| Document | Privacy Notice |
| Version | 1.0 |
| Effective from | 30 August 2026 |
| Review date | 30 August 2027 |
| Owner | The Society of Mesotherapy of the United Kingdom |
1. Who we are
The Society of Mesotherapy of the United Kingdom (“SoMUK”, “we”, “us”) is the professional society for mesotherapy practice in the United Kingdom, founded in 2013. We provide professional membership, congress information and a practitioner directory, and we administer bookings for training courses.
SoMUK is the data controller for the personal data described in this notice — that is, we decide what is collected, why, and how it is used.
Training courses are delivered by PHP Training Academy, a branch of PHP Health First Ltd (company number 07008563). Where you book a training course, we pass your booking details to PHP Training Academy so that the training can be provided, and PHP Health First Ltd is a controller of that information in its own right. Both organisations operate from the same address.
| Controller | The Society of Mesotherapy of the United Kingdom (SoMUK) |
| Training provider | PHP Training Academy, a branch of PHP Health First Ltd (company no. 07008563) |
| Address | 22 Harley Street, Suite 8a, London W1G 9PL, United Kingdom |
| General enquiries | contact@somuk.co.uk |
| Course bookings and cancellations | corine@somuk.co.uk |
| Telephone / WhatsApp | +44 (0) 7798 900 511 |
| Website | www.somuk.co.uk |
Both SoMUK and PHP Health First Ltd are registered with the Information Commissioner’s Office and pay the annual data protection fee.
2. What this notice covers
This notice applies to personal data we collect when you:
- visit www.somuk.co.uk
- apply for or hold membership of SoMUK
- book, attend or enquire about our training courses
- register an interest in a congress, or contact us about one — note that congress places are booked with the organiser of the event, not with SoMUK
- appear in, or search, our practitioner directory
- subscribe to our newsletter
- contact us by email, telephone, WhatsApp or through a form on our website
- apply for, or hold, congress accreditation, or act as a sponsor
It does not cover other websites we link to, including those of sponsors, partner societies or PHP Training Academy. Those organisations have their own privacy notices.
3. The personal data we collect
3.1 Information you give us
| When | What we collect | Why |
| Membership application and renewal | Name, title, professional qualifications, professional registration numbers, place of work, postal address, email, telephone, payment details, membership category | To assess eligibility, administer membership, take payment and keep the register of members |
| Training bookings | Name, contact details, professional background and qualifications, relevant medical or accessibility information you choose to give us, dietary requirements, payment details | To confirm your place, verify eligibility for the course, deliver the training safely, and issue certificates |
| Congress registration | Name, contact details, organisation, professional role, dietary and accessibility requirements, payment details | To register you, plan the event and issue attendance or CPD certificates |
| Directory listing | Name, qualifications, practice name and address, telephone, email, website, areas of practice, photograph | To publish your entry in the public practitioner directory, at your request |
| Newsletter | Name and email address | To send you the newsletter you asked for |
| Enquiries | Your name, contact details and whatever you choose to tell us in your message | To answer you and keep a record of the correspondence |
3.2 Information we collect automatically
When you visit our website, we may collect limited technical information such as your IP address, browser type, device type, the pages you view, and the dates and times of your visits.
This information may be collected through server logs, cookies and other website analytics technologies. Our cookie notice explains which cookies and similar technologies we use and, where applicable, allows you to accept or decline those that are not strictly necessary.
3.3 Special category data
Some of the information we hold is “special category” data under the UK GDPR and needs extra protection. This includes any health information you give us in connection with attending a course or congress — for example an allergy, a medical condition relevant to a practical session, or an accessibility requirement.
We only collect this where you volunteer it, we use it only for the purpose you gave it, we share it only with those who need it to keep you safe, and we delete it once the event has passed.
We do not collect patient data. If you are a member or a course delegate, any information about your own patients remains your responsibility as their clinician, and must not be sent to us.
4. Why we use your data, and our lawful basis
The UK GDPR requires us to have a lawful basis for everything we do with your personal data. Ours are set out below.
| Purpose | Lawful basis | Notes |
| Administering your membership | Contract | Processing is necessary to provide the membership you have applied and paid for |
| Taking and recording payments | Contract, and legal obligation | Financial records are kept to meet accounting and tax requirements |
| Delivering training and congresses | Contract | Necessary to provide the course or event you booked |
| Health and accessibility information for an event | Explicit consent (Article 9(2)(a)) | Given voluntarily, used only for that event, deleted afterwards |
| Publishing your directory entry | Consent | Published only at your request; you can ask us to remove it at any time |
| Sending the newsletter | Consent | You can unsubscribe from any newsletter, at any time |
| Answering enquiries | Legitimate interests | It is in both our interests that we respond to people who contact us |
| Keeping the website secure and working | Legitimate interests | Protecting the site, its users and our records from misuse |
| Keeping records of certification and CPD | Legitimate interests, and legal obligation where applicable | So that certificates and attendance can be verified later |
Where we rely on consent, you can withdraw it at any time by emailing contact@somuk.co.uk. Withdrawing consent does not affect anything we did with your data before you withdrew it.
5. The practitioner directory
Our directory is a public page. If you ask to be listed, the details in your entry can be seen by anyone visiting the website and may be indexed by search engines and copied by third parties.
Please only give us details you are content to publish. Do not give us a home address unless you are willing for it to be public. You may ask us to correct or remove your entry at any time and we will act on that request promptly, but we cannot control copies already taken by search engines or others.
6. Who we share your data with
We do not sell personal data, and we do not share it for anyone else’s marketing.
