![]() |
Treatwell
Download our free app.
|
Loading, please wait.
Please read these Terms and Policies carefully before you start to use our Website or our Apps and before booking any third party goods or services through our Website or our Apps. We recommend that you print a copy of these for future reference. By using our Website or our Apps, you confirm that you accept these Terms and Policies and that you agree to comply with them regardless of whether you choose to register with us. If you do not agree to these Terms and Policies, you must not use our Website or our Apps in any way.
Please read these Website & App Terms of Use carefully before you start to use our Website or our Apps, as they apply to your use of our Website and our Apps. We recommend that you print a copy of these for future reference.
These Website & App Terms of Use refer to the following additional terms which also apply to your use of our Website and our Apps:
By using our Website or our Apps, you confirm that you accept these Website & App Terms of Use and that you agree to comply with them. If you do not agree to these Website & App Terms of Use, you must not use our Website or our Apps. Please note: these Website & App Terms of Use only cover your use of our Website and our Apps, they DO NOT apply to the third party goods and services which are available for booking on our Website or our Customer mobile application. Please see our Booking Terms and Conditions [insert hyperlink] for the terms and conditions which apply when you make any bookings or purchase any vouchers from our Website or our Customer mobile application. Within these Website & App Terms of Use, the phrase “Terms and Policies” refers to any or all of the following policies: our Privacy and Cookie Policy, our User Generated Content Policy, these Website Terms and Conditions and our Booking Terms and Conditions.
If you know or suspect that anyone other than you knows your username or password, you must promptly notify us via chat.
The basics
Who are we? We are Treatwell Limited (we, our, us) and in these Terms we are described in different ways depending on the activity we engage with concerning your data. We process your personal data if you are a business, and we have a lawful and reasonable basis to do so. We process your personal data if you are a customer of our App or Website and we have a lawful and reasonable basis to do so. When we process your data in these instances we are regarded as a "data controller". In certain situations, you may provide your data to a partner and in this instance, they are "data controller's" and we are "data processors".
If you have any questions about how we collect, use or share your data, please contact us at support.treatwell.com/hc/en-nl or dpo@treatwell.com, or write to us at Treatwell Limited, 1st Floor, 6 St Andrew Street, London EC4A 3AE.
What is the purpose of this policy?
We are committed to protecting the privacy of our customers and business partners. We have written this Privacy Policy (policy) to ensure you have all the information you need about how we collect and process your personal data, and how we make sure it is kept safe. When we collect and process your personal data, we are regulated under the General Data Protection Regulation (EU) 2016/679 (the GDPR) which applies across the EEA (including in the UK) and the Data Protection Act 2018.
Who does this policy apply to?
This policy applies to anyone who uses:
(together, the Platform).
How can you complain?
You can complain to us at any time using the details above. You also have the right to make a complaint to the ICO, or any supervisory authority in the EU Member State where you live. We would, however, appreciate the chance to deal with your concerns before you approach any supervisory authority, so please contact us first.
How do we update this policy?
We understand that things change, so we will continue to review the effectiveness of this policy and make sure it is achieving its goals. We might update the policy from time to time and will post the most recent version on this page. If we make a change to this policy that we consider material, we will notify you via the Platform.
If you have any questions about this policy or how it works, please get in touch and we would be happy to chat!
The details - how we are collecting and using your data, and why
What personal data do we collect and why?
We use a few different methods to collect your personal data. Sometimes you provide us with this data and other times it will be collected automatically when you visit and/or use the Platform.
We collect personal data for a number of reasons, including to meet our legal obligations, manage our operations, improve our organisation and deliver our services to you. Under data protection law we can only use your personal data where we have a legal basis to do so (e.g., legal duty, contract, legitimate interest, consent, etc).
The legal basis, the purpose and the retention period which we apply to our main processing activities are set out below:
Purpose 1: To set up and administer your requested account.
Purpose 2: Processing your comments, reviews or survey responses.
Purpose 3: Delivering any emails, surveys, newsletters and alerts that you have signed up to.
Purpose 4: Delivering our services to you.
Purpose 5: Delivering our services to you.
