Skip to main content

Privacy Policy

Privacy in force since 18 June 2026 updated 18 June 2026

1. Data controller and DPO

The data controller is INOVA DIGI-TECH (SAS), RCS Nancy 918 907 809, SIRET 918 907 809 00027, VAT FR26 918 907 809, registered office: Bâtiment D1, 16 Rue de la Côte, 54000 Nancy, France, publisher of the Bellisy platform.

For any question about your data, you can contact our Data Protection Officer (DPO) at dpo@bellisy.fr or by post to the registered office, marked “FAO the DPO”.

2. Scope and roles

Bellisy is a SaaS platform providing beauty professionals with an AI-powered virtual receptionist, appointment booking, client management and a Marketplace allowing end clients to discover and book services.

  • For professional accounts (salons, practitioners): Bellisy is the data controller.
  • For end-client data entered by a salon in its workspace: Bellisy is a processor, the salon being the controller (a DPA governs this relationship).
  • For end clients booking via the Bellisy Marketplace: Bellisy and the salon are joint controllers within the meaning of Article 26 GDPR, each for its own purposes.

3. Categories of data processed

The table below details the categories of data, examples and the associated retention period:

CategoryExamplesRetention
IdentificationFirst/last name, e-mail, phoneAccount duration + 3 years
Account & salonCredentials, role, salon name, addressAccount duration
AppointmentsDate, service, history, preferencesSalon account duration
AI interactionsMessages with the AI receptionistUp to 24 months
PhotosBefore/after photos (if enabled by salon)Salon account duration
Health data (Art. 9)Allergies, contraindicationsSalon account duration
BillingAmounts, invoices, payment token10 years (legal obligation)
Technical dataLogs, IP address, device type12 months maximum
Cookie consentProof of consent, timestamp6 months

4. Health and biometric data

Special categories (Art. 9 GDPR). Some aesthetic services (permanent makeup, treatments) may lead a practitioner to record allergies or contraindications. If a salon enables before/after photos and these allow a face to be identified, they may constitute biometric data.

  • Processing is based on explicit consent obtained by the professional from the end client.
  • This data is encrypted, access-restricted, never used for advertising or shared with unauthorised third parties.
  • It is never used to train AI models and is excluded from any profiling.
  • Bellisy never requires face photos: their use is an option controlled by the salon and the client.

5. Legal bases for processing

  • Performance of contract (Art. 6.1.b): account creation, service provision, appointment management.
  • Consent (Art. 6.1.a and 9.2.a): non-essential cookies, health data, marketing communications.
  • Legitimate interest (Art. 6.1.f): security, fraud prevention, service improvement.
  • Legal obligation (Art. 6.1.c): invoicing, accounting, anti-money-laundering.

6. Automated decision-making and profiling

The AI receptionist automatically processes messages to suggest slots, answer common questions and confirm appointments. This processing produces no legal effect or similarly significant consequence within the meaning of Article 22 GDPR: no purely automated decision (service refusal, individualised pricing) is taken without the possibility of human intervention by the salon.

7. Sub-processors, APIs and recipients

Bellisy relies on carefully selected providers acting as sub-processors within the meaning of Article 28 GDPR. Each is bound by a processing agreement and appropriate safeguards. The up-to-date list is maintained in the DPA:

ProviderRoleLocation
OVHHosting, infrastructureEuropean Union
StripeCard paymentsEU / USA (SCC)
PayPalPaymentsEU / USA (SCC)
WhatsApp Business (Meta)AI receptionist messagingEU / USA (SCC)
Instagram (Meta)Messaging, contact formsEU / USA (SCC)
AI model providerAI response generationEU / USA (SCC)
Transactional e-mail serviceConfirmations, remindersEuropean Union
Audience analytics toolStatistics (with consent)European Union

Bellisy never sells personal data and does not share it for third-party advertising. The Meta integrations (WhatsApp, Instagram) are used only to route messages between the end client and the salon.

8. Transfers outside the European Union

Data is mainly hosted in the European Union. Where certain sub-processors (Stripe, Meta, AI providers) process data outside the EU, transfers are governed by the European Commission Standard Contractual Clauses (SCC), supplemented where necessary by additional technical measures (encryption, pseudonymisation).

9. Retention, backups and logs

  • Retention periods are set out in the table in section 3 and are reviewed regularly.
  • Encrypted backups are performed daily and kept for up to 30 days to allow recovery after an incident.
  • Security logs (logins, access, sensitive events) are kept for up to 12 months for traceability and incident detection.
  • On expiry, data is irreversibly deleted or anonymised, including in backups as they rotate.

10. Your rights

  • Right of access: obtain a copy of your data.
  • Right to rectification: correct inaccurate data.
  • Right to erasure (“right to be forgotten”).
  • Right to restriction of processing.
  • Right to portability: receive your data in a structured, machine-readable format.
  • Right to object, in particular to direct marketing.
  • Right to withdraw consent at any time.
  • Right to set instructions on the fate of your data after your death.

To exercise these rights, write to dpo@bellisy.fr. We respond within one month. You may lodge a complaint with the CNIL (www.cnil.fr). If your data was entered by a salon, we forward your request to the responsible salon and assist you.

11. Deletion procedure

  • On account closure, active data is deleted or anonymised within 30 days.
  • Data in encrypted backups is removed during the rotation cycle (within 30 days at the latest).
  • Data subject to a legal obligation (invoices) is kept in isolation until the legal period expires, then deleted.
  • An individual deletion request can be sent at any time to dpo@bellisy.fr.

12. Minors

Bellisy professional accounts are reserved for adults. Where a minor end client books an appointment, the salon is responsible for obtaining the consent of the holder of parental authority in accordance with applicable law. Bellisy does not target minors or serve them advertising.

13. Public profiles and Marketplace

On the Marketplace, certain information is displayed publicly: salon name, description, city, photos and portfolio, services and indicative prices, rating and verified reviews, and where applicable the name and specialty of professionals. This information is published by the salon, which warrants it holds the necessary consents, in particular for photos and professionals’ names.

Reviews are collected from clients who actually received a service (verified reviews) and displayed publicly with the visit date. The author’s first name may appear. The author of a review can request rectification or deletion of their data at dpo@bellisy.fr. Details are in the Review Policy and the Profile & Marketplace Policy.

14. Cookies and trackers

The use of cookies and trackers is described in detail in Bellisy’s Cookie Policy, compliant with CNIL guidelines. No non-essential cookie is set without your consent, which can be withdrawn at any time via the dedicated banner.

15. Data security

Bellisy implements technical and organisational measures detailed in the Security Policy: encryption in transit (TLS) and at rest, access control, multi-factor authentication, logging, backups and an incident management procedure with notification to the CNIL and the data subjects within the legal deadlines.

16. Changes and contact

This policy may be updated to reflect legal or technical changes. The version in force is always published on bellisy.fr/privacy with its date. In case of a substantial change, users are informed.

  • General questions: contact@bellisy.fr
  • DPO / data protection: dpo@bellisy.fr
  • Support: support@bellisy.fr
Related documents Cookie Policy

GDPR

Full compliance with Regulation (EU) 2016/679 and CNIL guidance.

EU AI Act

Clients always know they are talking to an AI. The salon stays in control.

Data in the EU

Hosting in France, TLS and AES-256 encryption, backups inside the EU.

Export in one click

Your data belongs to you: export and deletion straight from the cabinet.