Privacy policy
Last updated: 27 July 2026
This policy explains how BookOS (CVR: 46540352) processes personal data when you visit bookos.dk, sign up for a BookOS account, or use the BookOS platform to run your salon. It is written to comply with the EU General Data Protection Regulation (GDPR) and Danish data-protection law.
1. Who we are
BookOS is operated as a sole proprietorship (enkeltmandsvirksomhed) registered in Denmark (CVR 46540352). For privacy questions, contact admin@bookos.dk.
2. Our two roles
- Controller — for data about salon owners, staff, and prospects who interact directly with BookOS (account sign-up, billing, support, marketing).
- Processor — for data about a salon’s end customers (bookings, contact details, preferences). The salon is the controller; BookOS processes that data on the salon’s instructions under our Data Processing Agreement.
3. Data we collect as controller
- Account data — name, work email, phone, password hash, role, salon name. Lawful basis: contract (Art. 6(1)(b)).
- Billing data — company name, VAT/CVR number, address, Stripe customer ID, subscription tier, invoice history. Lawful basis: contract and legal obligation (Art. 6(1)(b), (c)).
- Usage & security data — IP address, browser, pages visited, error logs, audit-log entries. Lawful basis: legitimate interest in operating and securing the service (Art. 6(1)(f)).
- Support correspondence — emails and chat transcripts you send to us. Lawful basis: contract and legitimate interest.
- Marketing — product newsletters and onboarding tips. Lawful basis: consent (Art. 6(1)(a)), withdrawable any time via the unsubscribe link.
4. Data we process on behalf of salons
When a salon uses BookOS, end-customer data (names, contact details, booking history, payments) is stored in our database in isolated rows scoped to that salon. We do not use this data for our own purposes. The salon’s privacy policy applies. See the DPA for full details.
4a. Sources of data (Art. 14 GDPR)
Most data we hold is provided directly by you when you sign up or use the Service. We also receive:
- identifiers from third parties you connect (e.g. Google account email when you enable Google Calendar sync; Stripe customer ID when billing is set up);
- technical metadata generated by your browser, device, or network operator (IP address, user-agent, language);
- limited information from publicly available sources where you have asked us to verify a business (e.g. CVR/VAT lookups via Erhvervsstyrelsen).
4b. Special-category data and children
BookOS is built for professional adult use. We do not knowingly collect personal data from children under 13 (the age of digital consent in Denmark under Datatilsynet guidance). End customers booking through a salon site must be adults or have parental consent.
Free-text notes about a customer’s allergies, scalp condition, medical history, or similar may constitute health data under GDPR Art. 9. We process such data strictly on the salon’s instructions to enable the requested service. Salons should obtain explicit consent under Art. 9(2)(a) before entering such data and should keep notes to the minimum required.
4c. Automated decision-making (Art. 22 GDPR)
BookOS does not make decisions about you that produce legal or similarly significant effects based solely on automated processing. Spam/fraud filtering of inbound messages, rate-limiting, and security signals use rules and machine-learning where appropriate, but final decisions involving account suspension or restriction are reviewed by a human.
4d. Google API user data
When a salon administrator explicitly connects a stylist’s Google Calendar, BookOS reads calendar event identifiers, titles, start and end times, and cancellation status to prevent conflicting appointment slots. BookOS also creates, updates, and deletes the Google Calendar events generated from that stylist’s BookOS bookings. BookOS does not access calendar sharing permissions, access-control lists, or account settings.
OAuth access and refresh tokens are encrypted before storage. We also store the connected calendar identifier and limited synchronization metadata needed to receive event changes. Google Calendar data is used only to provide the user-facing calendar synchronization and availability features. It is not sold, used for advertising, or used to train general-purpose AI models. We do not transfer Google user data except to service providers acting on our behalf where necessary to operate those features, subject to confidentiality and data-processing obligations.
Users can disconnect Google Calendar from the stylist settings page. Disconnecting revokes BookOS access and deletes the stored Google credentials, synchronization metadata, and mirrored external availability records. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4e. Managed domain registration
If you ask BookOS to register a domain, we collect the domain name and the legal registrant’s name, organization, postal address, email address, telephone number, country, and any registry-required business or VAT identifier. We send this information to our registrar, OpenSRS (Tucows Inc.), and the relevant domain registry to check availability, register and renew the domain, configure DNS, meet registry verification requirements, and support transfers. Registry rules may require some registration data to be disclosed through WHOIS or to public authorities. BookOS stores the registrant snapshot and registration lifecycle while we manage the domain and for the legal, accounting, dispute, and transfer periods that apply afterward.
5. Retention
- Active account data — for the lifetime of the subscription, then 90 days for export.
- Invoices and billing records — 7 years (Danish Bookkeeping Act).
- Security logs — up to 13 months, then aggregated.
- Marketing data — until consent is withdrawn.
6. Sub-processors and international transfers
We use the vendors listed on our sub-processors page. EU data is hosted in the EU/EEA where possible. Where transfer outside the EEA is necessary (e.g. Stripe US for card processing), we rely on EU Standard Contractual Clauses, the EU–US Data Privacy Framework (where the recipient is self-certified), the UK IDTA, and the Swiss revFADP equivalents, as applicable. We give 30 days notice before adding or replacing a sub-processor.
6a. Government access requests
We disclose Customer Data to government or law-enforcement authorities only where compelled by valid legal process binding on us or, in good faith, where disclosure is necessary to prevent imminent harm. We challenge overbroad requests, push for narrowest scope, and notify affected customers unless legally prohibited from doing so. Aggregated statistics will be published in our annual transparency report from our first full reporting year.
7. Security
Personal data is encrypted in transit and at rest, isolated per tenant, and accessible only to authorised personnel under least-privilege controls. Backups are taken regularly and restore procedures are tested. Full technical and organisational measures are detailed in Schedule 2 of our DPA.
8. Your rights
You may request access, rectification, erasure, restriction, portability, or object to processing by emailing admin@bookos.dk. We respond within 30 days. You may also withdraw consent at any time without affecting prior processing.
9. Cookies
For details on cookies we use and how to manage consent, see our cookie policy.
10. Complaints
You may complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk) or to your local supervisory authority.
10a. DAC7 tax reporting
Where BookOS is required to report information about your salon under Council Directive (EU) 2021/514 (DAC7), the lawful basis for that processing is legal obligation under GDPR Art. 6(1)(c). See our DAC7 information page for what is collected, what is reported, and to whom.
11. Changes
We may update this policy from time to time. Material changes will be announced by email or in-product notice at least 30 days before they take effect.
