Skip to main content

GDPR Compliance

Regulatory information in force since 18 June 2026 updated 18 June 2026

1. GDPR principles applied

  • Lawfulness, fairness and transparency of processing.
  • Purpose limitation and data minimisation.
  • Accuracy and storage limitation.
  • Integrity, confidentiality and accountability.

2. Records of processing (Art. 30)

Bellisy maintains a record of processing activities describing purposes, categories of data and persons, recipients, retention and security measures. Summary extract:

ProcessingPurposeLegal basis
Pro accountsProvide the serviceContract
Client bookingsManage appointmentsContract / processing
AI assistantAnswer, bookContract
Health dataService safetyConsent (Art. 9)
MarketingCommunicationsConsent
BillingAccounting obligationsLegal obligation

3. Data Protection Impact Assessment (DPIA)

For high-risk processing (health data, conversational AI), Bellisy carries out and keeps up to date a data protection impact assessment, in accordance with Article 35 GDPR.

4. Privacy by design and by default

Data protection is built in from the design stage: minimisation, pseudonymisation where possible, most protective default settings (non-essential cookies off, optional photos).

5. Handling data subject rights

Any request to exercise rights (access, rectification, erasure, portability, objection) is handled within one month via dpo@bellisy.fr. Where Bellisy acts as a processor, the request is forwarded to the responsible salon, which Bellisy assists.

6. Data breaches

Bellisy documents any breach, notifies the CNIL within 72 hours where required and informs the data subjects in case of high risk (Art. 33 and 34 GDPR). See the Security Policy for the detailed procedure.

7. Transfers and sub-processors

Sub-processors are bound by Article 28-compliant contracts (see DPA). Transfers outside the EU are covered by standard contractual clauses. The sub-processor list is kept up to date and provided on request.

8. DPO contact and supervisory authority

DPO: dpo@bellisy.fr. Competent supervisory authority: CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr), with which any person may lodge a complaint.

Personal data

Read how personal data is used and how to submit a privacy request.

AI assistance

Read about AI features, their limits and the salon’s controls.

Security information

Consult the published security policy and contact the security team with concerns.

Data requests

Request a copy of your salon data or submit a deletion request from your account.