Privacy Policy
Last updated: July 2026 (version 2026-07)
1. Who we are
This platform is operated by [Your company name].
Contact: use our contact form
We provide a business management platform to interior styling companies (“customers”). This privacy policy describes the personal data we collect and process about our customers and their staff in our capacity as data controller for that relationship.
Our customers use the platform to manage their own client projects, which may involve personal data about private individuals (homeowners and households). For that data, our customers are the data controllers and we act as their data processor. The processing of end-client data is governed by our Data Processing Agreement (DPA), not this policy.
2. Data we process as controller
We collect and process the following personal data about individuals at styling companies that use our platform:
Account holders and staff
- Name
- Email address
- Role within the organisation
- Hashed (non-reversible) password
- Account status and creation date
Lawful basis: Performance of a contract (GDPR Art. 6(1)(b)) — necessary to provide access to the platform under the subscription agreement.
3. Data we process as processor
When styling companies use the platform to manage their projects, they may enter personal data about their own clients (such as names, contact details, and property addresses). We process this data solely on the instructions of the styling company concerned, which remains the data controller for that data.
We do not use end-client data for our own purposes. We do not sell, share, or analyse it beyond what is necessary to operate the platform. The terms governing this processing are set out in the Data Processing Agreement (DPA) agreed with each styling company customer.
AI-assisted engineering and support: our engineering team uses Anthropic’s Claude, an AI coding/support assistant, to help build, debug, and maintain this platform. This can involve Claude being given access to production systems and data (for example, to diagnose a bug or investigate a support request) under our engineers’ supervision. Anthropic acts as a sub-processor for any personal data it is exposed to this way and is listed in the sub-processor table below. [Confirm the applicable data-handling and model-training terms in your Anthropic commercial agreement and reflect them here accurately before publishing.]
End clients of styling companies who wish to exercise GDPR rights (access, erasure, portability, etc.) should contact the styling company directly, as it is the data controller for their data.
4. Sub-processors
We use the following sub-processors to operate the platform. All are engaged under appropriate data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting and database | EU West |
| Cloudflare R2 / AWS S3 | Photo and file storage | EU (if configured) |
| Vercel | Frontend hosting | Global CDN |
| Anthropic (Claude) | AI assistant used by our engineering team to build, debug, and support the platform; may be exposed to production data during that work | United States |
5. Retention
Account and staff data is retained for as long as the subscription is active and for a reasonable period thereafter (up to two years) for legal and administrative purposes. Data entered by styling companies about their own clients is subject to the retention terms in the DPA and is deleted upon termination of the subscription or on written request.
6. Cookies and technical data
This platform uses a single strictly necessary httpOnly session cookie (refresh_token) to keep you logged in. It contains no personal data, only a cryptographic token, and is never readable by JavaScript. No analytics, tracking, or advertising cookies are used.
7. Security
We implement appropriate technical and organisational measures including encrypted connections (HTTPS/TLS), bcrypt password hashing, short-lived access tokens, rate limiting on authentication endpoints, and tenant-scoped access controls. In the event of a personal data breach we will notify affected controller customers without undue delay and within 72 hours of becoming aware of the breach.
8. Your rights (platform users)
If you are a staff member at a styling company using this platform, you have the following rights regarding your account data:
- Access — request a copy of your personal data (Art. 15)
- Rectification — ask us to correct inaccurate data (Art. 16)
- Erasure — ask us to delete your account (Art. 17)
- Portability — receive your data in a machine-readable format (Art. 20)
To exercise any of these rights, submit a request through our contact form (category “Privacy (GDPR)”). We will respond within 30 days.
9. Complaints
You have the right to lodge a complaint with your national data protection authority. In Norway this is:
Datatilsynet — www.datatilsynet.no
10. Changes
We may update this policy when our practices change. When we publish a new version, signed-in users are shown a one-time notice and asked to acknowledge it the next time they use the platform. The current version is always available at this URL.
Version history
- 2026-07 (July 2026) — disclosed Anthropic (Claude) as a sub-processor with potential access to production data for engineering and support purposes; added a link to the new Data Processing Agreement.
- 2025-06 (June 2025) — original policy.