skin clinics, aesthetic services and associated hospitality and retail services under trading names including:

  • Alchemy & i;
  • Cecily;
  • Cecily Spa;
  • Cecily Skin;
  • Cecily Beauty; and
  • any other Alchemy & i Group trading names identified when you make a booking.

The data controller responsible for your information will normally be the legal company operating the location you visit or providing the service you purchase.

The relevant company name may be shown on your booking confirmation, receipt, invoice, website location page or other correspondence.

Our group companies may share certain central services, including reservations, marketing, finance, administration, information technology, client care and business management. Depending on the particular activity, the companies may act as separate controllers or may jointly determine how information is used.

You may contact us centrally about any Alchemy & i Group business, and we will direct your enquiry to the appropriate company.

A schedule of the relevant legal companies should appear at the end of this notice.

3. How to contact us

For questions about this notice or how we use your personal information, please contact:

Data Protection Lead
Alchemy & i Group
Email: info@alchemyandi.co.uk
Postal address: 10 Castle St, Berkhamsted HP4 2BQ

You may also contact the salon, spa or clinic you normally visit.

4. Information we may collect

The information we collect depends on how you interact with us and the services you receive.

Identity and contact information

This may include:

  • your name;
  • title;
  • date of birth or age, where relevant;
  • postal address;
  • email address;
  • telephone number;
  • gender or pronouns, where voluntarily provided;
  • emergency contact details; and
  • parent or guardian details where the client is under 18.

Booking and account information

This may include:

  • your Fresha account or client profile information;
  • appointment dates and times;
  • the location, services and team members booked;
  • appointment history;
  • cancellations, rescheduling and no-show information;
  • waiting-list information;
  • booking preferences;
  • membership and loyalty information;
  • gift-card information;
  • deposits and account credit; and
  • notes needed to manage your appointments.

Service and treatment information

Depending on the service, this may include:

  • hair type, colour formulas and technical history;
  • skin type and skin concerns;
  • treatment preferences;
  • product preferences;
  • consultation records;
  • patch-test and sensitivity-test information;
  • treatment plans;
  • service notes;
  • products used;
  • aftercare information;
  • treatment results;
  • consent forms; and
  • before-and-after photographs.

Health and special-category information

Some hair, beauty, spa, skin and aesthetic services require us to ask about health matters so that we can assess whether a service is suitable and provide it safely.

This may include information about:

  • allergies or sensitivities;
  • medical conditions;
  • medication;
  • pregnancy or breastfeeding;
  • previous procedures or treatments;
  • skin conditions;
  • injuries;
  • contraindications;
  • adverse reactions; and
  • other information relevant to the safety of a treatment.

Health information is treated as special-category personal information and receives additional protection.

You should only provide information that is relevant to the service or treatment you are considering.

Payment and transaction information

This may include:

  • payments made;
  • refunds;
  • deposits;
  • outstanding balances;
  • products and services purchased;
  • payment method;
  • transaction references; and
  • limited payment-card information made available to us by our payment provider.

We do not generally receive or store your complete payment-card number. Card payments are processed through Fresha or another authorised payment provider.

Communications

This may include:

  • emails;
  • text and WhatsApp messages;
  • social-media messages;
  • online enquiries;
  • telephone enquiries;
  • booking conversations;
  • feedback;
  • reviews;
  • complaints;
  • data-protection requests; and
  • records of our responses.

Where telephone calls are recorded, or an automated booking assistant is used, you will be informed at the beginning of the call or interaction.

Marketing and preference information

This may include:

  • whether you have agreed to receive marketing;
  • the types of services you are interested in;
  • your preferred location;
  • communication preferences;
  • responses to promotions;
  • whether you opened or interacted with a marketing message; and
  • records of unsubscribes and objections.

Website and technical information

When you use our website, we may collect:

  • IP address;
  • browser and device type;
  • operating system;
  • pages visited;
  • dates and times of visits;
  • referring website;
  • cookie identifiers;
  • approximate location derived from your IP address; and
  • website interaction and analytics information.

Further details should be provided in our separate Cookie Notice.

CCTV information

CCTV may capture:

  • your image;
  • your movements within monitored areas;
  • the time and date of your visit; and
  • information about an incident involving you.

CCTV is not installed in toilets, changing areas or treatment spaces where clients would reasonably expect a high level of privacy.

