Who we are
Pinkly (pinkly.eu) is booking and management software for beauty professionals. The salon or specialist you book with is the controller of your data. Pinkly is the processor, processing data on behalf of the salon under a data processing agreement.
What data we process
- ✓Name, phone and email – to handle the booking and send reminders.
- ✓Personal ID code – only encrypted and to reliably recognise the same person. Salon staff see a masked form; only the owner can see the full code with a new eID confirmation, and every view is logged.
- ✓Bookings, visits and payments – to provide the service and for accounting.
- ✓Verification method and time, and the security log – to ensure security.
PIN codes are never requested or stored. Certificates are not retained.
Legal basis
Performance of a contract (the booking), legitimate interest (security, fraud prevention) and consent (marketing messages). You can change your consent at any time on the “My bookings” page.
Where data is stored
In data centres located in the European Union, encrypted. The encryption keys for ID codes are kept separately from the database.
Your rights
- ✓You can download your data (data portability, GDPR art. 20).
- ✓You can delete your data (GDPR art. 17) – bookings and payments are kept anonymised for accounting purposes.
- ✓You can refuse marketing messages.
Both actions are available on the “My bookings” page after verifying yourself with eID.
Retention
Client data is kept as long as the salon needs it to provide the service or until you delete it. The security log is kept for 24 months.
Contact
For data protection questions write to tere@pinkly.eu. You can also lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee).