Privacy policy
Last updated: 29 July 2026
Only the German version of this privacy policy is legally binding. Translations are provided for ease of understanding only; in the event of any discrepancy or question of interpretation, the German version prevails.
1. Controllers (joint controllership, Art. 26 GDPR)
The joint controllers within the meaning of Art. 26 GDPR for the processing of personal data on this website are:
Apropos Haare GmbH, Mönchhofstr. 3b, 69120 Heidelberg, Germany
Apropos Haare Mannheim GmbH, Tattersallstraße 41, 68165 Mannheim, Germany
An arrangement pursuant to Art. 26(1) GDPR determines which company fulfils which obligations. The essence for you: Apropos Haare GmbH is the primary point of contact for data subject rights; you may exercise your rights against either controller. Contact: datenschutz@aproposhaare.de
No data protection officer has been appointed (§ 38(1) BDSG, German Federal Data Protection Act).
2. Data, purposes and legal bases
Purposes of processing: provision of this online offering · online appointment booking and customer accounts · appointment confirmations and reminders · responding to contact and job-application enquiries · abuse prevention · internal analysis and improvement of our offering.
Depending on the purpose, the legal basis is Art. 6(1)(a) GDPR (consent), (b) (contract or pre-contractual measures), (c) (legal obligation) or (f) (legitimate interests). The applicable basis is stated with each processing activity below.
Health-related information (Art. 9 GDPR) — compatibility notes in the treatment record (Section 4) and information you provide voluntarily in the notes field of a booking — is processed exclusively with your explicit consent (Art. 9(2)(a) GDPR).
Categories of personal data processed:
- Master data (e.g. name)
- Contact data (e.g. email address, telephone number)
- Content data (e.g. text entered in forms, profile photo, application documents)
- Treatment data (e.g. booked services, appointment history)
- Contractual data (e.g. booked service, assigned salon)
- Usage and access data (e.g. pages visited, IP address, timestamp)
3. Categories of recipients and third-country transfers
Service providers processing data on our behalf are bound by a contract pursuant to Art. 28 GDPR. Beyond that, we disclose data only where we are legally required to do so. Categories of recipients:
- Hosting, database and security providers — processing also takes place in the USA; the transfer is based on the EU–US Data Privacy Framework and additionally on Standard Contractual Clauses under Art. 46 GDPR.
- The provider of our booking system (established in the EU) and its sub-processors — for email dispatch a provider in the USA, covered by Standard Contractual Clauses under Art. 46 GDPR; for SMS a provider within the EEA.
- Email provider for our own messages — established and processing within the EU.
- Provider of the map display — established in the United Kingdom; the transfer is based on the EU adequacy decision.
- Providers of advertising and conversion measurement — only after your marketing consent; named in Sections 10 and 11.
- Where photos are published online (Section 6): the respective platform operators — only to the extent of your consent.
4. Contractual services — booking, customer account, treatment record
Appointment booking: master, contact, treatment and contractual data to carry out the appointment (Art. 6(1)(b) GDPR), processed via the provider of our booking system (Section 3).
Customer account: sign-in and account management under Art. 6(1)(b) GDPR. For abuse prevention and as evidence of consent, at registration and sign-in we store pseudonymous access details and a timestamp (Art. 6(1)(f) GDPR). Upon termination, deletion unless statutory retention obligations preclude it (Section 14).
Waiting list: name and contact details to notify you of appointments that become available (Art. 6(1)(b) GDPR). After you delete your entry, an anonymised remainder without any personal reference is retained for internal statistics for as long as required (Art. 6(1)(f) GDPR).
Booking suggestions: we suggest suitable appointments to signed-in users, derived from appointment history and visit frequency (Section 13). Within a booking process already started, Art. 6(1)(b) GDPR; outside of one, Art. 6(1)(f) GDPR. No automated decision-making with legal effect or similarly significant impact (Art. 22 GDPR) takes place.
Treatment record: consultation outcome, colour formula and appointment notes, to continue your treatment professionally (Art. 6(1)(b) GDPR — performance of the hairdressing contract). Accessible to the stylists of the responsible company, additionally based on Art. 6(1)(f) GDPR (continuity and cover). Deleted once no longer required for further treatment and no statutory retention obligations preclude it.
5. Notifications and reminders
Appointment confirmations and reminders by email and/or SMS, sent via sub-processors of our booking system provider (Section 3). Legal basis: Art. 6(1)(b) GDPR.
Notification log: type, channel, time and delivery status of automated notifications; the message content is not stored. The purpose is accountability under Art. 5(2) GDPR and abuse prevention (Art. 6(1)(f) GDPR). Deleted once no longer required.
6. Photos
Release of your own images: images taken during a photo session can be released for you to download in your customer profile, and we inform you by email (Art. 6(1)(b) GDPR). The release is time-limited (Art. 5(1)(e) GDPR); you may request early termination at any time.
7. Contact and job-application forms
When you get in touch or submit a job application, we process your name, email address, message content and, where applicable, application documents to handle your enquiry (Art. 6(1)(b) or (f) GDPR). Dispatch via our email provider within the EU; application documents are additionally stored with our hosting provider (Section 3) for as long as required for the process and to defend against potential claims.
8. Technical safeguards and logging
Server log files: when the website is accessed, access data is processed (page requested, time, data volume transferred, browser, operating system, referrer URL, IP address) on the basis of our legitimate interest in security and stability (Art. 6(1)(f) GDPR). Retained only briefly; data required for evidentiary purposes until the incident has been resolved.
Protecting the booking interface: to prevent overload and erroneous mass requests, we limit the number of requests per visitor. For this we use a short-lived, pseudonymous value that is not attributed to any person and is automatically discarded after a short time (Art. 6(1)(f) GDPR).
Change log for internal costing bases: we record which administrative account made a price-relevant change (Art. 6(1)(f) GDPR, additionally § 26 BDSG). No customer data is affected; anonymised once no longer required.
10. Google Ads (conversion tracking and remarketing)
With your explicit consent via the cookie banner ("Marketing" category), we use Google Ads. Our contractual partner is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; processing is carried out in part by Google LLC (USA). The legal basis is exclusively your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
The purposes are conversion measurement — which advertisement led to a booking, a phone call or a WhatsApp contact — as well as remarketing and personalised advertising: for this, Google may combine your behaviour on this website into advertising audiences and show you our advertisements again across the Google advertising network. Without your consent, Google Ads is not loaded.
Cookies with the prefix "_gcl" are set (retention approximately 90 days), and for remarketing, identifiers on Google’s own advertising domains, in particular "IDE" on doubleclick.net (retention as determined by Google, several months). The transfer to the USA is based on the EU-US Data Privacy Framework.
Joint controllership (Art. 26 GDPR): we and Google Ireland Ltd. are joint controllers for the collection and transmission of the data on this website. We decide on its use, the design of the consent mechanism and which events are transmitted; Google is responsible for the further processing, in particular storage, creation of advertising audiences and delivery of personalised advertising. You may exercise your rights against us (datenschutz@aproposhaare.de) and directly against Google.
You may withdraw at any time via the cookie settings, with effect for the future; data already transmitted to Google is not deleted as a result. After withdrawal the cookies are removed and no further transmissions take place.
11. Meta Pixel conversion tracking (Meta Ads / Facebook, Instagram)
With your explicit consent via the cookie banner ("Marketing" category), we use the Meta Pixel (Meta Ads, including Facebook and Instagram). Our contractual partner is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; processing is carried out in part by Meta Platforms, Inc. (USA). The legal basis is exclusively your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
The purpose is conversion measurement — attributing a completed booking or a phone-call or WhatsApp click to a previously seen advertisement. No remarketing, no Automatic Advanced Matching in the browser, and no transmission of form-field content. Upon a confirmed appointment booking, we additionally transmit your email address and phone number to Meta in cryptographically hashed, non-reversible form, to improve ad attribution.
Cookies with the prefixes "_fbp" and "_fbc" are set (retention approximately 90 days). The transfer to the USA is based on the EU-US Data Privacy Framework.
Joint controllership (Art. 26 GDPR): we and Meta Platforms Ireland Ltd. are joint controllers for the collection and transmission of the event data (Schedule, Contact); the details are governed by Meta’s Controller Addendum to the advertising terms of use. We decide on its use, the design of the consent mechanism and which events are triggered; Meta is responsible for the further processing of the event data it receives. You may exercise your rights against us (datenschutz@aproposhaare.de) and directly against Meta.
You may withdraw at any time via the cookie settings, with effect for the future; data already transmitted to Meta is not deleted as a result. After withdrawal the cookies are removed and no further transmissions take place.
12. Embedded third-party services and content
- Map display — OpenStreetMap: when a map is loaded, your browser retrieves map tiles directly from the OpenStreetMap Foundation (United Kingdom); your IP address is transmitted in the process (Art. 6(1)(f) GDPR; transfer based on the EU adequacy decision).
- Bot protection — Cloudflare Turnstile: for security-sensitive functions a verification token is processed; no cookies are set (Art. 6(1)(f) GDPR).
13. Internal analytics and consent records
Internal analytics: from booking and usage data we derive metrics (e.g. visit frequency, customer retention, lifetime value, demographics) and analyse the booking process, including where and why it was abandoned. The purpose is internal business management (Art. 6(1)(f) GDPR); for signed-in users this data is linked to the customer account. You may object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). No automated decision-making with legal effect or similarly significant impact (Art. 22 GDPR) takes place. Anonymised or deleted once the personal reference is no longer required for the analysis.
Consent records: consents given are logged with purpose, time, text version and pseudonymous details of their origin, in order to meet the burden of proof under Art. 7(1) GDPR (Art. 6(1)(f) GDPR). We remove the origin details once no longer required; for consent-based processing the record is retained until you withdraw.
Consent rate: we count how often the cookie banner is displayed and the "Marketing" category is accepted or declined — exclusively as daily counters without any session or customer identifier, so attribution to an individual is not possible (Art. 6(1)(f) GDPR). Consent under § 25 TDDDG is not required for this.
14. Retention and deletion
We delete personal data as soon as it is no longer required for its purpose and no statutory retention obligations preclude deletion; otherwise we restrict processing to the retention purpose. Statutory retention: 6 years under § 257 HGB (German Commercial Code) or 10 years under § 147 AO (German Fiscal Code) (Art. 6(1)(c) GDPR). The criteria applicable to each processing activity are stated in the relevant section.
When you delete your website account, we remove all account-related personal data. The appointment and receipt records mirrored from the booking system remain, because they are subject to the statutory retention obligation (§ 147 AO); deleting your account data removes their personal reference.
15. Your rights, objection and complaints
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR) without affecting the lawfulness of processing carried out prior to withdrawal.
You may object at any time to the processing of your data for direct marketing purposes (Art. 21(2) GDPR).
To exercise your rights: datenschutz@aproposhaare.de, the request form (link below) or — with a website account — the customer area under "My profile". Without a website account, deletion in the booking system takes place once your request has been verified by email, within 30 days of that verification (Art. 12(3) GDPR). To handle it we keep a request record containing your name, email address and request history (Art. 6(1)(c) GDPR in conjunction with Art. 12 GDPR), retained for as long as required to evidence its proper handling.
Independently of this, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular with the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (www.baden-wuerttemberg.datenschutz.de).