1. Who we are
BuiltBy2 Ltd operates Elysium Bookings. We are registered in England and Wales under company number 17153424. Our registered office is 44 Stokesay Drive, Cheadle, Staffordshire, ST10 1YU, United Kingdom.
For privacy enquiries or rights requests, email support@builtby2.co.uk.
2. When BuiltBy2 and an Elysium business are responsible
BuiltBy2 Ltd is the controller for Elysium account administration, platform security, subscriptions, service support, product operations, legal compliance and our own communications.
An appointment business is normally the controller for the client records, booking information, forms, treatment information, communications and business policies it creates or collects through Elysium. BuiltBy2 processes that information to provide Elysium on the business's instructions. The business remains responsible for its own privacy notice, lawful basis, staff access and retention decisions.
In some activities both organisations may have separate responsibilities. We will help identify the correct contact if a request concerns information controlled by an Elysium business.
3. Information we collect
Depending on how you use Elysium, we may handle:
- identity, contact, authentication, account and business-profile information;
- staff roles, services, availability, locations, business media and public-listing content;
- client records, appointments, waitlists, requests, messages, reviews, notes, preferences, forms, consents and treatment-related information;
- payment status, transaction references, saved-payment descriptors, refunds, disputes and subscription entitlement information, but not full payment-card numbers;
- files and images you choose to upload, including business media and expense receipts;
- notification preferences, push tokens and delivery information;
- approximate or precise location when you choose a location-based discovery feature and grant device permission;
- device, browser, IP address, session, security, diagnostic and usage information; and
- support, privacy, complaint and business-enquiry correspondence.
4. Where information comes from
Information may come from you, an Elysium business or authorised staff member, a client making a booking, another account user, your device, or a provider you choose to connect. Providers can include Apple, Google, Stripe, Mailchimp and other services shown at the point of connection.
5. Why we use information and our lawful bases
We use information to create and operate accounts; provide bookings, client management and business tools; authenticate users; process payments and subscriptions; deliver messages and notifications; provide support; prevent fraud and misuse; maintain, diagnose and improve the service; keep records; and comply with law.
Depending on the activity, we rely on performance of a contract, compliance with legal obligations, our legitimate interests in operating a secure and reliable service, or consent where the law requires it. Where we rely on legitimate interests, we consider the effect on the people concerned. Consent can be withdrawn without affecting earlier lawful processing.
6. Health and other sensitive information
Client notes, intake answers, allergies, patch-test records, treatment plans or other appointment information may reveal health information or other special-category data. An Elysium business must only collect information genuinely needed for its services and must identify both an Article 6 lawful basis and an Article 9 condition under UK data-protection law.
BuiltBy2 processes this information to provide the business's chosen Elysium features. Do not send unnecessary health information to general support channels.
7. Payments and subscriptions
Stripe processes appointment payments and subscriptions purchased on the web. Apple processes subscriptions purchased in the iOS app and Google processes subscriptions purchased in the Android app. Elysium receives identifiers, payment status, entitlement, refund and lifecycle information needed to provide and reconcile the service. Apple Pay and Google Pay may be offered through the relevant payment provider.
8. Optional connections and business-directed sharing
A business may choose to connect services such as Google Calendar, Google Sheets, Google Drive, Mailchimp, Stripe or Agent Connect. Elysium shares only the information needed for the enabled connection and authorised scope. The business controls whether the connection is enabled and should review the connected provider's terms and privacy information.
Agent Connect allows a business to authorise a compatible external agent to access selected Elysium tools. Access is limited by the scopes the business approves and can be revoked by the business.
Where a business enables Meta Conversions API for its web booking activity, Elysium may send web booking or checkout events to Meta with contact identifiers transformed using hashing for matching. Hashing is not anonymisation. Native iOS and Android booking activity is excluded from this advertising connection for launch. The participating business is responsible for having an appropriate lawful basis and providing any additional notice or choice required for its advertising activity.
9. Who receives information
Information may be shared with the Elysium business and authorised staff involved in a booking; the client concerned; payment and app-store providers; hosting, database, authentication, email, push-notification, form-delivery and support providers; optional providers selected by a business; professional advisers; or public authorities where disclosure is legally required.
Key infrastructure and service providers currently include Supabase, Vercel, Expo, Apple, Google, Stripe, Resend and Formspree. Optional business connections can add other recipients such as Mailchimp and Meta. We do not sell personal information.
10. International transfers
Some providers process information outside the United Kingdom. Where UK law requires a transfer safeguard, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another permitted safeguard. You may ask us for more information about the safeguard relevant to your information.
11. Retention
We retain information only for as long as needed for the purpose for which it was collected, account operation, security, disputes and legal obligations. Retention can differ because an Elysium business controls its own client and treatment records.
Client and business closure requests have a 30-day recovery period before protected deletion processing begins. Completed closure removes account access and information that no longer needs to be retained. Appointments, payment evidence, reviews, clinical records and audit evidence may be retained or anonymised where the relevant business or BuiltBy2 has a lawful operational, financial, fraud-prevention, complaints or legal reason. Backups expire through the applicable protected backup cycle rather than being altered immediately.
12. Account deletion and data export
Account holders can request a machine-readable export before deletion. Client deletion removes the client login and direct account links while preserving business records that must remain. Genuine reviews may remain, but the reviewer identity and direct account association are removed. Business closure removes public availability, services, integrations, assets and team access after the recovery period while preserving records that must lawfully remain.
See the Account deletion guide for the current steps and retained-data summary.
13. Security
We use access controls, tenant separation, encryption in transit, protected credentials, audit records, authentication controls and operational monitoring appropriate to the service. No system can be guaranteed completely secure. Keep account credentials private and contact us promptly if you suspect unauthorised access.
14. Your rights
Depending on the circumstances, UK data-protection law may give you rights to be informed, access information, correct it, erase it, restrict or object to processing, receive portable information, and withdraw consent. You may also object to direct marketing at any time.
Send a request to support@builtby2.co.uk. We may need to verify your identity. If an Elysium business controls the information, we may refer the request to that business or assist it in responding.
You can complain to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the opportunity to address the concern first.
15. Children
Elysium is not intended for children to create business accounts. A business that provides services to a person under 18 remains responsible for obtaining any required parent or guardian authority and for handling that person's information lawfully.
16. Changes and contact
We may update this policy when the service, providers or law changes. Material changes will be brought to account holders' attention where appropriate. The current version and effective date will remain published here.
Privacy contact: support@builtby2.co.uk.