We share it only where we need to, with:
- Our website host and technical suppliers, who store the site and its database
- Our payment provider, who processes card payments — we do not hold full card numbers ourselves
- Our email and newsletter provider, to send messages you have asked for
- PHP Training Academy (PHP Health First Ltd), which delivers the training you book through us
- Course trainers, models and venues, where they need your name and any safety-relevant information to run the session
- Awarding, accrediting or CPD bodies, where a course or congress leads to a certificate they issue or verify
- Our accountants and, where necessary, our professional advisers
- Law enforcement, regulators or courts, where we are legally required to do so
[CONFIRM: Name the remaining suppliers. The website is hosted with OVH (SARL OVH, 2 rue Kellermann, 59100 Roubaix, France) and training is delivered by PHP Training Academy. Still needed: the payment provider, the newsletter provider, and any CPD or accreditation body. Naming recipients is a UK GDPR requirement, not optional.]
Each of these suppliers acts as our processor. They may only use your data on our instructions and must keep it secure.
7. Where your data is held
We aim to keep personal data within the United Kingdom, and we do not transfer it to any country that does not have an adequate level of protection under UK data protection law.
Where personal data is held in the European Economic Area — for example by our website host — that transfer is covered by a UK adequacy decision, and no additional safeguard is required.
Where any supplier is located in a country without an adequacy decision, we put in place one of the safeguards permitted by the UK GDPR, normally the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
[CONFIRM: Two points to check before publication, because “no data leaves the UK” may not be accurate as things stand. First, the website is hosted by OVH, a French company; ask OVH which data centre the site actually sits in, since OVH operates in both the UK and France. Either answer is fine — France is covered by adequacy — but the notice should say which. Second, several services on the site are operated from the United States: WhatsApp is provided by Meta and is used as a contact route from the website; Jetpack is provided by Automattic; Site Kit and any Google analytics are provided by Google. If any of these are in use, data does leave the UK and the safeguard relied on must be named here.]
8. How long we keep it
| Record | Kept for | Why |
| Membership records | Duration of membership, then 6 years | To answer queries about past membership and to meet accounting requirements |
| Training and certification records | [CONFIRM: suggested 7 years, or longer if an awarding body requires it] | So certificates and attendance can be verified later, by SoMUK and by PHP Training Academy |
| Health or accessibility information for an event | Deleted within 1 month of the event | No longer needed once the event has passed |
| Financial records | 6 years from the end of the relevant financial year | HMRC and accounting requirements |
| Directory entries | Until you ask us to remove it, or membership ends | Published at your request |
| Newsletter subscriptions | Until you unsubscribe | Consent-based |
| General correspondence | 2 years | Long enough to be useful, no longer |
| Website server logs | [CONFIRM: typically 30 to 90 days with the host] | Security and troubleshooting |
When a retention period ends we delete the data or anonymise it so that it can no longer identify you.
9. Keeping your data secure
We take appropriate technical and organisational measures to protect personal data. These include restricting access to those who need it, keeping our website software and plugins up to date, using encrypted connections (HTTPS), taking regular backups, and reviewing our security arrangements.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and, where the risk is high, tell you directly.
10. Your rights
Under the UK GDPR you have the right to:
- be told how your data is used — which is what this notice is for
- ask for a copy of the personal data we hold about you (a subject access request)
- have inaccurate data corrected
- ask us to delete your data, where there is no good reason for us to keep it
- ask us to restrict how we use your data while a concern is resolved
- ask us to transfer your data to you or to another organisation, in a machine-readable format
- object to processing we carry out on the basis of legitimate interests
- withdraw consent at any time, where consent is our lawful basis
To exercise any of these, email contact@somuk.co.uk. We will respond within one month. If your request is complex we may extend that by up to two further months and will tell you if we do.
There is no charge. We may ask you to confirm your identity before we release information, so that we do not disclose your data to someone else.
11. Complaints
If you are unhappy with how we have handled your personal data, please tell us first — email contact@somuk.co.uk with “Data protection complaint” in the subject line. We will acknowledge your complaint within 30 days and respond without undue delay.
If you remain dissatisfied, you can complain to the Information Commissioner’s Office:
| Information Commissioner’s Office | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
| Helpline | 0303 123 1113 |
| Website | www.ico.org.uk |
Complaining to us first does not affect your right to go to the ICO at any time.
12. Cookies
Our website uses cookies and similar technologies to ensure that the website functions properly, to maintain security, and, where applicable, to understand how visitors use our website.
Strictly necessary cookies, which are required for the website to operate and cannot reasonably be disabled, do not require your consent. Any non-essential cookies, including statistical or analytics cookies, are used only where permitted and, where consent is required, only after you have accepted them through our cookie banner.
You can accept or decline non-essential cookies when you first visit our website, and you can change or withdraw your cookie preferences at any time.
For full details of the cookies used on our website — including the name of each cookie, its purpose, whether it is a first-party or third-party cookie, and how long it remains on your device — please see our Cookie Policy.
Our Cookie Policy is available through the “Learn more” link in the cookie banner and from the footer of our website.
13. Children
Our website and services are intended for healthcare and aesthetic professionals. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, please contact us and we will delete it.
14. Changes to this notice
We review this notice at least once a year and whenever our processing changes. The version number and effective date at the top show when it was last revised. Material changes will be notified to members by email.
15. How to contact us
For anything in this notice, including any request about your personal data:
| contact@somuk.co.uk | |
| Post | Data Protection, SoMUK, 22 Harley Street, Suite 8a, London W1G 9PL |
Prepared for SoMUK. This notice should be checked by a suitably qualified adviser before publication, and the remaining items marked CONFIRM resolved first. It replaces the previous privacy policy on www.somuk.co.uk, which referred to KeyDesign, Incubator and buyproxies.io — organisations unconnected with SoMUK — and described advertising activities SoMUK does not carry out. It should be read with the SoMUK Terms and Conditions and the Cancellation and Rescheduling Policy.

