Privacy policy
DATA PROTECTION (GDPR) POLICY 2025–2026
Applicable to:
• Secret Diamond Holdings Ltd
• Voyager Machines
• Belleza Machines
Version: 2025–2026
Review Date: July 2027
⸻
1. Policy Statement
Secret Diamond Holdings Ltd, Voyager Machines and Belleza Machines are committed to protecting the privacy and personal information of our customers, students, employees, contractors and business partners.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and all applicable privacy legislation.
This policy explains how we collect, store, process and protect personal information.
⸻
2. Scope
This policy applies to:
• Employees
• Directors
• Trainers
• Contractors
• Students
• Customers
• Website visitors
• Suppliers
• Finance providers
• Business partners
It covers all personal information held electronically or in paper format.
⸻
3. Personal Information We Collect
We may collect:
• Name
• Address
• Telephone number
• Email address
• Date of birth (where required)
• Identification documents
• Payment details
• Finance application information
• Purchase history
• Training records
• Assessment records
• Certificates
• Attendance records
• Medical declarations where relevant to treatment or training
• Website enquiries
• CCTV images where applicable
• IP addresses and website analytics
⸻
4. Why We Collect Data
We process personal data to:
• Supply products
• Deliver training
• Process payments
• Arrange finance or lease agreements
• Deliver machines
• Provide warranty support
• Book appointments
• Issue certificates
• Respond to enquiries
• Meet legal obligations
• Prevent fraud
• Improve customer service
• Maintain business records
⸻
5. Lawful Basis for Processing
We process information where one or more of the following lawful bases applies:
• Contract
• Legal obligation
• Legitimate interests
• Consent
• Vital interests (where applicable)
⸻
6. Marketing
Where consent has been provided, we may contact customers regarding:
• New products
• Training courses
• Promotions
• Offers
• Events
• Product updates
Customers may unsubscribe at any time.
⸻
7. Storage of Information
Personal information is stored securely using:
• Password-protected systems
• Secure cloud storage
• Locked filing cabinets
• Secure business premises
• Encrypted devices where appropriate
Only authorised personnel have access.
⸻
8. Sharing Information
We do not sell personal information.
Information may be shared where necessary with:
• Finance companies
• Delivery companies
• Warranty engineers
• Training partners
• Awarding organisations
• Accountants
• Solicitors
• Courts
• Regulatory bodies
• Government authorities where legally required
⸻
9. Data Retention
Information is retained only for as long as necessary.
Typical retention periods include:
• Customer records – up to 7 years
• Financial records – up to 7 years
• Training records – as required by awarding organisations and legal obligations
• Warranty records – duration of warranty plus applicable limitation periods
• CCTV recordings – normally up to 30 days unless required for investigation
Data is securely destroyed when no longer required.
⸻
10. Customer Rights
Individuals have the right to:
• Access their personal information
• Correct inaccurate information
• Request deletion where appropriate
• Restrict processing
• Object to processing
• Request data portability where applicable
• Withdraw consent where consent is the lawful basis
Requests should be made in writing.
⸻
11. Data Security
We take appropriate technical and organisational measures including:
• Secure passwords
• Firewalls
• Anti-virus protection
• Staff confidentiality agreements
• Secure disposal of documents
• Access controls
• Regular software updates
⸻
12. Data Breaches
Any suspected data breach must be reported immediately to management.
Where required by law, reportable breaches will be notified to the Information Commissioner’s Office (ICO) without undue delay and affected individuals will be informed where there is a high risk to their rights and freedoms. (ICO)
⸻
13. Staff Responsibilities
All staff must:
• Keep personal information confidential.
• Use information only for authorised business purposes.
• Keep passwords secure.
• Lock computers when unattended.
• Report suspected breaches immediately.
• Follow company procedures at all times.
Failure to comply may result in disciplinary action.
⸻
14. Website and Cookies
Our websites may use cookies and analytical software to improve user experience.
Visitors may manage cookie preferences through their browser settings or any cookie controls provided on our websites.
⸻
15. CCTV
Where CCTV operates, it is used for:
• Crime prevention
• Staff safety
• Customer safety
• Protection of company property
Images are retained only as long as necessary.
⸻
16. International Transfers
Where information is transferred outside the United Kingdom, appropriate safeguards will be implemented to ensure compliance with UK GDPR requirements.
⸻
17. Children’s Data
Where training or services involve individuals under the age of 18, appropriate parental or guardian consent will be obtained where required.
⸻
18. Contact Details
For any GDPR or data protection enquiries, please contact:
Secret Diamond Holdings Ltd
Queens Dock Business Centre
309 Mariners House
Norfolk Street
Liverpool
L1 0BG
Email: thesecretdiamondacademy@gmail.com
⸻
19. Complaints
If you are dissatisfied with how we handle your personal information, please contact us first so we can investigate.
You also have the right to complain to the UK Information Commissioner’s Office (ICO).
⸻
20. Policy Review
This policy will be reviewed annually or sooner if legislation changes.
Approved by:
Claudia Barnicle
Director
Secret Diamond Holdings Ltd
Effective Date: July 2026
Review Date: July 2027

