Privacy Policy

Your trust matters. This policy explains how Beyond Brows collects, uses, and protects your information.

Beyond Brows deeply values our clients' digital privacy rights and is committed to protecting personal data in accordance with industry best practices and applicable privacy laws, including Lithuanian, European Union, and General Data Protection Regulation requirements where applicable.

Effective Date: June 7, 2026

Beyond Brows ("we," "our," or "us") values your privacy. This Privacy Policy describes how we collect, use, protect, and share personal data when you interact with our website, engage our services, or otherwise communicate with us.

1. Introduction

  • Protecting client and student information is a core part of how Beyond Brows operates. We collect only the information needed to provide beauty, permanent makeup, lash, brow, training, and related services, support inquiries, improve the website experience, and meet legal obligations. We handle that information with care and with a focus on confidentiality, security, and transparency.
  • This policy applies when you interact with our brow services, lip blush services, lash lift and tint services, and training offerings through the website.

2. Who We Are (Data Controller)

  • Beyond Brows is the data controller responsible for the personal data described in this policy. "Beyond Brows" is both our trading name and our registered legal name. You can reach us using the contact details at the end of this page.

3. Information We Collect

  • We may collect the following categories of personal data:
  • Website usage data collected through cookies, analytics tools, and similar technologies (only after you consent to non-essential cookies; see Section 9).
  • Contact information such as your name, email address, mailing address, and phone number.
  • Appointment details, service preferences, booking notes, and consultation information.
  • Health, skin, allergy, contraindication, consent, and procedure-related information needed to evaluate service suitability. This is "special category" health data under Article 9 GDPR, and we only collect it with your explicit, separately recorded consent through our Before Booking consent forms.
  • Before-and-after photographs of the treated area when you choose to provide them, used only for your own treatment record and, only with your separate explicit consent, for portfolio or marketing use.
  • Training and certification records related to enrollment, progress, and course participation.
  • Payment information when required to complete or hold an appointment, processed through trusted payment providers; Beyond Brows does not store full card numbers.

4. How We Use Information and Our Legal Bases

  • We use personal data to support the delivery and improvement of our services. For each purpose below, we rely on the legal basis for processing shown in parentheses, as required by Article 6 (and, for health data, Article 9) of the GDPR:
  • Provide and manage brow, permanent makeup, lip blush, lash lift, tint, waxing, and training services, including reviewing your Before Booking suitability information (performance of a contract; explicit consent for health data).
  • Process inquiries, requests, bookings, and service-related communications, including appointment confirmations and reminders (performance of a contract; legitimate interest in responding to enquiries).
  • Improve website functionality, content relevance, and overall client experience (legitimate interest; consent for any non-essential analytics cookies).
  • Communicate with clients and students regarding appointments, aftercare, training, updates, and, only where you have separately agreed, marketing communications (performance of a contract for service-related messages; consent for marketing).
  • Comply with legal, licensing, safety, sanitation, payment, tax/accounting, and operational requirements (legal obligation).
  • Detect, investigate, and prevent unauthorized access, fraud, or misuse of our systems (legitimate interest).

5. Sharing of Information

  • Beyond Brows does not sell personal data. We share information only where necessary to operate our business responsibly and lawfully, and only to the extent needed for the purpose. Current categories of recipients are:
  • Google Cloud / Firebase (Google Ireland Limited and its affiliates) — hosting, database, file storage, authentication, and the booking/CRM functions that run our website and studio operations.
  • Google Workspace (Gmail API) — sending appointment, password-reset, and account-access emails from our studio mailbox.
  • Google Maps Platform — validating and suggesting addresses you enter in the booking flow.
  • Training, licensing, insurance, or professional partners, only when necessary to fulfill a service or course request.
  • Regulators, courts, law enforcement, or other legal authorities, when required by law or a valid legal process.
  • We do not currently use third-party marketing/advertising analytics providers; if that changes, this policy and our cookie banner will be updated first. Where a third party processes personal data on our behalf, we require them to protect it appropriately and use it only to provide the agreed service, under a data processing agreement where one is required by law.

6. International Data Transfers

  • Our hosting and email providers (Google Cloud / Firebase and Google Workspace) may process personal data outside the European Economic Area, including in the United States. Where this happens, Google provides a recognized transfer safeguard, such as the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, alongside its data processing terms for Google Cloud and Google Workspace. You can ask us for more information about the safeguards that apply to a specific transfer.

7. Data Retention

  • We keep personal data only for as long as necessary for the purpose it was collected, and no longer than required by law. In practice, that means:
  • Appointment, consultation, and health/consent records are kept for as long as needed to provide safe, continuous care and to meet applicable record-keeping obligations for cosmetic procedures.
  • Accounting and payment records are kept for the period required by Lithuanian tax and accounting law.
  • Marketing consent records are kept until you withdraw consent, plus a short period afterward to evidence that withdrawal was honored.
  • Website enquiry and contact-form submissions that do not lead to an appointment are kept only as long as needed to respond and for a limited follow-up period.
  • We are finalizing exact retention schedules for each category; contact us for the current retention period applicable to your data, and see Section 12 for how to request deletion.

8. Cookies and Tracking

  • Our website uses cookies and similar technologies to improve browsing experience, understand site performance, and support relevant content and analytics. Non-essential cookies are only set after you actively consent through our cookie banner; you can accept, reject, or customize your choices there, and change them at any time using the "Manage cookie preferences" link in the website footer.
  • We may use the following categories of cookies:
  • As of the effective date of this policy, we have not enabled third-party analytics or advertising cookies; the categories above describe what may be enabled in the future, gated by your consent choice. If enabled, these services may collect information such as your IP address, browser type, pages visited, and referring URL.

9. Data Security

  • We implement appropriate technical and organizational measures to protect personal data from unauthorized access, misuse, alteration, or disclosure, including access controls that restrict staff to the data needed for their role. While no online system can guarantee absolute security, we take commercially reasonable steps to safeguard the information entrusted to us and to detect and respond to any incident affecting it.

10. Automated Decision-Making

  • We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not use automated profiling to decide whether to provide you with a service. Our booking system may show staff a suggestion for when you may be due for a follow-up appointment based on your service history; this is only an internal scheduling aid, is reviewed by a person before any communication is sent, and does not decide anything about you on its own.

11. Your Rights

  • Depending on your location and applicable law, including the GDPR, you have rights related to your personal data. These include the right to:
  • Be informed about how your data is processed (this policy).
  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure of your data, subject to legal retention requirements.
  • Restrict or object to certain processing, including processing based on legitimate interest.
  • Receive a copy of data you provided us in a portable format, where processing is based on consent or contract and carried out by automated means.
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframe required by applicable law and may need to verify your identity before acting on a request.

12. Complaints (Supervisory Authority)

  • If you believe your data protection rights have been violated, you can contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority, in particular in Lithuania:
  • State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija) — L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania. Please verify current contact and submission details on the Inspectorate's official website before relying on them, as they may change.

13. Third-Party Links

  • Our website may include links to third-party websites or services. Those external sites operate under their own privacy policies and practices. Beyond Brows is not responsible for the content, security, or privacy practices of third-party websites.

14. Policy Updates

  • We may update this Privacy Policy periodically to reflect operational, legal, or regulatory changes. When we do, we will revise the effective date and provide notice where appropriate.
  • Terms governing website use are outlined separately in our Terms of Service.

15. Contact Information

  • For questions, requests, or concerns related to this Privacy Policy or your personal data, please contact us at info@beyondbrows.lt.