your data, your rights

Privacy Policy

Last updated: March 2026

1. Introduction

Annayah Aesthetics ("we", "our", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website, book treatments, or interact with our services.

We are based at Floatspa, 125 Church Road, Brighton and Hove, BN3 2AN, and operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data We Collect

We may collect the following personal data when you use our website or services:

Contact information: your name, email address, telephone number, and postal address when you enquire about or book treatments.

Consultation data: information you provide during consultations, including skin concerns, medical history, and treatment preferences.

Payment information: payment details processed securely through our payment provider (GoCardless). We do not store your full card or bank details on our systems.

Website usage data: information about how you use our website, including pages visited, time spent, and referring sources, collected through analytics cookies.

Newsletter subscriptions: your email address when you subscribe to receive our Longevity Guide or marketing communications.

3. How We Use Your Data

We use your personal data for the following purposes:

To process and manage your treatment bookings and consultations.

To communicate with you about your appointments, treatment plans, and aftercare.

To process payments securely through GoCardless.

To send you marketing communications where you have given consent, including our Longevity Guide and treatment updates.

To improve our website and services through anonymised analytics.

To comply with legal and regulatory obligations.

4. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR:

Consent: when you subscribe to our newsletter, download our Longevity Guide, or accept non-essential cookies.

Contractual necessity: when we process data to fulfil treatment bookings and consultations you have requested.

Legitimate interest: when we use anonymised data to improve our website and services.

Legal obligation: when we are required to retain records for regulatory compliance.

5. Cookies

Our website uses cookies to ensure it functions properly and to help us understand how visitors interact with our content. We use two types of cookies:

Essential cookies: these are necessary for the website to function correctly, including session management and security. They cannot be disabled.

Analytics cookies: these help us understand how visitors use our website so we can improve the experience. Analytics cookies are only set when you give your consent through our cookie banner.

You can change your cookie preferences at any time by clearing your browser cookies and revisiting our site.

6. Data Sharing

We do not sell your personal data to third parties. We may share your data with the following trusted partners only as necessary to deliver our services:

GoCardless: for secure payment processing.

Randox Health: for blood diagnostic testing, where you have consented to this service.

Brighton Bio Labs: our partner for bio-optimisation services, where relevant to your treatment plan.

All third-party partners are required to process your data securely and in accordance with UK data protection law.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Treatment records are retained for a minimum of 8 years in accordance with healthcare record-keeping requirements. Marketing consent records are retained until you withdraw your consent.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of access: you can request a copy of the personal data we hold about you.

Right to rectification: you can ask us to correct any inaccurate or incomplete data.

Right to erasure: you can request that we delete your personal data, subject to legal retention requirements.

Right to restrict processing: you can ask us to limit how we use your data.

Right to data portability: you can request your data in a structured, commonly used format.

Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, please contact us at [email protected].

9. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. All data transmitted through our website is encrypted using SSL/TLS technology. Payment processing is handled by PCI-compliant third-party providers.

10. Contact & Complaints

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Email: [email protected]

Phone: 07795 841 981

Address: Floatspa, 125 Church Road, Brighton and Hove, BN3 2AN

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.