Privacy Policy
Last updated: 5 October 2026
1. Who is covered and who processes your data?
This policy covers visitors, customers, professionals and their teams on the Bookelya website and in the customer and professional mobile apps. It also covers people whose records a salon imports or creates, even if they have no Bookelya account.
Bookelya is operated by KURT Brûsk, an individual trading as NOWAVE, enterprise number 0803.438.231, VAT BE 0803.438.231, Rue T. Marcotty 5A, 4101 Seraing, Belgium. Contact: contact@bookelya.com; telephone: +1 646 208 2714.
Bookelya is the controller for accounts, the marketplace, searches and booking tracking in your account, billing professionals for its services, its support, security and its own marketing. The salon is a separate controller for preparing, providing and billing its treatments.
For the calendar, customer records, notes, forms and campaigns managed for a salon, the salon determines the purposes and legal bases; Bookelya acts as processor on its instructions. The salon must provide its own privacy information, including if you have no Bookelya account. Stripe is a separate controller for its payment, verification and compliance purposes.
2. What data and what sources?
You provide your contact details, login credentials, preferences, bookings, messages, reviews and, depending on the features used, photos or form answers. Professionals also provide their business identity, salon details and services, billing information and team permissions. Passwords are stored as hashes.
A salon may enter or import your contact details, date of birth, preferences, notes and history. Your verified email address may be used to link a salon record to your account so you can view your appointments. If a link is incorrect, contact us and the salon to have it corrected.
Google, Facebook or Apple sign-in provides the information authorised by that provider, including the login identifier and available contact details. Payments and subscription purchases provide references, amounts, statuses and information needed for tracking. Bookelya stores neither full card numbers nor card security codes. Identity documents and bank details requested by Stripe are collected in its own flow.
Technical data includes IP addresses, browser and device information, notification identifiers, logs, interactions and the source of visits or campaigns. Published reviews and salon business information are available to visitors as displayed. Salon contact details may also originate from an import into the directory.
3. Purposes, legal bases and retention
Contract covers operations needed for the service you request. Legitimate interests concern reliable operation, security, support and defending rights; you may object based on your situation. Consent applies to optional uses that require it. Legal obligations concern accounting records in particular. For salon processing, the salon must determine the applicable legal basis.
The periods below distinguish automatic deletion, retention obligations and processing whose duration depends on actual need. Data is cleaned up when the scheduled task runs; an outage or an operation still in progress may delay it. The absence of automatic deletion does not justify indefinite retention. Contact us or the relevant salon to request erasure of data that is no longer needed.
| Purpose and controller | Data categories | Legal basis | Retention and current limitations |
|---|---|---|---|
| Accounts and marketplace | Identity, contact details, credentials, preferences, favourites, history and reviews. | Performance of a contract (Art. 6(1)(b)). | For the lifetime of the account. Customer accounts with no login or booking for 3 years are deleted after a warning email sent 30 days beforehand. Professional accounts are not automatically deleted for inactivity and follow termination of the contractual relationship. Reviews are published and retained for 3 years after publication, then deleted. Legal exceptions and financial evidence follow their own rules. |
| Salon calendar and customer records | Appointments, identity, contact details, birth date, preferences, notes and attachments. | Basis determined by the salon: contract for the treatment, justified legitimate interest for follow-up; additional condition for health data. | The salon determines the period needed to manage its relationship with you and meet its obligations, and must delete data that is no longer needed. There is no general automatic deletion of old appointments, notes or attachments. Deleting your customer account does not delete the salon’s records; you may request erasure from the salon, subject to its legal obligations. |
| Form answers and photos | Answers, photos, question shown, respondent and date; health data where necessary. | Basis determined by the salon (Art. 6) and, for health data, an Art. 9 condition, including explicit consent where required. | Answers and photos, including health data: deletion 24 months after the customer’s last appointment at the salon, when daily cleanup runs. Files reserved by a payment operation still in progress may remain necessary until it is resolved. |
| Temporary form photos | Private file, upload token, uploader and expiry date. | Performance of a contract (Art. 6(1)(b)). | Unattached upload: expires after 24 hours, then a one-hour grace period and the next daily cleanup. Orphaned file without expiry: after 24 hours and the next run. Files reserved by an open payment are kept until its outcome. |
| Salon claim supporting documents | Supporting document, applicant and decision. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Document deleted on the daily run after 30 days from processing the request. Unprocessed requests are excluded. The purge targets the document, not the whole request. |
