Legal
Privacy Policy
What we collect, why we collect it, who processes it for us, and what you can ask us to do about it.
Last reviewed 29 August 2026
Who controls your data
AuraLuxe Professional Beauty Studio & Academy, Unit 1, The Mall, Riverside Way, Midleton, Co. Cork, Ireland, is the data controller for personal data collected through this website and in the studio. You can reach us about any privacy matter, including a data request, at alexis@auraluxe.ie.
What we collect and why
We collect only what a particular purpose needs, and each form on this site tells you what it is for before you send it.
- Enquiries, contact messages, Interest List entries and VTCT upgrade requests: your name, contact details and what you asked about, so we can reply and, where relevant, quote.
- Studio appointments: your name, contact details, the services requested, appointment times and deposit status.
- Client consultation and treatment records: your consultation answers, treatment consent, patch-test details (product and brand, batch or lot where available, method and site, the date and time, the manufacturer interval followed, the result and any reaction and action taken), treatment notes and aftercare given.
- Health and suitability information: allergies, medication, medical conditions, pregnancy or breastfeeding, skin and eye conditions and contra-indications. This is special-category health data and is held in a separate, restricted record.
- Guardian information where a client aged 16 or 17 is treated with guardian consent: the guardian's name, relationship and contact details.
- Learner records: enrolment details, course and route, dates and attendance, assessment and certification records, kit choices, model and patch-test guidance acknowledgements and learner declarations.
- Payment records: amounts, currency, product, payment status and payment references. We never see or hold your full card number or security code.
- Account records: your profile name, email and phone if you create an account, and your role on the site.
- Marketing preferences: whether you opted in, when, and whether you later opted out.
We do not sell personal data, and we do not use it for automated decision-making or profiling.
Our lawful bases
- Contract and steps before a contract: answering enquiries, arranging appointments, delivering training, taking payment and administering your course.
- Legal obligation: keeping financial and tax records, and meeting our obligations under consumer and data protection law.
- Legitimate interests: keeping accurate service, safety and claims records, preventing fraud and misuse of our forms, and keeping our own accountability records. We balance this against your interests and keep the data to what those purposes need.
- Consent: marketing, and the processing of health and suitability information you give us for a consultation.
Where we rely on consent you can withdraw it at any time, and withdrawing it does not affect anything we did lawfully beforehand.
Health information
Health, medical, contra-indication, allergy, medication, pregnancy and patch-test information is special-category data under Article 9 of the GDPR. Ordinary treatment consent and marketing consent are not enough to process it. Where you give this information through this website, we ask for a separate, explicit, never pre-ticked consent for the specific purpose of checking whether a treatment is safe and suitable for you, carrying it out safely, and keeping the treatment and patch-test record our insurer requires. We record which version of that consent wording you agreed to and the time you agreed.
We hold health information in a restricted record that only AuraLuxe staff and administrators can see. It is never used for marketing, and learners assisting on a supervised model treatment are not given access to client health records.
If you would prefer not to give the health information a treatment needs, we may be unable to carry that treatment out safely and may have to decline or adapt it. Please do not put medical details into a general notes or message box — we will ask for them on a consultation form so they are kept in the protected record.
Where a different Article 9 condition applies in the studio rather than explicit consent, we record which condition we relied on for that record.
Marketing
Marketing is always separate and optional. Sending an enquiry, attending a consultation or enrolling on a course never signs you up. If you opt out we keep the minimum record needed to keep that opt-out working, so you are not contacted again by mistake — we do not delete a suppression entry just because a marketing consent was withdrawn. To opt out, email alexis@auraluxe.ie or use the unsubscribe link in any marketing email.
Who processes data on our behalf
We use a small number of service providers, each for a defined purpose and under their processing terms:
- Website and database hosting, which stores the records described above.
- Stripe, which processes card payments. Stripe handles card details directly; we receive only the payment result and reference.
- Transactional and business email providers, used to send confirmations and to receive and answer your messages.
- Google Workspace and Google Drive, where we hold operational records such as consultation and course administration files.
- Awarding and accreditation bodies, where registration, assessment or certification on a qualification route requires your details to be shared.
- Professional advisers and insurers, where genuinely necessary — for example a claim, a complaint or a legal obligation.
Where a provider processes data outside the European Economic Area, we will use a lawful transfer mechanism and rely on that provider's safeguards as required by the GDPR, and we maintain an internal register of the processors we use. The exact transfer documentation for each provider is being confirmed as part of our ongoing review, and we will state it here once it is verified rather than describe arrangements we have not checked.
How long we keep it
These periods are AuraLuxe policy choices based on our risk, insurance and accreditation obligations, except where a statutory period applies. They set the point at which a record is reviewed, not an automatic deletion.
- Enquiries, contact messages and unanswered or closed Interest List entries: reviewed 12 months after our last meaningful contact, then deleted or anonymised unless they became a client or learner relationship or are needed for a live dispute.
- Client consultation, health and suitability, treatment consent, patch-test and treatment records: 6 years after your last relevant treatment, as a risk, claims and insurance policy, and longer if an insurer requires it.
- Records of anyone treated while under 18: not deleted before their 21st birthday, and only reviewed after that. This is a deliberately conservative safeguard.
- Learner enrolment, attendance, assessment, certification and payment-linked records: reviewed 6 years after completion or withdrawal, and kept longer where an accreditation or awarding-body requirement (for example ABT, VTCT, internal or external quality assurance) needs them. Certificate identifiers may be kept longer where that is needed to verify a qualification.
- Financial, payment and tax records: 6 years, consistent with Irish Revenue record-keeping requirements.
- Consent evidence: while the consent is active and for 6 years after it is withdrawn or changed, so we can show what was agreed. Withdrawals are added as new entries and never overwrite the original record.
- Marketing opt-out records: kept until you positively opt back in or the address is no longer relevant.
- Account and profile data: while your account is active; after closure we keep only what another retention period still requires and delete or anonymise the rest.
- Data rights requests and breach records: 6 years, as an internal accountability policy.
Nothing is deleted automatically. A retention period sets the date we review a record, and a legal, insurer or awarding-body hold prevents deletion until that hold is lifted, so every deletion or anonymisation is a deliberate, recorded decision.
Your rights
You have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on it. Email alexis@auraluxe.ie with what you would like and we will respond within one month. We may ask you to confirm your identity before releasing personal data, and we will tell you if an exception applies — for example where an insurer, awarding body or legal obligation requires us to keep a record.
If you are unhappy with how we handle your data you can complain to the Data Protection Commission at dataprotection.ie, or by post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28. You can also take a case to court.
We keep an internal record of every data request and of any personal-data breach, including whether the Data Protection Commission had to be notified.
Nothing in this policy limits or removes your statutory rights under Irish and EU consumer law, including your rights under the Consumer Rights Act 2022 and the General Data Protection Regulation. Where anything here conflicts with those rights, your statutory rights prevail.
Who we are
AuraLuxe Beauty StudioUnit 1, The Mall, Riverside Way, Midleton, Co. Cork, Ireland
alexis@auraluxe.ie
We have not published a company registration or VAT number on this page. Where one applies it will be added here rather than assumed.
