Your data
Privacy policy
This notice explains transparently which data we use for secure operation, your appointment request and optional functions chosen by you.
1. Controller
Haarstudio Style, owner Cornelia Buchsbaum
St. Veiter Ring 43, 9020 Klagenfurt am Wörthersee, Austria
Email: co.buchsbaum@gmx.at
Phone: +43 664 439 59 59
2. Netcup hosting, server logs and email
The website and database run on the Netcup web-hosting product we commissioned at its Vienna server location. The provider is netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. A request causes the web server to process the IP address, time, requested address, status code, transfer volume, referrer and browser/system information. Purposes are delivery, error analysis and attack detection, based on our legitimate interest in a secure and stable website (Article 6(1)(f) GDPR). Routine server logs are deleted within 14 days; extracts concerning a specific security incident may be retained longer until investigation and defence are complete.
Emails sent to the published GMX address are processed by 1&1 Mail & Media GmbH, Karlsruhe branch, Brauerstraße 48, 76135 Karlsruhe, Germany. Sender and recipient information, time, delivery metadata and message content are involved. The legal basis is Article 6(1)(b) GDPR for enquiries and otherwise Article 6(1)(f) for business communications. Correspondence is deleted according to the case and applicable legal evidence obligations.
3. Cloudflare proxy, CDN and security
Cloudflare operates in front of the Vienna origin as reverse proxy, content delivery network and security layer. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. It processes the IP address, destination, time, HTTP/TLS and device information, security signals and, depending on the enabled protection, essential cookies. Purposes are fast delivery, TLS, availability and abuse prevention, based on Article 6(1)(f) GDPR.
Cloudflare uses a global Anycast network, so connection data may be processed outside the EEA. Depending on the recipient, transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or safeguards such as EU Standard Contractual Clauses. Cloudflare publishes its current subprocessors.
4. Appointment requests and retention
For an appointment request we process your name, mandatory phone number, optional email address, requested service, preferred date/time window and voluntary notes. Mandatory data is required to assess the request and answer questions. The legal basis is pre-contractual action under Article 6(1)(b) GDPR. The checkbox merely acknowledges this notice and is not consent to the processing required to answer you.
Do not enter diagnoses, medication, treatment details or other health data in the free-text field. For a personal consultation concerning wigs, hair density or scalp, a neutral appointment description is sufficient; medical details do not belong in the web form.
Unconfirmed, contacted-only, rejected or cancelled requests are deleted after 365 days without further handling. Confirmed, completed or archived records are deleted after no more than seven years unless a longer statutory duty or specifically documented legal defence requires otherwise. The long-term booking does not store an IP hash. Security audit data with a pseudonymous IP hash is deleted after 730 days; completed or permanently failed notification jobs after 90 days.
5. Internal email, Telegram or WhatsApp notifications
To handle an appointment request, authorised salon staff receive an email with the reference, name, supplied contact details, requested service, preferred date and time, optional message, request language and receipt time. Internal notes and IP addresses are not included. Email is sent using encrypted SMTP through Netcup and received by the salon through GMX (1&1 Mail & Media GmbH). It also includes a protected dashboard link. Email copies are deleted when no longer needed for handling, unless a retention duty applies.
Optional Telegram and WhatsApp alerts continue to contain only a pseudonymous case reference and protected admin link, not form contents. The reference remains personal data while internally identifiable. Telegram alerts involve Telegram Messenger Inc.; WhatsApp for EEA users involves WhatsApp Ireland Limited. These optional channels remain disabled until configured.
The purpose is prompt handling, based on Article 6(1)(b) and (f) GDPR. Where a third-country transfer is involved, the mechanisms described above apply. Provider account metadata also follows the deletion rules of the enabled account. The local queue item is removed 90 days after successful or permanently failed delivery.
6. Local analytics
Only after consent to “Analytics” do we count selected events such as a page view, phone click or successfully submitted request. We store only daily aggregates by page, language and referring domain. No user profile, full referrer, device identifier or raw IP address is stored in analytics. Aggregates are physically deleted after no more than 395 calendar days. The basis is Article 6(1)(a) GDPR together with section 165(3) Austrian Telecommunications Act 2021.
7. Campaign attribution
Only with marketing consent do we keep limited UTM source, medium, campaign, content and term values for the current browser session. Each value is limited to 100 characters from a restricted set; complete query strings, gclid/fbclid, referrer paths and form fields are excluded. A successfully saved request may store first and last touch with the consent version. Session attribution is removed on withdrawal; attribution attached to a request follows that request’s deletion period.
8. Google Tag Manager, Analytics, Ads and verification
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Under the default Basic Consent Mode, Google tags load only after you permit analytics and/or marketing. Google Analytics 4 may then process online identifiers, IP/device/browser information, pages and interactions. Under Google’s standard configuration, _ga and _ga_<ID> may last up to two years; the event/user retention configured in the Google account applies in addition. Google Ads and conversion measurement activate only with marketing consent; possible _gcl_ cookie periods depend on the deployed Google configuration.
An advertising conversion is triggered only after the request was saved successfully. The website code sends no name, phone number, email address, free text or selected service to Google. Enhanced Conversions remain disabled. Google/Meta tags are technically blocked on privacy pages and health-adjacent topics. Search Console and Bing verification meta tags themselves create no visitor connection to those services.
