Privacy Policy

Last updated: January 2026

1. Introduction

Imperial Dermal ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

The data controller is Imperial Dermal, a company registered in England and Wales, operating from the United Kingdom.

2. Information We Collect

We collect information that you provide directly to us, including:

  • Name, email address, and contact information
  • Billing and shipping addresses
  • Payment information (processed securely via Stripe)
  • Business or professional verification information (where required for restricted products)
  • Order history and preferences

Professional or business verification information is collected only where required for access to specific restricted products or categories.

We do not store full payment card details. Payment information is handled directly by our PCI-DSS compliant payment processor (Stripe).

3. How We Use Your Information

We use the information we collect to:

  • Process and fulfil your orders
  • Verify business or professional status for restricted product categories
  • Ensure compliance with applicable trade regulations
  • Communicate with you about orders, services, and support enquiries
  • Comply with legal and regulatory obligations
  • Improve our products, services, and platform usability

4. Legal Basis for Processing (UK GDPR)

We process personal data under the following lawful bases:

  • Contract: To fulfil orders and provide services
  • Legal obligation: To comply with tax and other applicable legal requirements
  • Legitimate interests: To verify professionals, ensure appropriate product access, prevent fraud, secure our platform, and improve service reliability
  • Consent: For marketing communications where required

5. Data Sharing

We may share your information with:

  • Payment processors (Stripe) as a data processor for secure payment handling
  • Delivery partners as data processors for order fulfilment
  • Third-party verification services where necessary to confirm business or professional status for restricted products
  • Authorities or regulators where legally required

We only share the minimum data necessary and never sell your personal information.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption, secure servers, role-based access controls, and regular security assessments. However, no method of transmission over the internet is completely secure.

7. Data Retention

We retain your personal data for as long as necessary to provide our services and comply with legal obligations. Order records are retained for 7 years for accounting and regulatory purposes. Practitioner verification records are retained for as long as the account remains active and for a reasonable period thereafter to comply with regulatory and audit requirements.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Request erasure of your data (subject to legal obligations)
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time (for consent-based processing)

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time.

9. International Transfers

We do not routinely transfer personal data outside the UK or EEA. Where trusted service providers process data internationally, appropriate safeguards are used in accordance with UK GDPR, such as adequacy regulations or standard contractual clauses.

10. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

11. Cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts. Where required by law, we will obtain your consent before placing non-essential cookies on your device. You can manage cookie preferences via our cookie banner or browser settings.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

13. Contact Us

For privacy-related enquiries or to exercise your rights, please contact us at