GDPR / privacy

Privacy policy

This policy explains how we process personal data in connection with the ALIA Barber website and services. For privacy matters, please use the contact details.

Data controller

The controller of personal data within the scope described in this policy is ALIA BARBER ALINA REDKA.

Address: Księdza Kardynała Stefana Wyszyńskiego 40A/lokal 8, 43-100 Tychy, Polska.
Contact for data-protection matters: +48 511 860 380.

Scope of this policy

The ALIA Barber website is a static site. It does not provide customer accounts or maintain its own booking database. Online bookings are handled through Booksy. Some website functions use third-party services; their roles are described below.

Data we may process

  • booking and service data: first name, surname if provided, phone number, selected service, appointment date and time, information needed to handle the appointment and booking history available to the controller through Booksy;
  • data you provide when contacting the salon, such as message content, contact details and information relating to an enquiry, complaint or course;
  • technical website data such as IP address, request date and time, requested resource, browser or device information and security data, to the extent generated when the site is delivered through hosting/CDN infrastructure;
  • data contained in publicly posted reviews, such as the author’s displayed name, review text, rating, date and source; the website may display static copies originating from Booksy or Google;
  • data processed by external services after they are activated or opened, including Booksy, Google Maps, Instagram or Facebook, under the relevant provider’s rules.

Sources of data

  • directly from you, when you contact the salon or provide data needed to perform a service;
  • from Booksy, when you book through the platform and Booksy makes the data necessary for the partner to perform the service available to that partner;
  • from public sources, especially public Booksy or Google reviews, and automatically from your device/network to the extent of technical data necessary to handle a request.

Purposes and legal bases for processing

  • entering into and performing a service contract and taking steps at your request before entering into a contract, in particular handling bookings and appointment-related communication — Article 6(1)(b) GDPR;
  • complying with legal obligations imposed on the controller, in particular tax, accounting and consumer-law obligations — Article 6(1)(c) GDPR;
  • the controller’s legitimate interests, such as website security, handling correspondence, establishing, exercising or defending legal claims and presenting authentic service reviews — Article 6(1)(f) GDPR;
  • your consent — Article 6(1)(a) GDPR — only where consent is the appropriate legal basis for a specific activity, for example certain marketing, publication of an image or optional technologies requiring consent;
  • commercial communications sent by electronic means and access to information stored on an end device are also subject to the Polish Electronic Communications Law (Prawo komunikacji elektronicznej), in particular Articles 398–400.

How we use the data

  • handling bookings, performing services and appointment-related organisational communication;
  • answering enquiries, handling complaints and communicating about courses or other services;
  • meeting tax, accounting and other legal obligations;
  • protecting the website, preventing abuse, maintaining service continuity and establishing, exercising or defending legal claims;
  • presenting reviews and materials concerning the salon and, only where a proper legal basis exists, carrying out marketing activities.

Whether providing data is required

Providing data necessary to book or perform a service is voluntary but necessary to enter into or perform the contract; without it, a booking or service-related contact may not be possible. Data required by law must be provided when such an obligation applies. Where processing is based on consent, consent is voluntary and refusing it does not affect access to the website’s core functions or services, except where the relevant function cannot lawfully be enabled without that consent.

Recipients and service providers

  • Cloudflare and providers of infrastructure, CDN, hosting, security and technical maintenance services, to the extent necessary to deliver and protect the website;
  • Booksy in connection with the booking platform; depending on the specific operation, Booksy may act as a separate controller or as a processor acting on the partner’s instructions;
  • accounting, legal, IT and other support providers, only to the extent necessary for their services and under an appropriate legal basis or data-processing agreement where required;
  • Google, Meta or other operators of external services, only to the extent resulting from your use of their features, such as activating a map or opening a social-media service;
  • public authorities or other authorised entities, only where disclosure is required by law.

Transfers outside the European Economic Area

Because global infrastructure providers and external services may be used, data may be processed outside the EEA, including in the United States. Where such a transfer occurs, it should rely on a mechanism permitted by Chapter V GDPR, such as an adequacy decision of the European Commission — including the EU–US Data Privacy Framework for certified entities — or Standard Contractual Clauses together with required safeguards. The current privacy documents of Booksy, Cloudflare, Google and Meta also describe the transfer mechanisms they use.

Retention periods

  • booking and service data — for as long as necessary to provide the service and then for the period required for settlements, legal obligations and the applicable limitation periods for claims;
  • correspondence and enquiry data — until the matter is resolved and, where justified, until relevant claims are time-barred or mandatory retention ends;
  • technical and security data — for a period resulting from the security purpose, service configuration and the relevant infrastructure provider’s rules, no longer than necessary for that purpose;
  • data processed on the basis of consent — until consent is withdrawn or the processing purpose ends earlier, unless another legal basis permits continued retention;
  • public reviews and materials displayed on the website — while they are published and relevant for the purpose, taking into account rights to object, request erasure and changes in the source data.

Your rights

Depending on the legal basis and circumstances of processing, you may request access to your data, rectification, erasure or restriction of processing.

You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation; you may object to direct marketing at any time.

The right to data portability applies in the circumstances set out in Article 20 GDPR, in particular where processing is automated and based on consent or a contract.

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. These rights are not absolute and may be subject to exceptions provided by the GDPR or other applicable law.

Right to lodge a complaint

If you believe that the processing of your data infringes data-protection law, you may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland. You may also contact the controller first so that the matter can be clarified directly.

Automated decision-making and profiling

The controller does not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. The short course-matching questionnaire runs locally in your browser, does not send your answers to the controller and only displays an indicative recommendation.

Cookies and similar technologies

In the current version of the website, ALIA Barber does not deploy its own Google Analytics, advertising pixels or first-party user profiling. The infrastructure delivering the website may nevertheless process technical data necessary for transmission, security and abuse prevention.

External services, in particular Booksy and Google Maps after the map is activated, may use their own cookies or similar technologies. Their purposes, lifetimes and controls are also governed by the relevant provider.

Under Articles 399–400 of the Polish Electronic Communications Law, storing information on an end device or accessing information already stored there generally requires prior information and consent unless a statutory exception applies, for example where the technology is necessary for transmission or for an electronic service expressly requested by the user.

Bookings through Booksy

When you use Booksy, the platform processes data under its own rules. Booksy states that it acts as controller for customer-account data, while the partner — ALIA Barber — is a separate controller for data needed to provide the booked service. For certain operations, Booksy may also process personal data on the partner’s behalf.

Loading the Booksy module may establish a connection with Booksy infrastructure and transmit technical data such as an IP address or browser information. Data entered into Booksy is transmitted and stored under the platform’s rules.

Booksy privacy policy

Google Maps, social media and reviews

Google Maps is not loaded automatically. The website first displays a locally hosted map façade and connects to Google Maps only after the user chooses to display the map. From that point, Google may process technical data under its own privacy policy.

Links to Instagram, Facebook, Google Maps or other external services take you outside the ALIA Barber website. Once you open such a service, its operator determines how your data is processed. Reviews displayed on this website are imported into static site content; displaying them does not itself require a live connection to Google or Booksy.

Google privacy policy

Data security

We apply technical and organisational measures appropriate to the nature of the website and the risks involved, including HTTPS encryption, data minimisation, access controls for administrative tools and infrastructure providers with security mechanisms. No transmission or storage method can, however, guarantee that all risk is eliminated.

Changes to this policy

This policy may be updated when the law, website features or processing practices change. The current version is published at this address. Last updated: