Privacy Notice
1. Data controller
The operator of the Frexima platform and the data controller under this notice is:
Bsolar és Klíma Kft.
Registered office: 4150 Püspökladány, Árpád utca 60., Hungary
Tax number: 12618831-2-09
Company registration number: 09-09-007862
For privacy requests or questions, email [email protected] or write to the registered office above. We process the information required to identify the requester and respond to the request.
2. Scope of this notice
This notice applies to visitors and users of Frexima's web, mobile, and installable web application interfaces, including clients, salon and brand users, and other individuals who interact through the platform. Salons are responsible for their own independent processing activities, such as their client records, treatments, invoicing, and marketing. Frexima is responsible for processing required to provide its own platform services.
3. Data, purposes, and legal bases
- Account and identity: name, email address, phone number, secure password hash, role, and profile information. Purpose: registration, sign-in, account administration, and access control. Legal basis: performance of the service contract.
- Bookings and client relationships: selected salon, service, professional, appointment time, booking status, related messages, and notes supplied by the user. Purpose: creating, delivering, changing, and supporting bookings. Legal basis: performance of a contract and, where applicable, legitimate interests in preventing and resolving disputes.
- Connected Google Calendar: when a salon professional chooses to connect Google Calendar, we process the OAuth access and refresh tokens, granted permission scopes, the connected calendar identifier, identifiers and synchronization status for Frexima-created appointment events, and free/busy availability returned by Google. Frexima uses this information only to add or update the professional's Frexima appointments in their calendar, synchronize busy periods, prevent double booking, maintain the requested connection, and diagnose synchronization errors. Frexima does not import event titles, attendee details, descriptions, or other event content for advertising or profiling. The legal basis is the user's request to provide the connected-calendar service and performance of the service contract.
- Community and content features: posts, stories, comments, reactions, saved items, follows, images, and videos. Purpose: providing the selected feature, moderation, and abuse prevention. Legal basis: performance of a contract and legitimate interests in platform safety. Content published as public may be visible to other users.
- Media processing data: original uploads, processed and compressed renditions, posters, file type and size, dimensions, duration, technical checksums, processing status, moderation status, and access metadata. Purpose: secure upload, technical validation, storage optimization, playback, moderation, deletion, and abuse prevention. Legal basis: performance of the service contract and legitimate interests in operating a secure and efficient platform.
- Messages, forums, tasks, lookbooks, referrals, and rewards: content, status information, attribution records, subscription-payment milestones, fraud and duplicate checks, and relationships created through the relevant feature. Purpose: providing the feature, verifying whether reward conditions were met, preventing duplicate or abusive claims, and maintaining an auditable reward ledger. Legal basis: performance of the service contract and our legitimate interests in preventing fraud and resolving financial disputes.
- Referral reward payout information: we do not request payout details before a salon referral becomes eligible. After eligibility, we may process the account-holder name, encrypted IBAN or local bank-account number, masked account identifier, bank country, tax-residence country, tax status, required declarations, payout amount, due date, transfer status, and bank reference. Purpose: verifying payout readiness, making and reconciling the transfer, and meeting accounting, tax, sanctions, and other legal duties. Legal basis: performance of the reward terms, compliance with legal obligations, and legitimate interests in secure payment and fraud prevention.
- Notifications: notification preferences, browser or device identifiers, and notification tokens. Purpose: delivering requested booking, message, and system notifications. Legal basis: consent, which can be withdrawn in the device or account settings.
- Security and technical logs: IP address, device and browser information, sign-in records, and error information. Purpose: fraud and abuse prevention, information security, and troubleshooting. Legal basis: legitimate interests.
- Legal obligations: records required by accounting, complaint-handling, or authority rules. Legal basis: compliance with a legal obligation.
Only provide special-category information, such as health information, when a specific service makes it strictly necessary. Frexima does not request it as general profile information. If you provide such information directly to a salon, ask the salon for its own privacy notice as well.
4. Recipients and international transfers
The selected salon receives the information required to manage a booking and its relationship with the client. Public community content is available to users according to the selected visibility settings. We may use processors for hosting, storage, backups, notifications, security, and troubleshooting. For referral reward payouts, relevant information may also be disclosed to our bank, payment service providers, accountants, tax advisers, auditors, and competent authorities where necessary. They may act only on documented instructions or under their own applicable legal duties and only to the extent necessary. Information about current processors is available on request.
Images and videos may be delivered by contracted object-storage and content-delivery providers using short-lived access links. Those providers process the technical request data needed to transmit the requested media, such as the IP address, request time, object identifier, and device or network information.
Google Calendar data is exchanged with Google only when the user enables that integration. We do not sell Google user data, use it for advertising, or disclose it to third parties except to infrastructure processors acting on our instructions, where necessary for security or support with the user's permission, or where required by law. Human access is prohibited unless it is necessary for security, legal compliance, or support requested by the user. Frexima's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Personal data is transferred outside the European Economic Area only when an appropriate safeguard is available, such as an adequacy decision or standard contractual clauses approved by the European Commission.
5. Retention
Account data is retained while the account remains active. After an account is closed or deletion is requested, information may be retained in a restricted form where required for legal claims, abuse investigations, or mandatory retention periods, and is then deleted or irreversibly anonymized. Referral attribution, payout, accounting, and tax records are kept for the period required by applicable law or for the establishment, exercise, or defence of legal claims. Full bank-account details are stored in encrypted form and are deleted or made unusable when they are no longer required for an open payout or a mandatory retention duty; only a masked identifier may remain in the user interface and audit records. Deleted data is removed from backups during the applicable overwrite cycle.
Google OAuth tokens are encrypted at rest and retained only while the calendar connection is active. Disconnecting Google Calendar revokes and removes the stored tokens and deletes imported Google busy periods from Frexima. The user can also revoke Frexima from their Google Account permissions. Frexima appointment records remain subject to the ordinary booking-retention rules, and event copies previously created in Google Calendar may remain until the user removes them there.
Original video uploads are normally deleted immediately after successful processing. Failed or interrupted original uploads are retained for no longer than 30 days for retry and fault recovery. Processed media and posters remain while the content or account is active; after 30 days they may be moved automatically to a lower-cost storage tier while remaining available through the service.
Stories are shown to the selected audience for 24 hours. An expired Story may then remain available only to its account holder in the private Story Archive for no longer than 30 days under the active retention policy. At the end of that period, or after an earlier archive-deletion request, media used only by that Story is removed from active storage. Media that is still referenced by another non-deleted Story or Community post is retained for that continuing purpose.
When media is deleted, it is made unavailable without undue delay and active object copies are removed. Isolated noncurrent object versions and backup copies are automatically erased within no more than 90 days, unless a longer period is required for a legal obligation, security investigation, fraud prevention, or the establishment, exercise, or defence of legal claims. Such isolated copies are not used for ordinary delivery.
6. Your rights
You may request access, correction, deletion, restriction, or portability of your personal data, object to processing, and withdraw consent at any time. We normally respond without undue delay and within one month. These rights are subject to legal limits; for example, information that must be retained by law or affects another person's rights may not always be deleted immediately.
You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; email: [email protected]; website: naih.hu. You may also seek a judicial remedy before a competent court, including the court of your habitual residence, workplace, or the place of the alleged infringement.
7. Security and changes
We use reasonable technical and organizational measures to reduce the risk of unauthorized access, loss, alteration, or disclosure. Google OAuth tokens and payout account details are encrypted at rest, excluded from analytics and application logs, and restricted to the processes and authorized personnel that require them. Payout account details are also masked in ordinary user and administration views. Users must keep their account credentials confidential. Material changes to this notice will be published on the platform and, where required, communicated separately.