Privacy Policy
Last updated: August 2026
1. Who we are
Your Business Name, located at 16 Main Street, City, is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) when you use this booking site.
2. What we collect
When you book an appointment, we collect your name, email address, phone number, and the service, stylist, and time you request. When you use the booking form, our bot-protection provider (see below) also processes your IP address and browser signals to confirm you're a real visitor.
3. Why we process it (legal basis)
We process your booking details to perform the contract formed when you request an appointment — Article 6(1)(b) GDPR — including sending you a confirmation email. We rely on legitimate interest — Article 6(1)(f) — to protect our booking form from automated abuse.
4. How long we keep it
Appointment records are retained only until the appointment date has passed, at which point they are automatically and permanently deleted from our active database. We do not keep a historical archive of past bookings.
5. Who we share it with
We use a small number of service providers to run this booking system. None of them may use your data for their own purposes.
- Brevo SAS — sends your booking confirmation email. Brevo is headquartered in France with EU-hosted data, so this data does not leave the EU for this purpose.
- Hetzner Online GmbH — hosts the server and database this system runs on, physically located in Germany.
- Cloudflare, Inc. — protects our booking form from automated bots (Cloudflare Turnstile), provides DNS for our domain, and stores staff/service photos uploaded through the admin panel (Cloudflare R2). Cloudflare is US-headquartered; where data is transferred outside the EU/EEA, this is covered by Standard Contractual Clauses under Cloudflare's own data processing agreement.
- Google Ireland Limited — displays an embedded map of our location on the site (Google Maps). Loading the map sends your browser's IP address and standard request data to Google; see Google's own privacy policy for details.
- Our website's technical operator — retains administrative access to this system for maintenance, security, and account-recovery purposes.
6. International data transfers
Where a provider listed above is based outside the EU/EEA, your data is protected either by using an EU data region (as we do for email) or by contractual safeguards such as Standard Contractual Clauses.
7. Cookies and similar technology
We do not use advertising or analytics cookies. Cloudflare Turnstile, which protects our booking form, may set a small technical cookie or token solely to distinguish human visitors from bots — see Cloudflare's own privacy policy for details. Signing in to the admin panel (staff only) sets a session cookie; this is never set for visitors booking an appointment.
8. Your rights under GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data
- Restrict or object to our processing
- Receive a copy of your data in a portable format
- Lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your own country's data protection authority
To exercise any of these rights, contact us using the details in section 12.
9. Data security
We use encrypted connections (HTTPS/TLS) between your browser and our server, database-level access controls, and strict data isolation between businesses using this platform.
10. Children's privacy
This service is not directed at children, and we do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the most recent revision.
12. Contact us
Questions about this policy or your data, or to exercise any right listed above: bookings@mournaros.cc, or write to us at 16 Main Street, City.