1. Data controller
The data controller within the meaning of Article 4(7) GDPR is Self Love Spot, ul. Barska 61A / LU1, 30-307 Kraków, Polska.
For any matters related to personal data protection please contact us at kontakt@selflovespot.pl or by phone at +48 574 472 931.
2. Scope of processed data
The selflovespot.pl website itself does not contain any forms where we collect personal data from you. We are limited to the technical data necessary for the operation of the site (IP address, browser type, visit date) kept in server logs provided by Cloudflare.
If you choose to book a visit through the Booksy system (via the “Book” buttons), your data is collected directly by Booksy sp. z o.o. under Booksy’s own privacy policy. Once your appointment is confirmed, the data necessary to deliver the service is made available to us (first name, phone, chosen treatment, time slot).
During your visit we may process your contact details (first name, phone) and information necessary to perform the treatment correctly (e.g. allergies, preferences, treatment history). This data is stored in the Booksy system.
3. Purposes and legal bases
We process your data exclusively for the following purposes:
• performance of the contract for hair and beauty services — Art. 6(1)(b) GDPR;
• fulfilment of legal obligations, including tax and sanitary law — Art. 6(1)(c) GDPR;
• legitimate interest of the controller (billing, complaint handling, site security) — Art. 6(1)(f) GDPR;
• where you consent to the newsletter or marketing — Art. 6(1)(a) GDPR.
4. Recipients of data
We may share personal data with trusted processors:
• Booksy sp. z o.o. (booking and payment system);
• Cloudflare, Inc. (hosting and site delivery);
• Google LLC (embedded Google Maps and any technical statistics);
• Meta Platforms, Inc. (embedded Instagram posts — loaded only after cookie consent);
• providers of accounting and legal services — to the extent necessary for settlement and complaints.
We do not sell personal data and do not share it with third parties for marketing purposes.
5. Retention periods
We retain data for as long as necessary to achieve the purposes listed in section 3 and for the period required by applicable law (e.g. tax law — 5 years from the end of the year in which an accounting document was issued).
Data collected on the basis of consent is processed until consent is withdrawn.
6. Your rights
In connection with the processing of personal data you are entitled to:
• the right of access (Art. 15 GDPR);
• the right of rectification (Art. 16 GDPR);
• the right to erasure (Art. 17 GDPR) — subject to legal obligations;
• the right to restrict processing (Art. 18 GDPR);
• the right to data portability (Art. 20 GDPR);
• the right to object (Art. 21 GDPR);
• the right to withdraw consent at any time;
• the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
To exercise your rights, please contact us at kontakt@selflovespot.pl.
7. Transfers outside the EEA
Some of our providers (Cloudflare, Google) may process data outside the European Economic Area. Such transfers are carried out under standard contractual clauses approved by the European Commission, ensuring an appropriate level of protection.
8. Cookies
Detailed information about cookies used is provided in a separate document — the Cookie Policy.
9. Changes to the policy
This Privacy Policy may be updated along with changes in the services offered or legal requirements. The latest version is always published on this page together with the date of the last update.