Youzse Ltd
Data Protection and GDPR Statement
Last updated: 6 August 2026
About this statement
This statement explains how Youzse Ltd meets its obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). It sits alongside our Privacy Policy, which describes in plain terms what data we collect and why.
We take data protection seriously. Our priorities are simple: keep your data secure and use it only to provide a smooth and reliable service. We do not sell your data and we do not exploit its contents.
1. Who we are
- Data controller: Youzse Ltd, company number 17254677
- Registered office: 66 Paul Street, London, England, EC2A 4NA
- Data protection contact: [email protected]
You can contact us about anything in this statement using the details above.
2. Our role: controller and processor
Youzse provides software to businesses such as salons, garages and beauty professionals. Our role under data protection law depends on whose data is involved.
- For the personal data of our own account holders and website visitors, Youzse Ltd is the data controller.
- For the personal data a business records about its own customers through Youzse, that business is the data controller and Youzse Ltd is its data processor.
Every business accepts a Data Processing Agreement (DPA) before using Youzse. As a processor, we act only on the documented instructions of the business. We maintain records of our processing activities as required by Article 30 of the UK GDPR, covering both our controller and our processor activities.
3. The principles we follow
We handle personal data in line with the data protection principles in Article 5 of the UK GDPR. We process data:
- lawfully, fairly and in a transparent way
- only for specified and legitimate purposes
- limited to what is necessary for those purposes
- accurately, and kept up to date
- for no longer than is necessary
- securely, with appropriate technical and organisational measures
We are accountable for meeting these principles and we can demonstrate how we do so.
4. Lawful bases for processing
We always identify a lawful basis before processing personal data. Depending on the activity we rely on:
- Contract: to create and run your account, manage bookings and take payments.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, and improve how it works.
- Consent: for analytics and marketing technologies, location features and special category data.
- Legal obligation: to meet our tax, accounting and regulatory duties.
Where we rely on consent you can withdraw it at any time. Withdrawing consent does not affect processing carried out before you withdrew it.
5. Special category data (Article 9)
Some bookings involve information that the UK GDPR treats as special category data, for example health details, or appointment images that may reveal a health condition.
- We only process special category data where explicit consent has been given, separately and not bundled into agreeing to our terms.
- We record what was shown and when consent was given.
- The data is encrypted while stored, access to it is restricted and logged, and it is kept for a strict and limited period.
- Consent can be withdrawn at any time, and the data can be deleted on request.
We never use special category data for marketing or profiling.
6. Your rights
Under UK data protection law you have the right to:
- be informed about how your data is used
- access the personal data we hold about you
- have inaccurate or incomplete data corrected
- have your data erased, also known as the right to be forgotten
- restrict how your data is processed
- receive your data in a portable and machine readable format
- object to processing based on legitimate interests, and to direct marketing
- not be subject to solely automated decisions that have a significant effect on you
We do not carry out automated decision making that produces legal or similarly significant effects.
7. Deleting your account
If you use Youzse as a customer to book with businesses, you can delete your account from inside the app. Go to Account, then My data, then Delete Account, and confirm. You can take a copy of your data first from the same screen using Request Download.
When a customer account is deleted we remove or anonymise your profile and contact details, your bookings and appointments, your memberships and loyalty records, your vehicle records and your marketing preferences. Financial records such as invoices, payments and gift card transactions are anonymised rather than deleted, and the underlying figures are kept for six years because UK tax and accounting law requires it. Audit log entries are anonymised so that they no longer identify you.
If you run a business on Youzse and want your account closed, email [email protected]. We handle business closures individually because they involve your team, your own customers' records and your subscription. We respond within one calendar month.
If you cannot sign in to make a request, email [email protected] and we will verify your identity another way.
8. How to exercise your rights
To make a request, contact us at [email protected]. We will respond within one calendar month. In limited cases we may extend this by a further two months for complex requests, and we will tell you if we need to.
There is normally no charge. We may ask you to confirm your identity before we act, so that we do not disclose data to the wrong person.
Where the data is held by Youzse on behalf of a business as its processor, that business is the controller. In that case we will pass your request to them without delay and support them in responding.
9. International data transfers
Some of our service providers may process data outside the UK. Where data is transferred outside the UK, we make sure it is protected by an appropriate safeguard recognised under UK data protection law, such as:
- the UK's recognition of a country as providing an adequate level of protection
- a UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
A current list of the providers we use is set out in our Subprocessors page.
10. Retention
We keep personal data only for as long as we need it for the purpose it was collected, or for as long as the law requires.
- Account data is kept while your account is active and for a reasonable period afterwards.
- Appointment information and images are kept for the limited period set by the relevant business, and deleted sooner if consent is withdrawn.
- Financial records are kept for as long as tax and accounting law requires.
- Diagnostic and usage data is kept for a limited period and then deleted or anonymised.
When data is no longer needed we securely delete or anonymise it.
11. Security
We use technical and organisational measures appropriate to the risk, including:
- encryption of data in transit and encryption of sensitive data at rest
- protection through our Cloudflare security layer
- strict access controls, with access to sensitive data restricted and logged
- on device biometric authentication that keeps your biometrics off our servers
- regular review of our security practices
No system is ever completely secure, but we work continuously to protect your data.
12. Personal data breaches
We have procedures to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to individuals, we will also tell those affected without undue delay. Where we act as a processor for a business, we will notify that business without undue delay so that it can meet its own obligations.
13. Children
Our service is intended for users aged 18 and over. We do not knowingly collect the personal data of children. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at [email protected] so we can try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113.
15. Changes to this statement
We may update this statement from time to time. We will change the effective date and, where changes are significant, we will take reasonable steps to make them known.
Contact Youzse Ltd: [email protected].