Purpose 6: Facilitating your booking and delivering the services to you.
Purpose 7: Responding to complaints, questions and feedback and providing information about your requested service.
Purpose 8: Responding to complaints, questions and feedback and providing information about your requested service.
Purpose 9: Receiving feedback about our services.
Purpose 10: Resolving the litigation and investigation.
Purpose 11: Administering the Platform and other systems and protecting them.
Purpose 12:To improve the Platform and services, using data analytics.
Purpose 13: Showing you content and features that are personal to you and your interests.
Purpose 14: Understanding your preferences for marketing, automated decision-making, profiling, cookies and any other processing activities that you can opt-out of.
Purpose 15: Developing and carrying out marketing activities.
Personal Data
Type of personal data: Contact information
Delivering our services to you.
Processing your comments and reviews.
Delivering any emails, surveys, newsletters and alerts that you have signed up to.
When it is our legal duty.
When you consent to it.
When it is in our legitimate interest to:
Type of personal data: Sensitive information
:Type of personal data: Financial information
When it is in our legitimate interest to:
Type of personal data: Communications
Providing information about your requested service.
When you consent to it.
When it is in our legitimate interest to:
Type of personal data: Data that identifies you
When it is in our legitimate interest to:
Type of personal data: Data on how you use the Platform
Showing you content and features that are personal to you and your interests.
When you consent to it.
When it is in our legitimate interest to:
Type of personal data: Preferences and consents
To send information about your requested services (i.e., appointment reminders).
Developing and carrying out marketing activities.
When it is in our legitimate interest to:
What about the information I give when I make a booking for someone else?
If you plan to give us someone else’s personal data (e.g., when making a booking for them), they must have access to this policy and you must get their consent before sharing any information with us.
How long do we keep your data for?
When we decide how long we need to keep your data for, we take into account the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure of your data, the purposes we use your data for and whether we can achieve those purposes another way.
The retention period which we apply to your personal data is defined in the table above.
You can contact us for more details on our data retention policy.
Do we use cookies and other tracking technologies?
A cookie is a small file of letters and numbers that is stored on your browser or the hard drive of your computer. As with other commercial websites and apps, the Platform uses standard technologies including cookies and similar tools to enhance your user experience, improve our systems and provide tailored offers to you. You cannot actually see cookies as they sit in the background of our systems, but they are probably present on most sites you visit.
For more information on the cookies we use, please take a look at our Cookie Policy.
What marketing activities do we conduct?
We want you to know all about us, our Partners and the services available. To do this, we undertake marketing activities which sometimes involve using your personal data - such as sending you newsletters via email or showing you online adverts.
You will not receive marketing from us by email or text unless you have given us permission, or unless you have used our services before. These messages might contain information about our services, offers, competitions and other important information.
Third parties
We may disclose your personal data to a select group of third parties. But we treat the security and method of processing your personal data very seriously, and we will never sell your personal data.
We have outlined below who those third parties are:
Type of third party: Other Treatwell companies
Type of third party: IT and hosting providers
Type of third party: Our Partners
Type of third party: Business support tools
Type of third party: Partner’s IT and hosting service providers
Type of third party: Competitions
Type of third party: Third parties involved in business reorganisation
Type of third party: Government and regulatory organisations
Type of third party: Marketing, business development and sales partners
How will my reviews be used?
Any personal data you upload to publicly visible areas of the Platform (such as review sections), may be collected by third parties, and we have no control over this and are not responsible for how they may use this information. We recommend you are careful about the information you disclose in these areas.
What about third-party links on our Site?
The Platform might include links to third party websites, and often these links are solely there as pointers to information on topics that might be useful to you. Clicking on those links might allow third parties to collect or share data about you.
We do not control these third-party websites and are not responsible for their privacy standards. When you leave the Platform, please remember that this policy no longer applies, and we encourage you to read the privacy policy of any website you visit.
What happens to information you provide via social media?
