Privacy policy
Last updated:
This is a translation provided for convenience. In case of any discrepancy, the French version prevails.
This policy covers four distinct surfaces:
- the
www.hairtechpro.aiwebsite (the “Site”); - Lia by HairTechPro (“Lia”), the app for salon clients;
- HairTechPro, the app for hairdressing professionals;
- the web back office, used by salons and by HairTechPro’s own teams.
They do not involve the same processing, nor — in part — the same controllers, so they are distinguished throughout this document. If you are a salon client, the sections that concern you are those about the Site and Lia; if you are a professional, those about the HairTechPro app and the back office.
1. Who is responsible for your data
The hairtechpro.ai website
HairTechPro is the controller for the whole website: page browsing and newsletter sign-up.
The Lia app (clients)
The app brings together three parties, whose roles differ.
- HairTechPro is the controller for the account itself: account creation and authentication, identity and contact details, preferences, security, aggregated usage statistics and service improvement.
- Your salon is the controller for its own business records: its client file, the services performed, appointment notes, the invoices it issues and the photographs taken in the salon. HairTechPro then acts as the salon’s processor, on its instructions only.
- You decide to connect your account to a given salon. Until that connection is established, the salon has no access to your profile.
The HairTechPro app and the back office (professionals)
The professional app and the back office are used with one and the same account: the processing described below applies to both, and deleting that account applies to both as well.
- HairTechPro is the controller for the professional account itself: the professional’s identity and contact details, authentication, public profile, preferences and security.
- Your salon is the controller for what concerns the organisation of work and its business: schedule, availability, travel range, services performed, and the salon’s client data.
- HairTechPro acts as the salon’s processor for the client data you consult or enter in the professional app and in the back office.
If you are an employee or contractor of a salon, questions about using these tools as part of your work are for your salon in the first instance, in its capacity as controller and, where applicable, employer.
Controller’s contact details: HairTechPro, 18 avenue Auber, 78360 Montesson, France — privacy@hairtechpro.ai. The legal notice gives the company’s full identification.
Data protection officer: Morgan Durand — dpo@hairtechpro.ai.
2. The data we process
2.1 On the website
The website is a showcase site. It has no account, no personal area and no audience measurement. The only data you can send us is your email address, if you enter it in the newsletter sign-up form, together with the display language of the site.
2.2 In the Lia app (clients)
| Category | Data |
|---|---|
| Identity | first name, last name, gender, date of birth |
| Contact | email address, phone number |
| Address | home address, associated geolocation coordinates, access instructions |
| Account | password (stored as a hash), sessions, notification preferences, language |
| Photographs | profile photo, progress and inspiration albums, before / after appointment photographs |
| Hair diagnostic | your answers to the questionnaire, and those entered by your stylist (see §3) |
| Salon activity | appointments, services, products used, appointment notes, the salon’s notes about you |
| Billing | invoices issued, amounts, details shown on the invoice |
| Messaging | messages exchanged in the app |
| Technical | notification tokens, device identifiers, technical logs and crash reports |
2.3 In the HairTechPro app and the back office (professionals)
| Category | Data |
|---|---|
| Identity | first name, last name, email address, phone number |
| Public profile | trading name, biography, profile photo, services offered |
| Account | password (stored as a hash), sessions, notification preferences, language |
| Work organisation | schedule and availability, work locations, time off and absences, kits and equipment |
| Travel | departure point and travel range, where you offer home visits |
| Subscription | billing data for the salon’s subscription |
| Technical | notification tokens, device identifiers, technical logs and crash reports |
The salon’s own legal details (legal form, SIRET, VAT number) are the company’s, not personal data about you; they are shown to you read-only.
Location. The professional app asks for access to your device’s position in order to show where you are on the itinerary map between two home-visit appointments. That position is read on the device, in the foreground and only while the itinerary screen is open: it is not recorded, not sent to our servers, and not used to track your activity. You can decline the permission; only the map display is affected.
3. The hair diagnostic: health data
The hair-diagnostic questionnaire collects, among other things, the condition of your scalp (dandruff, sensitivity, itching, redness), hair loss and its pattern, hormonal changes (pregnancy, post-partum, perimenopause), rapid weight loss, your stress level and associated life events, and a free-text comment field.
This information is data concerning health within the meaning of article 9 GDPR. It benefits from reinforced protection:
- it is processed solely on the basis of your explicit consent (article 9(2)(a) GDPR), collected before the diagnostic and separately from acceptance of the terms of use;
- you may withdraw that consent at any time, without giving a reason; withdrawal stops the processing for the future and your answers are deleted;
- declining the diagnostic does not prevent you from using the rest of the app or from booking appointments;
- it is accessible only to the professionals of the salon you have chosen to connect to.
We ask that you avoid entering health information in free-text comment fields or in the messaging beyond what is useful to your hairdresser.
4. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Create and manage your account, authenticate you | Performance of a contract (art. 6(1)(b)) |
| Let you book appointments and communicate with your salon | Performance of a contract (art. 6(1)(b)) |
| Build your hair profile and suggest care routines | Explicit consent (art. 9(2)(a)) |
| Send reminders and notifications about your appointments | Performance of a contract (art. 6(1)(b)) |
| Issue and retain invoices | Legal obligation (art. 6(1)(c)) |
| Send you the website newsletter | Consent (art. 6(1)(a)) |
| Keep the service secure, prevent fraud and abuse | Legitimate interest (art. 6(1)(f)) |
| Diagnose technical incidents and improve the app | Legitimate interest (art. 6(1)(f)) |
| Manage the professional account and the salon’s access to its tools | Performance of a contract (art. 6(1)(b)) |
| Organise schedules, availability and travel | Performance of a contract, and the salon’s legitimate interest (art. 6(1)(b) and (f)) |
| Manage the salon’s subscription and its billing | Performance of a contract (art. 6(1)(b)) |
5. Who accesses your data
5.1 Recipients
- The professionals of the salon you are connected to: your profile, your hair diagnostic, your appointments and your messages. Until you have accepted the connection with a salon, it has no access to them.
- Other professionals at the salon, when they work on your file: the back office lets a salon member view your agenda and diagnostic profile, and book or cancel an appointment on your behalf — during a phone call, for instance.
- HairTechPro’s teams, strictly within what is necessary for support and for operating the service. Platform administrators can, from the back office, view an account and carry out its erasure at the request of the person concerned. These actions are logged.
Your data is never sold, rented or transferred to third parties for advertising purposes.
5.2 Processors
| Processor | Role | Location |
|---|---|---|
| Google Cloud Platform / Firebase (Google Ireland Ltd) | Hosting, database, file storage, Android notifications | European Union (europe-west1), EU storage |
| Brevo (Sendinblue SAS) | Website newsletter only | France / European Union |
| Twilio Inc. | SMS delivery (sign-in codes, invitations, reminders) | United States |
| Resend | Transactional email delivery | United States |
| Expo / EAS | Push-notification delivery | United States |
| Stripe | Salon subscription payments | United States / Ireland |
| Google Maps Platform | Address entry and validation | Outside the European Union |
| Sentry | Crash reports and technical diagnostics | United States |
| Google Fonts (back office) | Fonts loaded at runtime, which transmits the browser’s IP address | Outside the European Union |
| Mistral AI (inference provider) | Generating routine recommendations and appointment notes | France / European Union |
Each processor is bound by a contract compliant with article 28 GDPR and acts only on our instructions.
6. Transfers outside the European Union
Hosting, the database and file storage remain in the European Union. Some of the processors listed above are, however, established outside the European Union, mainly in the United States. Those transfers are governed by the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional technical measures. You can obtain a copy by writing to privacy@hairtechpro.ai.
7. AI-assisted features
Two features of the app rely on a language model:
- the care-routine recommendation, computed from your hair profile;
- the assisted drafting of appointment notes offered to your stylist.
The data sent to the inference provider to produce a recommendation includes the client’s hair profile and the identifying details of both the client and the professional attached to the appointment. We are working to narrow those transmissions to only the data the recommendation needs.
These features produce suggestions. They make no decision producing legal effects concerning you and do not amount to a solely automated decision within the meaning of article 22 GDPR: your stylist alone decides on the services and advice they give you. You may write to us to contest a recommendation or ask for a generated note to be corrected.
8. Retention periods
| Data | Period |
|---|---|
| Account and profile | For as long as you use the service, then deleted at your request |
| Hair diagnostic | Until you withdraw consent or delete your account |
| Photographs | Until you delete them, or until the account is deleted |
| Messages | For as long as you use the service, then deleted with the account |
| Invoices and accounting records | 10 years from the close of the accounting year (art. L. 123-22 of the French commercial code) |
| Newsletter email address | Until you unsubscribe |
| Technical logs | 30 days |
| Crash and diagnostic reports (Sentry) | 90 days |
| Professional account and work organisation | For as long as you work with the salon, then deleted on request |
Exactly what is erased and what is kept when an account is deleted is set out on the account deletion page.
9. Your rights
Under the GDPR you have the following rights:
- Access: obtain confirmation that your data is processed and receive a copy of it.
- Rectification: have inaccurate or incomplete data corrected. Most of your profile information can be edited directly in the app.
- Erasure: have your data deleted. The procedure is described on the account deletion page.
- Portability: receive the data you provided to us in a structured, machine-readable format.
- Objection: object to processing based on our legitimate interest.
- Restriction: ask for processing to be frozen while a point is verified.
- Withdrawal of consent: at any time, for the hair diagnostic as for the newsletter, without affecting the lawfulness of processing carried out before withdrawal.
- Post-mortem directives: set instructions on what becomes of your data after your death.
To exercise these rights, write to privacy@hairtechpro.ai. We reply within one month, extendable by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to the identity of the requester.
If you believe your rights are not being respected, you may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr — or with the supervisory authority of your country of residence.
These rights belong to clients and professionals alike: a user of the HairTechPro app or of the back office exercises them at the same address and within the same time limits.
Where a request concerns data for which your salon is the controller (client file, appointment notes, invoices, schedule and work organisation), we forward it to the salon concerned and let you know.
10. Security
Traffic is encrypted in transit. Passwords are stored as hashes. Photographs are only reachable through signed links with a short validity period. Access to a salon’s data is restricted to that salon’s professionals, and access to your profile requires that you have accepted the connection. Administrative actions carried out from the back office by HairTechPro’s teams are logged.
11. Changes
This policy may change. The date of the last update is shown at the top of this page. Where a change is substantial, you are informed in the app before the new version applies to you.
12. Contact
privacy@hairtechpro.ai — HairTechPro, 18 avenue Auber, 78360 Montesson, France.