Privacy Policy
Updated 2026-07-28
This describes what personal data Ayzora processes, why, and who we share it with. It covers both the salons using the service and those salons' clients.
1. Roles: who is responsible for what
For a salon's client data, the SALON is the controller - it decides whom to record and why. We act as processor, handling that data on the salon's instructions. For the salon's own data and its staff accounts, we are the controller.
2. What we process
From the salon: name, address, contacts, staff details (name, email, role), subscription payment details (handled by Stripe - we only see the last digits of the card). From the salon's clients: name, phone, email, visit history, amounts paid, notes and tags added by the salon, reviews. Technical: IP address and request time in logs, for security and abuse prevention.
3. Why, and on what basis
Performance of a contract - to make the service work: bookings, reminders, payments. Legitimate interest - security, abuse prevention and basic service analytics. Consent - marketing campaigns the salon sends to its clients through us; every message carries an unsubscribe link.
4. Client notifications
Appointment reminders go out by email, Telegram or WhatsApp, depending on what the salon enabled and what the client chose. These messages pass through the corresponding providers listed in the table below.
5. AI analytics
When a salon generates an AI report, a summary of the period's metrics is sent to the model - revenue, occupancy, visit counts - along with staff names and service names. Client names, phone numbers and email addresses are not included in that summary.
6. Where data is stored
The main database and the application are hosted in the European Union. Some providers in the table below also process data in the United States; those transfers rely on the EU Standard Contractual Clauses.
7. How long we keep it
Salon data - for the life of the subscription and 90 days after it ends, so you can come back without losing anything. After that we delete it on request or automatically. Logs containing IP addresses - up to 90 days. Accounting records - as long as the law requires.
8. Your rights
You have the right to obtain a copy of your data, correct it, delete it, restrict or object to its processing, and port it to another service. Clients of a salon should contact that salon first - it is the controller; we help it fulfil the request. You may also complain to your data protection authority.
9. Cookies
We use only technical cookies: the login session, the chosen language, and the current salon. There are no advertising or third-party analytics cookies, which is why there is no consent banner.
10. Security
Passwords are stored only as hashes, access between salons is separated at the database level, connections are encrypted, and administrator actions are logged. If a breach is likely to affect your rights we will inform you and the supervisory authority within 72 hours.
11. Changes to this policy
The current version is always on this page, with the update date at the top. We notify the salon owner by email about significant changes.
Who we share data with
| Company | Purpose | Processed in |
|---|---|---|
| Vercel | Application hosting | EU (Frankfurt) |
| Neon | Database | EU |
| Upstash | Rate limiting (Redis) | EU |
| Stripe | Subscription payments | EU / USA |
| Resend | Transactional email | EU / USA |
| Anthropic | AI analytics: aggregated salon metrics and staff names | USA |
| Telegram | Bot notifications - if the salon enables them | per Telegram's terms |
| Meta (WhatsApp) | WhatsApp notifications - if the salon enables them | per Meta's terms |