Politique de confidentialité
This document is published in English, which is the authoritative version. Any translation is provided for convenience only; in case of any discrepancy, the English version prevails.
1. Who we are
This Privacy Policy explains how Bellora S.R.L., a company registered in Romania (registration no. [COMPANY REGISTRATION NO. / CUI — fill in]), registered office [REGISTERED OFFICE ADDRESS, Romania — fill in] ("Bellora", "we", "us"), collects and uses personal data when you use the Bellora website and apps (the "Platform"). Bellora is the data controller for the personal data described here. For any privacy question, or to exercise your rights, contact us at privacy@bellora.pro.
2. The data we collect
Depending on how you use the Platform, we collect: • Account data — name, email address, phone number, password (stored only as a secure hash), and your role (Client or Professional). • Professional data — business name and details, service locations and addresses (including approximate geographic coordinates used for map search), portfolio images, and payout/identity information you provide to our payment provider for onboarding. • Booking data — the services you book or offer, appointment times, locations, and any free-text notes you add to a booking. • Payment data — deposit and payout amounts, transaction and subscription records. Full card details are collected and stored by Stripe, not by us. • Content — reviews, ratings, uploaded images (avatars, review and portfolio photos), and messages. • Technical data — device and app information, IP address, and, where you consent, analytics about how you use the Platform (see our Cookie Policy). • Communications — push-notification tokens and your notification preferences, and the content of support requests.
3. How and why we use your data (legal bases)
We use your personal data on the following legal bases under the GDPR: • To perform our contract with you (Art. 6(1)(b)) — creating your account, enabling bookings, processing deposits and payouts, and providing support. • For our legitimate interests (Art. 6(1)(f)) — keeping the Platform secure, preventing fraud and abuse, enforcing our Terms, and improving our services — where these interests are not overridden by your rights. • With your consent (Art. 6(1)(a)) — optional analytics and any marketing communications; you can withdraw consent at any time. • To comply with legal obligations (Art. 6(1)(c)) — for example accounting, tax and anti-fraud record-keeping.
4. Who we share data with
We do not sell your personal data. We share it only with service providers ("processors") who help us run the Platform, under contracts that require them to protect it: • Stripe — payment processing, deposits, payouts, subscriptions and fraud prevention. • Google — sign-in, maps/location, push notifications (Firebase Cloud Messaging) and, where you consent, analytics. • Apple — Sign in with Apple authentication. • Our email and (where used) SMS providers — to send transactional messages such as verification codes and booking updates. • Our hosting/infrastructure provider — to operate the servers that run the Platform. We also share the limited data necessary to complete a booking between the Client and the Professional involved (for example, the appointment details each side needs). We may disclose data where required by law or to protect our rights or users' safety. [Confirm this list matches your production sub-processors before launch.]
5. International transfers
Some of our providers (such as Stripe and Google) may process data outside the European Economic Area, including in the United States. Where they do, the transfer is protected by an appropriate safeguard under the GDPR — typically the European Commission's Standard Contractual Clauses or an approved adequacy/certification framework.
6. How long we keep it
We keep personal data only for as long as we need it: • Account data — for as long as your account is active, and for a limited period afterwards. • Booking free-text notes and location details — the sensitive, free-text and location parts of a completed booking are automatically scrubbed a set number of months after the appointment; the financial and scheduling record needed for accounting is retained separately. • Payment and tax records — for the period required by applicable accounting and tax law. When data is no longer needed we delete or anonymise it.
7. Your rights
Under the GDPR (and UK-GDPR if you are in the UK) you have the right to: • access the personal data we hold about you; • have inaccurate data corrected; • have your data erased in certain circumstances; • restrict or object to certain processing; • receive your data in a portable format; • withdraw consent at any time, where processing is based on consent. To exercise any of these, contact us at privacy@bellora.pro. You also have the right to complain to a data-protection authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro), or the authority in your country of residence.
8. Security
We take appropriate technical and organisational measures to protect your data — including encryption in transit, hashed passwords, access controls, and rate limiting. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authority of a data breach where the law requires.
9. Children
The Platform is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes and contact
We may update this Privacy Policy from time to time and will notify you of material changes through the app or by email. For any question about this policy or your data, contact Bellora S.R.L. at privacy@bellora.pro.