Who We Are & Scope
Hathor is an all-in-one operating platform for beauty businesses, operated by NEXEMA Group SASU ("Hathor", "we", "us"). This policy describes how we collect and use personal data when you use the Service.
Controller vs processor
We play two distinct roles. For personal data about our business customers and their account — for example the salon owner's contact and billing details — we are the data controller, and this policy governs that processing. For End-Client Data — the personal data of a salon's own clients that the salon uploads to or collects through the Service — the salon is the controller and we act only as the salon's data processor, following the salon's instructions under our Data Processing Agreement.
If you are a client of a salon and have questions about how your data is used, please contact that salon directly, as it is the controller of your data.
Data We Collect
Account and business data
When you register and use the Service we collect account details such as your name, business name, email address, phone number, login credentials, and Subscription and configuration settings.
Customer Data and End-Client Data
We process the business data you enter and the End-Client Data you upload or collect, which may include your clients' names, contact details, appointment history, notes, and communication history. We process End-Client Data only as your processor and on your instructions.
Health-related data (special category)
The Service lets a salon optionally record health-related details about its own clients — such as skin type, skin concerns, and allergies. This is special-category data under GDPR Article 9. The salon is the controller of this data and is responsible for obtaining each client's explicit consent before recording it. To support this, the Service requires the salon to affirm that consent before such fields can be saved, and records when that consent was captured; without it, these fields are not stored. As processor, we do not use health-related data for any purpose other than providing the Service on the salon's instructions.
Payment data
Subscription payments are processed by Stripe and, where enabled, PayPal. We do not store raw card numbers; the processor tokenizes and handles card data. We receive limited information such as billing status, the last four digits, and transaction identifiers.
Usage, device, and cookie data
We automatically collect technical data such as IP address, browser and device type, pages viewed, and actions taken, together with cookies and similar technologies used to operate and secure the Service.
How & Why We Use Data
We use personal data for the purposes below, each supported by a legal basis under the GDPR where we act as controller.
- To provide, operate, and maintain the Service and your account — legal basis: performance of our contract with you.
- To process payments, manage Subscriptions, and prevent fraud — legal basis: performance of contract and our legitimate interests.
- To send transactional and service messages such as confirmations and security notices — legal basis: performance of contract and legitimate interests.
- To improve, secure, and develop the Service, including analytics on usage — legal basis: our legitimate interests, balanced against your rights.
- To send marketing about our own products where permitted — legal basis: consent, or legitimate interests where allowed by law, with an opt-out.
- To comply with legal, tax, and accounting obligations — legal basis: compliance with a legal obligation.
When we act as a processor of End-Client Data on a salon's behalf, the salon is responsible for establishing the legal basis for that processing.
Sub-Processors
We use carefully selected sub-processors to deliver the Service. Each is bound by data protection obligations consistent with this policy and the DPA. Our current sub-processors are listed below.
- Supabase — database, authentication, and storage, hosted in the EU.
- Vercel — application hosting and content delivery.
- Stripe — payment processing.
- PayPal — alternative payment processing.
- SendGrid — transactional and marketing email delivery.
- Twilio, Vonage, MessageBird, and AWS SNS — SMS message delivery.
- Upstash — rate-limiting and caching.
- Google — calendar integration and Google OAuth / social sign-in, where you enable them (processing may occur outside the EEA under Standard Contractual Clauses).
- Meta Platforms — identity verification for Facebook social sign-in, where you enable it (processing outside the EEA under Standard Contractual Clauses).
- Anthropic — AI text generation (United States). Listed in advance of activation: this sub-processor is not yet active and processes no personal data until an AI-assisted feature that uses personal data is enabled and this notice is updated.
We may update this list as the Service evolves and, where we act as your processor, will provide notice of new sub-processors as set out in the DPA.
International Transfers
Our core infrastructure and data hosting are located in the European Union (including eu-central-1 and eu-west-2 regions). We aim to keep personal data within the EU wherever practicable.
Where a sub-processor or transfer involves processing outside the European Economic Area, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, together with additional measures where needed, to protect the data.
Data Retention
We retain personal data for as long as needed to provide the Service and your account, and thereafter only as required to meet legal, tax, accounting, or dispute-resolution obligations.
After your account is terminated, we provide a 30-day window during which you may export your Customer Data and End-Client Data. After that window, we delete or anonymize the data, except where longer retention is legally required. For End-Client Data, retention and deletion follow the salon's instructions and the DPA.
Security Measures
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, authentication, rate-limiting, network segregation, and regular review of our security practices. Payment card data is handled by PCI-compliant processors and is not stored by us in raw form.
No system can be guaranteed to be completely secure. You are responsible for keeping your credentials confidential and for configuring access within your account appropriately. We will notify you of any personal data breach as required by applicable law and the DPA.
Your Rights
Where we act as controller, and subject to applicable law, you have rights over your personal data under the GDPR and UK GDPR.
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to correct inaccurate or incomplete data.
- Erasure — to request deletion of your data in certain circumstances.
- Portability — to receive your data in a structured, machine-readable format.
- Objection — to object to processing based on legitimate interests, including direct marketing.
- Restriction — to limit how we process your data in certain cases.
- Withdrawal of consent — where processing is based on consent, at any time.
To exercise these rights, contact us at support@hatthor.online. You also have the right to lodge a complaint with your local data-protection supervisory authority. As we are established in France, our lead authority is the Commission Nationale de l'Informatique et des Libertés (CNIL, www.cnil.fr); in the UK, it is the Information Commissioner's Office (ICO).
California rights (CCPA/CPRA)
If you are a California resident, you have rights to know what personal information we collect, to access and delete it, to correct it, and to opt out of any sale or sharing of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights. To make a request, contact us at support@hatthor.online.
Where we process End-Client Data as a processor, requests from a salon's clients should be directed to the salon as controller; we will assist the salon in responding as set out in the DPA.
Marketing Communications & Opt-Out
We may send you marketing about our own products and features where permitted by law. You can opt out at any time using the unsubscribe link in our emails or by contacting support@hatthor.online. Opting out of marketing does not stop essential transactional or service messages.
Marketing that you send to your own clients through the Service is your responsibility as controller. You must obtain any consents required by law, honor opt-out requests, and comply with applicable email and SMS marketing rules.
Children
The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal data from individuals under 18 as controller, and our Acceptable Use Policy prohibits using the Service to process data of children under 18.
If you believe a child has provided us with personal data where we are the controller, please contact us at support@hatthor.online and we will take appropriate steps to delete it.
Data Processing Agreement
For business customers who are controllers of End-Client Data, our Data Processing Agreement (the "DPA") governs how we process that data as your processor. The DPA forms part of our agreement with you and sets out the scope, duration, and purpose of processing, our confidentiality and security commitments, sub-processor terms, breach notification, and assistance with data-subject requests.
The DPA includes Standard Contractual Clauses where required for transfers outside the EEA. If you need a copy of the DPA, contact us at support@hatthor.online.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or the law. If a change is material, we will provide notice, for example by email or an in-product notice.
The date of the latest version will be shown on this page. Your continued use of the Service after an update takes effect indicates your awareness of the revised policy.
Contact & Data Protection Enquiries
For any privacy or data protection enquiry, including exercising your rights, requesting the DPA, or raising a concern, contact us at support@hatthor.online.
The data controller for account and business data is NEXEMA Group SASU, 38 Rue des Mathurins, 75008 Paris, France.