Instructions for Salons: How to Use and Deploy Changes
This guidance and clause are indicative only and do not constitute formal legal advice. You should seek independent legal advice to ensure compliance with your own specific circumstances and obligations under UK GDPR.
To ensure your salon remains compliant with UK GDPR when using the Phorest and Colourstart Passport integration, please follow these steps:
(To be copied into your Privacy Policy / T&Cs)
Sharing of Client Data with Colourstart Passport via Phorest
As part of our commitment to providing compliant colour services, we use Phorest (our salon management software), which integrates with Colourstart Passport, a specialist hair colour allergy alert and skin sensitivity screening service.
All our colour services are carried out in accordance with industry best practice. To facilitate this, your relevant personal data—strictly limited to your name, contact details, and a colour compliance status (indicating solely whether we can or cannot proceed with your colour service)—will be shared between Phorest and Colourstart Passport via a secure integration. We do not process or share specific health, allergy, or medical information as part of this integration.
Legal basis for processing: This data sharing is carried out by us on the basis of legitimate interests (Article 6(1)(f) UK GDPR). Ensuring you have a valid compliance status is an essential operational requirement for us to deliver our colour services in line with industry standards. This data is used by the salon solely for service compliance and never for marketing purposes.
How your data is used: Your data is shared with Colourstart Passport to facilitate the colour compliance screening process, link your compliance status with your salon profile within Phorest, and allow Colourstart to instruct you on how to participate where required. Once transferred, Colourstart Passport processes your information in accordance with its own Privacy Policy, which includes use for service administration, internal analytics, and system improvements. Colourstart will only use your data for third-party direct marketing if you give them your separate, explicit consent.
Data retention: Data shared with Colourstart Passport is retained in accordance with its privacy policy, available at https://colourstart.com/privacy-policy. You may request details of how your data is stored at any time.
Your rights: You have the right to access, rectify, or request erasure of your personal data, subject to any overriding legal obligations. To exercise your rights regarding the data held by our salon, please contact us at [insert salon email/address].