Your data
Privacy policy
This notice explains transparently which data we use for secure operation, your appointment request and optional functions chosen by you.
1. Controller
Haarstudio Style, owner Cornelia Buchsbaum
St. Veiter Ring 43, 9020 Klagenfurt am Wörthersee, Austria
Email: [email protected]
Phone: +43 664 439 59 59
2. Netcup hosting, server logs and email
The website and database run on the Netcup web-hosting product we commissioned at its Vienna server location. The provider is netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. A request causes the web server to process the IP address, time, requested address, status code, transfer volume, referrer and browser/system information. Purposes are delivery, error analysis and attack detection, based on our legitimate interest in a secure and stable website (Article 6(1)(f) GDPR). Routine server logs are deleted within 14 days; extracts concerning a specific security incident may be retained longer until investigation and defence are complete.
Emails sent to the published GMX address are processed by 1&1 Mail & Media GmbH, Karlsruhe branch, Brauerstraße 48, 76135 Karlsruhe, Germany. Sender and recipient information, time, delivery metadata and message content are involved. The legal basis is Article 6(1)(b) GDPR for enquiries and otherwise Article 6(1)(f) for business communications. Correspondence is deleted according to the case and applicable legal evidence obligations.
3. Cloudflare proxy, CDN and security
Cloudflare operates in front of the Vienna origin as reverse proxy, content delivery network and security layer. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. It processes the IP address, destination, time, HTTP/TLS and device information, security signals and, depending on the enabled protection, essential cookies. Purposes are fast delivery, TLS, availability and abuse prevention, based on Article 6(1)(f) GDPR.
Cloudflare uses a global Anycast network, so connection data may be processed outside the EEA. Depending on the recipient, transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or safeguards such as EU Standard Contractual Clauses. Cloudflare publishes its current subprocessors.
4. Appointment requests and retention
For an appointment request we process your name, mandatory phone number, optional email address, requested service, preferred date/time window and voluntary notes. Mandatory data is required to assess the request and answer questions. The legal basis is pre-contractual action under Article 6(1)(b) GDPR. The checkbox merely acknowledges this notice and is not consent to the processing required to answer you.
Do not enter diagnoses, medication, treatment details or other health data in the free-text field. For a personal consultation concerning wigs, hair density or scalp, a neutral appointment description is sufficient; medical details do not belong in the web form.
Unconfirmed, contacted-only, rejected or cancelled requests are deleted after 365 days without further handling. Confirmed, completed or archived records are deleted after no more than seven years unless a longer statutory duty or specifically documented legal defence requires otherwise. The long-term booking does not store an IP hash. Security audit data with a pseudonymous IP hash is deleted after 730 days; completed or permanently failed notification jobs after 90 days.
5. Internal email, Telegram or WhatsApp notifications
Optional internal alerts tell the salon team only a pseudonymous case reference and protected admin link; form contents are not placed in the notification. The reference remains personal data while it can be linked internally to a request. Email uses the configured SMTP provider. Telegram alerts involve Telegram Messenger Inc.; WhatsApp alerts for EEA users involve WhatsApp Ireland Limited. These channels remain off until configured in the hosting environment.
The purpose is prompt handling, based on Article 6(1)(b) and (f) GDPR. Where a third-country transfer is involved, the mechanisms described above apply. Provider account metadata also follows the deletion rules of the enabled account. The local queue item is removed 90 days after successful or permanently failed delivery.
6. Local analytics
Only after consent to “Analytics” do we count selected events such as a page view, phone click or successfully submitted request. We store only daily aggregates by page, language and referring domain. No user profile, full referrer, device identifier or raw IP address is stored in analytics. Aggregates are physically deleted after no more than 395 calendar days. The basis is Article 6(1)(a) GDPR together with section 165(3) Austrian Telecommunications Act 2021.
7. Campaign attribution
Only with marketing consent do we keep limited UTM source, medium, campaign, content and term values for the current browser session. Each value is limited to 100 characters from a restricted set; complete query strings, gclid/fbclid, referrer paths and form fields are excluded. A successfully saved request may store first and last touch with the consent version. Session attribution is removed on withdrawal; attribution attached to a request follows that request’s deletion period.
8. Google Tag Manager, Analytics, Ads and verification
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Under the default Basic Consent Mode, Google tags load only after you permit analytics and/or marketing. Google Analytics 4 may then process online identifiers, IP/device/browser information, pages and interactions. Under Google’s standard configuration, _ga and _ga_<ID> may last up to two years; the event/user retention configured in the Google account applies in addition. Google Ads and conversion measurement activate only with marketing consent; possible _gcl_ cookie periods depend on the deployed Google configuration.
