Untitled 4

SOU respect your privacy.

We are committed to protecting your Personal Data. This privacy policy explains how and why we use your Personal Data.

Purpose of this Privacy Policy

This privacy policy aims to give you information on how we collect and process your Data when using SOU website and when you interact with SOU via email, letter or social media. 

Salon Owners United is accessible to UK salon owners only and is not intended for use by children.

It is important that you read this privacy policy in conjunction with other notices and policies. If you are directed to a third-party website, the terms of their privacy policy will apply.

This privacy policy aims to give you information on how SOU collects and processes your Personal Data.

Data Privacy

Salon Owners United is the controller of data for the purposes of the data protection legislation.

Changes to this Privacy Notice and your duty to inform us of changes

We keep this privacy policy under regular review. This version was last updated 1st November 2024

It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us by email to hello@sou.org.uk

Identity and contact details of the data privacy team

If you have any concerns as to how your data is processed, or if you have any questions about this privacy policy or our privacy practices more generally, you can contact our data privacy team via email at hello@sou.org.uk Please mark Privacy Policy in your subject header. 

FAQs

Who does this policy relate to?

  • Members and prospective members,

  • Email subscribers,

  • Individuals, sole traders, partnerships, and companies,

  • Businesses we wish to promote products and services to,

  • Individuals who contact us on social medial,

  • Individuals who visit our website.

  • Individuals already signed up to our legacy Facebook or other social sites. 


    Under exceptional circumstances where adjustments to normal processes may be required, individuals who have responsibility for managing, or being a point of contact, for another individual member.

_______________

What data do we collect?

We only collect data that is catagorised as essential to manage your membership.

Personal data means any information about an individual person who can be identified from that information, or from other information we hold or could reasonably hold in the future. It does not include data where the identity has been removed (anonymous data). We only collect Personal Data relevant to your SOU membership the types of data we collect, use, store and transfer are:

  • Identity Data such as title, first name and last name,

  • Contact Data includes billing address, business address, email address, social media handles and telephone numbers,

  • Financial Data includes bank account and payment card details, this is via our (Stripe system only)

  • Membership Data includes details about payments to and from you and other details of products and services you have purchased,

  • Technical Data includes internet protocol (IP) address, your login data, browser type and versions, operating system and platform and other technology on the devices you use to access this website,

  • Profile Data includes your username and password, your interests with regard to SOU activity, preferences, feedback, and survey responses,

  • Usage Data includes information about how you use our website, products, and services,

  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use, and share aggregated data such as statistical or demographic data which does not identify you. If however we combine or connect aggregated data with your Personal Data so that it can directly or indirectly identify you, we will treat that combined data as Personal Data which will be used in accordance with this privacy policy.

We do not collect Personal Data relating to your race or ethnicity, religious or philosophical beliefs, sex life, or sexual orientation, however, it may in some circumstances be necessary.  However, sometimes There may be occasions where Special Categories of Personal Data are collected at or during an SOU event or survey we will explain to you when we do this, why it is needed, and it will be your choice whether to provide it.

_______________

If you do not provide or keep us updated on changes to your data

Where we need to collect Personal Data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or intend to have with you e.g. to provide you with goods or services. In cases like this, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.

_______________

How is your data collected?

We use different methods to collect data from and about you including through:

  • Direct interactions – You may give us your identity, contact and financial data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes Personal Data you provide when you:

    • apply for membership,

    • express an interest in membership,

    • subscribe to email communications as a non-member,

    • request information about SOU 

    • attend an SOU event,

    • complete an industry survey

    • contact any member of the SOU team

  • Automated technologies or interactions – As you interact with our website, and receive our marketing emails, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this information by using cookies and other similar technologies. For more information on the cookies we use and how you can control your cookie preferences see our Cookie Policy.

  • Third parties or publicly available sources – We may receive Personal Data about you from various third parties and public sources as set out below:

    • Technical data from the following parties:

      • analytics providers, such as Google based outside the EU,

      • search information providers, such as Google based outside the EU,

    • Identity, contact and financial data from partners ( see partnership page for details of who we partner with)

    • Contact, financial and transaction data from providers of technical, payment and delivery services,

    • Identity, contact, business and financial data from data brokers or aggregators based inside the UK,

    • Identity and contact data from publicly available sources such as the Electoral Register based inside the UK, ( this is to provide lookup for any address) or Companies House to validate your membership. 

