Privacy Policy
[Insert publish date, e.g. "21 July 2026"] · Version 1.0
This Privacy Policy explains how Lean Salon ("we", "us") collects, uses and protects personal data when you use our website, dashboard, booking portal and WhatsApp assistant. Lean Salon is designed for salons based in the EU, and we process personal data in line with the General Data Protection Regulation (GDPR).
1. Who we are
Lean Salon provides salon management software, including online booking, a WhatsApp AI assistant, payments, inventory management and business insights, to independent salons and their clients.
Lean Salon is a sole proprietorship (eenmanszaak) registered in the Netherlands, located at Pijnsweg 29, 6419 CH Heerlen, and registered with the Dutch Chamber of Commerce (KvK) under number 42089738.
2. What personal data we collect
Depending on how you use Lean Salon, we process the following categories of personal data:
- •Salon owner and staff accounts: name, email address and login information (managed via our identity provider).
- •Client data entered by a salon: name, email address, phone number, appointment history and notes.
- •Booking and WhatsApp messages: content of messages exchanged with our AI assistant, used to schedule, reschedule or cancel appointments.
- •Payment data: processed by our payment provider, Mollie — Lean Salon does not store full card or bank details itself.
- •Uploaded documents: purchase invoices forwarded by email, which may contain supplier and product information.
- •Technical data: IP address, browser type and usage data collected via analytics tools on our marketing website.
3. Why we process this data
We process personal data to provide the Lean Salon service: to schedule and manage appointments, process payments, send reminders and confirmations, respond to WhatsApp messages, and generate business insights for salon owners.
Where we use AI models (Google Gemini, OpenAI and Anthropic Claude) to interpret messages, read invoices, generate strategic advice or reporting, or generate other suggestions, this processing is limited to what is necessary to deliver the requested feature.
4. Who we share data with
We work with a limited number of sub-processors, each bound by a data processing agreement, to deliver the service:
- •Microsoft Azure — hosting and infrastructure (Northern Europe region).
- •Mollie — payment processing.
- •Mailgun — transactional and inbound email.
- •Meta (WhatsApp Business Platform) — WhatsApp messaging.
- •Google (Gemini) — AI processing of messages, invoices and images.
- •OpenAI — AI processing used to generate strategic salon advice and periodic business reports.
- •Anthropic (Claude) — AI processing of messages, invoices and images.
5. International data transfers
We aim to host and process data within the European Economic Area (EEA) — our hosting infrastructure (Microsoft Azure) runs in the Northern Europe region.
Some of our sub-processors (including OpenAI and Anthropic, both based in the United States) are located outside the EEA. For these, we rely on Standard Contractual Clauses (SCCs) — contract templates approved by the European Commission that legally require the receiving party to protect personal data to a standard equivalent to the GDPR, even though the country itself does not have an EU "adequacy decision". You can read more about Standard Contractual Clauses on the European Commission's website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
6. How long we keep data
We do not keep personal data for longer than necessary for the purpose it was collected for, or for longer than required by law:
- •Client data of a salon (name, contact details, appointment history, notes): for the duration of the salon's subscription to Lean Salon, and up to 2 years after the subscription ends or after the client's last contact with the salon, unless deletion is requested earlier.
- •Invoices and payment records: 7 years, in line with Dutch statutory accounting/tax retention requirements.
- •WhatsApp and booking messages: up to 1 year after the last related appointment, after which they are deleted or anonymised.
- •Salon owner and staff account data: for the duration of use of Lean Salon, and up to 30 days after account closure.
- •Uploaded purchase invoices: 7 years, under the same statutory retention requirement as above.
7. Your rights
Under the GDPR, you have the right to access, correct, delete or export your personal data, and to object to certain processing. To exercise these rights, contact us at the email address below. You also have the right to lodge a complaint with your national data protection authority.
8. Cookies and analytics
On leansalon.com, we use cookies and similar technologies for analytics (such as Google Analytics and Microsoft Clarity) and, where applicable, marketing. Non-essential cookies are only activated once you have given explicit consent via our cookie banner; you can withdraw this consent at any time via the cookie settings on this website.
Salons using Lean Salon's auto-website feature can enable their own third-party trackers on their own salon website, including Meta, Microsoft, Google, LinkedIn, Snapchat and Pinterest. The same principle applies on these salon websites: non-essential cookies are only activated after a visitor gives explicit consent via that salon's own cookie banner. For questions about cookies on a specific salon's website, please contact that salon directly.
9. Security
We use industry-standard technical and organisational measures to protect personal data:
- •Hosting with Microsoft Azure (Northern Europe region), with encryption of data in transit (TLS) and at rest.
- •Passwords, API keys and other secrets are never stored in source code, but managed via Azure Key Vault.
- •Access to Azure resources uses Managed Identity, avoiding long-lived credentials that could leak.
- •Strict separation of data between salons at the database level (Row-Level Security), so that one salon's data is never accessible to another salon — even in the event of an application-level bug.
- •Role-based access within a salon's own dashboard (e.g. owner versus staff member).
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we update both the date and the version number at the top of this page, so you can always see whether — and when — something has changed. Earlier versions remain available on request.
11. Contact
Questions about this policy? Email us at privacy@leansalon.com.