Privacy Policy
This policy explains what personal data is collected when you visit thebeautyclinic.co.nz, why, who else can see it, how long it is kept and what you can require us to do about it. It is written to be specific rather than reassuring: where the honest answer is that a category of data is not collected at all, this policy says so instead of reserving the right in case that changes later.
Behind the policy is a small operation: an independent information resource about adult web traffic and the networks that sell it, described further on the about page. It is not an advertising network, does not operate any gambling or adult content service, and does not process payments. The controller for the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) is the operator of this site, reachable at [email protected].
1. What you give us directly
Nothing, unless you email us. There is no registration, no account, no newsletter sign-up, no comment section and no contact form on this site. The only route by which you can hand over personal data is writing to one of the addresses on the contact page.
The person reading those messages is the one on the author page. If you do email, we receive your email address, whatever name you sign with, the subject line and the content of your message, including anything you attach. We use it to answer you and, where the message is a correction, to check and update the page in question. We do not add correspondents to any mailing list, because there is no mailing list.
We never ask for and do not want: payment card details, advertising account credentials, passwords, API keys, identity documents or campaign data belonging to your clients. Please do not send them.
2. What is collected automatically
Standard web server logs are generated whenever a page is requested. They contain the IP address making the request, the browser user agent string, the address of the page requested, the referring address if your browser sent one, and the timestamp.
These exist for two reasons and no others. The first is operational: diagnosing errors, seeing that pages load, and identifying automated traffic that degrades availability. The second is aggregate interest in which pages are read, which informs what gets written next. Logs are not used to build profiles of individual visitors, and no attempt is made to link an IP address to a named person.
3. What is not collected
How the material itself is produced and checked is a separate question, covered by the editorial policy and the verification standards. One analytics platform runs on this site: Google Analytics 4, property G-Q6H434KJ2J, operated by Google LLC. It records which pages are opened, roughly where in the world the request came from, the device and browser type, and how visitors move between pages. IP addresses are truncated by Google before storage, and the data is used to see which material is read and which is ignored.
Nothing else is loaded. There is no Google Tag Manager, no Meta pixel, no advertising or retargeting tag, no heatmap or session-recording tool, and no A/B testing script. There are no embedded third-party fonts, no embedded video players and no social media widgets, each of which would otherwise report your visit to a company you did not choose to deal with. Analytics data is never used to build advertising audiences and is not shared with any advertising network.
Pages are otherwise static HTML with a single stylesheet and images served from the same domain. You can verify the whole list by viewing the page source or opening your browser's network inspector, and anyone evaluating a privacy policy should do exactly that, since claims like this one are cheap to make.
4. Cookies and similar technologies
Analytics cookies are the only ones this site is responsible for. Google Analytics sets _ga, which distinguishes one visitor from another and expires after two years, and _ga_Q6H434KJ2J, which holds session state for the same period. Neither carries your name, email or any identifier you have given us, and neither is readable by any other website. No advertising, retargeting or fingerprinting technology is loaded here.
You can switch analytics off before it collects anything. Google publishes a browser opt-out add-on at tools.google.com/dlpage/gaoptout, most browsers block third-party and cross-site cookies in their privacy settings, and clearing cookies for this domain removes both of the above. Confirm what is actually stored by opening developer tools and looking at the storage panel.
Cookies you may nonetheless encounter come from elsewhere. Sign-up buttons here lead directly to AdsCompass, carrying campaign parameters in the URL rather than in any stored file, and those parameters are visible to you in the address bar. Once you arrive, that platform will typically set a session cookie to keep you signed in through registration, an attribution cookie recording which source sent you, and functional cookies for interface preferences. All of them are set by that company under its own policies, and this site can neither read nor clear them. The same applies to the regulators, legislatures and standards bodies linked as sources.
Browser settings override anything any website offers, which is the level worth configuring. Chrome, Firefox, Safari and Edge all expose third-party cookie blocking under their privacy settings, all offer a private window that discards cookies and storage on close, and all allow clearing cookies for one site without touching the rest. One practical caution: blocking cookies globally will break the registration flow of any advertising platform, because a session cookie is what keeps you signed in between form steps. Blocking third-party cookies while allowing first-party ones removes most cross-site tracking without breaking normal use. Do Not Track and Global Privacy Control signals have nothing to act on here, and are worth enabling anyway for the sites that do process data for advertising.
