1. Who we are
edapi (edapi.io) is a booking and salon management system provided in Lithuania by an individual engineering practice. For any data question write to [email protected] — we answer within 30 days, usually sooner.
This policy covers www.edapi.io, salon pages on edapi.io subdomains and the emails the system sends.
2. Two roles: controller and processor
For salon account data (the owner and staff) we are the data controller: we decide what is needed for the account, its security and billing.
For the salon clients data we are a processor: the salon is the controller and we process the data only on the salon instructions and only to make the system work. A client request about their own data is handled first by the salon; our obligations towards the salon are set out in the Data processing agreement.
3. Salon account data
We collect: name, email address, a cryptographic hash of the password (we never store or see the password itself), phone number if you entered one, salon name, address and contacts, sign-in records, an action log (who changed what and when) and technical error records.
Why: to provide the service (GDPR Art. 6(1)(b)), to protect the account against unauthorised access and to meet accounting and subscription obligations (Art. 6(1)(c) and (f)).
Subscription payments are handled by Stripe. Card details never reach us — Stripe receives and stores them; we only see the payment fact, amount and status.
4. Salon client data
On the salon instruction the system may hold: client name, phone number, email address, salon notes about the client, allergy or health notes, no-show count, a blocked flag, and how and when the record was created.
If the salon merged two records of the same client, the name, phone and email from the merged record are kept too, so it is visible where the data came from.
For visits: service, specialist, time, status, price, visitor name (when booking for someone else), the client note, cancellation reason, number of reschedules, series information and deposit payment facts.
For messages and consent: marketing consent status, its history (when, from where and through which channel), types and statuses of emails sent, the content of personal messages, campaigns received and opt-outs, and reviews the client left.
Allergy and health notes are special category data (GDPR Art. 9). The lawful basis for them is the salon responsibility — the system offers the field but never requires it.
Consent records store a protected (peppered hash) value of the IP address, so that we can prove when consent was given without being able to reconstruct the address itself. It is not shown in the export.
5. Where the data comes from
From the owner — at sign-up, in the setup wizard and later in the admin area, including when importing a client list.
From the client — when booking a time on the salon page, confirming or changing a visit through the link in an email, or leaving a review.
Automatically — system records: sign-in times, the action log, error records and email delivery statuses.
6. Who receives the data
We use these providers (sub-processors), each only for the stated function: Contabo (Germany) — server and database hosting; Cloudflare — domain, traffic protection, the Turnstile check in the booking form and R2 photo storage; Resend — system and campaign emails; Stripe — subscription and deposit payments; Google (Gemini) — text draft generation when the owner asks for it.
Only the text the owner types herself (hints for a service description) is sent to Gemini — client data is not sent there.
We receive technical error notifications (the error text and the place in the code) through Telegram — an internal tool for us, not a client data channel.
Fonts are loaded from Google Fonts, so Google receives your browser IP address and the name of the requested font. No cookies are set for this.
We do not sell data and do not share it with anyone for marketing purposes. We disclose it only where the law requires it or where the salon itself asks us to.
7. Transfers outside the EEA
The server and database are in the European Union. Some providers (Cloudflare, Resend, Stripe, Google) are US-based and may process data outside the EEA — such transfers rely on the European Commission standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
8. How long we keep it
We keep salon account and client data for as long as the salon uses the system. The owner can delete an individual client personal data at any time — name, phone, email, notes, allergies, message and review texts are then removed irreversibly, while visit times and amounts remain without personal data (the salon needs them for its own accounting).
Action log entries survive the deletion of personal data but without personal data — they show who performed an action and when.
Email delivery records are kept so the same email is not sent twice and so we can resolve undelivered mail.
Exact retention periods after an account is closed will be published together with the account closing feature; until then data is deleted at the owner request sent from the account email address.
9. How we protect it
All traffic is encrypted (HTTPS). Passwords are stored only as cryptographic hashes. Every database query is mandatorily scoped to a single salon — without a salon context the system refuses to run it.
Nothing is deleted silently: a destructive action is written to the action log together with its author. The booking form is protected against automated requests by Cloudflare Turnstile and rate limits.
Only we have server access, and it is protected by an SSH key, with no password login.
10. Your rights
You have the right to access your data, to have it corrected or erased, to restrict processing, to object to processing and to receive a copy in a portable format.
A salon owner and a staff member can download a copy of their own data in the admin area (Security → My data), and a copy of the whole salon data in the salon settings.
A client whose data is in a salon record should ask the salon for a copy or erasure — the salon is the controller and can do it with one button. If the salon does not respond, write to [email protected] and we will remind them.
You can opt out of marketing emails at any time — every such email carries an unsubscribe link that works without signing in.
If you believe your data is processed unlawfully you may complain to the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).
11. Changes
The version and date of this policy are shown at the top of the page. If processing changes materially we notify salon owners by email before the change takes effect.