    • Identity and contact data where you have made information available in the public domain including posting on one of our social media pages such as Facebook, Twitter or LinkedIn depending on your settings or the privacy policies of these social media and messaging services,

Other data which may relate to, or identify you, that is provided by a third party and not explicitly requested by SOU

_______________

How is your data used

We will only use your data in circumstances where the data protection legislation allows us to. Most commonly, we will use your Personal Data in the following circumstances:

  • Where we need to perform a contract we are about to enter into or have entered into with you,

  • Where it is necessary for your or our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests,

  •  Where we need to comply with a legal obligation, or where we have received your information and specific consent to do so.

Below is a description of all the ways we plan to use your Personal Data, and which of the legal bases we rely on to do so, we have also identified what our legitimate interests are where appropriate.

Note in some cases we will;

  • process your Data on more than one lawful ground depending on the specific purpose for which we are using your data, or

  • process your Data without your knowledge or consent;  in compliance with this policy and where this is required or permitted by law.

Consent 

Where you have provided specific consent, we will rely on that to process your information for the purposes set out at the time that the request for consent was made. This includes:

  • As a member or account holder, to provide you with:

    • Information about membership benefits,

    • Local news and events,

    • Policy, lobbying and campaign activity,

    • First Voice magazine, emails, and webinars.

  • As a subscriber, to issue you with information about FSB activities and services,

  • As a non-member, to provide you with information about our activities, membership and services,

  • As the subject of an FSB case study.

  • To promote the work of FSB and the contribution of small businesses to the UK economy.

All marketing communications will contain an unsubscribe option however you may change any of your consent preferences at any time by contacting us on 0808 20 20 888, by email to customerservices@fsb.org.uk, or by setting your preference choices by logging into the FSB website.

Performance of a Contract or in readiness of such contract

The main purpose for which we process your Personal Data is so that we can provide you with products and services in accordance with the relationship/membership you have with us.

We process your data to deliver services to you in the following ways:

  • To register you as a member or subscriber,

  • To process your membership renewal,

  • To deliver membership support,

  • To provide you with account management functionalities (such as to update your contact information),

  • To process and collect payments,

  • To notify you of changes to our terms or privacy policy,

  • To administer events and to register you as an attendee or applicant,

  • To ask you to leave a review,

  • To enable you to partake in or complete a survey,

  • To process, verify and validate nominations and voting for an FSB volunteer office,

  • To vote in the Annual General Meeting.

Legal Obligation 

As an organisation we have various regulations and legal obligations we must comply with:

  • Notifying you of changes to our terms and this privacy policy,

  • To administer and protect our business, and this website (including troubleshooting, data analysis, testing, system reporting and hosting of data),

  • Maintaining accounting and invoicing records.

Legitimate Interests 

Where we, or a third-party, have a legitimate interest, ensuring that those interests are balanced against your data and privacy rights and freedoms.  This includes:

  • Email updates to all members

  • Asking you to take part in research or industry surveys to:

    • allow us to develop our goods and services in line with members' business needs, and

    • enable us to keep you updated on industry and SOU news

    • Lobby to UK Government along with partner organisations for change to policy to benefit SOU members

  • To provide you with updates relating to:

    • The products and services available to you,

    • SOU membership benefits,

    • Local news and events,

    • SOU Policy, lobbying and campaign activity,

    • SOU publicity material, CEO newsletters and Salon CEO magazine
      where we do not have your explicit consent, and have offered you the opportunity to opt-out

  • Using data analytics to;

    • improve our websites and any mobile app

    • to keep our websites updated and relevant,

    • monitor customer relationships and experience,

    • understand engagement with our marketing communications and events,

    • understand usage of our products and services, to update, improve services offered

    • define and measure types of businesses that may benefit from our products and services and develop our marketing strategy.

  • Delivering a personalised approach to our website functionality and content, to provide you with information that is relevant to you and your salon to improve your SOU membership experience.

  • Using photographs of virtual and physical events to promote salon businesses and SOU, by sharing on SOU social channels and within marketing materials.

Where we have identified a legitimate such as:

  • Providing accessibility functions on our websites and apps which you may turn on or off from our websites and apps displayed on your screen.

We will only use your data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason, and that reason is compatible with the original purpose.  If we need to use your data for an unrelated purpose, we will notify you in advance, explaining what we intend to do and providing you an opportunity to object.

Opting out

All marketing communications will contain an unsubscribe option however you may change any of your consent preferences at any time, by email to hello@sou.org.uk or by setting your preference choices by logging into the SOU website.

If you are a member of SOU, please be aware that when you opt out of receiving marketing messages, we will still use those channels to communicate with you in respect of your membership where there is a legitimate business interest regarding the functionality of your membership. 

