Looking for corporate hair wellness advice? Visit our B2B Portal
UK GDPR, DPA 2018 & PECR

Privacy Policy

Last Updated: August 2026

Rootli Group Ltd (Company No. 14167623, London, United Kingdom) is the data controller for personal data processed through rootli.co.uk. We are committed to protecting your privacy in full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR).

Data Controller & Regulatory Information

Rootli Group Ltd is registered as a Data Controller with the UK Information Commissioner’s Office (ICO) under registration number ZC223001.

ICO Data Protection Registration: ZC223001

Data Protection Contact: privacy@rootli.co.uk

Supervisory Authority: Information Commissioner’s Office (ICO), United Kingdom — ico.org.uk

01What We Collect

  • Clients: name, email address, mobile phone number, city/postcode, booking history, communication logs, written reviews, and consent records.
  • Independent Specialists: profile details, professional bio, specialties, service pricing, calendar availability, portfolio photographs/videos, public liability insurance documents, and business verification details.
  • Workspace Hosts: studio name, physical address, chair capacity, amenities, and listing media.
  • Payment & ID Verification Data: debit/credit card details, bank account numbers, and government-issued IDs are processed directly by Stripe via encrypted iFrames and APIs. Rootli never stores or has direct access to full raw card numbers or unencrypted ID documents.
  • Technical & Device Data: IP address, browser type, operating system, and essential session logs. Non-essential analytics cookies are processed only with your prior consent.
  • Age Limit: Rootli is intended exclusively for individuals aged 18 and over (or 16+ where accompanied by an adult). We do not knowingly collect personal data from children.
Special category data (Article 9 UK GDPR)

Allergy patch test confirmations, skin sensitivity disclosures, and hair diagnostic notes are classified as special category health data. We collect this only with your explicit consent prior to chemical or colour treatments, and store it under strict access controls.

02Lawful Bases for Processing

Under UK GDPR Article 6 (and Article 9 for health/allergy data), we process data under the following bases:

  • Contract Fulfilment (Art. 6(1)(b)): operating your account, processing booking deposits, dispatching appointment confirmation alerts, releasing payout disbursements to specialists, and managing cancellation refunds.
  • Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a)): direct marketing emails, promotional SMS messages, non-essential cookies, allergy patch test logs, and corporate profile visibility for specialists. Consent can be revoked at any time in your Settings or via the Cookie Preference Manager.
  • Legitimate Interests (Art. 6(1)(f)): protecting marketplace integrity, verifying specialist credentials, detecting fraud, moderating client reviews, and improving platform performance — balanced against your privacy rights.
  • Legal Obligation (Art. 6(1)(c)): retaining transaction, invoice, and accounting records to comply with UK tax laws (HMRC) and statutory auditing rules.

03Data Processors & Sub-Processors

We partner with a minimal set of vetted third-party processors, each bound by strict Data Processing Agreements (DPAs):

  • Supabase Inc — primary database hosting, user authentication, and encrypted file storage (UK/EU data center region).
  • Stripe Payments Europe Ltd — payment processing, payout disbursements, and identity verification (acting as an independent controller for anti-money laundering and financial compliance).
  • Resend Inc — transactional email generation (booking receipts, password resets, travel notifications).
  • Postcodes.io — UK postcode geolocation lookup for distance-based search (processes postcodes only; no personal identity linked).
  • Cloudflare Inc — content delivery network (CDN), web application firewall (WAF), and DDoS protection.
International data transfers

Where data is transferred outside the UK, we ensure adequate protections using the UK International Data Transfer Addendum (IDTA) or approved Standard Contractual Clauses (SCCs).

04Your Statutory Data Rights

Under UK GDPR, you hold the following rights regarding your personal data:

  1. Right of Access (Subject Access Request - SAR): request a free copy of all personal data held about you.
  2. Right to Erasure (’Right to be Forgotten’): request account deletion and data removal (subject to §05 retention obligations).
  3. Right to Rectification: correct inaccurate or incomplete profile information.
  4. Right to Restrict & Object: object to direct marketing or processing based on legitimate interests.
  5. Right to Data Portability: receive your structured personal data in a machine-readable format.
How to exercise your rights

Email privacy@rootli.co.uk with the subject line “SAR” or “Data Erasure”. We will verify your identity (without ever asking for passwords) and fulfill your request within one calendar month as mandated by law.

If you believe your data has been handled unlawfully, you have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

05Retention, Security & Breach Protocol

  • Retention Periods: financial transactions, booking invoices, and account ledgers are retained for six (6) years following account closure to comply with HMRC tax requirements. Portfolio images and bio data are deleted immediately upon account deletion.
  • Technical Security: data in transit is protected using TLS 1.3 encryption. Database access is governed by strict Row-Level Security (RLS) policies per user ID.
  • Data Breach Protocol: in the unlikely event of a security breach compromising high-risk personal data, Rootli will notify the ICO and affected users within 72 hours in compliance with UK GDPR Article 33.
6-year HMRC retention rule

UK tax law requires us to retain transaction and accounting records for six years after account closure. Erasure requests will always honour this statutory retention window, and we will tell you exactly what is retained and why.

06Telephone, SMS Data & PECR Compliance

Mobile numbers provided during signup are used exclusively for transactional appointment updates, two-factor authentication (2FA), and critical service notifications under Contract Fulfilment. Promotional SMS alerts are sent only where you have provided explicit opt-in consent under PECR regulations.

You can opt out at any time by replying STOP or updating your Profile Settings. We never sell mobile numbers or share them with third parties for marketing.

Questions about these policies? Email support@rootli.co.uk.