Privacy Notice
Delight Aesthetics LTD (trading as Delight Aesthetics) is the data controller for the personal and health data we process about our clients, enquirers and website visitors. This notice explains what we collect, why, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Delight Aesthetics LTD
Company No. 16759149, registered in England and Wales
Registered office: 209 Old Marylebone Road, London NW1 5QT
Data Protection Lead: Viktorija Maslikova (Director)
Deputy Data Protection Lead: Anna Kovaliova (Clinical Lead)
Contact: info@delightaesthetics.co.uk
What data we collect
-
Identity and contact: name, date of birth, address, email, phone number
-
Clinical data: medical history, medications, allergies, pregnancy status, skin assessment, consultation notes, treatment plan, consent, and clinical photography where clinically indicated
-
Appointment data: bookings, reminders, cancellations, payments
-
Website data: IP address, device type, pages viewed, cookie identifiers
-
Marketing data: your preferences and responses to our communications (only if you have opted in)
Why we process your data (lawful bases)
-
Contract: to deliver the treatments you have booked
-
Legal obligation: to keep clinical records, report adverse events to the MHRA Yellow Card scheme, and meet HMRC, employment and sponsorship duties
-
Legitimate interests: to improve the service, prevent fraud, and respond to enquiries, balanced against your interests
-
Consent: for marketing emails, optional clinical photography and cookies that are not strictly necessary
-
Vital interests and public interest (health): used only where a medical emergency or public-health duty applies
Special category (health) data is processed under UK GDPR Article 9(2)(h) (provision of health care) with the additional safeguards in Schedule 1 of the Data Protection Act 2018.
Who we share it with
-
Our clinical and administrative team under confidentiality obligations
-
Our consent and records platform (Faces Consent), Google Workspace (secure document and email storage), and our appointment system
-
Clinical waste and sharps carriers (non-identifying operational data only)
-
Our insurer and our indemnity agent (AXIS Aesthetics Agent) where required
-
Regulators and authorities where law requires it (MHRA, HSE, ICO, Police, NHS, local safeguarding teams)
-
Professional advisers (accountant, legal counsel) under confidentiality
-
CCTV: Delight Aesthetics does not operate CCTV. Any CCTV at the host premises (WOW Beauty Marylebone South) is operated by the host as a separate data controller; requests relating to that footage should be directed to them.
We do not sell your data. We do not share it for third-party marketing.
International transfers
Our core systems are hosted in the UK or EEA. Where data is transferred outside the UK (for example to a US-based cloud provider), we rely on the UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum.
How long we keep it
-
Clinical records, consent and treatment notes: 8 years from last treatment
-
Clinical photography: 8 years alongside the clinical record
-
Accident book entries: 3 years
-
Incident and adverse event records: 10 years
-
Marketing contacts: until you withdraw consent, with a 24-month reconfirmation cycle
-
Website analytics: as set in our Cookie Notice
-
Accounting records: 6 years (HMRC)
​
Full retention detail for employees, applicants and sponsored workers is set out in our internal Data Protection and Privacy Notice Policy, available on request.
Your rights
Under UK GDPR you have the right to:
-
Be informed (this notice)
-
Access your data (Subject Access Request)
-
Rectification of inaccurate data
-
Erasure, where the law allows (clinical records usually cannot be erased during the retention period for patient-safety and regulatory reasons)
-
Restriction and objection
-
Data portability for data you provided to us under contract or consent
-
Withdraw consent at any time where consent is the lawful basis
​
To exercise any right, email info@delightaesthetics.co.uk. We respond within one calendar month.
Cookies
We use strictly necessary cookies to make the site work and, with your consent, analytics and preference cookies. Details are in our Cookie Notice.
Data breaches
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where the risk is high, we will also notify you.
Complaints
If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow SK9 5AF
0303 123 1113 · ico.org.uk
Last updated: 23/04/2026