Datenschutzerklärung
Privacy Policy
Last Updated: April 22, 2026
At Salonbear ("we," "our," or "us"), we are committed to safeguarding the privacy of our customers and platform users. This Privacy Policy outlines how we collect, use, process, and protect your personal data when you use the Salonbear SaaS platform, website, and related services (collectively, the "Service").
This Policy is formulated in strict compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws as of 2026.
1. Important Context: Data Controller vs. Data Processor
Salonbear operates as a Business-to-Business (B2B) platform for salon owners.
- Salonbear as Data Controller: When you (the salon owner or representative) register for a Salonbear account, make a payment, or contact our support, we act as the Data Controller of your personal data (e.g., account details, billing info).
- Salonbear as Data Processor: When you use our platform to store the data of your end-clients (e.g., appointment schedules, client contact information), you are the Data Controller, and Salonbear acts strictly as your Data Processor. Our processing of such data is governed by our standard Data Processing Agreement (DPA). We assume no liability for your direct compliance with the GDPR regarding your end-clients.
2. Information We Collect
As a Data Controller, we collect the following categories of data directly from you or automatically via the Service:
- Account Information: Name, email address, phone number, and business details (e.g., KVK number).
- Billing & Financial Data: Credit card details (processed securely by third-party payment processors like Stripe or Curo Payments), billing address, and transaction history.
- Usage & Technical Data: IP addresses, browser types, device information, login timestamps, and platform diagnostic data critical for monitoring performance and security.
- Communications: Records of support requests, feedback, or any correspondence between you and Salonbear.
3. How We Use Your Information (Purpose & Legal Basis)
We strictly limit the use of your data to legitimate business purposes:
- Providing the Service: To deliver core functionalities, manage your account, and provide technical support. (Legal Basis: Performance of a Contract)
- Billing & Administration: To process payments, issue invoices, and prevent fraudulent transactions. (Legal Basis: Performance of a Contract & Legal Obligation)
- Service Improvement & Analytics: To analyze usage trends, optimize our infrastructure, and implement updates. (Legal Basis: Legitimate Interest)
- Marketing & Communications: To send you updates about new features or promotional offers. You may opt out at any time. (Legal Basis: Consent / Legitimate Interest)
- Compliance: To comply with national and international laws, court orders, or regulations. (Legal Basis: Legal Obligation)
4. Data Sharing & Third-Party Processors
In order to provide our Service securely and efficiently, we may share your data with trusted third parties (Subprocessors). We ensure these partners adhere to strict confidentiality and security standards:
- Cloud Infrastructure Providers: Such as Google Cloud / Firebase, for hosting and databases.
- Payment Gateways: For processing subscriptions securely (we do not store raw credit card numbers).
- Analytics & Communication Tools: For performance monitoring and customer relationship management.
- Legal Authorities: We will disclose data if required by law or if strictly necessary to protect Salonbear’s rights, property, or safety.
5. International Data Transfers
Salonbear's primary servers are hosted within the European Economic Area (EEA). If data must be transferred outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, and adherence to updated 2026 international frameworks.
6. Data Security Measures
Salonbear implements rigorous, industry-standard technical and organizational security measures to protect data against unauthorized access, loss, or alteration. These include encryption of data in transit and at rest, role-based access control (RBAC), and continuous monitoring. However, no digital platform guarantees 100% security; use of the Service is at your own risk.
7. Data Retention
We retain your personal data exclusively for as long as is necessary to fulfill the purposes outlined in this Policy, or to comply with statutory retention periods (e.g., Dutch tax laws requiring 7 years of financial records). Upon account deletion, Customer Data is hard-deleted from our active systems within thirty (30) days, except where legally required otherwise.
8. Artificial Intelligence & Algorithms
Inline with the EU AI Act (2026), Salonbear uses algorithms primarily for standard software functionalities (e.g., scheduling logic, basic data matching). We do not use High-Risk AI systems for automated decision-making that produces legal effects concerning you, without explicit human oversight.
9. Your Data Protection Rights
Under the GDPR, you possess the following rights regarding your personal data:
- Right to Access & Portability: Request a copy of the data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure (Right to be Forgotten): Request deletion of your data, barring legal retention requirements.
- Right to Object / Restrict Processing: Limit or object to certain types of processing (e.g., direct marketing). To exercise these rights, please contact info@salonbear.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Cookies & Tracking Technologies
The Service uses cookies and similar tracking technologies to ensure core functionality, track user sessions securely, and analyze performance. For a granular breakdown, please refer to our dedicated Cookie Policy. By default, strictly necessary cookies are always active.
11. Changes to this Privacy Policy
Salonbear reserves the right to modify this Privacy Policy at our sole discretion. Any changes will become effective immediately upon posting to the Service. Continued use of the platform after updates have been published constitutes your acknowledgment and acceptance of the revised terms.
12. Contact Information
If you have any questions or concerns regarding this Privacy Policy or our data practices, please contact us at:
Salonbear KVK: 76377334 Rode Geus 10, 9613DA Meerstad, The Netherlands Email: info@salonbear.com