Last modified: January 24, 2026
This privacy notice describes how we will collect, use, share and otherwise process your personal data in connection with your use of:
This App is not intended for those under 13 and we do not knowingly collect data relating to children.
Please read the following carefully to understand our practices regarding your personal data and how we will treat it.
This notice is provided in a layered format so you can click through to the specific areas set out below:
Umia Technology Inc, trading as Umia Beauty, is the controller and is responsible for your personal data (Umia Beauty, we, us or our in this notice).
Our full details are:
We are based outside of the UK, so we have appointed Umia Beauty Ltd as our UK representative under the UK GDPR. You can contact them on the details below.
Our UK representative's full details are:
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues.
We keep our privacy notice under regular review.
This version was last updated on January 24th, 2026. It may change and, if it does, those changes will be posted on this page and notified to you by push notification, by email, when you next start the App and/or log onto your account. You may be required to read and acknowledge the changes to continue your use of the App or the Services.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you. Please visit the settings section of your Account to update your details.
Our App and Services may, from time to time, contain links to and from the websites of third parties, including third party sites via which to book Services. Please note that these websites (and any services accessible through them) are controlled by those third parties and are not covered by this privacy notice. You should review their own privacy notices to understand how they use your personal data before you submit any personal data to these websites or use these services.
We collect, use, store and transfer different kinds of personal data about you. To make it easier for you to use this privacy notice, we group these into the following categories. Each of these categories is described in more detail [LINK TO Description of categories of personal data].
We do not collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data).
We do not collect data relating to criminal offences.
We collect your personal data in the following ways:
We use cookies (small files placed on your device) and other tracking technologies on the App and in our direct marketing emails to improve your experience and our development of the App and our Services.
We will only use your personal data when we have a lawful basis to do so. Our lawful basis for each purpose for which we use your personal data is specified below. Most commonly we will use your personal data in the following circumstances:
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To permit you to install the App and register you as a new App user | Identity Contact Financial Device | Performance of a contract Legitimate interests (delivering our App to you) |
| To take steps towards providing you with services at your request, to process and fulfil in-App orders and deliver services to you, including managing payments and sending you service communications | Identity Contact Transaction Device Location | Performance of a contract |
| Enforce our terms and conditions, including to collect money owed to us | Identity | Legitimate interests (to recover debts due to us) |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| Combining the information we collect about you into a single customer account profile | Contact Direct marketing | Legitimate Interests (to publicise and grow our business) |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To send you direct marketing communications via email, text and/or push notification | Contact Device Direct Marketing | Consent Unless we can rely on the soft opt-in and you have not opted out, in which case we rely on Legitimate Interest (to publicise and grow our business) |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To administer, monitor and improve our business, Services and this App including troubleshooting, data analysis and system testing | Identity Contact Device Image | Legitimate interests (for running our business, provision of administration and IT services, network security, maintaining the security of our App and Services, providing a secure service to users and preventing fraudulent and other misuse of our App) |
| Applying security measures to our processing of your personal data, including processing in connection with the App | All personal data under this privacy notice | Legal obligation (applying appropriate technical and organisational measures under Article 32 of the UK GDPR) |
| Otherwise monitoring use of the App and deploying appropriate security measures | Contact Security Transaction | Legitimate interests (running our business, provision of administration and IT services, network security, maintaining the security of our App and services, providing a secure service to users and preventing fraudulent and other misuse of our App) |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To comply with our other legal obligations, including compliance with tax legislation, judicial, law enforcement and government authorities' requests | All personal data under this privacy notice | Legal obligation |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To deploy and process personal data collected via Cookies that are strictly necessary | Cookies | Legitimate interests (delivering and securing the App and our Services) |
| To deploy and process personal data collected via Cookies that are not strictly necessary | Cookies | Consent |
| To deliver (personalised) recommendations and advertisements to you | Personalisation | Consent |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| To notify you of changes to the App, Services, your purchases and our terms and conditions for ongoing contracts | Contact | For ongoing or prospective contracts, Performance of a contract Otherwise, Legitimate interests (in servicing our users and prospective users) |
| To notify you of updates to this privacy notice | Contact Transaction | Legal obligation (to inform you of our processing under Articles 13 and 14 of the UK GDPR) |
| To respond to your requests to exercise your rights under this notice | As relevant to your request | Legal obligation (complying with data subject requests under Chapter 3 of the UK GDPR) |
| To ask you to complete a survey and process your response | Contact | Legitimate interests (to analyse how users use our products or Services and to develop them and grow our business) Unless you have previously opted out, where we will rely on Consent |
| To otherwise respond to your enquiries, fulfil your requests and to contact you where necessary | As relevant to your enquiry or request | Legitimate interests (service our users and prospective users) |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| Share personal data with our third-party providers for purposes not otherwise set out above (see Disclosures of your personal data) | Identity Contact Transaction | Legitimate interests (for the purpose relevant to the recipient, as set out at "Disclosures of your personal data") |
| Purpose or Activity | Type of Personal Data | Lawful Basis for Processing |
|---|---|---|
| Process personal data relating to staff members of our business contacts, including suppliers, customers and prospects | Contact | Legitimate interests (servicing and receiving products or services, to or from our business contacts and carry out our B2B business) |
We do not make decisions based solely on automated processing or profiling that produce legal effects concerning you (or have similarly significant effects).
We may share your personal data with the following third parties:
Where we transfer your personal data between the UK and the EEA those transfers are made pursuant to the UK government's adequacy decision in favour of countries in the EEA and the European Commission's adequacy decision in favour of the UK.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us using the contact details above if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
All information you provide to us is located in the EEA or Hong Kong. Any payment transactions carried out by us or our chosen third-party provider of payment processing services, Stripe, will be encrypted using mutual transport layer security (mTLS) and dedicated PGP Keys. Where we have given you (or where you have chosen) a password that enables you to access certain parts of our App or Services, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Once we have received your information, we will use strict procedures and security features to protect your personal data from loss, unauthorised use or access.
[We will collect and store personal data on your device using [application data caches and browser web storage (including HTML5) OR [ALTERNATIVE MECHANISMS]] and other technology.] Please see our cookies policy.
We have put in place procedures to detect and respond to personal data breaches and notify you and any applicable regulator when we are legally required to do so.
By law we have to keep basic information about our customers (including Contact, Identity, Security and Transaction Data) for six years after they cease being customers for tax purposes.
In some circumstances you can ask us to delete your data: see Your Legal Rights below for further information.
Once we no longer have a legal right to hold your personal data, we will delete or, in some circumstances, we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
You have the following rights under data protection laws in relation to your personal data: