Skip to main content

Legal

Privacy Policy

This policy explains how Hathor handles personal data. For your own business and account data we act as a controller; for your clients' personal data that you manage in the Service, you are the controller and we are your processor.

Last updated 29 July 2026

Read the Terms of Service

This document is a good-faith template provided for transparency. It is not legal advice and should be reviewed and adapted by qualified counsel before it is relied upon.

01

Who We Are & Scope

Hathor is an all-in-one operating platform for beauty businesses, operated by NEXEMA Group SASU ("Hathor", "we", "us"). This policy describes how we collect and use personal data when you use the Service.

Controller vs processor

We play two distinct roles. For personal data about our business customers and their account — for example the salon owner's contact and billing details — we are the data controller, and this policy governs that processing. For End-Client Data — the personal data of a salon's own clients that the salon uploads to or collects through the Service — the salon is the controller and we act only as the salon's data processor, following the salon's instructions under our Data Processing Agreement.

If you are a client of a salon and have questions about how your data is used, please contact that salon directly, as it is the controller of your data.

02

Data We Collect

Account and business data

When you register and use the Service we collect account details such as your name, business name, email address, phone number, login credentials, and Subscription and configuration settings.

Customer Data and End-Client Data

We process the business data you enter and the End-Client Data you upload or collect, which may include your clients' names, contact details, appointment history, notes, and communication history. We process End-Client Data only as your processor and on your instructions.

Health-related data (special category)

The Service lets a salon optionally record health-related details about its own clients — such as skin type, skin concerns, and allergies. This is special-category data under GDPR Article 9. The salon is the controller of this data and is responsible for obtaining each client's explicit consent before recording it. To support this, the Service requires the salon to affirm that consent before such fields can be saved, and records when that consent was captured; without it, these fields are not stored. As processor, we do not use health-related data for any purpose other than providing the Service on the salon's instructions.

Payment data

Subscription payments are processed by Stripe and, where enabled, PayPal. We do not store raw card numbers; the processor tokenizes and handles card data. We receive limited information such as billing status, the last four digits, and transaction identifiers.

Usage, device, and cookie data

We automatically collect technical data such as IP address, browser and device type, pages viewed, and actions taken, together with cookies and similar technologies used to operate and secure the Service.

04

Cookies & Analytics

We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand how it is used. Strictly necessary cookies are required for the Service to function.

Where required by law, we ask for your consent before setting non-essential cookies, including analytics cookies. You can manage your preferences through your browser settings and any cookie controls we provide in the Service.

05

Sub-Processors

We use carefully selected sub-processors to deliver the Service. Each is bound by data protection obligations consistent with this policy and the DPA. Our current sub-processors are listed below.

  • Supabase — database, authentication, and storage, hosted in the EU.
  • Vercel — application hosting and content delivery.
  • Stripe — payment processing.
  • PayPal — alternative payment processing.
  • SendGrid — transactional and marketing email delivery.
  • Twilio, Vonage, MessageBird, and AWS SNS — SMS message delivery.
  • Upstash — rate-limiting and caching.
  • Google — calendar integration and Google OAuth / social sign-in, where you enable them (processing may occur outside the EEA under Standard Contractual Clauses).
  • Meta Platforms — identity verification for Facebook social sign-in, where you enable it (processing outside the EEA under Standard Contractual Clauses).
  • Anthropic — AI text generation (United States). Listed in advance of activation: this sub-processor is not yet active and processes no personal data until an AI-assisted feature that uses personal data is enabled and this notice is updated.

We may update this list as the Service evolves and, where we act as your processor, will provide notice of new sub-processors as set out in the DPA.

06

Sharing & Disclosure

We do not sell personal data. We share personal data only as needed to run the Service: with the sub-processors listed above, with professional advisors under confidentiality, and in connection with a merger, acquisition, or sale of assets, in which case the data remains subject to this policy.

We may disclose personal data where required to comply with applicable law, legal process, or a lawful government request, or to protect the rights, safety, and security of Hathor, our customers, or the public.

07

International Transfers

Our core infrastructure and data hosting are located in the European Union (including eu-central-1 and eu-west-2 regions). We aim to keep personal data within the EU wherever practicable.

Where a sub-processor or transfer involves processing outside the European Economic Area, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, together with additional measures where needed, to protect the data.

08

Data Retention

We retain personal data for as long as needed to provide the Service and your account, and thereafter only as required to meet legal, tax, accounting, or dispute-resolution obligations.

After your account is terminated, we provide a 30-day window during which you may export your Customer Data and End-Client Data. After that window, we delete or anonymize the data, except where longer retention is legally required. For End-Client Data, retention and deletion follow the salon's instructions and the DPA.

09

Security Measures

We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, authentication, rate-limiting, network segregation, and regular review of our security practices. Payment card data is handled by PCI-compliant processors and is not stored by us in raw form.

No system can be guaranteed to be completely secure. You are responsible for keeping your credentials confidential and for configuring access within your account appropriately. We will notify you of any personal data breach as required by applicable law and the DPA.

10

Your Rights

Where we act as controller, and subject to applicable law, you have rights over your personal data under the GDPR and UK GDPR.

  • Access — to obtain a copy of the personal data we hold about you.
  • Rectification — to correct inaccurate or incomplete data.
  • Erasure — to request deletion of your data in certain circumstances.
  • Portability — to receive your data in a structured, machine-readable format.
  • Objection — to object to processing based on legitimate interests, including direct marketing.
  • Restriction — to limit how we process your data in certain cases.
  • Withdrawal of consent — where processing is based on consent, at any time.

To exercise these rights, contact us at support@hatthor.online. You also have the right to lodge a complaint with your local data-protection supervisory authority. As we are established in France, our lead authority is the Commission Nationale de l'Informatique et des Libertés (CNIL, www.cnil.fr); in the UK, it is the Information Commissioner's Office (ICO).

California rights (CCPA/CPRA)

If you are a California resident, you have rights to know what personal information we collect, to access and delete it, to correct it, and to opt out of any sale or sharing of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights. To make a request, contact us at support@hatthor.online.

Where we process End-Client Data as a processor, requests from a salon's clients should be directed to the salon as controller; we will assist the salon in responding as set out in the DPA.

11

Marketing Communications & Opt-Out

We may send you marketing about our own products and features where permitted by law. You can opt out at any time using the unsubscribe link in our emails or by contacting support@hatthor.online. Opting out of marketing does not stop essential transactional or service messages.

Marketing that you send to your own clients through the Service is your responsibility as controller. You must obtain any consents required by law, honor opt-out requests, and comply with applicable email and SMS marketing rules.

12

Children

The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal data from individuals under 18 as controller, and our Acceptable Use Policy prohibits using the Service to process data of children under 18.

If you believe a child has provided us with personal data where we are the controller, please contact us at support@hatthor.online and we will take appropriate steps to delete it.

13

Data Processing Agreement

For business customers who are controllers of End-Client Data, our Data Processing Agreement (the "DPA") governs how we process that data as your processor. The DPA forms part of our agreement with you and sets out the scope, duration, and purpose of processing, our confidentiality and security commitments, sub-processor terms, breach notification, and assistance with data-subject requests.

The DPA includes Standard Contractual Clauses where required for transfers outside the EEA. If you need a copy of the DPA, contact us at support@hatthor.online.

14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or the law. If a change is material, we will provide notice, for example by email or an in-product notice.

The date of the latest version will be shown on this page. Your continued use of the Service after an update takes effect indicates your awareness of the revised policy.

15

Contact & Data Protection Enquiries

For any privacy or data protection enquiry, including exercising your rights, requesting the DPA, or raising a concern, contact us at support@hatthor.online.

The data controller for account and business data is NEXEMA Group SASU, 38 Rue des Mathurins, 75008 Paris, France.

Questions? Email support@hatthor.online.