GDPR and data processing agreement
Updated 24 September 2026
This page is for salons with clients in Europe, the United Kingdom or Canada, and for anyone who wants to know how data processing is arranged. It also serves as the data processing agreement between the salon and KAIZER Booking: by accepting the Terms, the salon accepts this page too.
Roles
The salon is the controller: it decides what data about its clients to collect and why. KAIZER Booking is the processor: it stores the data and works on it only on the salon's instructions and only to run the program.
What the processor undertakes
- To process data only on the salon's instructions, which are expressed by the program's settings and by this document.
- Not to use the salon's client data for its own purposes, not to sell it and not to pass it on for advertising.
- To let only staff who need it for support and maintenance near the data, and only with a key.
- To apply the protection described on the Security page: a separate database for every salon, an encrypted connection, hashed passwords, a limit on login attempts, daily backups.
- To use only the sub-processors listed below, and only those the salon switched on itself.
- To tell the salon about a breach that affected its data without undue delay after we learn of it.
- To help the salon answer its clients' requests: exporting everything about a person and deleting them for good are available to the owner right in the program.
- At the end of a subscription, to let the data be exported and then delete it together with the backups on their own schedule.
Sub-processors
Services that receive data when the salon switches the matching integration on: Stripe and Square (payments), Intuit QuickBooks (books), Google (calendar), Resend (e-mail), GreenAPI (WhatsApp), Meta (ads, hashed fingerprints only), Plaid (the salon's bank feed), Anthropic (translation of templates without client data), DigitalOcean (the server in the USA). Changes to this list are announced in the program under What's new.
Where data is processed
On a server in New York, USA. For clients in Europe this is a transfer outside the EU. It rests on the standard contractual clauses, included in this document by reference, and on the protection described above.
Rights of the salon's clients
A client of a salon may learn what data exists about them, correct it, ask for it to be deleted, restrict its processing or receive a copy. The request goes to the salon. The owner fulfils it in the program: a card can be corrected, exported as one file and deleted for good, including photos, documents, letters and the name on every appointment. If the salon does not answer, write to us and we will pass the request to the owner.
Time limits
The salon answers a client's request within 30 days. We answer salons' requests within 5 working days. Backups are kept for 30 days, so deleted data leaves the backups within a month.
What depends on the salon
- Having a lawful basis for collecting data and sending mailings: consent, or a contract with the client.
- Telling clients that their data is kept in the program, for example in its own policy.
- Collecting only what the work needs and not keeping what is not needed.
- Giving staff access only to the sections they need and closing it in time.
Contact
Data processing questions, and any other: support@kaizerbooking.com.
GDPR и договор об обработке данных
Обновлено 24 сентября 2026
Эта страница для салонов, у которых есть клиенты из Европы, Великобритании или Канады, и для всех, кому важно, как устроена обработка данных. Она же служит договором об обработке данных между салоном и KAIZER Booking: принимая пользовательское соглашение, салон принимает и её.
Роли
Салон — контролёр: он решает, какие данные своих клиентов собирать и зачем. KAIZER Booking — обработчик: хранит данные и выполняет операции с ними только по поручению салона и только для работы программы.
Что обязуется обработчик
- Обрабатывать данные только по инструкциям салона, которые выражены настройками программы и этим документом.
- Не использовать данные клиентов салона для собственных целей, не продавать и не передавать их для рекламы.
- Допускать к данным только сотрудников, которым это нужно для поддержки и обслуживания, и только по ключу.
- Применять меры защиты, описанные на странице «Безопасность»: отдельная база для каждого салона, шифрование соединения, хеширование паролей, ограничение попыток входа, ежедневные резервные копии.
- Привлекать субобработчиков только из списка ниже и только тех, кого салон включил сам.
- Сообщать салону об утечке, затронувшей его данные, без неоправданной задержки после того, как мы о ней узнали.
- Помогать салону отвечать на запросы его клиентов: выгрузка всех данных о человеке и полное удаление доступны владельцу прямо в программе.
- По окончании подписки дать выгрузить данные и затем удалить их вместе с резервными копиями по графику их хранения.
Субобработчики
Службы, к которым данные попадают, если салон включил соответствующую интеграцию: Stripe и Square (оплаты), Intuit QuickBooks (бухгалтерия), Google (календарь), Resend (почта), GreenAPI (WhatsApp), Meta (реклама, только хешированные отпечатки), Plaid (банковская выписка салона), Anthropic (перевод шаблонов без данных клиентов), DigitalOcean (сервер в США). Об изменении списка мы сообщаем в программе через «Что нового».
Где обрабатываются данные
На сервере в Нью-Йорке, США. Для клиентов из Европы это передача за пределы ЕС. Основание — стандартные договорные условия, включённые в этот документ ссылкой, и меры защиты, описанные выше.
Права клиентов салона
Клиент салона может узнать, какие данные о нём есть, исправить их, попросить удалить, ограничить обработку или получить копию. Запрос подаётся в салон. Владелец салона выполняет его в программе: карточку можно исправить, выгрузить одним файлом и удалить полностью, включая фотографии, документы, письма и имя во всех записях. Если салон не отвечает, напишите нам, и мы передадим запрос владельцу.
Сроки
На запрос клиента салон отвечает в течение 30 дней. Мы отвечаем на обращения салонов в течение 5 рабочих дней. Резервные копии хранятся 30 дней, поэтому удалённые данные исчезают из копий в течение месяца.
Что зависит от салона
- Иметь законное основание для сбора данных и рассылок: согласие или договор с клиентом.
- Рассказать клиентам, что их данные хранятся в программе, например в своих правилах.
- Собирать только то, что нужно для работы, и не хранить лишнего.
- Выдавать сотрудникам доступ только к нужным разделам и закрывать его вовремя.
Связь
По вопросам обработки данных и любым другим: support@kaizerbooking.com.
RGPD y acuerdo de tratamiento de datos
Actualizado el 24 de septiembre de 2026
Esta página es para los salones con clientes en Europa, el Reino Unido o Canadá, y para quien quiera saber cómo está organizado el tratamiento de datos. Sirve además como acuerdo de tratamiento de datos entre el salón y KAIZER Booking: al aceptar los Términos, el salón acepta también esta página.
Roles
El salón es el responsable: decide qué datos de sus clientes recoge y para qué. KAIZER Booking es el encargado: guarda los datos y trabaja con ellos solo por instrucción del salón y solo para que el programa funcione.
A qué se compromete el encargado
- Tratar los datos solo según las instrucciones del salón, expresadas en los ajustes del programa y en este documento.
- No usar los datos de los clientes del salón para fines propios, no venderlos ni cederlos para publicidad.
- Dejar acercarse a los datos solo al personal que lo necesita para soporte y mantenimiento, y solo con clave.
- Aplicar la protección descrita en la página Seguridad: base de datos separada por salón, conexión cifrada, contraseñas con hash, límite de intentos de acceso, copias diarias.
- Usar solo los subencargados de la lista de abajo, y solo los que el salón haya activado.
- Avisar al salón de una filtración que afecte a sus datos sin demora indebida desde que la conozcamos.
- Ayudar al salón a responder a sus clientes: exportar todo lo que hay sobre una persona y borrarla por completo está disponible para la propietaria en el propio programa.
- Al terminar la suscripción, permitir exportar los datos y después borrarlos junto con las copias según su calendario.
Subencargados
Servicios que reciben datos cuando el salón activa la integración correspondiente: Stripe y Square (cobros), Intuit QuickBooks (contabilidad), Google (calendario), Resend (correo), GreenAPI (WhatsApp), Meta (publicidad, solo huellas cifradas), Plaid (extracto bancario del salón), Anthropic (traducción de plantillas sin datos de clientes), DigitalOcean (servidor en EE. UU.). Los cambios en la lista se anuncian en el programa, en Novedades.
Dónde se tratan los datos
En un servidor de Nueva York, EE. UU. Para clientes de Europa es una transferencia fuera de la UE. Se apoya en las cláusulas contractuales tipo, incluidas en este documento por referencia, y en la protección descrita arriba.
Derechos de los clientes del salón
Un cliente del salón puede saber qué datos hay sobre él, corregirlos, pedir que se borren, limitar su tratamiento o recibir una copia. La solicitud se dirige al salón. La propietaria la atiende en el programa: la ficha se puede corregir, exportar en un archivo y borrar por completo, incluidas fotos, documentos, correos y el nombre en todas las citas. Si el salón no responde, escríbanos y trasladaremos la solicitud a la propietaria.
Plazos
El salón responde a la solicitud de un cliente en 30 días. Nosotros respondemos a los salones en 5 días laborables. Las copias de seguridad se conservan 30 días, así que los datos borrados desaparecen de las copias en un mes.
Qué depende del salón
- Tener una base legal para recoger datos y enviar comunicaciones: consentimiento o contrato con el cliente.
- Decir a los clientes que sus datos se guardan en el programa, por ejemplo en su propia política.
- Recoger solo lo necesario para el trabajo y no conservar lo que sobra.
- Dar al personal acceso solo a las secciones necesarias y cerrarlo a tiempo.
Contacto
Cuestiones de tratamiento de datos y cualquier otra: support@kaizerbooking.com.