Privacy policy
Privacy Policy
Last updated: 6 September 2026
1. Controller and contact
The controller for koreanlashlift.eu is BEAUTYBOOST LTD, Evagora Pallikaridi 38, 8010 Paphos, Cyprus, company registration number HE466648. Privacy contact: hello@koreanlashlift.eu. WhatsApp messaging: +49 1579 2300075. We do not offer telephone support.
This policy explains processing connected with the store, accounts, courses, orders, support, returns, professional applications and direct communications. A third-party service may provide its own notice when it acts as an independent controller.
2. Data we process
Depending on your interaction, we may process:
- identity and contact data, including name, billing and delivery address, email and messaging contact;
- account and authentication data, password-reset and security events, preferences and account status;
- transaction data, including products, prices, VAT, discounts, payment status, delivery choice, returns, refunds and fraud indicators; we generally receive status and limited payment identifiers rather than full card details;
- course and certificate data, including enrolment, access, progress, assessment, completion and certificate records;
- support, return and claim data, including messages, photographs, video, batch details, treatment or storage information voluntarily supplied and our response history;
- professional and business data for salon, training, affiliate, retail, distribution or collaboration requests;
- technical and usage data, including IP address, browser, device, timestamps, pages, referral data, security logs, cookie or similar identifiers and consent status;
- marketing preferences, campaign interaction and any review or publication permission separately given.
Please do not send unnecessary sensitive data. If evidence about a reaction or contraindication contains health information, provide only what is needed. We process such information only where an Article 9 GDPR condition applies, for example explicit consent or the establishment, exercise or defence of legal claims.
3. Sources
We collect data directly from you and automatically from your device. We may also receive relevant data from payment providers, fraud-prevention services, DHL, fulfilment and course providers, account administrators, referral or affiliate partners, and persons acting for a Business Customer. If another person provides your details, that person must have authority to do so.
4. Purposes and legal bases
We process data only where a legal basis applies:
- Contract and pre-contract steps: operate the cart and checkout; take and fulfil orders; arrange DHL delivery; create and secure accounts; supply courses and certificates; process returns, refunds and support.
- Legal obligation: tax, accounting, product-safety, traceability, sanctions, consumer, data-protection, fraud-reporting and dispute obligations.
- Legitimate interests: secure the website and accounts; prevent fraud, abuse and chargebacks; keep evidence; recover debts; improve operations; manage claims; protect intellectual property; communicate with business contacts; and understand aggregated service performance. We balance these interests against individual rights.
- Consent: optional marketing, non-essential tracking and any publication permission or processing that specifically requires consent. Consent may be withdrawn for future processing without affecting prior lawful processing.
- Legal claims and substantial public interest where applicable: investigate and defend product, safety, fraud, payment and legal claims, including strictly necessary processing of special-category data.
We do not make consent to unnecessary processing a condition of fulfilling an order. Service messages about an order, security, password reset, course access, delivery, recall, return or direct request are not marketing messages.
5. Recipients and processors
We disclose only what is reasonably needed to:
- hosting, security, backup, website, WordPress and WooCommerce service providers;
- payment, fraud-prevention, accounting and tax providers;
- German fulfilment operations, DHL and shipment-tracking providers;
- email, form, helpdesk, customer-relationship and marketing providers;
- course, learning-platform and certificate providers;
- analytics or advertising providers where lawfully enabled;
- professional advisers, insurers, auditors, purchasers of a business or assets, and finance or debt-recovery providers;
- regulators, courts, law enforcement, tax authorities and other persons where required or permitted by law.
Processors may act only on documented instructions under the required safeguards. Independent controllers process under their own legal duties and notices.
6. International transfers
Some providers or support operations may process data outside the European Economic Area. Where the destination is not covered by an adequacy decision, we use an available lawful safeguard such as approved Standard Contractual Clauses, assess relevant transfer risks and add supplementary measures where required. A transfer may instead rely on a specific GDPR derogation only in the limited circumstances allowed by law.
