PRIVACY AND DEVICE STORAGE POLICY
for the Salonivo service
Document date: 18 September 2026
| This Policy distinguishes two roles: (1) the Service Provider as controller of Account/billing/support data and (2) the Service Provider as processor of data entered by the salon. This Policy should not be replaced with a “GDPR consent” – the legal basis depends on the purpose of processing. |
1. Data controller
| Controller | H&S Agnieszka Adamska |
| Address | ul. Bażantów 24/9, 40-668 Katowice |
| Polish Tax ID (NIP) | 2220930216 |
| Privacy e-mail | kontakt@salonivo.pl |
| Data Protection Officer (DPO) | Not appointed unless such an obligation or decision arises in the future |
2. When the Service Provider is the controller and when it is the processor
• The Service Provider is the controller of data necessary to create and operate the Account, handle billing, licences/subscriptions, contact, support, security and fraud/abuse prevention.
• If the Customer enters personal data of employees, contractors or clients into the Salon, the Customer determines the purposes and scope of that data and, as a rule, remains its controller. The Service Provider processes the data on the Customer’s behalf under the Data Processing Agreement.
• The Customer should provide persons whose data it enters with its own privacy notice covering the use of the SaaS system.
3. Categories of data and purposes
| Category | Examples | Purpose | Legal basis |
| Account data | name/display name, e-mail/login, account and salon identifiers | registration, sign-in, provision of the service | Art. 6(1)(b) GDPR – performance of a contract |
| Business and billing data | business name, NIP, sales-document data, plan/licence, payment | billing, invoicing, tax obligations | Art. 6(1)(b) and (c) GDPR |
| Support data | ticket content, correspondence, technical details of the issue | handling support requests and complaints | Art. 6(1)(b) or (f) GDPR |
| Security and operational data | sign-in time, technical identifiers, session/synchronisation information, IP address in provider logs | security, diagnostics, fraud/abuse prevention | Art. 6(1)(f) GDPR |
| Marketing data – if enabled | e-mail, consent history | newsletter/offers | Art. 6(1)(a) GDPR and any required electronic-communications consents |
| Salon data processed on behalf of the Customer | employee names, service reports, settlements, settings, notes entered by the Customer | operation of Application functions | Art. 28 GDPR – processing on the Customer’s instructions; the Customer determines the legal basis in relation to data subjects |
4. Sources of data
• directly from the Customer/User during registration, configuration, use of the Application and contact with support
• automatically from systems and devices during use, to the extent necessary for security, sessions, synchronisation and diagnostics
• from payment or infrastructure providers – only to the extent necessary for billing or service operation, where such an integration is used
5. Device storage, PWA and local data
• The Application uses browser/device storage mechanisms necessary for operation: localStorage, sessionStorage, IndexedDB, Cache Storage and Service Worker.
• Local storage may contain, among other things, Salon settings, local caches of reports and settlements, rotating local backups, version/licence data, synchronisation cursor, technical session data and interface settings.
• If the User chooses to remember sign-in details, the identifier/login may be stored locally. In the current version, on supported devices, the password is encrypted locally using Web Crypto/AES-GCM and stored in IndexedDB; if a secure mechanism is unavailable, the Application should not store the password in plain text.
• The “Log out and remove data from this device” function is used to remove local data from that device. Before using it, the User should ensure that the cloud state has been synchronised correctly.
• As of this version, the Application does not use advertising/marketing cookies in its own code. If non-essential analytics or marketing tools are added in the future, a prior-consent mechanism compliant with applicable law will be implemented.
• Storage mechanisms necessary to provide a service requested by the User may be used without separate consent under the exception for elements strictly necessary to provide that service; the User should nevertheless receive clear information about their purpose.
6. Recipients and infrastructure providers
• Data may be entrusted to providers of hosting, databases, authentication, CDN, e-mail, support, payments or accounting – only to the extent necessary for their role.
• The Application’s current technical architecture uses, among others, Supabase (backend, authentication and database), Netlify (hosting/front-end/CDN) and Plus Five Five, Inc. / Resend (transactional messages and e-mail notifications).
• Public authorities may receive data where required by applicable law and a valid request.
7. Transfers outside the EEA
• The main Supabase project data is configured in the Central EU (Frankfurt) region. The project location alone does not mean that every ancillary process of the provider takes place exclusively within the EEA.
• Some providers may process certain data outside the EEA. Resend states that customer data, including message content and delivery logs, is stored in the United States; transfers are protected, among other mechanisms, by Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable. In other cases, the Service Provider uses GDPR transfer mechanisms appropriate to the relevant provider.
8. Retention periods
• account and contractual data – for the duration of the agreement and then for the period necessary to establish, pursue or defend claims and handle settlements;
• accounting/tax documents – for the period required by tax and accounting law;
• support/complaint correspondence – until the case is closed and for a period justified by possible claims or the need to return to the request;
• security/diagnostic data – for the period necessary for security and incident analysis, in accordance with the providers’ actual log configuration;
• Salon data processed as processor – for the duration of the service and, after termination, in accordance with the Data Processing Agreement; as a rule, deletion from active systems within up to 30 days, subject to backup rotation and legal obligations.
9. Rights of data subjects
• right of access to personal data and to obtain a copy
• right to rectification
• right to erasure – where the relevant conditions are met
• right to restriction of processing
• right to data portability – where applicable
• right to object to processing based on legitimate interests
• right to withdraw consent at any time – without affecting the lawfulness of processing carried out before withdrawal
• right to lodge a complaint with the President of the Personal Data Protection Office (UODO)
If a request concerns data for which a specific salon/employer is the controller, the Service Provider may forward the request to that controller or direct the person to the appropriate contact point.
10. Automated decision-making
The Service Provider does not plan to make decisions about Users that produce legal effects or similarly significantly affect a person solely on the basis of automated processing. Statistics and rankings in the Application are informational and operational.
11. Security
• encrypted HTTPS/TLS connections
• authentication and role-based access control to the Salon
• logical separation of salon data on the backend
• local encryption of remembered passwords on supported devices
• Application and Service Worker updates
• procedures restricting administrative access to data and handling incidents
• regular tests and reviews appropriate to the scale and risk of the service
12. Contact and changes to this Policy
Privacy questions should be sent to kontakt@salonivo.pl. This Policy may be updated due to changes in law, functionality, infrastructure or providers. The date of the current version should always be visible in the Application.
