How BYOUTY LTD collects, uses and protects personal data
Last updated: 2 September 2026
This Privacy Policy explains how BYOUTY LTD processes personal data when you visit shop.byouty.uk, create an account, place an order, contact us, request product or trichology support, book an appointment or otherwise interact with us.
It is intended to provide the information required by the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and related UK data-protection legislation as amended from time to time.
BYOUTY LTD is the controller responsible for the personal data covered by this Policy.
BYOUTY LTD
Company number: 13643982
Registered office: Next To 54 College Road, Kensal Vintage Shop
London, England, NW10 5ET
Email: shop@byouty.uk
Website: https://shop.byouty.uk
Contact us at shop@byouty.uk for privacy questions, rights requests or complaints. We have not appointed a data protection officer because we do not currently consider one legally required.
This Policy covers the Website, online shop, account area, contact forms, order and return communications, delivery administration, customer support and connected appointment or communication services used by BYOUTY. Separate third parties may act as independent controllers under their own privacy notices.
Depending on how you interact with us, we may collect:
We collect personal data directly from you when you register, order, communicate, return goods, request an invoice, book or attend a consultation, submit a review or provide product-safety information. We also collect data automatically through the Website and may receive limited information from payment providers, Royal Mail or other couriers, appointment providers, fraud-prevention services, analytics services and social or review platforms.
We process personal data only where we have a lawful basis. The main purposes and bases are:
Registration may create an account, temporary password, password-setting link or automatic authenticated session. We process username, email, security and session data to provide restricted price access, maintain the account and protect the Website. Passwords are stored in protected hashed form rather than as readable text.
We may use the registration email to send necessary service information, including account security, password, product-use instructions relevant to the requested service, order administration and the availability of requested support. We will not treat a necessary service email as consent to unrelated marketing.
Order data is used to take payment, assess fraud risk, confirm and fulfil orders, issue tracking, provide support, process returns and maintain financial records. Payment methods shown at checkout are provided by third-party payment processors that receive the information necessary to authorise and settle payment. Their handling of card or wallet data is governed by their own privacy information.
We may review unusual ordering patterns, repeated claims, payment failures, chargebacks, account activity and delivery information to prevent fraud and protect customers and BYOUTY. We do not currently make decisions producing legal or similarly significant effects solely by automated means without appropriate safeguards.
We share necessary recipient, address, contact, parcel and tracking information with Royal Mail or another selected carrier. For international delivery, information may be disclosed to postal operators, customs authorities, freight or clearance providers and destination carriers, including outside the United Kingdom.
You must provide accurate delivery and customs information. Carrier tracking and delivery data may be returned to us so that we can administer the order and investigate loss or delivery disputes.
When you contact us by form, email or WhatsApp, we process the details and content of the communication to respond, keep an appropriate record and protect legal rights. WhatsApp is provided by a Meta group company and may process account, device and communication metadata under its own terms and privacy notice.
Do not send more personal or sensitive information than necessary. We may move a conversation to email or another appropriate channel where this better protects privacy or creates a reliable record.
A message about hair loss, alopecia, allergies, irritation, scalp conditions, medication or health history may reveal special-category health data. Please do not include health information in a general shop message unless it is necessary for the support or consultation you request.
Where you intentionally provide health-related information for a trichology enquiry or product-safety report, we will use it only for the relevant request, safety assessment, referral or legal obligation. Where required, we will ask for explicit consent or identify another lawful Article 9 condition before further processing. Information may be shared with the selected trichology professional or product-safety recipient only where necessary and with appropriate safeguards.
Online product or trichology communications are not emergency or medical services. Do not submit urgent medical information through the Website.
If you request or book an appointment, consultation or related service, relevant contact, booking and service information may be processed through Fresha or another scheduling provider. That provider may act as our processor for some functions and as an independent controller for its own platform operations. Its own privacy notice also applies.
We will not add shop customers to an appointment platform merely because they purchased a product unless this is necessary for a service they requested or another lawful basis applies.
We process product, order, contact, photographic, batch and incident information to investigate defects, adverse reactions, safety concerns and recalls. Where necessary, we may disclose limited information to the manufacturer, Nubea, the UK Responsible Person, importer, distributor, insurer, professional adviser or competent authority.
We do not routinely provide customer data to Nubea for marketing or ordinary sales administration. A safety-related disclosure will be limited to what is reasonably necessary or legally required.
The Website uses cookies and similar storage or access technologies. These may include:
Where the law requires consent, non-essential technologies should not be used until consent is obtained. Certain limited statistical technologies may be used without consent where the legal statistical-purpose exception applies, clear information is provided, data is appropriately aggregated and a simple free means of objection is available. You can also control cookies through browser settings, although disabling essential cookies may prevent account or checkout functions.
BYOUTY does not currently treat account registration or purchase as automatic consent to newsletters or WhatsApp marketing. If marketing is introduced, we will use consent or the limited existing-customer exception only where its legal conditions are met and will provide an easy opt-out in each electronic message.
You may withdraw marketing consent or object at any time by using the unsubscribe method provided or contacting shop@byouty.uk. We may keep a minimal suppression record so that your preference is respected.
We may share personal data, only as necessary, with:
Service providers are required to protect data and use it only for authorised purposes where they act on our behalf. Some recipients act as independent controllers and provide their own privacy information.
Some providers, carriers or recipients may process personal data outside the United Kingdom, including in the European Economic Area, the United States or the delivery destination. Where UK data-protection law requires safeguards, we rely on an adequacy regulation, the UK International Data Transfer Agreement or Addendum, approved contractual safeguards, or another lawful transfer mechanism. You may contact us for information about the applicable safeguards.
We keep personal data only for as long as reasonably necessary for the purposes described, including legal, accounting, safety and dispute requirements. Our current retention criteria are:
We use reasonable technical and organisational measures designed to protect personal data, including access controls, account authentication, restricted administrative access, payment-provider separation, backups and security monitoring appropriate to the nature of the data. No internet service is completely secure, and you are responsible for protecting your password and devices.
Access is limited to BYOUTY personnel, authorised fulfilment support and service providers who need it for their role. If we become aware of a personal-data breach, we will assess and notify the Information Commission and affected individuals where legally required.
Depending on the circumstances, UK data-protection law gives you the right to:
Rights are not absolute and exemptions may apply. To make a request, email shop@byouty.uk. We may ask for proportionate identity verification. We normally respond within one month, subject to lawful extensions for complex or multiple requests.
You may ask us to close your account by emailing shop@byouty.uk. Closing an account does not require deletion of order, payment, tax, product-safety or dispute records that we must or may lawfully retain. Where possible, non-essential account data will be deleted or anonymised.
Please contact shop@byouty.uk first if you have a concern about our use of personal data. We will acknowledge a data-protection complaint within 30 days and respond without undue delay, taking into account its nature and complexity.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Information is available at https://ico.org.uk. If you live outside the UK, you may also have a right to contact your local data-protection authority.
The Website account and checkout are intended for adults aged 18 or over. We do not knowingly create shop accounts for children. If a product is purchased for a child, the adult purchaser is responsible for checking the label, ingredients, age suitability and instructions. Contact us if you believe a child has provided account data without appropriate authority.
The Website may link to Nubea, social networks, review platforms, payment services, Fresha or other third parties. We do not control their independent processing. Review their privacy notices before providing data directly to them.
We may update this Policy to reflect legal, technical or business changes. The current version will be published on the Website with a revised date. Where a change materially affects how we use existing data, we will provide additional notice or seek consent if required.