Privacy Policy
Version 1.0 · 8 September 2026
Amvela handles two quite different kinds of personal data, and the law treats them differently. Section 1 explains the split, because almost everything else depends on it.
1The two roles
Under UK GDPR, whoever decides why and how personal data is used is the controller. Whoever handles it on the controller’s instructions is the processor. Amvela is both, depending on whose data we are talking about.
- Salon account data — The salon owner and staff who sign up, log in and pay us. Here Amvela is the controller — section 2.
- Salon client data — The people your salon books in. Here the salon is the controller and Amvela is only the processor — section 3.
If you run a salon, this is the part to take away: your clients’ personal data is yours, legally as well as practically. You decide what is collected, why, and how long it is kept. We hold it for you and do what you tell us with it. If one of your clients asks to see their record or wants it deleted, that request is yours to answer — and section 3 sets out how we help you answer it.
2When we are the controller
This covers the people who run and use a salon’s Amvela account.
What we hold
- Account details — salon name, the handle it trades under, contact email.
- Staff logins — name, username, role, and a one-way hash of the password. We do not hold passwords and cannot recover or read one.
- Billing — plan, price, invoice history and a Stripe customer reference. We never see or store card numbers.
- Technical records — sign-in times, IP addresses and an audit log of significant actions, kept for security and to answer “who changed this?”.
Why, and on what basis
- To provide Amvela — Performance of our contract with you.
- To take payment — Performance of our contract, and our legal obligation to keep accounting records.
- To keep it secure — Our legitimate interest in preventing unauthorised access — this is why failed sign-ins and IP addresses are recorded.
- To email you about the service — Performance of our contract. These are service messages, not marketing. We do not send marketing to salon accounts.
3When we are the processor
Everything a salon records about its clients, its appointments and its takings, we hold on that salon’s instructions. This section, together with the Terms of Service, forms the written processing agreement required by Article 28 of the UK GDPR.
What the processing covers
- Subject matter — Hosting and operating salon management software.
- Duration — For as long as the salon’s account is open, plus the retention period in section 9.
- Nature and purpose — Storing, organising, retrieving, backing up and deleting salon records so the salon can book appointments, keep client histories and take payment.
- Data subjects — The salon’s clients, and the salon’s own staff.
- Types of data — Names, phone numbers, email addresses, dates of birth, appointment history, free-text notes, colour formulas, patch test results, marketing consent records, purchase and payment history.
What we commit to
- We process client data only on the salon’s documented instructions — which, in normal use, means the actions taken in the software itself — unless the law requires otherwise, in which case we will tell the salon first unless forbidden from doing so.
- Everyone with access is bound by confidentiality.
- We keep appropriate security measures — section 7.
- We will not add a new sub-processor without telling salons first and giving them a chance to object — section 6.
- We help you answer your clients’ requests. Amvela lets you find, correct, export and delete a client record yourself; where that is not enough, ask us.
- We help you with security obligations, breach notification and impact assessments, so far as is reasonable given what we know.
- At the end of the account we delete or return the data, as you choose — section 9.
- We will provide the information you reasonably need to show you are complying, and allow an audit on reasonable notice.
One salon cannot see another’s data. Every salon gets its own separate database rather than sharing tables with a column marking whose row is whose. It means a mistake in a query cannot show one salon another’s takings, because the other salon’s rows are not in the database being queried at all.
4Patch tests and health data
Amvela records patch test results — whether a client reacted to a product, and when. That is almost certainly health data, which UK GDPR calls a “special category” and protects more strictly than a name and phone number.
Salons: this places a duty on you, not on us. To record a patch test result you need an Article 9 condition on top of your ordinary lawful basis. In practice that normally means the client’s explicit consent, given freely and recorded — not assumed because they sat in the chair.
The same applies to anything of that kind you type into a client’s notes: allergies, medication, pregnancy, skin conditions. The notes field will hold whatever you put in it. Treat it accordingly, and consider whether you need to record it at all.
We hold this data with the same protections as everything else in your salon’s database, but we are the processor here. What is lawful to collect, and on what basis, is the salon’s decision.
5Where your data is held
Amvela runs on servers in Falkenstein, Germany, operated by Hetzner Online GmbH. Your data does not leave the European Economic Area in the ordinary course of running the service.
The UK Government has determined that the EEA provides an adequate level of protection for personal data, so no additional transfer safeguards are needed for data moving from the UK to Germany.
6Who else touches it
We keep the list deliberately short. As of the date of this policy it is two:
- Hetzner Online GmbH — Germany. Hosting and daily backups. They hold the data at rest; they do not use it.
- Stripe — Payments. Handles subscription payments from salons to Amvela. Card details go directly to Stripe and never reach our servers. Stripe acts as a controller in its own right for parts of that data, under its own privacy policy.
There is no analytics provider, no advertising network, and no third-party tracking anywhere in Amvela or on this website.
If we ever add a sub-processor, salons will be told by email before it starts, with enough notice to object.
7Security
- All traffic is encrypted in transit (HTTPS, with HSTS).
- Passwords are stored only as one-way hashes, never in a form anyone can read.
- Each salon has a physically separate database.
- Sign-in attempts are rate-limited, and sessions time out when idle.
- Significant actions are written to an append-only audit log.
- Backups are taken daily and held encrypted.
- The server accepts connections only on the ports it needs, and administrative access requires a cryptographic key — not a password.
No system is perfectly secure and we will not claim otherwise. What we can say is that the measures above are actually in place, not aspirations.
8If something goes wrong
If personal data we hold is breached, we will tell affected salons without undue delay and in any event within 48 hours of becoming aware, with what we know: what happened, what data was involved, and what we are doing about it.
Where Amvela is the processor, the salon is the one who must decide whether to report to the ICO and whether to tell their clients — the 72-hour clock is theirs. We will give you what you need to make that decision quickly.
9How long we keep things
- Live salon data — For as long as the account is open. What is kept inside it is the salon’s decision.
- After an account ends — 90 days, then permanent deletion. Ask and we will delete sooner.
- Backups — Rotated on a rolling basis; deleted data disappears from backups as they age out.
- Billing records — 6 years, because HMRC requires it. This is invoice and payment information, not client records.
- Audit and security logs — Up to 12 months.
11Your rights
Under UK GDPR you can ask to see the personal data held about you, to have it corrected or deleted, to restrict or object to its use, and to receive it in a portable format.
Who to ask depends on which data it is.
- You run a salon — For your own account data, ask us directly — we are the controller.
- You are a salon’s client — Ask the salon. They are the controller of your record and they decide. If you contact us instead, we will pass your request to them and tell you we have done so; we cannot release or delete their records on our own authority.
We respond within one month.
12Contact and complaints
Amvela is operated by Catalina Andreea Ciofaca, trading as Amvela, of 111 Upton Park Road, London, E7 8LA, United Kingdom.
Email hello@amvela.app for anything in this policy.
If you are not satisfied with how we have handled a data protection matter, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but it is your right either way.