Last updated: 29 September 2026
This policy explains what personal data we collect when you use barbershop.mytaxconsultant.gr, why we need it, how long we keep it and what rights you have under the EU General Data Protection Regulation 2016/679 (GDPR) and Greek law 4624/2019.
Data controller
Barber Studio
VAT no.: —
Address: Οδός 1, Πόλη
Email: — · Phone: —
What we collect
- Booking details: name, phone, email, service, barber, date and time, and any notes you write to us.
- Security data: IP address and browser type when you book or when suspicious activity occurs, so we can protect the service from abuse.
- Haircut photos (only if you agree): so we remember the style we gave you. They are stored privately, seen only by the shop (and by you, if we send them to you) and deleted together with the booking details or whenever you ask.
- Technical session cookie: needed for the site and its forms to work securely. We use no advertising or analytics cookies.
- Member account (if you create one): name, email, phone, password (stored only as an Argon2id hash), language, favourite barber and booking history.
- Push notifications (if you enable them): a technical device identifier provided by your browser, so that we can send you notifications. You can turn them off at any time in your browser.
- Reviews (if you write one): rating, text and the name you choose to display.
- Waitlist (if you join): name, email, phone and the day you are interested in.
We do not ask for or process special categories of data (e.g. health).
Why we use it and on what legal basis
- To book and manage your appointment (confirmation, changes, cancellation): performance of a contract, Art. 6(1)(b) GDPR.
- To send you the necessary booking emails: performance of a contract.
- To send you a reminder before your appointment: legitimate interest in reducing missed appointments (Art. 6(1)(f)). You can ask us not to send reminders.
- For your member account (history, faster booking): performance of a contract, Art. 6(1)(b).
- For push notifications: your consent (Art. 6(1)(a)), given by tapping “Enable”, which you can withdraw at any time.
- To publish reviews: your consent when you submit the review. Only the name you choose is shown.
- For the waitlist: your request to be notified (Art. 6(1)(b)). Deleted automatically once the day has passed.
- For the loyalty program: we count the completed visits of your account (performance of a contract).
- For news and offers: only if you opt in (consent, Art. 6(1)(a)). Every message has a one-click unsubscribe link.
- To keep the service secure (preventing spam, attacks and abuse): legitimate interest, Art. 6(1)(f).
- For tax/accounting obligations, where required: legal obligation, Art. 6(1)(c).
We never send marketing messages without your explicit consent, and we never sell or share your data with third parties for their own purposes.
Who receives it
Only processors that help us run the service, bound by contract and confidentiality:
- the hosting provider of the website and database,
- the email delivery provider.
- your browser's push service (e.g. Google, Apple, Mozilla), only to deliver the notification; the content is sent encrypted.
Data is stored within the European Union / EEA unless stated otherwise here.
How long we keep it
- Bookings: for 24 months after the appointment date. After that your contact details are deleted automatically and only anonymous statistics are kept.
- Unconfirmed bookings: the time slot hold expires automatically after 30 minutes.
- Security logs (IP, failed logins): up to 180 days.
- Sent emails: their content is deleted from the server after 30 days.
- Member account: until you delete it (you can do so yourself from “My account → Privacy”). Unconfirmed accounts are deleted after 14 days.
Your rights
You have the right of access, rectification, erasure, restriction, portability and to object to processing, and you may withdraw your consent at any time. If you have an account, you can download all your data or delete the account yourself from “My account → Privacy”. For any request write to —. We will reply within one month at the latest.
If you believe your rights have been violated, you can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
Security
We use an encrypted connection (HTTPS), attack protection, access limited to shop staff and two-factor authentication (2FA) for administration.
Map
The Google map on the home page loads only if you tap "Show map". Until then no connection is made to Google. Once loaded, Google's privacy policy applies.
Changes
Whenever something that concerns your data changes, we update this page and the date at the top.