British Institute of LasersLoading page

Privacy and data protection

Privacy Policy

This notice explains how ZARAX (UK) LIMITED, trading as British Institute of Lasers, uses personal information when you visit our website, make an enquiry, request a demonstration, contact our service team or otherwise deal with us.

Who is responsible for your information

Data controller: ZARAX (UK) LIMITED, trading as British Institute of Lasers. Company number 06881441. Registered office: 19 Trossachs Road, Coventry, CV5 7BJ. Our showroom and trading address is 1 Ensign Business Centre, Westwood Business Park, Coventry, CV4 8JA.

You can raise a privacy question or data-protection complaint through our Contact page or by writing to the registered office above.

Information we collect

Depending on how you use the site, we may collect:

  • name, email address, telephone number and business/contact details;
  • information you provide in product enquiries, request-details forms and demonstration requests;
  • machine model, serial number, fault description, photographs, video or diagnostic information supplied for servicing and technical support;
  • information supplied when requesting a valuation, selling a laser, asking about Laser Protection Adviser services or making another business enquiry;
  • correspondence, appointment details and records of our response;
  • marketing preferences and records of consent, opt-out or suppression;
  • technical information such as IP address, browser/device information, security logs and website interactions;
  • cookie, analytics and similar storage/access information where the relevant technology is permitted or you have given any required consent.

Please do not submit health information or other special-category personal data unless we have specifically asked for it and it is necessary for the purpose being discussed.

Why we use personal information

We use personal information to respond to enquiries; provide quotations, demonstrations, training, servicing and support; administer orders and customer relationships; maintain security; improve our website and services; meet legal/accounting obligations; and send marketing where the law permits.

Our lawful bases may include taking steps at your request before entering a contract, performing a contract, complying with a legal obligation, pursuing legitimate interests such as responding to business enquiries and protecting our systems, and consent where consent is required or is the most appropriate basis.

Marketing

A request for information about a product or service allows us to answer that request; it does not automatically mean you have agreed to unrelated marketing. Where PECR or data-protection law requires consent for electronic marketing, we ask for a clear positive opt-in. Where a lawful soft opt-in or business-to-business rule applies, we still provide a simple way to opt out.

You can withdraw marketing consent or object to direct marketing at any time. We may keep a minimal suppression record so that we can respect an opt-out rather than accidentally adding the address back to a marketing list.

Cookies, analytics and similar technologies

We use storage and access technologies such as cookies, local storage, scripts and tags for site operation, security, preferences, measurement and—where enabled—marketing. Technologies that are strictly necessary, or otherwise fall within a legal exemption, may operate without consent. Where consent is required for analytics, advertising or other non-essential technologies, we use the website consent controls before enabling them.

You can change or withdraw cookie choices using the site’s cookie/privacy controls. Blocking some technologies may affect optional features, but core access to the site should not depend on accepting non-essential tracking.

Who receives information

We may use service providers acting on our behalf for website hosting, security, analytics, form/email delivery, customer communications, document storage, professional advice and—where you choose to use them—finance or payment-related services. We only provide the information reasonably required for their role and expect processors to protect it under appropriate contractual terms.

We may also disclose information where required by law, to establish or defend legal rights, or in connection with a genuine business reorganisation subject to appropriate safeguards.

International transfers

Some technology providers may process information outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, we use an applicable adequacy arrangement or appropriate contractual/other safeguards and assess the transfer as required.

How long we keep information

We keep information only for as long as it is reasonably needed for the purpose collected, our relationship with you and applicable legal requirements. As a working retention schedule, general enquiries are normally retained for up to 24 months after the last meaningful contact unless they develop into a customer or support relationship; order, warranty, servicing and accounting records may be retained for up to six years where needed for contractual, tax or legal purposes; marketing records are kept until consent is withdrawn or you opt out, with a limited suppression record retained to honour that choice; security and technical logs are normally retained for shorter operational periods unless an incident requires longer investigation.

Your data-protection rights

Depending on the circumstances, you may have rights to be informed, access your personal information, correct inaccurate information, request erasure, restrict processing, object to processing, receive portable information, and withdraw consent. You also have rights relating to certain automated decisions.

We do not intend to make decisions about individuals solely by automated means where those decisions produce legal or similarly significant effects.

To exercise a right, contact us through the Contact page. We may need information to verify identity before releasing or changing personal data.

Data-protection complaints

If you believe we have handled your personal information incorrectly, please contact us first so we can investigate. We will acknowledge and investigate data-protection complaints, keep appropriate records and respond without undue delay.

You also have the right to complain to the UK Information Commissioner’s Office (ICO). Information about raising a concern is available on the ICO website.

Security

We use technical and organisational measures intended to protect personal information against unauthorised access, loss, alteration and disclosure. No internet service can guarantee absolute security, so we also review access, software and security controls as the site changes.

Children

Our website and professional equipment services are intended for businesses, clinics and adult practitioners. They are not directed at children and we do not knowingly use the site to collect children’s information for marketing.

Changes to this policy

We update this notice when our services, forms, technology providers or legal requirements materially change. The current version will be published on this page.

Last reviewed: 17 August 2026.

This website notice should be reviewed alongside the organisation’s internal retention, processor, marketing-consent and security records. It is not a substitute for tailored legal advice where a processing activity creates additional risk.

Scroll

Our site uses cookies. By using this site, you agree to the Privacy Policy and Terms of Use.