| Treatment payments and contractual evidence | Amounts, statuses, Stripe references, refunds, disputes and accepted terms. | Contract for tracking; legal obligation for required records; legitimate interest for evidence and disputes. | Open operations remain subject to monitoring. Records required by law are retained for the applicable period; evidence relating to a complaint or dispute remains necessary until it is resolved and the applicable periods for legal remedies expire. The financial ledger is not subject to general automatic deletion; minimal financial identity information may remain after account deletion. |
| Accounting and professional billing | Billing identity, invoices, amounts and accounting records. | Legal obligation (Art. 6(1)(c)) for accounting records; contract to manage the subscription. | Invoices and accounting records are retained for the statutory periods applicable to their nature and the country concerned. Documents still needed for an audit or dispute may be retained for that purpose. No overall automatic deletion of these archives is provided; retaining them does not permit customer records to be reused for other purposes. |
| Technical subscription events | Stripe or store events, references and technical processing data. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Stripe subscriptions: processed receipts deleted after 30 days. Stores: processed events after 30 days, quarantined events after 90 days, completed tasks after 30 days. Unfinished events are retained. Daily cleanup. |
| Technical treatment payment events | Raw payment event content and tracking references. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Raw content erased after 30 days from processing if payment facts have been durably recorded; daily run. Unresolved or unreconciled events are retained. Tracking records and financial records are kept separately. |
| Mobile purchase references after deletion | Billing references dissociated from the account and purchase chain. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | References marked for deletion: 12 months after the chain’s last definitive event, provided no active entitlements, refund, dispute or pending event remain. Daily cleanup. This period does not apply to the general financial record. |
| Security and technical logs | Technical references, incidents, IP or request information depending on the log. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Scheduled rotation: general daily logs, API logs and public identifier logs, 14 days; Smart QR, 30 days; billing and payment alerts, 90 days. These periods apply to application logs configured with rotation, not all diagnostic copies or external alerts. A log without rotation has no automatic deletion; retention must remain limited to security or evidential needs. |
| Support and rights requests | Contact details, messages, correspondence and information needed for the request. | Contract for service support; legitimate interest for enquiries; legal obligation for exercising rights. | Correspondence is retained for as long as needed to handle and follow up the request or defend a right, subject to legal obligations. Support correspondence and email inboxes have no general automatic deletion. You may request erasure of messages that are no longer needed. |
| Direct marketing and campaigns | Contacts, preferences, segments, attribution, sends, opens and opt-outs. | Consent where required; for the salon, a lawful basis to determine by channel and existing relationship. Objections must be honoured. | Sending must stop after an applicable withdrawal or objection. Objections and necessary evidence may be retained to avoid contacting you again and demonstrate that your choice was respected. There is no general automatic deletion of prospects, deliveries or statistics; retention must remain limited to the relevant purpose and legal basis. |
| Maps, analytics and optional advertising | Searches, position if authorised, IP, pages, measurement identifiers and events. | Consent for optional uses that require it (Art. 6(1)(a)). | Cookie lifetimes are detailed in the separate policy; they are not the retention periods for data held by providers. Measurement data follows the settings of the relevant service. You can withdraw consent for uses that depend on it and request erasure under the GDPR. There is no general local automatic deletion of measurement data. |
| Devices and mobile notifications | Notification identifier, platform and linked account. | Contract for service messages; consent for notification permission and marketing that requires it. | Devices remain registered until removed or the account is deleted; there is no periodic deletion of inactive devices. You can disable notifications on your device. Data sent to the provider is subject to its policy and applicable rights. |
| Technical backups | Copy of the database and backed-up files, including recently deleted data. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Deletion in the application does not guarantee immediate erasure from backups. Normal 30-day cycle: all copies for 7 days, then one daily copy for 23 days. The latest recoverable copy may remain longer if new backups fail. These copies are for technical recovery and must not allow a use to resume after you have objected to it. |
| Mobile payment tokens and subscription previews | Exchange token, account reference and change preview. | Legitimate interests in service reliability and security (Art. 6(1)(f)). | Payment token valid for 5 minutes, session limited to 60 minutes; token deleted on the daily run after 24 hours from expiry. Expired unaccepted previews are cleaned daily; evidence of started operations is retained. |
4. Forms and health data
Custom forms may collect allergies, contraindications or other health information necessary for a treatment. The salon is the controller; Bookelya hosts and processes answers on its behalf. Before collection, the salon must explain the purpose, whether answers are mandatory or optional, who can access them and the retention period. It must limit questions and photos to what is strictly necessary.