5. Where we obtain your information

We may obtain information:

  • directly from you;
  • from a parent, guardian or person booking on your behalf;
  • through Fresha;
  • through our website;
  • from another Alchemy & i Group location;
  • through our reservations or client-care teams;
  • from a gift-card purchaser;
  • through social media;
  • from a referring client or professional;
  • from payment providers;
  • from our staff during consultations and appointments;
  • through CCTV;
  • through website cookies and analytics; or
  • from public sources where appropriate.

Where someone provides information about another person, they should have that person’s permission to do so.

6. How and why we use your information

We use personal information only where we have an appropriate reason under data-protection law.

To respond to enquiries and arrange appointments

We use your contact and booking information to:

  • respond to enquiries;
  • recommend appropriate services;
  • create and manage bookings;
  • manage waiting lists;
  • send confirmations and reminders;
  • contact you about changes;
  • process cancellations and rescheduling; and
  • provide information requested before an appointment.

Our lawful basis is normally taking steps at your request before entering into a contract, performing our contract with you, and our legitimate interest in managing appointments effectively.

To provide services and treatments

We use your information to:

  • provide the service you have booked;
  • record formulas, products and treatment history;
  • maintain continuity between visits;
  • personalise your experience;
  • provide aftercare;
  • assess the suitability and safety of a treatment;
  • identify contraindications; and
  • respond to reactions or concerns.

Our lawful basis is normally performing our contract with you and our legitimate interest in providing safe, consistent and high-quality services.

Where health or other special-category information is processed, we will also rely on an appropriate special-category condition. This will usually be your explicit consent.

Where a service is provided by a regulated healthcare professional, the practitioner or operating company may rely on the condition relating to the provision and management of health treatment, where the legal requirements for doing so are met.

You may withdraw consent to the future use of health information where consent is the basis relied upon. However, we may be unable to provide certain treatments without information needed to assess their safety.

To take and use photographs

Photographs may be taken:

  • as part of a treatment or clinical record;
  • to monitor progress;
  • to assess results;
  • to respond to a complaint or insurance matter; or
  • for training, promotional or social-media purposes.

Where photographs are required as part of your treatment record, we will explain why they are necessary.

We will obtain separate permission before using an identifiable photograph for advertising, social media, publicity, training materials or other promotional purposes. Declining promotional photography will not affect your ability to receive a service.

To process payments and administer our policies

We use personal and transaction information to:

  • process payments and refunds;
  • take deposits;
  • apply cancellation and no-show policies;
  • manage gift cards and memberships;
  • issue receipts and invoices;
  • prevent fraudulent transactions; and
  • maintain financial and tax records.

Our lawful bases are performing our contract with you, complying with legal obligations and our legitimate interest in protecting the business from fraud and financial loss.

To send service communications

Appointment confirmations, reminders, receipts, changes to bookings, aftercare information, safety information and changes to terms are service communications rather than marketing.

We may send these where necessary to fulfil our contract with you or for our legitimate interest in managing your appointment and maintaining an effective client relationship.

To provide client care and handle complaints

We may use your records to:

  • respond to questions;
  • investigate concerns;
  • manage complaints;
  • provide refunds or corrective services;
  • investigate accidents or adverse reactions;
  • respond to insurance matters;
  • establish, exercise or defend legal claims; and
  • improve our standards.

Our lawful bases are performing our contract, complying with legal obligations and our legitimate interests in resolving concerns and protecting clients and the business.

For safety, security and fraud prevention

We may use information to:

  • protect clients, staff, visitors and property;
  • prevent or investigate theft, fraud and misconduct;
  • manage safeguarding concerns;
  • investigate accidents and incidents;
  • maintain building security; and
  • cooperate with the police, insurers or regulators.

Our lawful bases are legitimate interests, legal obligations and, where applicable, establishing, exercising or defending legal claims.

For marketing

We may use your name, contact details, appointment history, location and service interests to send relevant information about:

  • services;
  • products;
  • new locations;
  • events;
  • team members;
  • availability;
  • offers;
  • memberships;
  • loyalty benefits; and
  • Alchemy & i Group news.

Email, text-message and similar electronic marketing will only be sent where you have consented or where the law otherwise permits it, such as where the existing-customer “soft opt-in” applies.

You may unsubscribe at any time by:

  • using the unsubscribe link in an email;
  • following the instructions in a text message;
  • changing your Fresha preferences;
  • contacting the salon; or
  • emailing info@alchemyandi.co.uk.

Service messages may still be sent where necessary for an active booking.

The rules for electronic marketing generally require consent or a valid soft opt-in, together with a simple opportunity to unsubscribe.

