Data Processing Notice and Sub-processors
Effective from 8 July 2026
This is a translation of the Hungarian original for convenience. In case of any discrepancy, the Hungarian version prevails.
Roles
The salon (the business using the service) is the controller, and CalmReserve is the processor. CalmReserve processes the personal data of the salon’s customers on the salon’s instructions, to the extent necessary to provide the service.
In practice this means that the salon decides about the data guests provide when booking (name, phone number, e-mail address): the salon determines what it is used for and how long it is kept, and the salon informs guests about data processing. CalmReserve provides the technical infrastructure for this, does not use the data for its own purposes, and deletes it at the salon’s request.
- Processor (operator of CalmReserve):
- Péter István e.v.
- Address:
- Vértes u. 50/A, 2800 Tatabánya, Hungary
- Tax number:
- 92202647-1-31
- E-mail:
- info@calmreserve.com
Obligations of the processor (GDPR Art. 28)
As processor, CalmReserve undertakes the following obligations on behalf of the salon (controller), in accordance with Art. 28 GDPR:
- processes personal data solely on the documented instructions of the salon, unless processing is required by law;
- ensures that persons with access to the data have undertaken a confidentiality obligation;
- applies technical and organisational security measures proportionate to the risk (Art. 32 GDPR);
- engages further sub-processors only on the general authorisation of the salon, with prior notice in accordance with the list below and under equivalent data protection obligations;
- assists the salon, with the means available to it, in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection);
- assists the salon in fulfilling its obligations regarding data security, breach notification and — where necessary — impact assessments;
- notifies the salon without undue delay upon detecting a personal data breach;
- on termination of the contract, deletes or returns the personal data at the salon’s choice (a data export can be requested for 30 days after termination), except data subject to a statutory retention obligation;
- makes available to the salon the information necessary to demonstrate compliance with these obligations, and allows for audits within reasonable limits.
Sub-processors engaged
We may engage the following sub-processors to provide the service. Some services are active only if the salon switches them on separately. We notify salons in advance of changes to the sub-processor list; the salon may object to a planned change on justified data protection grounds.
| Sub-processor | Seat / data location | Purpose | Data involved |
|---|---|---|---|
| Hostinger International Ltd. | Cyprus (EU) — server location within the EU | Hosting and server services, operation of the platform and the database | All stored data (over an encrypted connection) |
| Google Ireland Ltd. | Ireland (EU); transfer to the USA cannot be excluded, based on the Data Privacy Framework | Encrypted storage of the daily and weekly backups | All stored data (AES-256 encrypted; the key is not available to the storage provider) |
| Zoho Corporation | EU data centre region | Delivery of system e-mails (confirmation, reminder, notification) | Recipient e-mail address, name, booking data |
| Brevo (Sendinblue SAS) | France (EU) | Delivery of newsletter and transactional e-mails (if the salon enables it) | Recipient e-mail address, name |
| Stripe Payments Europe Ltd. | Ireland (EU) | Processing of the subscription and card payments | Billing data, payment identifiers |
| Google Ireland Ltd. | Ireland (EU); transfer to the USA based on the Data Privacy Framework | Calendar synchronisation (only if the salon switches it on) | Booking times, staff identifier |
| Telegram | Provider outside the EU; with guarantees under its general terms and conditions | Sending booking notifications (only if the salon switches it on) | Text of the booking notification |
| Meta Platforms Ireland Ltd. (WhatsApp Business) | Ireland (EU); transfer to the USA based on the EU standard contractual clauses (Art. 46 GDPR) | Sending booking notifications to the salon and the guest on WhatsApp (only if the salon switches it on) | Phone number, guest name, service name, booking time, staff name |
If the salon configures its own SMTP account for e-mail, delivery of the messages sent through it is handled by the mail provider chosen by the salon.
Security measures
Stored third-party secrets (e-mail passwords, API keys, integration tokens) are stored encrypted. Access to data processing is role-based and separated per salon (tenant). All connections are encrypted (HTTPS/TLS), and regular backups are taken.