Book in
Legal

Privacy policy

Last updated 25 September 2026. Dr Band Clinic Limited.

This notice explains what Dr Band Clinic Limited does with personal information about you, why, how long we keep it, who else sees it, and what you can ask us to do. It covers this website, our booking system, WhatsApp and email, and the clinic itself.

Who we are

Dr Band Clinic Limited, trading as SkinBros, is the controller of the personal information described here. Registered in England and Wales, company number 13170629. Registered office: 6 Glebe House, Cross Lanes, Guildford, England, GU1 1SX. The clinic is at 5 Goodge Place, London W1T 4SD.

For anything about your information, email [email protected]. We are a small clinic and are not required to appoint a data protection officer; that inbox reaches the person responsible.

What we collect, why, and on what basis

When you book

Your name, mobile number and email address, the treatment and time you booked, anything you type in the notes box, and, if you choose to tell us, how you heard about us. We use it to hold your appointment, send your confirmation and a reminder, let you move or cancel, and contact you about your visit.

The lawful basis is that you have asked us to book you in (UK GDPR Article 6(1)(b)). Because the treatment you book says something about your health, we treat the booking as health information too, and hold it under Article 9(2)(h): the provision of health care by, or under the responsibility of, a health professional bound by confidentiality (Data Protection Act 2018, Schedule 1, paragraph 2). Please keep medical details out of the notes box; the doctor goes through them with you in person.

When you come in

Your medical history, medication and allergies, what the doctor assesses and advises, what is done (including the product and its batch number), your consent, and clinical photographs. This is health information. We need it to treat you safely and we are professionally and legally required to keep an accurate record. The lawful bases are Article 6(1)(b) and 6(1)(c), and Article 9(2)(h). It is held in our clinical records system , not on this website.

Clinical photographs are part of your record. They are never used for marketing unless you have signed a separate consent for that specific use, and you can withdraw that consent at any time for anything not yet published.

When you pay

The amount, the date and the payment method. Card details go to the card terminal provider in the clinic, or to Stripe if you pay online when you book, not to us, and we never see a full card number. We keep payment records because tax law requires it (Article 6(1)(c)).

When you contact us

If you message us on WhatsApp, email us or use a form on this site, we keep what you send so we can reply and deal with it. The basis is our legitimate interest in answering you (Article 6(1)(f)), or taking steps you have asked for (Article 6(1)(b)). WhatsApp is run by WhatsApp Ireland Limited (part of Meta) under its own privacy terms; please keep medical details and photographs for your appointment rather than sending them by message.

Marketing

We only send you marketing if you ticked the box to say yes, and every message has a one-click way to stop. The basis is your consent (Article 6(1)(a) and the Privacy and Electronic Communications Regulations). Saying no has no effect on your booking or your care.

When you use this website

  • Your cookie choice is remembered on your device so we stop asking. That is strictly necessary for the banner to work.
  • Advertising identifiers. If you arrive from an advert, the address carries a click identifier and campaign tags. We only store these on your device if you accept advertising cookies, and we remove them if you refuse. If you book without accepting, the identifiers in the address of the page you book on are attached to your booking so we know which advert brought you, and are not stored on your device.
  • Analytics and advertising cookies (Google Analytics, the Google Ads tag and the Meta pixel) load only if you accept them, and nothing from a third party loads before you choose. They never load on the booking pages, whatever you choose, so what you book is never passed to Google or Meta. The basis is your consent, and you can change your mind at any time from the cookie link at the bottom of every page. The cookie page lists each one.

Keeping you and others safe, and legal claims

We may use your information to check you are 18 or over (we may ask for identification), to deal with a complaint or a legal claim, or where the law requires it. The bases are Article 6(1)(c) and 6(1)(f), and for health information Article 9(2)(f) (legal claims).

What you have to give us

To book, we need your name, a mobile number and an email address. To treat you, we need an honest medical history: without it the doctor cannot treat you safely and will not go ahead. Everything else is optional.

Who else sees it

We share only what each needs, and each works under a written agreement or its own legal duties.

  • Cloudflare hosts this website and our booking system, which is stored in its Western European region.
  • Resend sends your booking confirmation and reminder emails.
  • Our clinical records system provider holds your clinical record.
  • The card terminal provider processes your payment in the clinic.
  • Stripe processes your payment if you pay online when you book, including any refund. It receives your email address, the amount and the treatment you are paying for, and nothing from your medical history.
  • Google and Meta, only if you accept analytics or advertising cookies, and only what those tags collect.
  • WhatsApp (Meta), if you choose to message us there.
  • Our accountants, insurers and professional advisers, where they need it to do their job, under a duty of confidentiality.
  • Your GP or another health professional, only with your agreement, unless there is an urgent risk to your health.
  • Regulators, the courts or the police, where the law requires it. We will tell you unless the law prevents us.

We do not sell personal information, and we never will.

Where it is held

Our booking data is stored in the European Economic Area. Some providers are based in, or support their service from, the United States. Where information leaves the UK, it goes only to a country the UK recognises as adequate, to a US company certified under the UK-US data bridge, or under the Information Commissioner's International Data Transfer Agreement or Addendum.

How long we keep it

  • Clinical records, including photographs and consent forms: 8 years after your last treatment, in line with professional guidance for adult records, or longer if there is a complaint or claim still open.
  • Bookings you attended: kept with your clinical record for the same period.
  • Bookings that never led to a visit, and enquiries: 12 months, then deleted.
  • Payment and tax records: 6 years after the end of the financial year, as tax law requires.
  • Marketing consent: until you unsubscribe, and a record that you did so, so we never message you again.
  • Website analytics: up to 14 months. Advertising identifiers: up to 90 days.

Your rights

You can ask for a copy of your information, ask us to correct it, delete it, or restrict what we do with it, object to anything we do on the basis of legitimate interests, and ask for information you gave us in a portable form. Where we rely on your consent, you can withdraw it at any time; that does not undo what was lawful before. We do not make decisions about you by automated means. Email [email protected] and we will reply within one month.

Some rights work differently for clinical records: we cannot delete a record we are required to keep, but we will correct anything inaccurate and explain what we can and cannot do.

If you are unhappy with how we have handled your information, complain to us first at [email protected]: we will acknowledge your complaint within 30 days and tell you what we are doing about it. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Security

Access to our booking and clinical systems is limited to the people who need it, through individual accounts, and is logged. Information travels over encrypted connections. We only treat adults, and we do not knowingly collect information about anyone under 18.

Changes

If we change this notice we will update the date at the top, and if the change matters to you we will say so on the site.