Privacy Policy
Last updated: 25 August 2026
This policy explains what personal data we process when you visit https://before-and-after.ro, when you book an appointment and when you use our services, why we process it and what rights you have. It is written in line with Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 506/2004 on privacy in electronic communications.
1. Who the controller is
The data controller is Before & After Look SRL, a Romanian company, VAT/registration code 40190630, Trade Register no. J35/4123/2018, EUID ROONRC.J35/4123/2018, with its registered office at Str. Planetei 12, Et. 2, Ap. 9, Sat Giroc, Jud. Timiș, Cod 307220 and its salon at Bv. Constantin Brâncoveanu 3, Timișoara, Timiș county, postal code 300217, Romania.
You can reach us about anything concerning your personal data:
- Email: [email protected]
- Phone: 0771 107 948
- Post: at the salon address above
We are not legally required to appoint a Data Protection Officer, because we do not carry out large-scale systematic monitoring and do not process special categories of data on a large scale. Your requests are handled directly by salon management, at the contact details above.
2. What we process, why, and on what legal basis
a) Visiting the site
- Access and security logs: IP address, browser type and version, operating system, page requested,
referring page, date and time. This data is generated automatically by the infrastructure serving the site and is
needed to deliver pages and to protect against attacks and abusive automated traffic.
Basis: legitimate interest, Art. 6(1)(f) GDPR (security and operation of the site). - Storage on your device (localStorage): your theme preference and your cookie choice.
These values stay on your device and are never sent to us.
Basis: strictly necessary for the service you requested, Art. 5(3) of the ePrivacy Directive as transposed by Law no. 506/2004.
b) Traffic analysis
- Google Analytics 4: if you choose "Accept all" in the cookie banner, we collect statistical data about
how the site is used: pages visited, session duration, device type, traffic source and approximate city-level location.
We do not use this data for advertising and we do not combine it with your client records.
The Google Analytics script is not loaded at all until you consent, so until that moment no information about you
reaches Google through this site.
Basis: consent, Art. 6(1)(a) GDPR. You can withdraw it at any time.
c) Online booking through Scisso
-
When you book through the booking form on this site or through our Scisso-hosted page, the following is collected:
your first and last name, your phone number, optionally your email address and
date of birth, the service and stylist you chose, the date and time you want, and any note you write.
We use this to record, confirm and prepare your appointment and to keep a history of services performed.
Basis: performance of a contract or pre-contractual steps at your request, Art. 6(1)(b) GDPR.
d) Phone bookings and direct contact
-
When you call or write to us, we process your name, phone number or email address and the content of your request.
We do not record phone calls.
Basis: performance of a contract or pre-contractual steps, Art. 6(1)(b) GDPR, and legitimate interest, Art. 6(1)(f) GDPR, for correspondence unrelated to an appointment.
e) SMS reminders
-
We send a reminder SMS roughly 24 hours before your appointment, plus messages confirming, changing or cancelling it
where relevant. These messages are part of the booking service and contain only information about your reservation.
You can opt out at any time by asking us.
Basis: performance of a contract, Art. 6(1)(b) GDPR. We do not send you marketing or promotional messages without your separate consent.
f) Health information you give us in the salon
-
For certain services (colouring, facial treatments, laser hair removal) we may ask about known allergies, previous
reactions, skin or scalp conditions, pregnancy, or ongoing medical treatment. This is health data,
a special category. We use it solely to decide whether a service can be performed safely and how it should be adapted,
and we share it only with the person performing your service.
Basis: your explicit consent, Art. 9(2)(a) GDPR, to use this information in order to provide the service. You are not obliged to tell us, but without it we may decline or postpone the service, as set out in our Terms and Conditions.
Separately, we keep the completed form and any signed consent under Art. 9(2)(f) GDPR, for the establishment, exercise or defence of legal claims. That is why the document stays with us for as long as a claim could still be brought, even if you withdraw your consent for the processing based on point (a).
g) Photographs of our work
-
We publish photographs of work done in the salon in the site gallery and on our Instagram and Facebook accounts.
Where you are identifiable in a photograph, that photograph is personal data.
Photographs are taken and published only with your agreement, given in the salon before the photo is
taken and before it is published.
Basis: consent, Art. 6(1)(a) GDPR. You can withdraw it at any time and the photograph will be removed from the site and from our social accounts as soon as we reasonably can. Withdrawal does not affect the lawfulness of publication before that point.
h) Tax and accounting obligations
-
Issuing fiscal receipts and, on request, invoices, and keeping supporting documents.
Basis: legal obligation, Art. 6(1)(c) GDPR (Romanian tax and accounting law).
i) The map in the contact section
-
The interactive map is provided by an external service, so it never loads on its own.
It appears in only two situations: if you chose "Accept all" in the cookie banner, which names this map
explicitly, or if you press the "See map" button on the placeholder shown in its place.
Until one of those happens, your IP address is sent to nobody, and the placeholder shows you the salon
address anyway.
Basis: consent, Art. 6(1)(a) GDPR, given either through the banner or by pressing the button. You can use the Google Maps link instead, which takes you off this site.
