Data processing

Your data stays your data.

Saloncare processes your guests' personal data on your behalf and on your instructions. This overview summarises what the data processing agreement under Article 28 GDPR governs. We provide the full agreement as an annex on request.

Roles

Who is the controller, and who processes.

Under the General Data Protection Regulation you, as the salon, are the controller. Saloncare is the processor and acts solely on your documented instructions.

This is an English translation provided for convenience. The German version is the legally binding one.

You decide on the purpose and means of processing your guests' data; Saloncare provides the tool and processes that data only where it is necessary for the agreed service and where you have instructed it. There is no processing for Saloncare's own purposes.

This page reproduces the content of the data processing agreement in short form. The signed agreement, which we provide as an annex on request, is what governs.

Subject matter and duration

What it covers, and for how long.

Subject matter

The processing of personal data in the course of providing the Saloncare platform as an intelligent layer above the point of sale and booking system you already have.

Nature and purpose

Storing, structuring, analysing and providing salon and guest data for appointment management, consultation, billing and, where consent is given, communication.

Duration

For the term of the main contract. After it ends the data is deleted or returned, as you choose, unless a statutory retention obligation applies.

Location

Processing takes place on servers in Germany under German data protection law. Processing outside the EU does not take place without a separate legal basis.

Data subjects

Whose data we touch.

On your behalf we process data belonging to the people in contact with your salon. The circle is deliberately kept narrow.

  • Guests and clients of your salon, including prospective clients who enquire about an appointment.
  • Employees of your salon, insofar as they use the tool or appear in reporting.
  • Contacts at suppliers and manufacturers, insofar as you use the data bridge.
  • Other contacts you record in the system yourself, for instance for referrals or communication.

Categories of data

Which data is processed.

We process sparingly: only what the service actually needs. The categories below may arise depending on the features you use.

  • Master data: name, address, contact details, date of birth, where recorded.
  • Appointment and treatment data: history, services, notes, colour formulas, the consultation form.
  • Image data: before and after shots and treatment photos, where you take them.
  • Billing data: revenue, tips and commission entries, payment status.
  • Communication data: messages, reminders and consents, where used.
  • Usage data: access records and logs required for operation and security.

Particular care

Data that is especially protected.

Health-related information, such as skin sensitivities or intolerances in the consultation form, belongs to the special categories of personal data under Article 9 GDPR. We process such data only where you record it and a legal basis exists; as a rule, the data subject's consent.

Obtaining those consents remains your responsibility. Saloncare gives you the tools to document consents cleanly and to withdraw them on request.

Technical and organisational measures

How we protect the data.

The technical and organisational measures describe how we ensure a level of protection appropriate to the risk. The list below is a summary; the full statement is an annex to the agreement.

Encryption

Transmission and storage are encrypted. We rely on proven standards, not on home-made solutions.

Access control

Roles and permissions ensure each person sees only what they need. Access is logged and reviewed regularly.

Data separation

The data of different salons is logically separated. Test environments do not work with real guest data.

Availability

Operation on resilient infrastructure, with backups and a rehearsed restart after incidents.

Resilience

Regular backups and a documented procedure for restoring availability after an incident.

Commitment

Everyone entrusted with the processing is bound to confidentiality and trained in data protection.

Subprocessors

Who we bring in.

To deliver the service we use carefully selected subprocessors, for instance for hosting and infrastructure. With every subprocessor there is a contract that ensures an equivalent level of data protection. Processing takes place primarily in Germany and the European Union.

SubprocessorPurposeLocation
CloudflareHosting, delivery and databaseEU region, processing in Germany and the EU
Further subprocessors (planned)as required, for instance communicationEU preferred

We provide the current, complete list of subprocessors with the data processing agreement. We inform you of planned changes in good time, so that you can object.

Your rights and obligations

What you are entitled to, what we deliver.

  • Right to instruct: we process solely on your documented instructions.
  • Support: we help you meet your guests' requests for access, erasure and rectification.
  • Notification: in the event of a personal data breach we inform you without undue delay.
  • Audit: you can verify compliance with the agreed measures; we provide the necessary evidence.
  • Return and deletion: after the contract ends we return or delete the data, as you choose, unless a retention obligation prevents it.

The full agreement

How to obtain the DPA.

This overview does not replace the data processing agreement, it summarises it. We provide the full agreement under Article 28 GDPR, including the detailed technical and organisational measures and the current subprocessor list, as an annex on request.

Write to hello@salon.care. Before your salon goes into production we conclude the data processing agreement together.

Questions

Frequently asked questions.

What is a data processing agreement?

A contract under Article 28 GDPR governing how a service provider processes personal data on your behalf. It sets out the subject matter, purpose, duration, categories of data and protective measures.

Am I or is Saloncare responsible for the data?

You, as the salon, are the controller. Saloncare is the processor and processes your guests' data only on your documented instructions.

Where is my data processed?

On servers in Germany under German data protection law. Processing outside the European Union does not take place without a separate legal basis.

Which data does Saloncare process on my behalf?

Master data, appointment and treatment data, image data, billing and communication data, and the usage data needed for operation; always sparingly and only as far as the service requires.

How do you handle health data from the consultation form?

Such information belongs to the special categories under Article 9 GDPR. We process it only where you record it and a legal basis exists, as a rule consent.

Which subprocessors do you use?

Carefully selected providers for hosting and infrastructure, primarily in Germany and the EU, such as Cloudflare. The complete, current list is attached to the agreement.

What happens to my data after the contract ends?

It is deleted or returned, as you choose, unless a statutory retention obligation prevents it. You keep sovereignty over your data.

How do I get the full DPA?

As an annex on request. Write to hello@salon.care; before your salon goes into production we conclude the data processing agreement together.

The world's best salons run on Saloncare®.

GDPR compliantEncryptedServers in GermanyAudit ready