Parts of the Platform may allow you to submit your own content, such as reviews and photos of your experience. It is important to remember that these submissions can be viewed by the public, and we are not responsible for any actions taken by other individuals if you post personal data on one of our social media platforms. We recommend you are cautious about providing certain information (e.g., card details or your address) and that you refer to the privacy and cookie policies of the social media platforms you use.
What information do you need to know about our key third parties?
Stripe. We use a third-party payment processor, Stripe, to process all payments made by you on our Website & App. Treatwell does not store credit card details and instead relies on Stripe for this. We obtain limited information from Stripe such as the last four digits, the country of issuance and the expiration date. The processing of such data by Stripe is covered by their privacy policy which may be viewed here: https://stripe.com/privacy. Stripe’s services in Europe are provided by a Stripe affiliate, Stripe Payments Europe Limited, an entity located in Ireland. In providing its payment processing services, Stripe Payments Europe Limited transfers personal data to Stripe, Inc. in the US. For further information about the safeguards used when your information is transferred outside the European Economic Area, see the section of Stripe’s privacy policy entitled “International Data Transfers.
PayPal. Please note that all PayPal transactions are subject to the PayPal Privacy Policy which can be found here: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full. Please ensure that you are happy with the terms of the PayPal Privacy Policy if you wish to use PayPal to complete any transactions through the Platform.
Spa.lastminute.com. The spa.lastminute.com page is powered by Treatwell. Treatwell performs certain functions as a data controller in partnership with lastminute.com, also a data controller, and as a result Treatwell is required to process your personal information and share some of that information with lastminute.com when you browse and/or book on spa.lastminute.com. The purposes for which Treatwell collects, processes & shares your personal data with spa.lastminute.com are: (i) to fulfil a contract with you, by: (a) processing & managing your bookings; and (b) communicating with you about your booking; and (ii) to fulfil our, or third parties', legitimate interests, by: (a) providing search results; (b) communicating with you, including via Treatwell’s lastminute.com branded customer service function via telephone and email; and (c) on behalf of the relevant venue, collecting your consent (if you choose to provide it) at the checkout page to receive marketing emails from the particular venue with whom you are booking. As well as collecting personal information directly from you during the booking process, Treatwell also uses Cookies (defined below) on spa.lastminute.com in order to ensure spa.lastminute.com works correctly, to enhance and simplify your user experience, to enable us to understand how many users visit our spa.lastminute.com, to establish the source of your booking (channel, location, etc.) and consequently to enable verification of the booking as a lastminute.com booking and to send lastminute.com branded transactional communications to spa.lastminute.com customers. Please see the cookies section of this Privacy Policy for further information on the purposes for which we collect and use this information. For information on retention of your personal data, transfers of your personal data (to third parties and outside the European Economic Area), and your rights in respect of your personal data, please refer to the relevant sections of this Privacy Policy. If you have any queries or wish to exercise any of your rights in respect of the personal data processing described in this paragraph, please contact Treatwell using the details set out in this Privacy Policy.
Treatwell will also, on behalf of and under the instructions of lastminute.com, collect your consent (if you choose to provide it) at the checkout page to receive marketing emails from lastminute.com and pass this to lastminute.com daily via a secure data feed. For the avoidance of doubt, Treatwell does not collect any marketing opt-in for itself on spa.lastminute.com. lastminute.com also use cookies and similar tracking measures on spa.lastminute.com to collect information about your behaviour and for other purposes including personalisation, analytical and advertising and re-marketing. Please see lastminute.com's privacy policy here and cookie policy here for more information on how lastminute.com collects and processes your personal data. If you have any queries or wish to exercise any of your rights in respect of the personal data processing described in this paragraph, please contact lastminute.com using the details set out in their privacy policy.
Do we transfer data outside of the EEA?
The personal data that we hold about you will be held in the UK and the European Economic Area (EEA), but it might also be transferred to or stored outside the UK or EEA, including in the US and Israel.
When we transfer your data to third parties outside the EEA, we make sure your data is safe. We do this by putting one of the following safeguards in place:
If you are in the EEA, you can contact us at any time and we will let you know exactly what safeguards we have put in place for the transfer of your personal data outside the EEA. You can also contact us at any time at support.treatwell.com/hc/en-nl for a copy of the relevant mechanism.