Google may transfer data to affiliates and service providers outside the EEA. Depending on the recipient, adequacy decisions or safeguards such as Standard Contractual Clauses apply. Consent can be withdrawn at any time through Cookie settings.
9. Meta Pixel, Facebook and Instagram
The EEA provider for Facebook and Instagram is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Profile links transfer data only when clicked. A configured Meta Pixel loads only on unrestricted pages and after marketing consent. It may process the page address, IP, device/browser information, interactions, _fbp and, where present, _fbc; under the current Meta cookie policy those identifiers generally last up to 90 days. The pixel receives no form fields. Meta Conversions API and Automatic Advanced Matching are not enabled.
Article sharing links open the Facebook sharer or WhatsApp only after your deliberate click. They pass the article address and, for WhatsApp, the prepared title or message text to the selected platform; the provider also processes customary connection and, where applicable, account data. The EEA provider for WhatsApp is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. These sharing links create no connection before you click.
The server-side Instagram sync obtains only posts from the salon’s own professional account through the official API and stores them for one day by default. Expired cache data is physically removed. Your browser loads Instagram previews from the Meta/Instagram CDN only after consent to external content.
10. Customer images
Real customer images in “Fresh from the studio” or editorial areas are used only on the basis of verifiable, freely given publication consent under Article 6(1)(a) GDPR. The person, image, approved channels, grant date, duration and any withdrawal are recorded. Publication ends on expiry or withdrawal; delivery and local copies are then removed unless a short technical backup period or specific legal defence prevents this. Consent can be withdrawn at any time through the contact details above.
11. Google reviews
If enabled, we retrieve reviews from the verified Google Business Profile server-side. Public display name, review text, stars, timestamp, overall average and count are processed. Google is the source rather than the reviewer directly (Article 14 GDPR). The purpose is an authentic presentation of customer experience, based on our legitimate interest under Article 6(1)(f). Objections or correction/deletion notices may be sent to us and directly to Google.
The site delivers text locally, so reading it creates no direct browser connection to Google. Cache duration is one day by default and technically never more than 30 days; expired rows are physically removed. Any manually published review requires documented provenance and permission.
12. Google Maps
Google Maps loads only after consent to external content. For users in the European Economic Area the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Loading the map sends Google your IP address, browser/device information and the requested map. Google may use cookies or similar identifiers and associate data with a signed-in Google account. Processing by Google LLC in the USA and other Google companies is possible. Embedding relies on your consent under Article 6(1)(a) GDPR and section 165(3) Austrian Telecommunications Act 2021. You can withdraw consent through Cookie settings at any time. Alternatively, deliberately open the external directions link, where Google’s privacy information applies.
13. Cookies and browser storage
Essential: hss_booking_form protects the booking form for two hours (HttpOnly, SameSite=Strict and Secure under HTTPS). style_admin is used only in the protected admin area for the current session (HttpOnly, SameSite=Strict and Secure under HTTPS). The haarstudio-style-consent:<version> choice remains in Local Storage for 30–365 days, default 180. Cloudflare may set essential security cookies according to the enabled protection.
Optional: haarstudio-style-campaign:<version> keeps UTM values only for the current session and only with marketing consent. Analytics consent may create Google _ga/_ga_<ID>; marketing consent may create Google _gcl_ and Meta _fbp/_fbc identifiers. Google Maps and Instagram previews load only with external-content consent. Withdrawal blocks subsequent provider requests and removes reachable first-party identifiers and the campaign session.
14. Recipients and international transfers
Depending on your use and only when the relevant function is enabled, recipients are Netcup, Cloudflare, 1&1 Mail & Media/the configured SMTP provider, Google, Meta, Telegram, WhatsApp and Google Maps. Providers receive only what is required for their task. Applicable processing terms are concluded with processors.
For recipients outside the EEA we use, depending on the recipient, an adequacy decision including the EU-US Data Privacy Framework for certified US recipients or safeguards, in particular EU Standard Contractual Clauses. You may request a copy of the essential safeguards through the email above.
15. Your rights and complaint
Subject to GDPR conditions, you have rights of access, correction, erasure, restriction, portability and objection. Consent may be withdrawn for the future through Cookie settings or by contacting us. No solely automated decision with legal or similarly significant effect takes place.
You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
16. Security and changes
We use transport encryption, role and access controls, secure admin sessions, rate limits, pseudonymised security logs, updates and limited retention. No internet service can guarantee absolute security.
We update this notice when functions, providers or applicable law change. Material changes receive a new privacy/consent version so that your choice is requested again.
Cloudflare Turnstile
When form protection is enabled, we use Cloudflare Turnstile, provided by Cloudflare, Inc., to prevent automated and abusive appointment requests. Verification starts only when the form is used and operates independently of optional statistics or marketing consent. Cloudflare may process IP address, browser and device information, and technical interaction and security signals. Cloudflare also processes these signals as an independent controller to improve its bot detection. Our server sends only the short-lived verification token and our secret service key, not form contents. We do not store the token. It is valid for no more than five minutes and one verification. This integration does not provide for pre-clearance. The purpose and basis are our legitimate interest in a secure, usable request form (Article 6(1)(f) GDPR); strictly necessary device access serves this requested protection function (section 165(3) Austrian TKG 2021). International transfers are subject to the safeguards described in the Cloudflare section. If you experience technical difficulties, you can call us.
Last updated: 6 September 2026 · Privacy notice version 2026-09-06.
