1. Introduction
At TonoLab, we work to provide the best possible experience through our products and services. In some cases, we need to collect and process personal data to provide the service (for example, to create your account, manage appointments, or process subscriptions).
This policy applies to the website and the TonoLab dashboard. It is provided for the purposes of Regulation (EU) 2016/679 (“GDPR”) and Law 34/2002 (“LSSI”).
2. Data controller
TonoLab is responsible for processing the personal data you share with us when using the service.
Contact: soporte@tonolab.com
3. Data we process
Below are the categories of data we may process and their purposes:
- Account & access: email, password (hash), account status, and data needed to log in, verify email, or reset password.
- Salon data: salon name and configuration details (for example, phone or contact email) when provided by the user.
- Clients: name, phone, email and notes entered to manage appointments.
- Appointments: date/time, status, notes, services and assigned staff for calendar management.
- Staff: name, phone and profile details when registered by the salon.
- POS & sales: items, amounts, payment method, VAT and information needed to record a sale and issue a receipt.
- Subscriptions & billing: subscription plan and status; payments may be handled by external providers (e.g., Stripe) under their own policies.
- Service communications: emails required to operate the service (verification and password recovery).
4. Legal basis
The legal bases may include:
- Contract performance: providing the service and allowing access to the dashboard.
- Consent: when required (for example, for non-essential communications if enabled in the future).
- Legal obligations: fraud prevention, authority requests, and claim handling.
- Legitimate interest: security, service improvement and support, provided user rights do not prevail.
5. Retention
We keep personal data only as long as necessary for the purposes it was collected for and to comply with legal obligations.
6. Recipients
When necessary to provide the service, we may share data with processors (email, infrastructure, or payment providers). They process data under our instructions and with appropriate security measures.
7. International transfers
In general, data is stored within the EU. If any provider transfers data outside the EEA, we apply the safeguards required by the GDPR (e.g., Standard Contractual Clauses).
8. Your rights
You can exercise your rights of access, rectification, deletion, restriction, portability and objection by writing to soporte@tonolab.com.
9. Accuracy
You are responsible for providing accurate and up-to-date information when registering or using the service.
10. Security
TonoLab implements reasonable technical and organizational measures to protect personal data against loss, misuse, unauthorized access or disclosure.
11. Changes
This policy may be updated. We recommend reviewing it periodically.