Skip to content
ARIVENOAll documents

Privacy

Ariveno Privacy Policy

Information about the processing of account, representative, billing, security and usage data in Ariveno.

Version 2026-09-07-beta.10 · effective from 2026-09-07

Download the immutable Markdown source.

Version: 2026-09-07-beta.10 Effective date: from the publication of this version Controller of account and service data: Brillnet Piotr Adamski, ul. Henryka Sienkiewicza 73/6, 90-057 Łódź, NIP 7321779060, REGON 101551294 Contact for privacy matters: privacy@ariveno.com

This English translation is provided for convenience. The binding text of this document is the Polish original of the same version (2026-09-07-beta.10), available at https://ariveno.pl/legal/privacy.

1. Who and what this Policy applies to

  1. This Policy explains how the Operator processes the data of:
    1. persons visiting ariveno.pl and ariveno.com;
    2. persons creating an account, representing a Customer and using the Panel;
    3. persons contacting support or reporting an incident;
    4. persons involved in the Customer's billing.
  2. In these cases the Operator is the controller.
  3. With respect to Salon Client data, data of team members entered by the Customer and appointment data, the controller is the salon/organisation using Ariveno. The Operator processes such data on its behalf under the Data Processing Agreement.
  4. A person who wishes to exercise rights concerning a booking, an appointment or a client record should first contact the relevant salon. Ariveno supports the salon in handling the request.
  5. Confirming that you have read this Policy does not constitute consent to data processing. The Operator bases its processing on the legal grounds indicated below.

2. Data processed by the Operator as controller

Depending on how the Service is used, the Operator may process:

  1. account data: first and last name, e-mail address, encrypted authentication data, account identifier, language and settings;
  2. organisation and representation data: business/company name, address, NIP or another identifier, role, membership, scope of permissions and a declaration of authority to act;
  3. legal acceptance data: document version, date and time, account, organisation, source of acceptance and required declarations;
  4. billing data: plan, subscription status, Stripe identifiers, amounts, currency, invoices, tax data, KSeF status and limited payment method data provided by Stripe, e.g. the card brand and last digits;
  5. technical and security data: IP address, request time, session identifier, browser, operating system, device, login events, administrative operations, errors, correlation identifiers and abuse-prevention signals;
  6. support data: content of correspondence, ticket metadata, attachments and information needed to resolve the matter;
  7. service communication data: recipient, message type, dispatch and delivery status;
  8. aggregated data: statistics on the operation of the Service which are not used to identify Salon Clients.

The Operator does not store full payment card data.

3. Purposes, legal bases and periods

PurposeData categoriesLegal basis under Art. 6 GDPRPeriod
Creating an account and organisation and performing the agreementaccount, organisation, representation, settingsArt. 6(1)(b); in the case of a representative also point (f) — legitimate interest in performing the agreement with the organisationfor the term of the agreement, then data necessary for claims as a rule for up to 3 years
Authentication, security, abuse prevention and Turnstiletechnical data, session, IP, security eventsArt. 6(1)(f) — protection of the Service, persons and dataWorkers logs up to 7 days, logs forwarded to private R2 up to 90 days, operational audit trail up to 24 months; longer only in the event of an incident or a legal obligation
Billing, invoices, taxes and KSeForganisation, billing, paymentArt. 6(1)(b) and (c)for the period required by tax and accounting regulations, usually 5 years calculated in accordance with the applicable provisions
Recording contractual acceptances and defending claimslegal acceptances, account, organisation, timeArt. 6(1)(f) — demonstrating the conclusion of the agreement and defending claimsfor the term of the agreement and the period of potential claims
Handling questions, complaints and incidentscontact, support, technical dataArt. 6(1)(b), and before the agreement point (f); where a legal obligation applies, point (c)until the matter is closed, then up to 3 years, unless a longer period results from proceedings or the law
Transactional, security and Service-change communicationsaccount, e-mail address, dispatch statusArt. 6(1)(b), (c) or (f) depending on the messagefor the time needed to deliver and evidence the communication; logs in accordance with the security retention
Development and reliability measurement of the Serviceaggregated statistics and limited technical dataArt. 6(1)(f) — development and quality assurancefor the period necessary for analysis; identifying data in accordance with the log retention

If data is needed to establish, pursue or defend claims, the Operator may restrict its use and retain it until the matter is finally resolved.

4. Where the data comes from

  1. Directly from the data subject — during registration, login, contact and configuration.
  2. From the Customer, the organisation owner or another authorised User — when they invite a person to the team or complete representation data.
  3. Automatically from the device and from use of the Service — with respect to technical and security data.
  4. From providers used to perform the Service, in particular Stripe and e-mail and security providers — with respect to payment statuses, delivery and technical events.
  5. From public registers, where this is needed to verify a business or to comply with a legal obligation.

5. Is providing data mandatory

  1. Data marked as required is necessary to create an account, identify the contracting party, ensure security, process payments or comply with a legal obligation.
  2. Failure to provide it may prevent the conclusion or performance of the agreement.
  3. Optional data is clearly marked; not providing it does not block core functions, unless it is necessary for a function chosen by the Customer.

6. Recipients and providers

  1. Data may be received by:
    1. authorised persons supporting the Operator, bound by confidentiality;
    2. Cloudflare — hosting, database, object storage, network, security and primary e-mail;
    3. Resend, a service of Plus Five Five, Inc. — solely for emergency e-mail dispatch after confirmed unavailability or rejection of the primary service;
    4. Stripe — subscription and payment handling;
    5. providers of e-mail and support tools used by the Operator;
    6. public authorities, where the obligation to disclose arises from the law.
  2. With respect to data entrusted by the salon, the current entities and their roles are described in the Subprocessor List.
  3. SMSAPI is a provider selected and paid for directly by the salon. If the salon enables SMS, Ariveno transmits the number, content and delivery metadata as a technical connector in accordance with the salon's instructions.
  4. The Operator does not sell data, does not share it with data brokers and does not use salon data or Salon Client data to train AI models.