3. Who we share data with
We do not sell or rent your data. We share it only with the providers who help us run the salon and the site, under data processing agreements as required by Art. 28 GDPR, and with public authorities where the law requires it.
| Recipient | Role | What they receive | Where |
|---|---|---|---|
| KodeKind S.R.L. (Scisso), VAT RO54603957 | Processor. Booking platform and reminders | Appointment and client record data | European Union |
| S.C. SMSAdvert S.R.L. | Sub-processor of Scisso. Backup SMS delivery | Phone number and message text | Romania |
| Cloudflare, Inc. | Processor. Content delivery, anti-abuse protection and DNS for this site | IP address and request metadata | EU, with transfer to the USA under SCCs |
| Google Ireland Limited / Google LLC | Processor. Google Analytics 4 | Statistical usage data, only with consent | EU, with transfer to the USA under SCCs and the EU-US Data Privacy Framework |
| CARTO (map imagery) | Map provider | IP address, only if you choose to display the map | EU / USA |
| Accountants and tax authorities | Legal obligation | Supporting documents | Romania |
Scisso is operated by KodeKind S.R.L., which acts as our processor for our clients' data. Their privacy policy is available at scisso.app/en/privacy.
4. Transfers outside the European Economic Area
Appointment data is hosted on servers in the European Union. Some infrastructure and analytics providers are United States companies or may process data there. Those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework, together with additional technical measures such as encryption in transit.
5. How long we keep data
| Category | Retention |
|---|---|
| Access and security logs | Up to 30 days |
| Client record and appointment history | 2 years from your last appointment |
| SMS message content | Deleted immediately after delivery |
| Health information, consultation forms and signed consents | 5 years from the service, for the defence of legal claims |
| Photographs published with your consent | Until you withdraw consent |
| Email correspondence | Up to 3 years, as a record of requests |
| Tax and accounting documents | The periods required by Romanian tax and accounting law |
| Google Analytics | 14 months |
| Data stored in your browser | Until you delete it, or the expiry noted below |
6. Cookies and local storage
The law treats any information stored on your device the same way, whether it is a classic cookie or localStorage. Below is the complete list of what this site stores.
Strictly necessary, no consent required
| Name | Type | Purpose | Duration |
|---|---|---|---|
ba-consent | localStorage | Remembers your cookie choice so we do not ask on every page | 12 months, then we ask again |
theme-preference | localStorage | Remembers your chosen theme (light, dark or system) | Until deleted |
__cf_bm and similar | Cookie | Cloudflare security cookie, distinguishing human from automated traffic | Up to 30 minutes |
Analytics, only with your consent
| Name | Type | Purpose | Duration |
|---|---|---|---|
_ga, _ga_* | Cookie | Google Analytics 4. Distinguishes visitors and sessions | Up to 2 years |
Third parties loaded at your request
The booking form is provided by Scisso and runs in an isolated frame, loaded when you open the booking page or press a booking button. Scisso may store information inside that frame as needed for the form to work, and uses Cloudflare Turnstile to block automated submissions. Details are in the Scisso policy linked above.
You can change your choice at any time using the "Cookie preferences" button in the footer of every page. Withdrawing consent is as simple as giving it and takes effect immediately. Whenever we change what "Accept all" covers, we ask you again, because consent given for a narrower purpose cannot stand in for a new one. You can also clear stored data from your browser settings.
7. Your rights
Under the GDPR you have the right to:
- Access: find out whether we process your data and receive a copy of it
- Rectification: have inaccurate data corrected and incomplete data completed
- Erasure: have your data deleted where we have no remaining basis to keep it
- Restriction: have processing limited while a challenge of yours is verified
- Portability: receive the data you gave us in a structured, machine-readable format
- Objection: object to processing based on our legitimate interest
- Withdraw consent: at any time, without affecting the lawfulness of processing before withdrawal
- Not be subject to automated decisions: we do not make decisions with legal effects about you by purely automated means, and we do not profile
To exercise any of these rights, write to [email protected], call 0771 107 948, or come into the salon. We reply within one month of receiving your request, extendable by two months for complex requests, in which case we will tell you. Exercising your rights is free of charge. We may ask you to confirm your identity, so that we do not disclose your data to someone else.
If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania, www.dataprotection.ro. You also have the right to seek a judicial remedy.
8. Children
This site is not directed at children and we do not knowingly collect data from anyone under 16 through it. Online bookings must be made by a parent or legal guardian. Children are welcome in the salon when accompanied by a parent or legal guardian, who provides the necessary data and consents to the service.
9. Security
The site is served over HTTPS only, with TLS encryption. Access to the booking system is through individual password-protected accounts, and staff access is limited to what their work requires. Paper documents are kept in areas with restricted access. No system is perfectly secure, but if a personal data breach occurs that is likely to affect your rights, we will inform you and notify ANSPDCP within the deadlines set by Art. 33 and 34 GDPR.
10. Changes to this policy
We may update this policy when our services, providers or legal requirements change. The date of the last update is shown at the top of the page. If the changes are significant, we will tell you through a visible notice on the site. We recommend checking this page from time to time.