5. Legal bases for processing
Analytics is processed on the basis of consent under Article 6(1)(a) GDPR where consent is required in your jurisdiction, and on legitimate interests under Article 6(1)(f) elsewhere; you can withdraw it at any time using the opt-out described above, without affecting the lawfulness of what came before. Log data is processed on the basis of legitimate interests under Article 6(1)(f) GDPR: keeping the site available, secure and functioning is a legitimate interest, the data involved is minimal and retained briefly, and processing it does not override the rights of visitors who remain unidentified throughout.
Email correspondence is processed on the basis of legitimate interests under Article 6(1)(f) where you have written to us and expect a reply, and on the basis of legal obligation under Article 6(1)(c) where retention is required to demonstrate compliance. Where any processing were ever to rest on consent under Article 6(1)(a), you would be able to withdraw it at any time without affecting the lawfulness of what came before.
6. Who else sees the data
Google LLC processes analytics data as described above, under Google's own terms for Analytics customers. The hosting provider, which operates the servers and generates the logs, acts as a processor under a contract that limits use of the data to providing the hosting service. The email provider that carries correspondence to and from the addresses above acts as a processor on the same footing.
Nobody else. Data is not sold, is not shared with advertising networks, is not passed to data brokers, and is not disclosed to any advertising platform linked from this site. AdsCompass, with whom this site has the commercial relationship described in the editorial policy, receives no personal data from us at all: what it learns about you, it learns because you clicked through to its site and interacted with it directly.
Data would be disclosed to a public authority only where a valid legal obligation required it, and only to the extent required.
7. International transfers
Google Analytics involves transfer to the United States, covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. Server infrastructure and email may be operated by providers established outside your country, including inside and outside the European Economic Area. Where personal data is transferred outside the EEA, it is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses, depending on the provider. You may request details of the safeguards applicable to a specific transfer by writing to [email protected].
8. How long data is kept
Analytics data is retained by Google for 14 months from a visitor's last activity and then deleted automatically. Logs are retained for 90 days and then rotated out, which is enough for security investigation and short-term diagnosis and not enough to build a history of anyone's reading.
Correspondence by email stays for 24 months from the last message in the thread, so that a correction can be traced back to the source that prompted it, and then deleted. Correspondence that forms part of a legal record is kept for as long as the applicable limitation period requires.
9. Your rights
Where GDPR applies to you, you have the right of access under Article 15, to obtain confirmation of whether your data is processed and a copy of it. You have the right to rectification under Article 16 where data about you is inaccurate or incomplete. You have the right to erasure under Article 17, subject to any overriding legal obligation to retain. You have the right to restriction of processing under Article 18, the right to data portability under Article 20 in a structured, machine-readable format, and the right to object under Article 21 to processing based on legitimate interests.
To exercise any of them, write to [email protected]. Requests are acknowledged within 72 hours and answered within 30 days. Be aware of a practical limit: because logs contain no identifier beyond an IP address, locating your records generally requires you to supply the IP address and approximate time of your visits, and in many cases the retention period will have expired before a request arrives.
You also have the right to complain to a supervisory authority. In the EU this is the data protection authority of your country of residence; in the UK it is the Information Commissioner's Office; in New Zealand it is the Office of the Privacy Commissioner. Residents of California and other US states with their own privacy statutes may exercise comparable rights of access and deletion through the same address.
10. Security
Traffic runs exclusively over HTTPS with TLS encryption, so traffic between your browser and the server cannot be read in transit. Administrative access to the hosting account is protected by two-factor authentication and limited to the site operator. Server software is kept patched. Because the site holds no accounts, no payment data and no user database, the surface available to an attacker is small by design, which is a more reliable protection than any policy statement.
No system is completely secure. If a breach affecting personal data occurred, affected individuals and the relevant supervisory authority would be notified within the timeframes the applicable law requires.
11. Children
Adult advertising is the subject here, within the limits set out in the advertising standards, and the audience is professional adults aged 18 or over. It is not directed at children, no part of it is designed to appeal to them, and we do not knowingly collect data from them. If you believe a child has sent us personal data, write to [email protected] and it will be deleted immediately.
12. Changes
Revision is possible, for instance if the site ever adds a contact form or changes measurement provider. The current version is always the one on this page, with its effective date at the top, and material changes will be reflected in that date. Continued use of the site after a revision constitutes acceptance of the revised policy, alongside the terms and conditions.