1. Who we are
Hair Repair Management Group FZCO, trading as Hair Repair Club and Hair Repair Academy (“HRC”, “we”, “us”), operates academy.hairrepairclub.co.uk (the “Academy”). We are a Free Zone Company registered in Dubai, United Arab Emirates, with operations across the United Kingdom and internationally. For any data-related questions, contact academy@hairrepairclub.co.uk.
This policy explains what personal data we collect about you, how we use it, who we share it with, and your rights. Because we serve customers in the United Kingdom and European Economic Area, we apply UK and EU GDPR standards to all personal data we process, regardless of where you are based.
2. What data we collect
Data you give us directly
- Account data: your name and email address when you create an Academy account or download the free guide
- Purchase data: your name, billing address, and (via Stripe / Klarna) the last four digits of your payment card. We never see or store your full card number.
- Communications: the content of any emails, support messages, or community posts you send us
- Certification submissions: if you submit content for HRC certification, the video/image evidence you choose to share
Data collected automatically
- Usage data: which pages you visit, which videos you watch, how long you spend on the site, where you click. Used to improve the Academy and (where you’ve consented) for advertising
- Device data: IP address, browser type, device type, operating system. Used for fraud prevention and to detect account sharing (see Terms section 5.3)
- Cookies: we use essential cookies for the site to work, and (with your consent) analytics and advertising cookies
3. How we use your data
We use your data to:
- Provide your Academy account and deliver the courses you’ve purchased
- Take payment for purchases and process refunds
- Send you transactional emails (purchase confirmation, course updates, certification feedback)
- Send you marketing emails (with your consent — you can unsubscribe any time)
- Improve the Academy by analysing how it’s used
- Detect and prevent fraud, account sharing, and breach of Terms
- Comply with our legal obligations
- (With your consent) run targeted advertising on Meta and other platforms
Legal basis
Under UK GDPR, we process your data under the following lawful bases: contract (to deliver the courses you’ve bought), legitimate interests (to run, improve, and protect the Academy), consent (for marketing and advertising cookies, which you can withdraw any time), and legal obligation (where required by law).
4. Who we share your data with
We share data only with service providers who help us run the Academy. They’re contractually required to handle your data in line with this policy. These include:
- Kajabi (USA) — our course platform; hosts your account, course progress, and payment records
- Stripe and Klarna — payment processing
- Bunny.net (Slovenia) — image and video hosting CDN
- Meta (Facebook/Instagram) — where you’ve consented to advertising cookies, we share hashed email addresses to deliver targeted ads
- Google Analytics — where you’ve consented to analytics cookies, anonymised usage data
We never sell your personal data. We never share it with third parties for their own marketing purposes.
5. International transfers
Some of our service providers (Kajabi, Meta, Google, Stripe) are based outside the UK, primarily in the USA. We transfer data internationally only when we have appropriate safeguards in place — including Standard Contractual Clauses or where the provider is certified under recognised data-protection frameworks.
6. How long we keep your data
- Account data: for as long as your Academy account is active, then for 7 years after closure (to meet UK tax and accounting record-keeping requirements)
- Purchase records: 7 years (UK tax law)
- Marketing data: until you unsubscribe or withdraw consent
- Free guide email addresses: 24 months from last engagement, then deleted unless you become a paying student
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase your data (the “right to be forgotten”) — subject to our legal record-keeping requirements
- Restrict how we use your data
- Port your data to another service in a machine-readable format
- Object to processing based on legitimate interests, including for marketing
- Withdraw consent at any time, where consent is the lawful basis
- Lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk
To exercise any of these rights, email academy@hairrepairclub.co.uk with the subject line “Data request”. We’ll respond within 30 days.
8. Cookies
We use three categories of cookies:
- Essential — needed for the site to work (login, checkout, security). Always on.
- Analytics — Google Analytics, to understand how the site is used. Loaded only with your consent.
- Advertising — Meta Pixel and similar, to deliver targeted ads on social platforms. Loaded only with your consent.
You can manage your cookie preferences at any time via the cookie banner on the site.
9. Security
We use industry-standard technical and organisational measures to protect your data — including HTTPS encryption in transit, encrypted database storage at rest (via our service providers), restricted-access admin accounts, and routine review of who has access to what. No system is 100% secure, but we treat your data seriously.
10. Children
The Academy is intended for use by professionals aged 18 or over. We don’t knowingly collect data from anyone under 18. If you believe we’ve collected data from a child, please contact us and we’ll delete it.
11. Changes to this policy
We may update this policy from time to time. The current version always lives at academy.hairrepairclub.co.uk/privacy with a clearly displayed “Last updated” date. Material changes will be emailed to enrolled students.
12. Contact
Any privacy questions: academy@hairrepairclub.co.uk.
Hair Repair Management Group FZCO · Free Zone Company · registered in Dubai, United Arab Emirates.