1. Parties and scope
This Data Processing Agreement ("DPA") is concluded between the Customer who uses Glanevo for its salon, as controller, and Glanevo SRL (CUI 40041255), as processor. It forms part of the Terms of Use and is accepted together with them. It applies to the personal data that the Customer enters in Glanevo and to all other personal data that Glanevo processes on the Customer's behalf while providing the service.
2. Standard contractual clauses
The parties agree to apply the standard contractual clauses between controllers and processors set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (EUR-Lex), with Glanevo SRL as processor and the Customer as controller. Clauses 1 to 10 of that Annex are incorporated into this DPA by reference. Sections 3 to 6 below contain the information for Annexes I to IV.
Options chosen: for Clause 7.7, Option 2 (general written authorisation) applies, and Glanevo informs the Customer in writing of any intended addition or replacement of sub-processors at least 30 days in advance. The optional docking clause (Clause 5) is not used. If this DPA or the Terms of Use contradict the Clauses, the Clauses prevail (Clause 4).
3. Annex I — List of parties
Controller: the Customer, identified by the details of its Glanevo account; its contact person is the account owner.
Processor: Glanevo SRL, Str. Nicolae Corneanu nr. 18, Caransebeș, Caraș-Severin County, Romania; contact: gdpr@glanevo.com.
The Customer signs this DPA by accepting the Terms of Use when creating the account; Glanevo SRL signs it by publishing it and providing the service.
4. Annex II — Description of the processing
- Categories of data subjects: the salon's clients, people who book online, and the salon's staff.
- Categories of personal data: identification and contact data; appointments and service history; preferences and notes; photos uploaded by the salon; payment data (a token, never the card number); reviews and replies.
- Sensitive data: health information that the salon chooses to record, such as allergies, contraindications or medical notes (special categories of data, Art. 9 GDPR). Safeguards: the free-text medical note is encrypted at field level; the other health fields the salon can fill in — allergies, chronic conditions, current medication, blood group and emergency contact — are stored without field-level encryption. All of them can be opened only by staff to whom the salon has granted the client-editing permission, and every opening of a health record is written to the access log. Health data is not used for automated decisions or profiling (Art. 3(1) of Romanian Law No. 190/2018). Before recording such data, the Customer must have a legal basis, as a rule the client's explicit consent.
- Nature of the processing: hosting, storage, organisation and display of the data, sending notifications (SMS, e-mail and, where the salon enables them, messaging channels such as WhatsApp), and backups.
- Purpose: providing the salon management service under the Terms of Use.
- Duration: for the duration of the contract and of the transition and data-retrieval periods described in section 12 of the Terms of Use; afterwards the data is deleted, unless Union or Member State law requires it to be kept.
5. Annex III — Technical and organisational measures
- Encryption of all traffic (HTTPS/TLS enforced) and encryption at rest of the database storage by the hosting provider.
- Field-level encryption of the free-text medical note; permission control and access logging for every health record, including the allergy, chronic-condition and medication fields, which are not encrypted at field level.
- Separation of each salon's data from all other salons. An automated check runs before every commit and blocks code that would take the salon identity from a global setting instead of from the request; the separation itself is covered by tests in our test suite.
- Two-factor authentication available for panel accounts, role-based permissions set by the salon owner, and revocation of sessions.
- Continuous database backups with point-in-time recovery.
- Card data is processed only by the payment provider; Glanevo stores a token only.
- Confidentiality obligations for everyone at Glanevo who has access to personal data.
6. Annex IV — Sub-processors
The Customer authorises the sub-processors listed on the Sub-processors page. Glanevo imposes on each of them, by contract, the same data protection obligations as in this DPA and informs the Customer of changes to the list at least 30 days in advance. The Customer may object; if the objection cannot be resolved, the Customer may terminate the contract without extra cost.
7. Transfers outside the European Economic Area
Where a sub-processor processes personal data outside the European Economic Area, Glanevo relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) for certified recipients, or on the standard contractual clauses adopted by Implementing Decision (EU) 2021/914 (module 3, processor to processor). The clauses referred to in section 2 do not by themselves cover such transfers. On request, Glanevo tells the Customer which safeguard applies to a given sub-processor.
8. Personal data breaches
Glanevo notifies the Customer of a personal data breach without undue delay after becoming aware of it, with the information set out in Clause 9.2, so that the Customer can meet its obligations under Articles 33 and 34 GDPR.
9. End of the processing
When the contract ends, the Customer can export its data as described in section 12 of the Terms of Use. Glanevo then deletes the personal data processed on the Customer's behalf, including existing copies, unless Union or Member State law requires them to be kept (Clause 10).
10. Contact
Questions about this DPA, requests for assistance and audit requests: gdpr@glanevo.com.