A legal basis under Article 6 GDPR and a condition under Article 9 are required. Where explicit consent is the condition used, it must be specific, separate, freely given, informed and withdrawable through the salon. Reading this policy, accepting the terms or booking does not constitute explicit consent to processing health data. Refusal must not prevent a treatment for which this information is unnecessary.
Answers are linked to the relevant salon; form photos use private storage and temporary links. Access must be limited to salon staff who need it and to necessary authorised technical interventions. Answers and photos, including those containing health data, are deleted 24 months after your last appointment at that salon. The salon must obtain and be able to demonstrate explicit consent where required; a generic checkbox alone is insufficient. The current forms do not include a dedicated health consent mechanism; the salon must keep that evidence separately before collection. Do not send health data in public reviews or support chat.
5. Who receives the data?
Your chosen salon and its authorised team receive the information needed for your booking and treatment. Other salons do not gain access to its customer records merely by using Bookelya. Authorised operations and support staff may access information needed for their intervention. The providers below are involved depending on the features used and their activation.
Authorities or advisers may receive only the information needed to meet a legal obligation or defend a right. Sign-in services, app stores and Stripe also have their own purposes and policies. Inclusion in this list does not mean that they are all processors for the salon.
| Provider | Role and data concerned | Processing countries | Safeguards and provider information |
|---|---|---|---|
| Hetzner | Processor: hosting the application, database and backups. | Germany: Bookelya application, database and backups. | The main service is provided within the EEA, with no transfer outside the EEA for that service. The provider’s data processing agreement applies. Provider information |
| Resend | Processor: service emails and campaigns; recipient, content and delivery metadata. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Twilio | Processor: verification codes, text messages and campaigns; number, content, delivery and opt-out. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Stripe | Stripe may process payments, verification and fraud prevention information for its own purposes and obligations as a separate controller; customer payments, Connect and professional billing. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Crisp | Processor for activated support chat: name, email, messages and session information. | France for the main service. | The main service is provided within the EEA, with no transfer outside the EEA for that service. The provider’s data processing agreement applies. Provider information |
| Cloudflare Turnstile | Anti-bot protection when enabled: technical information about the device and connection. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| OneSignal | Processor for mobile notifications: device identifiers, content and notification links. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Google Tag Manager / Google Analytics / Google Ads | Tag management, analytics, attribution and events, including server measurement if enabled; IP and technical identifiers. Role depends on the service. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Microsoft Clarity | Interaction analysis if the relevant tags are enabled and subject to applicable consent. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Google (connexion) | Separate controller for its account; chosen sign-in and sharing authorised identifier, profile and contact details. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Facebook (connexion) | Separate controller for its account; chosen sign-in and sharing authorised profile information. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Apple (connexion) | Separate controller for its account; chosen sign-in, identifier and available email address, including private relay. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| RevenueCat | Technical management of professional mobile subscriptions if enabled: billing identifier, purchases, entitlements and events. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Apple App Store / Google Play | Separate controllers for their stores and purchases; professional subscription references and statuses exchanged for tracking. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| OVH | Domain registration and management if this option is used: domain, purchase contact and technical data. Role depends on registry obligations. | France for the main service; recipient registries depend on the domain extension. | The main service is provided within the EEA, with no transfer outside the EEA for that service. The provider’s data processing agreement applies. Provider information |
| Apple MapKit | Maps, address search and geocoding: IP, queries and coordinates used. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Adobe Fonts / Typekit | Fonts loaded by the browser: IP and technical request information. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
| Slack | Technical alerts if the channel is enabled; incident information and limited references depending on the channel. Customer records and health data must not be copied into alerts. | United States and other countries depending on the service and its recipients; transfers outside the EEA are possible. | The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914). Provider information |
6. Hosting and international transfers
The application, its database and backups are hosted in Germany by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The main service of Hetzner, Crisp and OVH is provided within the EEA and their data processing agreement applies. Other services may transfer data outside the EEA, including to the United States; their location and onward transfers depend on the service used.
The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are covered by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
7. Communications, cookies and mobile apps
Confirmations, reminders, login codes and messages needed for the service are distinct from commercial offers. The salon must have the required legal basis for its campaigns; Bookelya provides sending and unsubscribe tools. You can use unsubscribe links, available account preferences and, for the relevant text messages, reply STOP.
