Legal
Privacy Policy
This Privacy Policy explains how Appointso handles personal data across the website, application, API and connected services.
1. Who we are
Appointso is operated by CodeLogic, a software and services business based in Ljubuski, Bosnia and Herzegovina. You can contact us at [email protected].
This policy covers the Appointso website, application, API, booking pages, notification features, billing flows and messaging assistant features.
2. Controller and processor roles
For account, platform, billing, security, support and website analytics data, Appointso acts as a controller.
For personal data that salons enter or collect about their own customers through Appointso, the salon is usually the controller and Appointso acts as a processor. This includes customer names, phone numbers, email addresses, appointment history and booking-related messages processed on behalf of the salon. See our Data Processing Agreement for processor terms.
3. Data we collect from salon users
We may collect and process:
- name, email address, phone number and account role;
- password hashes, login sessions, refresh tokens and authentication events;
- salon profile, services, prices, staff, working hours, branding and booking rules;
- notification preferences, push subscription data and device/browser details;
- billing and subscription status received from payment providers;
- support messages, audit logs, IP addresses, request metadata and security logs.
4. Data we collect about salon customers
When a salon uses Appointso, we may process customer data such as:
- name, phone number and email address when provided;
- appointment date, time, service, employee, price and status;
- booking management tokens and cancellation or rescheduling activity;
- WhatsApp or other supported messaging content when the messaging assistant is enabled;
- technical metadata needed for security, delivery and abuse prevention.
5. Website analytics and cookies
The Appointso marketing website may use Google Tag Manager and analytics cookies only after you accept analytics cookies through the cookie banner. See our Cookie Policy for details.
The application may use necessary cookies or browser storage for authentication, security, language preference and application operation.
6. Why we process data
We process personal data to:
- provide and secure the Appointso service;
- create, manage and display appointments;
- send booking confirmations, reminders and administrative notifications;
- provide support and respond to requests;
- process billing and subscription status;
- prevent abuse, fraud and unauthorized access;
- improve reliability, performance and product quality;
- comply with legal, accounting and security obligations.
7. Legal bases
Where GDPR-style legal bases apply, processing may be based on contract performance, legitimate interests, consent, legal obligations or the salon’s documented instructions as controller.
For salon customer data, the salon is responsible for establishing a valid legal basis toward its own customers. Appointso processes that data according to the salon’s use of the platform and the DPA.
8. Sharing and subprocessors
We do not sell personal data. We share data with service providers only where needed to provide, secure, host, bill, communicate or improve the service.
Current subprocessors are listed on our Subprocessors page.
9. International transfers
Some providers may process data outside Bosnia and Herzegovina, the European Economic Area or the customer’s country. Where required, we rely on appropriate contractual, technical and organizational safeguards.
10. Retention
We keep data only as long as reasonably needed for the purposes described in this policy, including active service use, support, security, billing, legal and backup needs.
Salon customer data is retained according to platform settings, salon instructions and operational retention rules. Messaging history and logs may have separate retention windows.
11. Security
We use technical and organizational measures designed to protect personal data, including TLS, access controls, password hashing, audit logs, role-based access and operational monitoring. No system is perfectly secure, and salons should also protect their own accounts and devices.
12. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to or export your personal data.
Salon customers should normally contact the salon first for appointment or customer record requests, because the salon controls that data. You can also contact [email protected] for platform, privacy or security requests.
For the request procedure, including data received through Meta integrations, see our Data Deletion Instructions. Account closure or revoking an integration is not the same as requesting erasure of stored data.
13. Children
Appointso is not directed to children. Salons must use the platform in accordance with laws that apply to minors and their services.
14. Changes
We may update this policy as the service changes. The current version is published on this page.
15. Contact
Privacy requests can be sent to [email protected]. Appointso has not appointed a separate data protection officer at this stage; privacy requests are handled through the support contact.