7. Retention
We keep personal data only for as long as reasonably necessary for its purpose, legal duties, security and disputes. Criteria include applicable tax and accounting periods, the contract and limitation period, course-access duration, certificate verification, product batch and safety traceability, unresolved support or claims, fraud and chargeback risk, consent status and provider backup cycles.
We may retain:
- order, invoice, VAT and payment-status records for the legally required accounting and claim period;
- course enrolment, completion and certificate records for access and verification;
- product-safety, batch, complaint and recall evidence for the relevant safety and liability period;
- security and fraud logs for a proportionate detection and defence period;
- marketing data until consent is withdrawn, an objection is upheld or the data is no longer needed, plus a minimal suppression record to respect the choice.
When continued identification is unnecessary, data is deleted or irreversibly anonymised. Deletion from active systems may precede deletion from protected backups, which cycle out under controlled schedules.
8. Your rights
Subject to GDPR conditions and exemptions, you may request access, correction, erasure, restriction, portability or objection. You may withdraw consent at any time for future processing. You have a particular right to object to direct marketing, which we will honour.
Erasure is not absolute. We may retain data required for an order, tax, product safety, fraud prevention, certificate integrity, a legal claim or another lawful ground. Portability applies only to qualifying data and bases. An objection to legitimate-interest processing is assessed against compelling legitimate grounds and legal claims.
Send requests to hello@koreanlashlift.eu. We may ask for proportionate identity verification and clarification. We normally respond within one month; GDPR permits an extension for complex or numerous requests with timely notice. Manifestly unfounded or excessive requests may be refused or charged a reasonable fee where the law permits.
You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus or to another competent EEA supervisory authority, particularly in the country of your habitual residence, work or alleged infringement. Contact details for the Cyprus Commissioner are available at https://www.dataprotection.gov.cy/.
9. Automated assessment
Payment and fraud providers may use automated checks and may act as independent controllers. We do not make a solely automated decision with legal or similarly significant effects unless it is necessary for a contract, authorised by law or based on explicit consent and the required safeguards apply. Where GDPR Article 22 applies, available safeguards may include human intervention, the opportunity to express a view and to contest the decision.
10. Security and account responsibility
We use organisational and technical measures appropriate to risk, including access controls, encryption in transit where supported, updates, backups, monitoring and restricted staff or provider access. No online system is risk-free. Protect credentials, use a unique password and notify us of suspected unauthorised access. We may temporarily restrict access to contain a security risk.
If a personal-data breach is likely to create a risk to individuals, we notify the competent authority as required; if high risk is likely, affected individuals are informed unless a lawful exception applies.
11. Marketing and communications
We send electronic direct marketing only where consent or another lawful permission applies. You can use the unsubscribe method in the message or contact us. Withdrawal stops future marketing but not service communications or processing on another lawful basis. We keep a minimal suppression record where necessary to avoid contacting you again.
Business-contact communications may rely on legitimate interests where permitted and proportionate. Any objection is assessed promptly, and direct-marketing objections are absolute.
12. Cookies and similar technologies
Strictly necessary technologies support security, cart, checkout, account, language and consent choices. Non-essential analytics, advertising or similar technologies are used only under the consent and information rules applicable to the visitor. Browser blocking may affect necessary store functions. More specific choices presented by the site's consent interface prevail for the technologies it controls.
13. WhatsApp and external links
If you contact us through WhatsApp, the message and related identifiers are processed to answer the request; the provider may process data as an independent controller under its own terms. Email remains available if you do not wish to use WhatsApp.
External websites and embedded providers have their own notices. A link does not make us controller for an unrelated third party's processing.
14. Children
The store and professional training are not directed to children. Orders and course accounts require legal capacity. If we learn that data was supplied by a child without a valid basis or necessary authorisation, we may delete it after taking steps needed to protect the child, prevent fraud and meet legal duties.
15. Changes
We may update this policy when services, providers or legal duties change. The current version and date appear here. A material change affecting consent-based processing will be handled through the consent process required by law. Earlier processing remains governed by the policy and law applicable at that time.