Cookies

You can use this link to manage your cookies preference for this website.

Alternatively, you can set your browser to block cookies, please check your browser for instructions on how to do this. The effect of disabling cookies depends on which cookies you disable but, in general, the website may not operate properly if all cookies are switched off.

For more information about the cookies we use, please see our Cookie Policy.

Third-party links

SOU websites may include links to carefully selected third-party providers, websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third-parties to collect or share data about you. We do not have control of third-party websites and are not the legal owners or responsible for their privacy statements. When you leave our websites, we encourage you to read the privacy policy of any website you visit.

_______________

Sharing of data

We may disclose your personal information to other carefully selected third-party partners in the following circumstances:

  • When you have requested information about a service or product provided by a third-party service provider and only with your specific consent,

  • When you are a member you may wish other members to be able to contact you

  • External suppliers who provide and/or help us operate our IT systems.  We will only do this subject to strict contractual obligations and ensure the continued security of your information,

  • Financial organisations for purposes such as payment processing, and refunds under the performance of or in readiness of a contract with you,

  • Third-parties that subsidise your membership,

  • To marketing providers carrying out marketing activities on our behalf.  

  • When we are providing a service on your behalf. This data will be collected through online application forms, which are to be completed voluntarily and will only be shared with the organisations identified at the time it is requested.

When we share your Personal Data with any third party, we enter into a contract with them requiring strict adherence to our policies and ensuring your Personal Data is kept secure, is only used for clearly  defined purposes, and are then deleted in accordance with our data retention requirements.

_______________

How is data stored

SOU uses a number of systems to store data, both “on-premise” and in the “cloud”.  SOU are in full control of both physical and logical access to all on-premise systems, and it is our policy

For security reasons, we do not publicly name our IT infrastructure and security partners or the locations of our Data Centre operations.

  • All reasonable and appropriate security measures to protect your Data from unauthorised loss, damage or use, and we limit physical and logical access to only those employees, agents, contractors and other approved third parties, who have a necessary and justifiable need as part of their role.  Your Data will only be processed under our direct instruction and subject to a duty of care and confidentiality commensurate with our policies and procedures.

  • Procedures to detect and deal with any suspected (or actual) data security incident and where we are legally required to do so, will notify you and any applicable regulator of any such incident within 72 hours of becoming aware of it.

_______________

How long is data held

We will only retain your Personal Data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

  • As a Member:-  we will retain your Personal Data for as long as you are a member.
    After your membership ceases, your member account will be converted to that of an archived member/account holder

  • As an Account Holder, we will retain your data for up to 24 months after you last engage with us or until you unsubscribe from any further communications.
    If you were previously a Member, or an Account Holder who has engaged with SOU for a paid service or event, we are required for Accounting and Taxation purposes, to retain basic information (contact, identity, financial and transactional data) about you for up to seven years from the date your membership ceased or that transaction took place.

  • As a subscriber, we will retain your data until you unsubscribe from any further communications.

In all cases where unsubscribe, or exercise your right to object or erasure, we will retain indefinitely, sufficient data to enable us to identify you within any data we hold, or might obtain, in order to respect your choice to unsubscribe, object or be erased.  This will include your name, salon name, postal address, email address and telephone number.  Other Personal Data we hold about you will be anonymised and retained for our historic analysis purposes.

_______________

The legal bits

Under the data protection legislation, are provided a number of rights with regard to your Personal Data.  Depending upon the specific purpose for our processing your data, you may exercise your rights as follows:

Request access to your Personal Data (commonly known as a ‘data subject access request’). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it. ( a charge will be applied for supplying SAR at £25, which is payable on request, SAR will be processed within 90 days of request)

Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request the erasure of your Personal Data. This enables you to ask us to delete or remove Personal Data where you consider that there is no lawful reason for us to continue to process it. You also have the right to ask us to delete or remove your Data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to the processing of your Data where we are relying on a legitimate interest, or those of a third party, and where there is something about your particular situation which makes you want to object to processing on these grounds, as you feel it impacts negatively on your fundamental rights and freedoms.

You also have the right to object where we are processing your Personal Data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of the processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data where the following applies:

  • If you want us to establish your data’s accuracy,

  • Where our use of the data is unlawful, but you do not wish us to erase it,

  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims,

  • You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.

Request to transfer your Data to you or to a third party. We will provide to you, or a third party you have chosen, your Data in a structured, commonly used, machine-readable format. Note that this right only applies to information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

AllrightsSOU© 2024