Privacy Policy

Last updated: 20 July 2026

1. Introduction

This Privacy Policy explains how Ricorda ("we", "us", "our") collects, uses, stores and shares personal data when you use the Ricorda platform, which includes:

Ricorda is a business and record-keeping platform for beauty and wellness businesses. It enables professionals and studios to manage client records, schedule and document sessions, capture before-and-after session photos, and keep optional free-text session notes. Clients use the platform to view their session history, photos and receive notifications from their professional.

We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and the Privacy and Electronic Communications Regulations (PECR).

Important notice about roles: When professionals and studios use Ricorda to manage client records, the professional or studio is the data controller for client data, and Ricorda acts as a data processor on their behalf. For professional account data and platform operations, Ricorda is the data controller. This distinction is explained further in Section 3.

2. Who We Are

Ricorda is a service operated by UNKNWN LABS LTD, a company registered in England and Wales under company number 17301306, with its registered office at 10 Clifton Terrace, London, N4 3JP, United Kingdom. References to "Ricorda", "we", "us" and "our" in this Policy mean UNKNWN LABS LTD. UNKNWN LABS LTD is the data controller for the personal data described in Section 3.1.

For privacy-related enquiries, you can contact us at:

3. Our Role: Data Controller and Data Processor

Ricorda operates in two distinct data protection roles depending on the type of data involved:

3.1 Ricorda as Data Controller

We are the data controller for:

3.2 Ricorda as Data Processor

We act as a data processor on behalf of the professional or studio (who is the data controller) for:

When we process client data, we do so solely on the instructions of the professional or studio. The professional or studio is responsible for having a valid legal basis for collecting and processing their clients' data, including obtaining any necessary consents. We provide the professional or studio with a Data Processing Agreement that governs how we handle client data on their behalf.

If you are a client and wish to exercise your data protection rights in relation to your records, you should contact your professional or studio in the first instance, as they are the data controller for that information.

4. What Data We Collect

4.1 Professional and Studio Data

Category Data Collected Purpose
Account information Full name, email address Account creation and authentication
Business information Studio name, address, contact details Business profile and branding within the app
Subscription data Subscription plan, status, Stripe customer ID Managing access and billing
Authentication data Email address, one-time passcodes (OTP), Google Sign-In tokens Secure login and identity verification
Invitation data Invitation token, inviting party, email address Gated onboarding for new professionals

4.2 Client Data (processed on behalf of the professional/studio)

Category Data Collected Purpose
Personal identifiers Full name, date of birth, email, phone number Client identification and communication
Session records Session type, date, status, and any optional free-text notes the professional chooses to add Record-keeping and scheduling
Health and aftercare information Allergies, conditions, medication, medical history, aftercare details and related session notes Maintaining the record made available to approved professionals
Session photos Before-and-after session images Session record-keeping
Authentication data Email address, one-time passcodes (OTP) Secure login to the Ricorda ID app
Notification data Push notification tokens Sending session updates to clients
Health information requires additional protection. Data concerning health is special-category personal data. Professionals are responsible for identifying and documenting both an Article 6 lawful basis and an Article 9 condition before directing Ricorda to process it. Free-text fields should contain only information that is necessary for the stated record-keeping purpose.

4.3 Payment Data

Payment processing is handled entirely by Stripe. We do not collect, store or have access to your full payment card details. We receive only a Stripe customer ID and confirmation of payment status. Stripe's own privacy policy governs how they handle your payment information: https://stripe.com/privacy.

4.4 Technical and Usage Data

When you use our platform, we may automatically process limited operational data:

We do not currently collect product-usage analytics events in the website or mobile apps.

4.5 Business Contact and Outreach Data

For limited, one-to-one business outreach, we may process publicly available professional contact data relating to people working for corporate bodies in the beauty, wellness and medical-aesthetics sectors. This may include:

We do not use this activity to collect patient data or special-category data. Before unsolicited outreach, we take reasonable steps to verify that the recipient is a corporate subscriber, such as a limited company or limited liability partnership. We do not knowingly send unsolicited marketing email to sole traders or other individual subscribers unless consent or another applicable PECR exception is available.

5. Legal Basis for Processing

We process personal data only where we have a valid legal basis under the UK GDPR and EU GDPR. The legal bases we rely on are:

Data Type Legal Basis GDPR Article
Professional account and subscription data Contract performance — necessary to provide the Ricorda platform services under our terms of service Article 6(1)(b)
Client records (processed on behalf of the professional/studio) Determined by the professional/studio — the controller must identify and document an appropriate Article 6 lawful basis Article 6
Health or other special-category data (processed on behalf of the professional/studio) Determined by the professional/studio — the controller must identify both an Article 6 lawful basis and an applicable Article 9 condition, together with any additional requirements under the Data Protection Act 2018 Articles 6 and 9
Payment processing Contract performance — necessary to fulfil subscription agreements and process payments Article 6(1)(b)
Opt-in marketing communications Consent — where PECR requires consent, or where you have chosen to subscribe, we send marketing only in accordance with that choice Article 6(1)(a)
Limited B2B outreach to verified corporate subscribers Legitimate interests — introducing Ricorda to relevant businesses that could reasonably benefit from a professional record-keeping service. We apply the purpose, necessity and balancing tests; limit the data and frequency; and provide a simple opt-out in every message Article 6(1)(f)
Platform security and fraud prevention Legitimate interests — maintaining the security and integrity of the platform Article 6(1)(f)
Legal and regulatory compliance Legal obligation — where processing is necessary to comply with laws or regulations Article 6(1)(c)

6. How We Use Your Data

We use the data we collect for the following purposes:

6.1 Direct Business Outreach

Where we contact a business that has not previously engaged with Ricorda, we select recipients whose professional role and sector make the message reasonably relevant. Contact data is obtained from public business sources such as professional registers and the business's own website. Each message identifies Ricorda and UNKNWN LABS LTD, explains how to object or opt out, and links to this Privacy Policy.