To improve and manage the Group

We may analyse appointment and transaction information to:

  • understand demand;
  • improve staffing and opening hours;
  • measure service performance;
  • plan new services and locations;
  • understand client retention;
  • improve the client experience;
  • conduct staff training;
  • develop group strategy; and
  • maintain consistent standards across our businesses.

Where possible, information used for reporting will be aggregated or anonymised.

Our lawful basis is our legitimate interest in operating and improving the Alchemy & i Group.

7. Our use of Fresha

We use Fresha to support functions which may include:

  • online and in-salon bookings;
  • appointment management;
  • client profiles;
  • appointment confirmations and reminders;
  • deposits and payments;
  • gift cards;
  • memberships;
  • client communications;
  • marketing preferences;
  • point-of-sale transactions; and
  • business reporting.

Where we place information into Fresha as part of our salon or spa client records, the relevant Alchemy & i Group company will generally act as controller and Fresha will process that information on our behalf.

Where you create or use your own Fresha account, book through the Fresha marketplace, use Fresha payment services or receive marketing directly from Fresha, Fresha may also act as an independent controller. Fresha’s own privacy policy will apply to those activities.

A request concerning information in our treatment or client records should normally be sent to us. A request concerning your Fresha account, Fresha marketplace activity or Fresha’s own marketing may need to be sent directly to Fresha.

Fresha’s current terms distinguish between information it processes for a partner and information it processes as an independent controller.

Automated booking services

Where we use a Fresha automated or AI-assisted telephone or messaging service, the system may process:

  • your telephone number;
  • call or message content;
  • appointment requests;
  • service preferences;
  • booking information; and
  • information needed to respond to your enquiry.

We will provide appropriate notice where an interaction is automated or recorded.

We do not intentionally use automated decision-making to make decisions about you which produce legal or similarly significant effects without appropriate safeguards.

8. Sharing information within Alchemy & i Group

Information may be shared between relevant Alchemy & i Group businesses where necessary for:

  • central reservations;
  • transferring or managing appointments between locations;
  • providing continuity of service;
  • central client care;
  • resolving complaints;
  • finance and administration;
  • marketing where permitted;
  • information technology and security;
  • management reporting;
  • business planning; and
  • legal and regulatory compliance.

Access is limited to people who reasonably need the information for their role.

Health, treatment and consultation information will not automatically be available to every business or member of staff within the Group. Access should be limited according to the service provided and the person’s responsibilities.

9. Other organisations we may share information with

We may share relevant information with:

  • Fresha;
  • payment processors and banks;
  • website, hosting and cloud-storage providers;
  • communications and telephone providers;
  • email and marketing platforms;
  • information-technology and cybersecurity providers;
  • professional advisers, including accountants and solicitors;
  • insurers and insurance claims handlers;
  • healthcare professionals or emergency services, where appropriate;
  • product manufacturers where investigating an adverse reaction;
  • landlords, security providers or building managers where necessary;
  • the police, courts, regulators or government authorities;
  • prospective purchasers, investors or advisers in connection with a business sale, acquisition or restructuring; and
  • other organisations where you have asked or authorised us to share information.

We do not sell client personal information.

Service providers acting on our behalf are required to process information securely and only for agreed purposes.

10. International transfers

Some of our suppliers, or their subcontractors, may store or access information outside the United Kingdom.

This may include Fresha and providers of cloud hosting, communications, website analytics and marketing services.

Where personal information is transferred outside the UK, we will take steps intended to ensure it remains appropriately protected. Depending on the destination, this may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved EU Standard Contractual Clauses;
  • another legally recognised transfer safeguard; and
  • appropriate contractual, organisational and technical protections.

You may contact us for further information about the safeguards applying to a particular transfer.

The ICO currently identifies the UK IDTA and UK Addendum as recognised contractual safeguards for restricted transfers.

11. How long we retain information

We keep information only for as long as it is reasonably required for the purpose for which it was collected and to meet legal, regulatory, insurance and professional obligations.

Our retention decisions take account of:

  • the nature of the information;
  • whether it includes health or treatment information;
  • how often you visit us;
  • the type of service provided;
  • the risk of a complaint or claim;
  • insurance requirements;
  • professional or regulatory requirements;
  • tax and accounting obligations; and
  • whether the information relates to a child.

As a general guide:

Enquiries

Enquiries which do not lead to a booking will normally be retained for up to 12 months, unless there is a reason to retain them for longer.

Client and appointment records

Client profiles, appointment records and service histories will normally be retained while you remain an active client and for up to seven years after your last appointment.

