Privacy Policy
Last updated: September 2026
1. Overview of Data Protection
Thank you for your interest in our studio. The protection of your personal data is of the highest importance to us. This Privacy Policy informs you about what personal data we collect when you use our website and booking system, the purposes for which we process it, and your rights under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Personal data is any data with which you can be personally identified. We treat your data confidentially and in accordance with statutory data protection regulations and this Privacy Policy.
2. Data Controller
The controller responsible for data processing on this website under the GDPR is:
Zyron Barber Studio
Owner: Doniyor Inoyatov
Konstanzer Str. 58, 10707 Berlin, Germany
Due to our business size, we are not legally required to appoint an official Data Protection Officer (§ 38 BDSG). For any privacy-related questions, you can contact us directly using the contact details above.
3. On-Site Payment (No Online Payments)
No online payments take place through our website or booking system. We do not collect, process, or store credit card numbers, bank account details, or other payment credentials on this website at any time.
Payment for booked services takes place exclusively in person at the barber studio at the time of your appointment (in cash or by card terminal).
In our internal appointment management system, we only record whether and by which payment method (cash / card) the service was settled in the salon after completion. This serves solely to manage the booking status and satisfy commercial and tax bookkeeping requirements (e.g. under German HGB and AO).
4. Data Collection on Our Website
We collect and process only the data necessary to provide our services, manage appointment bookings, and offer customer support:
- Basic Details: Your full name (first name and last name).
- Contact Details: Email address and telephone number (used for booking confirmations, 24-hour reminders, and urgent inquiries about your appointment).
- Booking & Appointment Data: Selected service, requested barber, appointment date and time, appointment status, and optional notes.
- Technical Usage Data (Server Logs): IP address, date and time of request, browser type and version, operating system, and accessed pages.
- Account & Login Credentials: Authentication identifier managed via our authentication provider Clerk for secure sign-in without storing passwords on our own servers.
We do not knowingly collect data from minors and do not collect any special categories of personal data (such as health data, biometric data, or religious beliefs).
5. How We Collect Your Data
Data Provided Directly by You
Your data is primarily collected when you provide it to us, such as when registering an account, booking or canceling an appointment, or contacting us by phone or email.
Automated Collection During Your Visit
Other data is collected automatically by our IT systems when you visit the website. This primarily includes technical data (e.g., internet browser, operating system, time of page view) required for secure website delivery.
6. Purposes and Legal Bases for Processing
We process personal data exclusively in compliance with the provisions of the GDPR:
| Purpose / Activity | Data Processed | Legal Basis |
|---|---|---|
| Creation and provision of your customer account | Name, email address, authentication identifier | Art. 6(1)(b) GDPR (Performance of a contract) |
| Managing appointments, confirmations, and 24h reminders via email | Name, email address, phone number, service, booking time | Art. 6(1)(b) GDPR (Contract fulfillment) & Art. 6(1)(f) GDPR (Legitimate interest in minimizing missed appointments) |
| Customer service and direct phone contact for short-term schedule changes | Name, phone number, email address | Art. 6(1)(b) & Art. 6(1)(f) GDPR |
| Security, stability, and fraud prevention for our IT systems | Technical data, server logs, IP address | Art. 6(1)(f) GDPR (Legitimate interest in reliable, secure operation) |
| Compliance with statutory commercial and tax retention requirements | Appointment history, performed services, on-site payment record | Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB |
7. Hosting and Sub-Processors
To run our platform securely and reliably, we use specialized technical providers who act as data processors (Art. 28 GDPR) under Data Processing Agreements (DPA):
Vercel (Hosting & Web Delivery)
Hosting and serverless compute by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Hosting region is restricted to the EU region Frankfurt am Main (fra1). Vercel is certified under the EU-U.S. Data Privacy Framework.
Supabase (Database & Data Storage)
Database hosting and customer data storage by Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992, hosted in AWS Frankfurt (eu-central-1, Germany).
Clerk (User Authentication & Sign-in)
User authentication and profile access management by Clerk, Inc., 600 California Street, Suite 1100, San Francisco, CA 94108, USA, supporting secure passkey, password, and one-time code sign-in. Clerk is certified under the EU-U.S. Data Privacy Framework.
Resend (Transactional Emails)
Delivery of transactional appointment notifications (booking confirmations, 24-hour reminders, cancellation notices) by Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. No marketing or promotional emails are sent. Resend is certified under the EU-U.S. Data Privacy Framework.
Where data is processed in the US, transfers are safeguarded by the EU-U.S. Data Privacy Framework (adequacy decision under Art. 45 GDPR) or EU Standard Contractual Clauses (Art. 46 GDPR).
8. Cookies and Local Storage
Our website uses only technically necessary cookies and functional session storage.
These include session cookies from our authentication provider Clerk (to keep you signed in securely) and a cookie for remembering your language choice (NEXT_LOCALE).
We do not use advertising cookies, behavioral tracking mechanisms, or third-party web analytics (such as Google Analytics). Pursuant to § 25(2) TDDDG, consent banners are not required for strictly necessary functional cookies.
9. Data Retention and Account Deletion
We retain your personal data only for as long as necessary to fulfill the respective purpose or as required by statutory retention laws.
Statutory retention periods: Records of completed services and appointments are subject to commercial and tax retention requirements of 6 to 10 years (§ 147 AO, § 257 HGB). After these periods expire, records are routinely erased.
Self-service account deletion: You can delete your customer account at any time in your profile under 'Account & Privacy'. Your login and profile data are immediately and permanently removed, provided no statutory retention obligations prevent deletion.
10. Your Rights as a Data Subject
Under applicable GDPR regulations, you have the following rights at any time:
- Right of Access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed, and access to that data.
- Right to Rectification (Art. 16 GDPR): You have the right to obtain the rectification of inaccurate personal data or completion of incomplete data.
- Right to Erasure (Art. 17 GDPR): You have the right to obtain the erasure of your personal data, provided statutory retention obligations do not apply.
- Right to Restriction of Processing (Art. 18 GDPR): You have the right to request restriction of processing of your personal data under certain conditions.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): Where processing is based on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.
- Right to Withdraw Consent (Art. 7(3) GDPR): You have the right to withdraw previously given consent at any time with future effect.
To exercise your rights, you can contact us informally (e.g. via email at zyronstudio@gmail.com). To verify your identity, contacting us from your registered email address or account is sufficient; no copy of your passport or ID is required.
11. Right to Lodge a Complaint with a Supervisory Authority
In the event of GDPR violations, you have the right to lodge a complaint with a competent supervisory authority (Art. 77 GDPR). The competent authority for our studio in Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin, Germany
12. Data Security and Encryption
This site uses TLS/SSL encryption (HTTPS) for security reasons and to protect the transmission of confidential booking data.
We implement state-of-the-art technical and organizational security measures to protect your data against loss, destruction, alteration, or unauthorized access.