Cookie choices cover statistics, advertising and personalisation in particular. Google measurement and advertising tags and the attribution cookie require consent to the relevant category. Adobe Fonts remain loaded and transmit your IP address to Adobe in the United States even after optional cookies are refused. Retention periods and available choices are described in the cookie policy.
In the apps, device identifiers and notification tokens are used to send messages to registered devices. You can manage notifications and location, camera or photo permissions in your device settings when a feature requests them. Maps and place searches may send an address or location to Apple MapKit.
8. Children and young people
Accounts and online bookings are reserved for people aged at least 16. For a younger minor, a parent or guardian creates the account in their own name and makes the booking. This condition relies on the user’s declaration: current flows do not systematically verify date of birth. App store age ratings do not replace this rule. The salon must check the authorisations needed for any treatment involving a minor.
Where processing relies on a child’s consent for an online service, digital consent rules apply: age 13 in Belgium and 15 in France; below those ages, the holder of parental responsibility must be involved. These thresholds do not replace contractual capacity rules or authorisations relating to health data. A parent may contact us to report an account or exercise rights under the applicable legal conditions.
9. Profiling, automation and artificial intelligence
Search and ranking use factors including requested criteria, availability and salon information. Salons may select campaign recipients by history, birthday or activity. These segments personalise their communications; you can opt out of marketing. Advertising tags may support interest profiles depending on the applicable choices and settings.
The platform automates certain confirmations according to the salon’s choice, reminders, payment tracking and technical access limits. These rules may have practical consequences for a booking or subscription. If a problem arises, ask the salon or Bookelya for an explanation and intervention depending on the operation; Stripe’s own banking checks also fall under its procedures.
No artificial intelligence tool processes your data at present. For a solely automated decision producing legal or similarly significant effects, the safeguards in Article 22 of the GDPR remain applicable, including human intervention and the right to contest the decision where provided for.
10. Your rights and how to exercise them
Subject to GDPR conditions, you may request access and a copy, rectification, erasure, restriction, portability of data you provided that is processed automatically on the basis of contract or consent, and object to processing based on legitimate interests. You may always object to direct marketing and related profiling. You may withdraw consent without affecting the lawfulness of earlier processing.
Write to contact@bookelya.com or NOWAVE’s postal address above. Specify the account or salon concerned and your request, without sending identity documents or health data unsolicited. Proportionate additional verification may be requested if there is reasonable doubt about your identity. For salon processing, also contact the salon; we forward requests falling under its responsibility and assist it as processor.
We respond without undue delay and no later than one month after receipt. Where justified by complexity or the number of requests, the period may be extended by two months; we inform you within the first month and explain why. Any restriction or refusal is explained, with available remedies. Exercising rights is generally free, subject to the legal rules for manifestly unfounded or excessive requests.
Deleting an account or booking does not automatically erase necessary payment records or the records the salon must manage as a separate controller. You can delete your account using the available website or app features, or ask support for help. Appointments with financial history may remain subject to tracking, and some professional deletions are blocked while financial operations remain open. Backups follow their own cycle.
You may lodge a complaint with Belgium’s Data Protection Authority (APD), France’s Commission nationale de l’informatique et des libertés (CNIL), or the authority where you usually live or work or where the alleged infringement occurred. You do not have to contact us first.
Data Protection Authority (Belgium)CNIL (France)Account deletion information
11. Security and incidents
Passwords are stored as hashes. Other protections provided include access controls by salon and permission, checks for sensitive actions, private files and temporary links for forms, attempt limits and payment signature verification. Database backups are scheduled nightly and full backups weekly. Production connections use HTTPS. These measures reduce risk without guaranteeing that incidents cannot occur.
When bot protection is enabled, we use Cloudflare Turnstile on the website and in the apps to protect registration, Pro login, password reset requests, Bookelya contact forms and verification code delivery against automated abuse. This service analyses technical information about your device and connection.
We do not claim that all files and backups are encrypted at rest or that a security audit or certification has been obtained. In the event of a breach, applicable duties include notifying the competent authority within 72 hours of becoming aware of it where required, informing affected people where there is a high risk and alerting the salon without undue delay where Bookelya acts as processor.
12. Contact and changes to this policy
For questions, rights requests or information about recipients, contact contact@bookelya.com or NOWAVE, Rue T. Marcotty 5A, 4101 Seraing, Belgium. The salon remains your contact for its own processing. Material changes to this policy must be communicated appropriately; a new use requiring consent needs appropriate consent.