Privacy Policy

Last Updated: June 23, 2026

1. Introduction & Roles

In accordance with the GENERAL DATA PROTECTION REGULATION (EU) 2016/679 (GDPR), we provide the following information regarding the processing of personal data on the Klokk.org B2B cloud-based (SaaS) appointment booking software.

Critical Legal Clarification: Controller vs. Processor

In the relationship between Salons (Partners) using the Klokk system and their guests, the Salon is the Data Controller for the guest's personal data. SYNTAX-ENCODE Kft., as the software provider, acts merely as a Data Processor on behalf of the Salon. We (Klokk) never use guest data for our own purposes, do not sell it, and do not send marketing messages to guests.

As a Data Controller, we only process the data of our directly contracted Partners (salon owners, contact persons).

Software Operator

Name: SYNTAX-ENCODE Kft.
HQ: 8105 Pétfürdő, Móricz Zs.u.17., Hungary
Reg No: 19-09-517832
Tax No: 25290569-2-19
Email: info@klokk.org

2. Scope of Policy

Temporal scope: Effective from June 23, 2026. The operator reserves the right to modify this policy unilaterally, notifying Partners in advance.

Personal scope: Applies to the operator, subscribing SaaS partners (Salons), their staff, and the guests using the system (Data Subjects).

3. Data Processing Details

  • Guest Registration: To manage bookings and confirmations. Legal basis: Contract execution (Processor). Data: Name, email, phone. Retained until deletion request.
  • Partner Subscription: To provide SaaS access. Legal basis: Contract execution. Data: Contact info, business details. Retained 5 years post-contract.
  • Billing: Legal obligation. Data: Invoice name, address, tax ID. Retained 8 years under accounting law.
  • Online Payment (Stripe): Contract execution. Data: Name, email, transaction ID. Retained 8 years.

4. Profiling

We do not engage in profiling with legal effects or automated decision-making. The system only generates statistical analyses for salon owners (e.g. cancellation rates, revenues).

5. Data Processors

  • Billingo Technologies Zrt. (HU): Electronic invoicing.
  • Stripe Payments Europe, Ltd. (IE): Card processing.
  • Resend Inc. (US): Transactional email delivery.
  • Supabase, Inc. (US): Cloud database.
  • Vercel Inc. (US): App hosting.
  • Google Ireland Limited (IE): Analytics and Calendar sync.

6. Data Transfer

Transfers outside the EEA (e.g., to US infrastructure) are safeguarded by Standard Contractual Clauses (SCCs) and the Data Privacy Framework.

7. Cookies

We use essential cookies (`klokk-session`) for authentication, and functional ones (`next-intl-locale`, `_ga`) for language preferences and analytics.

8. Rights & Remedies

You have the right to access, rectify, delete, or restrict processing of your data. Contact us at adatvedelem@klokk.org. You may also lodge a complaint with your local Data Protection Authority or the Hungarian Authority (NAIH).

9. Data Security

We employ SSL/TLS encryption, strictly one-way bcrypt password hashing, and Row Level Security (RLS) across all cloud databases to ensure maximum security.

Főoldal
Demó
Foglalás
Belépés