Treatment and health records

Consultation, consent, treatment and health-related records may be retained for longer where required by:

  • the nature of the treatment;
  • a professional regulator;
  • our insurer;
  • safeguarding requirements;
  • the client’s age; or
  • applicable limitation periods.

Financial records

Invoices, transaction and accounting records will normally be retained for at least six years, or longer where required by tax or accounting law.

Marketing records

Marketing information will be retained until you unsubscribe, withdraw consent or object.

We may retain a limited suppression record after you unsubscribe so that we can continue to respect your preference and avoid adding you back to a marketing list.

Photographs

Treatment-record photographs will be retained in line with the related treatment record.

Promotional photographs will be retained while the permission remains valid and while there is a reasonable business purpose for continuing to use them. Where you withdraw permission, we will stop new uses where reasonably possible, although we may not be able to withdraw materials already printed or published.

Complaints and incidents

Complaint, accident, adverse-reaction and insurance records may be retained for the duration of the matter and any relevant legal or insurance limitation period.

CCTV

CCTV footage will normally be retained for 90 days and then automatically overwritten or securely deleted.

Relevant footage may be retained for longer where it is required for an incident, complaint, investigation, insurance claim or legal proceedings.

12. CCTV

CCTV is used in selected public and operational areas of our premises for:

  • client, staff and visitor safety;
  • crime prevention and detection;
  • protecting personal belongings;
  • protecting business property and equipment;
  • investigating accidents or incidents;
  • supporting safeguarding;
  • responding to complaints; and
  • managing insurance and legal claims.

Appropriate signs are displayed where CCTV is operating.

Access to recordings is restricted to authorised people. Footage may be shared with the police, insurers, legal advisers or other appropriate parties where this is necessary and lawful.

CCTV is not used for promotional purposes.

13. Information about children

Some of our services may be available to children or young people.

Where appropriate, we may:

  • require a parent or guardian to make the booking;
  • record the parent or guardian’s details;
  • require the parent or guardian to attend;
  • obtain parental or guardian consent;
  • ask for proof of age; or
  • refuse or adapt a service based on age, safety, insurance or professional requirements.

We do not knowingly send direct marketing to children where the necessary permission has not been obtained.

14. Security

We use reasonable organisational and technical measures intended to protect personal information against:

  • unauthorised access;
  • unlawful use;
  • loss;
  • alteration;
  • disclosure;
  • destruction; and
  • accidental damage.

Measures may include:

  • account permissions;
  • password and access controls;
  • staff confidentiality requirements;
  • staff training;
  • secure payment providers;
  • device and network security;
  • restricted access to treatment information;
  • data-backup arrangements; and
  • procedures for managing suspected data breaches.

No electronic system can be guaranteed to be completely secure. Clients should avoid sending health or payment-card information through unsecured messaging or social-media channels unless specifically asked to do so through an approved process.

15. Your data-protection rights

Depending on the circumstances and the lawful basis relied upon, you may have the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to delete information;
  • ask us to restrict how information is used;
  • object to certain uses of your information;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent; and
  • ask for human review of a significant decision made solely by automated means.

Some rights are subject to legal exemptions. For example, we may need to retain information to comply with legal obligations, protect another person’s rights or defend a legal claim.

We may ask for information to confirm your identity before responding to a request.

Your right to object to direct marketing

You have an absolute right to object to the use of your personal information for direct marketing.

You may unsubscribe or object at any time without charge.

16. Data-protection complaints

Please contact us first if you have concerns about how your information has been handled.

Data-protection complaints should be sent to:

Data Protection Complaint
Alchemy & i Group
Email: info@alchemyandi.co.uk
Postal address: 10 Castle st, Berkhamsted HP4 2BQ

Please include:

  • your name and contact details;
  • the location you visited;
  • a description of your concern;
  • any relevant appointment or correspondence details; and
  • what you would like us to investigate.

We will:

  • acknowledge your complaint within 30 days;
  • take reasonable and proportionate steps to investigate it;
  • keep you informed where appropriate; and
  • tell you the outcome without undue delay.

These complaint-handling duties have applied to organisations handling personal data since June 2026.

You also have the right to complain to the UK data-protection regulator:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

17. Changes to this notice

We may update this privacy notice where:

  • our services change;
  • we introduce new systems;
  • our group structure changes;
  • we appoint new service providers;
  • the way we use information changes; or
  • legal or regulatory requirements change.

The latest version will be published on our website with the date it was last updated.

Where a change significantly affects how we use existing personal information, we will take reasonable steps to bring it to your attention before the new use begins.