Skip to main content
BLISS, The Beauty Company

Privacy Notice

How we look after your data.

Bliss The Beauty Company (run by Rosa Group Ltd, a company registered in England and Wales, company no. 09766720) treats your personal data with the care we would expect for our own. This page explains exactly what we collect, why, who can see it, and the rights you have under the UK GDPR.

Effective: 27 April 2026

Who we are

We are Rosa Group Ltd (registered in England and Wales, company no. 09766720), trading as Bliss The Beauty Company. Our registered office address can be supplied on request via email. We are the data controller for the personal data we collect through this website and our courses.

What we collect

When you buy a course or sign in to your account: your name, your email address, your default language and country, the courses you have enrolled in, the lessons you have completed, and the orders you have placed.

When you make a payment: your card or wallet details are handled by our payment processor (Stripe). We never see, store, or have access to your full card number. We retain a transaction reference and the amount paid so we can issue refunds and produce receipts.

When you visit the site: a small set of analytics signals so we can see which pages people read and which courses they prefer. Aggregated, never tied to a real name unless you have signed in.

We do not collect special-category data (health, biometrics, political opinions, religion, etc.) and we do not knowingly process the data of children under 16.

Why we collect it

To run your account: signing you in, showing your courses, marking lessons complete, issuing certificates.

To take payment and provide receipts.

To send you transactional emails (purchase receipts, sign-in links, certificate copies, support replies).

To improve the platform: anonymous and aggregated usage signals tell us which lessons need more work and which features people actually use.

We rely on the lawful bases of contract (running your course access), legitimate interest (security and analytics), and consent (for non-essential cookies and marketing emails, where applicable).

Who has access

Our small team, on a need-to-know basis. Maicon Da Rosa is the sole administrator with full database access.

Our service providers, only for the slice they need: Stripe (UK and US card payments), InfinitePay (Brazil in-person booking payments), Hotmart (Brazil online courses), Resend (transactional email), Hetzner Online (server hosting in Germany), Cloudflare (caching and DDoS protection), Backblaze B2 (encrypted off-site backups). Each is GDPR-compliant and bound by a data-processing agreement.

We never sell your data. We never share it with advertisers.

How long we keep it

Your account: as long as the account is active. If you ask us to delete it, we soft-delete the personal fields (name, email) and retain the order history in anonymised form for our statutory accounting obligations (typically six years under UK tax law).

Inactive accounts (no sign-in for two years) get a reminder email. After three years of inactivity we anonymise automatically.

Backups: rolling 30 days of encrypted off-site backups; older copies are deleted automatically.

Your rights

You have the right to access, correct, delete, restrict, or port your personal data. You also have the right to object to processing based on legitimate interests, and to withdraw consent for non-essential cookies or marketing at any time.

To exercise any of these rights, email us. We respond within one calendar month. There is no charge for a reasonable request.

If you believe we have mishandled your data, you can complain to the UK Information Commissioner’s Office (ico.org.uk). We would prefer the chance to put it right first.

International transfers

Our servers are in Germany (Hetzner, Falkenstein). Backups are stored encrypted with Backblaze B2 in the EU. Some service providers (Stripe, Cloudflare, Resend) operate globally; transfers outside the UK and EEA happen under the appropriate Standard Contractual Clauses or adequacy decisions.

Cookies

We use a small number of cookies, all listed in our cookie banner the first time you visit. Strictly-necessary cookies (sign-in, basket, cookie-preference) cannot be disabled because the site does not function without them. Analytics and marketing cookies are off by default and only run if you accept.

Updates to this notice

We update this notice when our practices change. The effective date at the top tells you when. Material changes are emailed to active customers.

Questions

For any data-protection question, write to [email protected]. We treat every request seriously.

Contact page