An advertising conversion is triggered only after the request was saved successfully. The website code sends no name, phone number, email address, free text or selected service to Google. Enhanced Conversions remain disabled. Google/Meta tags are technically blocked on privacy pages and health-adjacent topics. Search Console and Bing verification meta tags themselves create no visitor connection to those services.
Google may transfer data to affiliates and service providers outside the EEA. Depending on the recipient, adequacy decisions or safeguards such as Standard Contractual Clauses apply. Consent can be withdrawn at any time through Cookie settings.
9. Meta Pixel, Facebook and Instagram
The EEA provider for Facebook and Instagram is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Profile links transfer data only when clicked. A configured Meta Pixel loads only on unrestricted pages and after marketing consent. It may process the page address, IP, device/browser information, interactions, _fbp and, where present, _fbc; under the current Meta cookie policy those identifiers generally last up to 90 days. The pixel receives no form fields. Meta Conversions API and Automatic Advanced Matching are not enabled.
Article sharing links open the Facebook sharer or WhatsApp only after your deliberate click. They pass the article address and, for WhatsApp, the prepared title or message text to the selected platform; the provider also processes customary connection and, where applicable, account data. The EEA provider for WhatsApp is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. These sharing links create no connection before you click.
The server-side Instagram sync obtains only posts from the salon’s own professional account through the official API and stores them for one day by default. Expired cache data is physically removed. Your browser loads Instagram previews from the Meta/Instagram CDN only after consent to external content.
10. Customer images
Real customer images in “Fresh from the studio” or editorial areas are used only on the basis of verifiable, freely given publication consent under Article 6(1)(a) GDPR. The person, image, approved channels, grant date, duration and any withdrawal are recorded. Publication ends on expiry or withdrawal; delivery and local copies are then removed unless a short technical backup period or specific legal defence prevents this. Consent can be withdrawn at any time through the contact details above.
11. Google reviews
If enabled, we retrieve reviews from the verified Google Business Profile server-side. Public display name, review text, stars, timestamp, overall average and count are processed. Google is the source rather than the reviewer directly (Article 14 GDPR). The purpose is an authentic presentation of customer experience, based on our legitimate interest under Article 6(1)(f). Objections or correction/deletion notices may be sent to us and directly to Google.
The site delivers text locally, so reading it creates no direct browser connection to Google. Cache duration is one day by default and technically never more than 30 days; expired rows are physically removed. Any manually published review requires documented provenance and permission.
12. OpenStreetMap
The embedded map loads only after consent to external content. The recipient is the OpenStreetMap Foundation (OSMF). A request may involve IP address, browser/device information, referrer, timestamp and the requested page or tile. OSMF operates and caches map services through international infrastructure, so data can also be processed outside Austria. The basis is Article 6(1)(a) GDPR and section 165(3) Austrian Telecommunications Act 2021. You may instead deliberately open the external directions link.
13. Cookies and browser storage
Essential: hss_booking_form protects the booking form for two hours (HttpOnly, SameSite=Strict and Secure under HTTPS). style_admin is used only in the protected admin area for the current session (HttpOnly, SameSite=Strict and Secure under HTTPS). The haarstudio-style-consent:<version> choice remains in Local Storage for 30–365 days, default 180. Cloudflare may set essential security cookies according to the enabled protection.
Optional: haarstudio-style-campaign:<version> keeps UTM values only for the current session and only with marketing consent. Analytics consent may create Google _ga/_ga_<ID>; marketing consent may create Google _gcl_ and Meta _fbp/_fbc identifiers. OpenStreetMap and Instagram previews load only with external-content consent. Withdrawal blocks subsequent provider requests and removes reachable first-party identifiers and the campaign session.
14. Recipients and international transfers
Depending on your use and only when the relevant function is enabled, recipients are Netcup, Cloudflare, 1&1 Mail & Media/the configured SMTP provider, Google, Meta, Telegram, WhatsApp and OpenStreetMap. Providers receive only what is required for their task. Applicable processing terms are concluded with processors.
For recipients outside the EEA we use, depending on the recipient, an adequacy decision including the EU-US Data Privacy Framework for certified US recipients or safeguards, in particular EU Standard Contractual Clauses. You may request a copy of the essential safeguards through the email above.
15. Your rights and complaint
Subject to GDPR conditions, you have rights of access, correction, erasure, restriction, portability and objection. Consent may be withdrawn for the future through Cookie settings or by contacting us. No solely automated decision with legal or similarly significant effect takes place.
You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
16. Security and changes
We use transport encryption, role and access controls, secure admin sessions, rate limits, pseudonymised security logs, updates and limited retention. No internet service can guarantee absolute security.
We update this notice when functions, providers or applicable law change. Material changes receive a new privacy/consent version so that your choice is requested again.
Last updated: 29 July 2026 · Privacy notice version 2026-07-29.