Your rights
What are your rights and how do you exercise them?
Under the GDPR, you are entitled to the following rights:
Sometimes we cannot meet your request because of legal reasons. But don’t worry, we will tell you if this applies when you make your request!
You can also object if we are making decisions that are automated or if we are using your data to profile you (this basically means we are using your data to guess what you are interested in or make decisions about you). If there are circumstances when it is really important for us to use your data, we may be unable to stop the processing. But don’t worry, we will let you know if this is the case - and our reasons.
We might ask you to give us information to verify your identity (especially when you ask for financial information). This is to make sure we keep your and our other customers’ personal data safe.
We try to respond to legitimate requests within 1 month of receiving them. Sometimes it might take us longer if your request is complicated or you have more than 1 request. But don’t worry, we will make sure to let you know if we need more time and will keep you updated.
There are some requests that we will not be able to fulfil, and this can be for many reasons, including when there is a risk that another person's personal data will be disclosed, or if we have a legal requirement or a compelling reason to continue processing your personal data which you have asked us to delete.
If you want to exercise any of these rights, please get in touch with us at support.treatwell.com/hc/en-nl. If you need more information about your rights, including the circumstances in which they apply to you, please see the ICO’s websites or contact us.
How can you withdraw your consent and opt-out of processing?
You can ask us to stop sending you marketing messages that you have previously consented to at any time you want. You can do this by following the instructions in our communication, or by using the details set out below:
When you opt-out or unsubscribe from marketing, we will stop using your personal data in the ways you have asked. However, we will not delete your data as we may need it for other reasons. If you want us to delete all your data, please ask us to do that, as well as opting-out of marketing messages.
If you withdraw your consent and/or opt-out, we might not be able to provide certain services to you. If this is the case, we will let you know. You can of course give us your consent again if you want to access our services.
Please note that when you have opted out using the above methods, you may still see our non-targeted ads when you are online as we have no control whether these ads are displayed to you.
You have a right to withhold your consent without suffering any adverse effects.
Security
What security measures do we have in place?
We use strict procedures and security features to protect personal data we receive from you.
This deed of appointment of the Data Processor and the related contractual regulation (hereinafter the "DPA") is entered into between
You, (hereinafter referred to for convenience as the “Salon”, “Data Controller” or “Controller”) and
Treatwell BNL B.V. (t/a Treatwell) having its registered office in The Netherlands, at address Vijzelstraat 79, 1017 HG Amsterdam, The Netherlands, VAT number 928047219 in the person of its legal representative p.t., (hereinafter referred to for convenience as “Treatwell”, “Data Processor” or “Processor”),
The Salon and Treatwell are hereinafter collectively referred to as the "Parties".
In view of all the above, it is hereby agreed and stipulated as follows.
● share with the Salon bookings and purchases made by Data Subjects through the Platform;
● facilitate bookings and purchases of beauty services offered by the Salon;
● share with Data Subjects the results/outcomes of the bookings/purchases made via the Platform;
● assisting Data Subjects with complaints and requests for information;
● any other processing of the Data Subjects' personal data necessary for the execution of the Agreement.
● Compliance with the applicable Data Protection Legislation. The Processor undertakes, when processing personal data, to comply with the principles on the processing of personal data set out in the GDPR (Article 5, GDPR) and, in accordance with the principle of minimisation, to process data only to the extent necessary to provide the activities or applications specified in the Agreement and in this DPA, ensuring that personal data belonging to the Processor itself or to its other clients are processed separately.
● Respect for purposes. The Data Processor undertakes to process personal data exclusively for the purposes set out in Art. 2 and in compliance with the instructions provided by the Data Controller.