We honour objections immediately and add the minimum information needed to a suppression list so that the business or individual is not contacted again. The right to object to processing for direct marketing is absolute.

7. Data Sharing and Sub-processors

We do not sell your personal data. We share data only with the following categories of third-party service providers ("sub-processors") who assist us in operating the platform:

Sub-processor Service Data Processed Location
Google Cloud / Firebase Cloud infrastructure: Firestore database, Cloud Functions, Firebase Authentication, Firebase Cloud Storage, Firebase Cloud Messaging All platform data (account data, client records, session images, authentication tokens) EU (Firestore: eur3 Europe; Cloud Functions: europe-west1 Belgium)
Stripe Payment processing and subscription management Payment card details, billing information, Stripe customer ID EU/US (Standard Contractual Clauses in place)
Resend Transactional email delivery (OTP codes, notifications, invitations) Email addresses, email content US (Standard Contractual Clauses in place)
Zoho CRM Customer relationship management and delivery or logging of one-to-one business correspondence Business contact details, public source information, correspondence and suppression status EU account/data centre

Each sub-processor is bound by a data processing agreement and is required to implement appropriate technical and organisational security measures. We maintain an up-to-date list of sub-processors and will notify affected users of material changes.

We may also disclose personal data where required by law, court order, or regulatory request, or where necessary to protect our legal rights.

8. International Data Transfers

We store the majority of data within the European Economic Area (EEA). Our primary database (Firestore) is located in the eur3 (Europe) multi-region, and our Cloud Functions run in europe-west1 (Belgium).

Some of our sub-processors (Stripe and Resend) may transfer personal data to the United States. Where this occurs, we ensure that appropriate safeguards are in place, including:

You may request a copy of the relevant transfer safeguards by contacting us at hello@ricorda.co.uk.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Data Type Retention Period Rationale
Client session records and notes While the relevant account remains open; deleted when the account owner submits and confirms an account-deletion request Kept on behalf of the professional for ordinary business record-keeping
Session photos (before/after images) While the relevant account remains open; deleted when the account owner submits and confirms an account-deletion request Part of the business record; retained for the same period
Professional account data While the account remains open; deleted on a confirmed account-deletion request Providing and securing the account
Payment and billing records 6 years plus the current financial year HMRC requirements and statutory limitation periods
One-time passcodes (OTP) 10 minutes Deleted automatically after expiry
Platform and technical logs 12 months Debugging, security monitoring and incident investigation
Marketing consent records Duration of consent plus 12 months Evidence of consent for PECR compliance
B2B prospect and correspondence records Up to 12 months after the last interaction, unless a longer period is necessary for an active business relationship or legal claim Managing proportionate one-to-one business outreach and avoiding repeated contact
Direct-marketing suppression records For as long as reasonably necessary to honour the objection Preventing future marketing after an opt-out; limited to the minimum identifying information required

When data reaches the end of its retention period, it is securely deleted or irreversibly anonymised.

10. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

For clients: If your request relates to records held by your professional or studio, please contact them directly, as they are the data controller for that information. We will assist them in responding to your request.

To exercise any of these rights in relation to data for which Ricorda is the controller, please contact us at hello@ricorda.co.uk. We will respond within one month. In complex cases, we may extend this by a further two months, but we will inform you of any extension within the first month.

There is no fee for exercising your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

While we take these measures seriously, no method of transmission over the internet or method of electronic storage is completely secure. We maintain a level of security appropriate to the risk, but we cannot guarantee absolute security, and we cannot be held responsible for unauthorised access that occurs despite our implementation of appropriate measures, to the extent permitted by law. This does not affect our obligations under UK GDPR Article 32 or your rights as a data subject.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

Where we are acting as a data processor, we will notify the affected professional or studio (as data controller) without undue delay upon becoming aware of a breach involving client data.

13. Cookies and Tracking

Our mobile apps do not use cookies. Our website uses only strictly necessary storage or cookies required for security, session management and payment flows.

We do not currently use analytics cookies, advertising cookies or third-party tracking technologies for behavioural advertising. Our one-to-one B2B outreach uses ordinary, untagged links and does not use tracking pixels or per-recipient open or click tracking. Ordinary server security logs may record an IP address and basic request information when someone visits our website, as described in Section 4.4.

If we introduce non-essential cookies, tracking pixels or similar storage and access technologies, we will update this policy and obtain consent where required before using them.

14. Children and Age Restriction

Ricorda is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe that a person under 18 has provided us with personal data, please contact us at hello@ricorda.co.uk and we will take steps to delete that information.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make material changes, we will:

We encourage you to review this Privacy Policy periodically.

16. Governing Law

This Privacy Policy, and any dispute or claim arising out of or in connection with it or its subject matter, is governed by and construed in accordance with the laws of England and Wales, and is subject to the exclusive jurisdiction of the courts of England and Wales. This does not deprive you of any protection afforded by mandatory provisions of the law of your country of residence, including your right to lodge a complaint with your local supervisory authority (see Complaints below).

17. Complaints

If you are not satisfied with how we handle your personal data or your privacy request, you have the right to lodge a complaint with the relevant supervisory authority:

We would appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us at hello@ricorda.co.uk in the first instance.

18. Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us: