This Privacy Policy applies to the Lovely Lash Day mobile application, the website lovelylashday.com, and associated account and support services.
Who operates the service
Lovely Brand Estonia OÜ (registry code 16818323, VAT EE102656857), Punane tn 16-1, 13619 Tallinn, Estonia. Privacy and rights requests: info@lovelylashes.ee; +372 534 12 383. “Lovely”, “we”, and “us” refer to this company.
Different roles for different information
We act as controller for our website visitors, marketing preferences, prospects, support enquiries, app user accounts, security records and our own communications. The self-employed professional or salon operating a workspace is generally controller for personal data entered into client, visit, consultation, staff and salon records. For that workspace data, we act as processor under our Data Processing Agreement (DPA). Some account identifiers and operational metadata may be processed for both roles for different specified purposes.
Clients seeking access to salon-held records should generally contact their salon first; we assist salon controllers. Our own account and marketing data requests can be sent directly to us.
What data is involved
- Account and business: account-holder name, email, sign-in provider, business identity, registration code where supplied, country, languages, phone, workspace locations, roles and settings.
- Staff and security: names, role assignments, authentication identifiers, PIN hashes where applicable, access events, account recovery, device/session information and security audit logs.
- Operational work records: opening/before-client/after-client/closing/weekly hygiene checks, sterilisation cycles and results, instrument pouches, equipment checks, cleaning products and batches, glue records, stock, training certificates, risk analysis and incident records.
- Client and visit records stored by salons: names, telephone numbers, dates of birth, visits, consent and signatures, lash maps, optional photographs, allergies and contraindications (including pregnancy or eye-related conditions where the salon records them), patch tests and reported reactions.
- Technical/support: app version, device and operating system, sync and diagnostics, support messages, screenshots and correspondence; screenshots may contain personal data if supplied.
- Website/marketing: IP address, browser and visit details, cookie/consent choices, analytics, advertising identifiers and interactions where permission is obtained; newsletter preferences and campaign performance.
Purposes and legal bases
We use data necessary to supply the account and core service under GDPR Article 6(1)(b) where the relevant contractual party is a natural person, or legitimate interests under Article 6(1)(f) where appropriate for business user contacts. Security, fraud prevention, service troubleshooting and responding to non-contractual enquiries generally rely on legitimate interests (Article 6(1)(f)); legal recordkeeping on legal obligation (Article 6(1)(c)). Marketing emails and non-essential website tracking rely on consent where required (Article 6(1)(a) and applicable ePrivacy rules); consent may be withdrawn at any time.
A salon or technician, as controller, determines the lawful basis for client and staff records, including an Article 6 basis and a separate Article 9 condition where special-category health information is involved. The optional consultation and data notices in the app support, but do not substitute for, the salon’s legal assessment. Treatment consent is distinct from consent to processing personal data.
Client health details and photographs
Records of allergies, adverse reactions, contraindications, patch-test results and related health circumstances may reveal health information protected by Article 9 GDPR. Such information is entered by a professional for their business purpose, and must not be reused for our advertising, profiling or product recommendations. Portfolio or social-media publication of identifiable client photographs requires a separate optional permission from the salon’s client; photos kept in client records must not automatically be published.
Recipients and marketing connections
We use service providers for hosting, emails, authentication, push notifications, website measurement and advertising where applicable. These may include DigitalOcean, Brevo, Google and Apple authentication, Firebase Cloud Messaging, Google Analytics 4, Google Tag Manager, Google Ads and Meta Pixel. Their roles and purposes are described further in the Provider and Subprocessor Register.
Lovely Lash Day may contain clearly identified links to professional products at lovelylashes.ee and training at lovelyacademy.ee. Non-personal UTM campaign parameters may indicate that a visit originated from Lovely Lash Day. A link does not permit us to send salon client records to those sites. If visitors continue to those separate sites, those sites’ own privacy and cookie notices apply.
International processing
We use EU-hosted infrastructure for the core service where configured. Some providers or their affiliates may process or access information outside the EEA. Where restricted transfers occur, we rely on a valid adequacy decision or appropriate transfer safeguards in accordance with GDPR Chapter V.
Security and confidentiality
We apply technical and organisational safeguards appropriate to the nature of the information, including access restrictions, secure transmission, account permissions, confidentiality measures, logging and backup protections. No online service can guarantee absolute security. Users are responsible for protecting their own devices and access credentials.
Storage, retention and deletion
Account information is retained for as long as required to operate an account and, after closure, only as long as necessary for lawful security, administrative and legal purposes. Workspace owners determine retention of salon records, subject to applicable law. Data held in backups is removed under the backup lifecycle; legally required records may be retained for longer. We do not keep personal information indefinitely without a purpose.
Rights and complaints
Subject to applicable conditions, individuals may request access, rectification, erasure, restriction, portability, and objection, and withdraw consent without affecting prior lawful processing. We normally respond within one month and may verify identity proportionately. Requests relating to salon-controlled client data will be directed to the relevant salon with our assistance. Complaints may be lodged with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee or another competent EU supervisory authority.
Children, notifications and changes
The professional app is intended for users aged 18 or over. Information about under-18 salon clients is handled by the salon under applicable local requirements; guardian consent for a beauty service is distinct from GDPR processing bases. Operational push notifications are intended to omit client names and sensitive details. Material policy changes will be announced appropriately before taking effect; the current published version and effective date will be shown.