Skip to main content

GDPR Compliance

Compliance in force since 18 June 2026 updated 18 June 2026

1. GDPR principles applied

  • Lawfulness, fairness and transparency of processing.
  • Purpose limitation and data minimisation.
  • Accuracy and storage limitation.
  • Integrity, confidentiality and accountability.

2. Records of processing (Art. 30)

Bellisy maintains a record of processing activities describing purposes, categories of data and persons, recipients, retention and security measures. Summary extract:

ProcessingPurposeLegal basis
Pro accountsProvide the serviceContract
Client bookingsManage appointmentsContract / processing
AI assistantAnswer, bookContract
Health dataService safetyConsent (Art. 9)
MarketingCommunicationsConsent
BillingAccounting obligationsLegal obligation

3. Data Protection Impact Assessment (DPIA)

For high-risk processing (health data, conversational AI), Bellisy carries out and keeps up to date a data protection impact assessment, in accordance with Article 35 GDPR.

4. Privacy by design and by default

Data protection is built in from the design stage: minimisation, pseudonymisation where possible, most protective default settings (non-essential cookies off, optional photos).

5. Handling data subject rights

Any request to exercise rights (access, rectification, erasure, portability, objection) is handled within one month via dpo@bellisy.fr. Where Bellisy acts as a processor, the request is forwarded to the responsible salon, which Bellisy assists.

6. Data breaches

Bellisy documents any breach, notifies the CNIL within 72 hours where required and informs the data subjects in case of high risk (Art. 33 and 34 GDPR). See the Security Policy for the detailed procedure.

7. Transfers and sub-processors

Sub-processors are bound by Article 28-compliant contracts (see DPA). Transfers outside the EU are covered by standard contractual clauses. The sub-processor list is kept up to date and provided on request.

8. DPO contact and supervisory authority

DPO: dpo@bellisy.fr. Competent supervisory authority: CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr), with which any person may lodge a complaint.

GDPR

Full compliance with Regulation (EU) 2016/679 and CNIL guidance.

EU AI Act

Clients always know they are talking to an AI. The salon stays in control.

Data in the EU

Hosting in France, TLS and AES-256 encryption, backups inside the EU.

Export in one click

Your data belongs to you: export and deletion straight from the cabinet.