Juhász Vivien Lashes & Beauty Pécs processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Hungarian law. This notice covers online booking, user accounts, reviews and operation of the website.
1. Data controller
Juhász Vivien Lashes & Beauty Pécs
Registered office / postal address: Pécs
Email: vivi.93.juhasz@gmail.com
Phone: +36303915550
Appointment of a data protection officer is generally not mandatory for this processing. Privacy questions and data subject requests may be sent using the contact details above.
2. Processing activities
We request only data necessary for the relevant purpose. Mandatory fields are marked; without the required data the relevant service cannot be provided.
Appointment booking
- Data
- Name, email, phone, service, appointment time, booking code, optional notes and answers to custom questions.
- Purpose
- Creating, performing, changing and cancelling bookings, confirmations and reminders.
- Legal basis
- Taking steps to enter into and perform a contract — GDPR Art. 6(1)(b).
- Retention
- Up to 5 years after performance or termination where needed for civil claims; accounting documents are retained separately for the statutory period.
User account
- Data
- Name, email, phone, securely derived password hash, profile image, language and identifiers from a selected OAuth provider.
- Purpose
- Account creation, authentication, profile and booking management, account security.
- Legal basis
- Contract performance — GDPR Art. 6(1)(b); legitimate interests for security logging — Art. 6(1)(f).
- Retention
- Until account deletion and, where applicable, until related legal claims or mandatory retention periods expire.
Transactional email
- Data
- Email, name, booking details, password-reset token and technical delivery data.
- Purpose
- Booking confirmations, reminders, cancellation notices and password reset.
- Legal basis
- Contract performance — GDPR Art. 6(1)(b); legitimate interests for account security — Art. 6(1)(f).
- Retention
- Password-reset links remain valid for 1 hour. Technical delivery-log retention follows the selected email provider's policy.
Reviews
- Data
- Name or account identifier, rating, review text and submission time.
- Purpose
- Publication of the guest's requested review after moderation.
- Legal basis
- Freely given explicit consent — GDPR Art. 6(1)(a).
- Retention
- Until consent is withdrawn or the review is deleted.
Security and abuse prevention
- Data
- IP address, request time, technical log data and failed-attempt counters.
- Purpose
- Preventing unauthorised access, automated abuse, fraud and service disruption.
- Legal basis
- Legitimate interests in protecting the controller and users — GDPR Art. 6(1)(f).
- Retention
- Application rate-limit data is short-lived and held in memory; necessary server logs may be kept for up to 90 days unless required for incident investigation.
Optional integrations
- Data
- OAuth identifiers and tokens, calendar account details and booking data sent to the calendar.
- Purpose
- Google/Facebook login and Google or CalDAV calendar sync enabled by the salon.
- Legal basis
- Contract performance for user-initiated login; service performance and controller instructions for calendar transmission.
- Retention
- Until disconnection; external calendar events are deleted or updated according to the sync rules.
3. Health and other special-category data
The free-text notes field is not intended to collect health data. Please do not enter allergies, medical conditions or other sensitive data; discuss them directly with the provider. If online processing of such data becomes necessary for a treatment, separate explicit consent and purpose-specific information will be required.
4. Processors and recipients
Personal data may be accessed only as necessary by the following categories of recipients:
- Website, database, hosting, server and operations providers.
- The configured SMTP or email delivery provider.
- Google Calendar or CalDAV/iCloud if enabled by the salon.
- Google or Facebook if selected by the user for sign-in.
- Authorities, courts and other bodies entitled by law.
The controller must maintain GDPR Article 28 agreements with processors and keep an up-to-date internal record of the providers actually used.
5. Transfers outside the EEA
Some optional providers may belong to international groups. Transfers outside the EEA may take place only with safeguards under Chapter V GDPR, such as an adequacy decision or standard contractual clauses. The actual provider and safeguard depend on integrations enabled in Admin.
6. Cookies and external content
The website uses session and security cookies necessary for core operation. No analytics or marketing cookies are currently used. Google Maps loads only after a separate click. Detailed cookie notice
7. Your rights
Where the legal conditions are met, you may exercise the following rights:
- Access — request information about the data we hold.
- Rectification — request correction of inaccurate data.
- Erasure ("right to be forgotten") — request deletion in certain cases.
- Restriction — request temporary restriction of processing.
- Data portability — request your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdrawal of consent — withdrawal does not affect the lawfulness of earlier processing.
We generally respond within one month. Identity verification may be required, and erasure does not override mandatory retention duties.
8. Automated decision-making
The system does not perform automated decision-making or profiling producing legal or similarly significant effects.
9. Data security
We use access controls, encrypted HTTPS, password hashing, authorisation checks, backups and abuse controls. Incidents are assessed and documented; where required, NAIH is notified within 72 hours.
10. Remedies
Please first contact the controller using the details above. A complaint may also be filed with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): www.naih.hu, 1055 Budapest, Falk Miksa utca 9–11.
11. Changes to this notice
Material changes are communicated on the website and, where necessary, by email. The current version is always available on this page.
This notice is a baseline aligned with the system's actual data flows. The controller's individual operations, providers and agreements should be reviewed by a Hungarian privacy professional before live use.