7. Transfers outside the EEA

  1. The core operational data of organisations is stored in D1 and R2 resources and handled by Durable Objects configured for the EU jurisdiction.
  2. Cloudflare operates a global network and support. Resend is a service of Plus Five Five, Inc., established in the United States; emergency e-mail dispatch may therefore involve a transfer of data outside the EEA under the mechanisms referred to in point 3. Further providers of Cloudflare or Plus Five Five may, in specific operations, cause a transfer of data outside the European Economic Area.
  3. The Operator relies on the mechanisms provided for in Chapter V of the GDPR, as applicable:
    1. an adequacy decision, including the EU–US Data Privacy Framework, where the given recipient and scope are covered by it;
    2. the European Commission's Standard Contractual Clauses;
    3. additional technical and organisational measures, where needed.
  4. Information about the mechanism applied, or a copy of it, can be obtained by writing to privacy@ariveno.com; parts of the content may be anonymised to protect secrets and security.

8. Cookies and browser storage

  1. Ariveno uses only mechanisms necessary to:
    1. maintain a secure session and login;
    2. remember essential settings;
    3. protect forms against bots and abuse, including Cloudflare Turnstile;
    4. keep bookings and the Panel working.
  2. Ariveno's first-party product analytics is cookie-free, limited to aggregated functional events and stored in Cloudflare resources configured for the EU jurisdiction. It does not require a marketing consent banner.
  3. The Operator does not use Google Analytics, Google Ads, Meta Pixel, session recording tools, remarketing or behavioural advertising.
  4. The PWA does not store Salon Client data, appointments or the schedule in persistent browser storage for offline operation.

9. Automated decisions

The Operator does not make decisions concerning individuals based solely on automated processing that would produce legal effects or similarly significantly affect them.

10. Security

The Operator applies measures appropriate to the risk, in particular:

  1. encryption of transmission and secrets management;
  2. logical isolation of organisations and private data resources;
  3. roles, authentication and access restriction;
  4. audit trail, security logging and alerting;
  5. data minimisation in queues and telemetry;
  6. backups, restore tests and incident procedures;
  7. change control and separation of production from the test environment through zones, tokens, resource prefixes, bindings and deployment safeguards;
  8. a prohibition on permanently storing operational personal data in the browser.

No system provides absolute security. The Customer should protect its accounts and should not send passwords or keys in support communications.

11. Rights of data subjects

To the extent provided for by the GDPR, a data subject has the right to:

  1. access their data and obtain a copy of it;
  2. rectify the data;
  3. request erasure of the data;
  4. request restriction of processing;
  5. receive the data in a structured format and port it, where the conditions are met;
  6. object to processing based on legitimate interest;
  7. withdraw consent at any time, where the specific processing is based on consent, without affecting the lawfulness of prior processing;
  8. lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

A request may be submitted through the secure data-subject rights form, which verifies identity through a verified e-mail address and routes the case to the relevant salon. For matters in which the Operator is the controller, privacy@ariveno.com also remains available. As a rule, a response is provided within one month; in a complex case the deadline may be extended by a further two months after informing about the reason.

Contact details of the supervisory authority are available on its official website: uodo.gov.pl.

12. Salon Client data processed on the salon's instructions

  1. The scope may include first name, last name, phone number, e-mail address, bookings, appointments, organisational preferences, communication history, consents and technical metadata.
  2. The scope should not include health data or other special categories of data.
  3. The default retention is 180 days from the last completed appointment; the salon may set between 30 and 3650 days. The active value visible in the given salon's Panel is its current configuration and takes precedence over the default value.
  4. The salon may handle access, rectification, restriction, erasure and portability through the privacy features. Erasure may take the form of irreversible anonymisation where retaining non-identifying records is needed for the consistency of the salon's billing or statistics.
  5. Detailed rules are set out in the Data Processing Agreement.

13. Changes to the Policy

  1. The Operator updates the Policy when purposes, providers, retention, features or the law change.
  2. The Operator gives notice of a material change by e-mail or in the Panel before it takes effect, unless an urgent change results from the law or security.
  3. A new version does not retroactively change the legal basis of processing already performed.
  4. Archived versions are available on request.
  5. Version 2026-09-02-beta.9 removes Google Ads measurement and the marketing banner, restores first-party cookie-free analytics, and adds a secure data-subject rights form with identity verification.
  6. Version 2026-09-01-beta.7 restores Resend (Plus Five Five, Inc.) as the emergency transactional e-mail provider, in line with the canonical product specification and the actual service configuration; EmailLabs (Vercom S.A.) is not used.
  7. Version 2026-08-29-beta.6 unifies the default retention of Salon Client data at 180 days and clarifies the precedence of the salon's active configuration.
  8. Version 2026-07-29-beta.4 introduced voluntary Google Ads conversion measurement; the integration was retired in version 2026-09-02-beta.9.

14. Contact

  • privacy and data subject rights: privacy@ariveno.com;
  • security: security@ariveno.com;
  • support and complaints: support@ariveno.com.

The Operator has not appointed a data protection officer because, according to its current assessment, the statutory conditions requiring such an appointment are not met. Questions may be directed straight to the privacy address.

Terms of ServiceDPASubprocessorsBeta terms