Privacy Policy
Last updated: May 2026
Website: www.bylois.co.uk
Business name: By Lois
By Lois (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, make a booking, or use our services.
1. Personal Data We Collect
We collect the following information:
A. Information You Provide
- Name
- Phone number
- Email address
- Booking details
- Treatment history
- Payment information (processed securely by third parties)
- Communication preferences
B. Data Collected Automatically
When you visit our website, we may collect:
- IP address
- Browser type
- Device information
- Cookies (see our Cookie Policy for details)
C. Payment Information
Payment data is not processed or stored by us directly. Instead, it is collected and processed securely by:
- Monzo
- SumUp
- LoPay
- Fresha Payments (if applicable)
These providers independently secure and process your data according to their own privacy policies.
2. How We Use Your Data
We use your data for the following purposes:
- Managing your bookings and appointments
- Processing payments (via Monzo, SumUp, LoPay, or Fresha)
- Maintaining treatment records
- Customer support and communication
- Sending appointment confirmations or reminders
- Improving our services and website performance
- Complying with legal and insurance obligations
- Marketing (only with your explicit consent)
3. Legal Basis for Processing
Under the UK GDPR, we rely on the following legal grounds:
- Contractual necessity – to fulfil your bookings and provide services
- Legitimate interests – to manage our business, improve services, and maintain records
- Consent – for marketing communications and certain cookies
- Legal obligation – for tax, audit, and insurance purposes
4. How Your Data Is Shared
We only share your data when necessary to run our business. Your information may be shared with:
A. Service Providers
- Fresha – bookings, client management, reminders
- Monzo, SumUp, LoPay – payment processing
- WordPress plugins (for site functionality only)
B. Legal or Regulatory Authorities
Only if required by law, insurance, safeguarding, or auditing obligations.
We do not sell or trade your personal information.
5. Data Retention
We keep your information only as long as necessary for the purposes described.
- Treatment records: up to 6 years (industry and insurance standard)
- Booking information: as long as you remain a client
- Payment records: as required by tax law
- Marketing consent: until you unsubscribe
6. Your Rights
Under data protection laws, you have the right to:
- Access your data
- Request correction of your data
- Request deletion (where legally allowed)
- Withdraw consent (e.g., marketing emails)
- Restrict processing
- Object to processing
- Request data portability
To exercise your rights, contact us using the details below.
7. How We Protect Your Data
We use a combination of physical, technical, and organisational measures.
These include:
- Secure booking system (Fresha)
- Encrypted payment systems (Monzo, SumUp, LoPay)
- Password-protected devices
- Secure website hosting
- Restricted access to client information
8. Children’s Privacy
Our colour services are not directed at children under 16.
We only collect child-related treatment information with the explicit consent of a parent or guardian.
9. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices.
10. Changes to This Privacy Policy
We may update this policy from time to time. The “Last updated” date will always indicate the latest version.
11. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact:
By Lois
Email: info@bylois.co.uk
Website: www.bylois.co.uk
Cookies Policy
This Cookie Policy explains how By Lois (“we”, “us”, “our”) uses cookies and similar technologies on www.bylois.co.uk (the “Website”).
Our Website is built on WordPress, which means some cookies are automatically placed to ensure proper functionality.
By using our Website, you agree to the use of cookies as outlined below.
1. What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help the site function, improve performance, and enhance your experience.
Cookies may be:
- Session cookies: removed when you close your browser
- Persistent cookies: remain until you manually delete them or they expire
2. Cookies We Use
A. Strictly Necessary Cookies
These cookies are essential for the Website to operate. They cannot be disabled through our cookie banner because WordPress needs them to work correctly.
These include:
1. WordPress Core Cookies (Required)
Used to maintain security, manage traffic, and enable essential features.
Examples:
- Cookies maintaining login sessions (for admin users)
- Cookies ensuring pages load correctly
- Cookies used for security and fraud prevention
2. Session Cookies (Enabled from May 2026)
These temporary cookies support core functions while you browse.
Used for:
- Keeping track of navigation during a single visit
- Maintaining temporary preferences
- Supporting forms and interactive elements
3. Security Cookies
These protect the website from malicious or suspicious activity.
Used for:
- Mitigating attacks
- Validating user actions
- Preventing unauthorised access to admin areas
B. Functionality Cookies (Enabled from May 2026)
These cookies allow the Website to remember your choices and improve your experience.
Examples:
- Remembering language or region
- Remembering cookie preferences
- Supporting video players, forms, comments, or plugins
- WordPress-specific features for layout and display
These cookies help personalise your visit but do not track you across other sites.
C. Performance & Analytics Cookies
If enabled, these help us understand how visitors use our Website so we can improve it.
Examples may include:
- Page visit statistics
- Time spent on the Website
- Browser and device information
D. Advertising & Third-Party Cookies
These cookies are only placed if you use third-party tools (e.g., Instagram feeds, embedded videos, ads, booking widgets).
They may collect data about your browsing activity across other sites.
If you integrate third-party services in future, they may place their own cookies.
4. How You Can Control Cookies
You can manage cookies through:
Browser settings
You can block, delete, or restrict cookies.
Most browsers allow you to:
- Block all cookies
- Block cookies from specific sites
- Delete existing cookies
Cookie Preferences
If our Website displays a cookie banner, you can adjust your preferences at any time by selecting:
“Cookie Settings”
Please note: Strictly Necessary cookies cannot be disabled, as the Website will not function without them.
5. Data Retention
- Session cookies: deleted automatically when you close your browser
- Persistent cookies: remain until expiry or manual deletion
- WordPress may set cookies lasting from a few minutes to up to 1 year, depending on the function
6. Updates to This Policy
We may update this Cookie Policy to reflect changes in technology, WordPress updates, or legal requirements.
The “Last updated” date at the top will always show the latest version.
7. Contact Us
For any questions about this Cookie Policy, please contact:
By Lois
Website: www.bylois.co.uk
Email: info@bylois.co.uk