● Duty to cooperate. The Data Processor shall promptly inform the Data Controller i) if it considers that the instructions given by the Data Controller violate the provisions contained in the GDPR or the Data Protection Legislation and ii) of the existence of a legal obligation to proceed with a transfer of personal data to a third country or an international organisation, unless the applicable law prohibits this for important reasons of public interest. The Data Processor also undertakes to assist the Data Controller in ensuring compliance with the obligations set out in articles 32 et seq. of the GDPR, by notifying the Data Controller of any potential personal data breach encountered within 48 hours of becoming aware of the event, and by providing any documentation/information that may be useful to enable the Data Controller to notify the Data Protection Authority pursuant to article 33 of the GDPR or the Data Subjects pursuant to article 34 of the GDPR. Where necessary, the Data Processor also undertakes to assist the Data Controller in the drafting of the Data Processing Impact Assessment (‘DPIA’) pursuant to article 35 of the GDPR or in the prior consultation with the Data Protection Authority pursuant to article 36 of the GDPR.
● Confidentiality. The Data Processor undertakes to ensure the confidentiality of the personal data processed by limiting access i) to persons authorised and specifically instructed to process the data in accordance with article 29 of the GDPR; ii) to sub-processors in accordance with article 28 of the GDPR.
● Sub-processors. The Controller generally authorises the Data Processor, pursuant to article 28, par. 2, of the GDPR, to delegate the processing of personal data under this DPA to sub-processors. Pursuant to article 28, par. 4, of the GDPR, an agreement must be concluded between the Data Processor and the sub-processor to ensure that the sub-processor fulfills its data protection obligations. In any case, the Data Processor remains responsible to the Controller for the processing activities delegated to sub-processors.
● Record of processing activities. Pursuant to article 30 of the GDPR, the Processor undertakes to keep a record of all processing activities carried out on behalf of the Controller.
● Transfers outside the European Economic Area. The Data Processor is authorised by the Data Controller to transfer personal data outside the European Economic Area, provided that it is to third countries that have obtained an adequacy decision pursuant to article 45 of the GDPR or that the security measures set out in articles 46 et seq. of the GDPR, including the so-called Standard Contractual Clauses ("SCC").
● Security. In accordance with the provisions of articles 25 and 32 of the GDPR, the Data Processor undertakes to adopt technical and organisational measures to ensure i) an adequate level of security of the personal data of Data Subjects and ii) the confidentiality, integrity, availability and resilience of the processing systems, the ability to promptly restore the availability and access of personal data in the event of a physical or technical incident. The Processor undertakes to implement procedures to regularly test, verify and evaluate the effectiveness of the security measures adopted. If the processing concerns particular data pursuant to article 9 of the GDPR, the Data Processor undertakes to implement technical and organisational measures and/or additional guarantees.
● Rights of Data Subjects. The Data Processor undertakes to assist the Data Controller in responding to requests from Data Subjects to exercise their rights pursuant to artt. 15 ss. GDPR (e.g. right of access, rectification, deletion, etc.). In the event that requests are sent to the Data Processor, the latter will forward them to the Data Controller within 72 hours of receipt. In more complex cases, the assistance provided by the Data Processor shall be adequately remunerated.
● Delation of the Controller's Personal Data. In the event of termination of this DPA or of the Agreement, the Processor undertakes to erase/destroy or return to the Controller any existing copies of the Personal Data, documenting in writing that such erasure/destruction has taken place, unless the retention is necessary under applicable Data Protection Law or to comply with legal obligations or to establish, exercise or defend a legal right.
● Audit. The Data Controller has the right to carry out verification activities ("Audits") on the Data Processor's compliance with the applicable Data Protection Law, at most once a year and with exclusive reference to the processing operations under this DPA, giving at least 90 days' notice and ensuring the maximum protection of the Data Processor's business operations. The Data Processor undertakes, pursuant to article 28, par. 3, lett. h, of the GDPR, to provide the Data Controller with the information necessary to monitor the fulfilment of its obligations under this DPA. The Controller shall bear all costs related to the audit activity.
…
Our policy on Cookies
In common with other commercial websites and apps, our Platform use standard technologies including cookies and similar tools including web server logs, web beacons, tokens, pixel tags, local storage, device identifiers and tracking IDs (together referred to as “Cookies” in this Privacy Policy) to enhance your user experience, to enhance your user experience, improve our site and provide tailored offers on Treatwell and other sites.
Please see the table below for a live breakdown of the Cookies that are used on our Platform.