Privacy Policy
Effective from 8 July 2026
This is a translation of the Hungarian original for convenience. In case of any discrepancy, the Hungarian version prevails.
What does this notice cover?
Here we summarise what personal data we process when you use the CalmReserve booking platform, what we use it for, how long we store it, and what rights you have in relation to it. We act in accordance with the EU General Data Protection Regulation (GDPR, 2016/679) and Hungarian Act CXII of 2011 on informational self-determination.
Who processes your data?
For the data of businesses (salons) registering on the CalmReserve platform, the operator of CalmReserve is the controller:
- Operator:
- Péter István e.v.
- Address:
- Vértes u. 50/A, 2800 Tatabánya, Hungary
- Tax number:
- 92202647-1-31
- E-mail:
- info@calmreserve.com
- Website:
- calmreserve.com
For the data of salons’ customers (guests), the salon is the controller and CalmReserve is the processor — this is covered separately in the Data Processing Notice.
What data do we process, why and for how long?
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Registration data (name, e-mail, phone number, business name and address) | Creating the account, providing the service, keeping in contact | Performance of a contract (GDPR Art. 6(1)(b)) | For the duration of the subscription, then deleted when the account is deleted (except data subject to statutory retention) |
| Billing and payment data | Collecting the subscription fee, invoicing (card data is handled by Stripe and never reaches us) | Performance of a contract, legal obligation | 8 years from the issue of the accounting document, under the Hungarian Accounting Act |
| Card verification during the trial | Filtering out abuse and fake registrations — no card is needed to register; any card given is handled by Stripe and is not charged during the trial | Legitimate interest (GDPR Art. 6(1)(f)) | At Stripe, for the duration of the subscription |
| Technical logs (IP address, browser identifier) | Security, prevention of abuse, troubleshooting | Legitimate interest (GDPR Art. 6(1)(f)) | Up to 90 days |
| Marketing consent (if given) | Sending product news and offers | Consent (GDPR Art. 6(1)(a)) — withdrawable at any time | Until consent is withdrawn |
| Complaint and the response to it | Investigating and answering the complaint and handling legal claims | Legal obligation and legitimate interest (GDPR Art. 6(1)(c) and (f)) | 5 years from the closure of the complaint |
Cookies and tracking technologies
CalmReserve always uses strictly necessary cookies: the session cookie storing your login state and the setting for the selected salon. Without these the platform could not work, so they cannot be switched off; session cookies are deleted on logout or when they expire.
In addition — depending on your consent — we may use statistical (analytics), preference and marketing/advertising cookies and similar technologies (e.g. advertising pixels), and may use third-party providers (for example Google, Meta, TikTok, LinkedIn or Microsoft services, or other analytics and advertising providers). These are activated only after your explicit consent, in line with Google Consent Mode v2; visitors who arrive without consent are not measured.
You can give, refuse or customise consent on the cookie banner shown on the website, and you can change or withdraw it at any time. The details — categories, specific providers and legal bases — are set out in the Cookie Policy.
Who has access to the data?
The data is accessible to the operators of CalmReserve and to our sub-processors (hosting provider, Stripe, e-mail delivery services), strictly to the extent necessary to provide the service and under a data processing agreement. We do not sell the data and do not use it for our own marketing towards salons’ customers.
Our providers store data primarily within the European Union. Where a provider may also involve a country outside the EU (e.g. Google Calendar sync, WhatsApp or Telegram notifications, if the salon enables them), the transfer takes place with the safeguards required by the GDPR — the EU–U.S. Data Privacy Framework or standard contractual clauses. Details are in the sub-processor list.
Google Calendar connection (Google user data)
If a salon connects its own Google account to CalmReserve for calendar sync, we use the Google Calendar API with the https://www.googleapis.com/auth/calendar scope. The connection is voluntary and can be removed at any time.
- What we access: the calendars of the connected Google account — we create per-staff (secondary) calendars, share them with the staff member’s e-mail address, write, update and delete booking events, and read events in the calendar (e.g. time off) so that they appear as busy time in the booking system.
- What we store: the OAuth access and refresh token received for the connection (encrypted), the identifiers of the calendars created, the staff e-mail address used for sharing, and the Google event identifiers belonging to synchronised bookings.
- What we do NOT do: we do not access any Google data other than Google Calendar (e.g. Gmail, Drive); we do not sell Google user data, do not use it for advertising or to train artificial intelligence, and use it solely to provide the calendar sync described above.
- Disconnecting: the salon can disconnect the Google account at any time in the admin interface; the stored tokens and connection data are then deleted and further syncing stops.
CalmReserve’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How do we protect your data?
- All connections are encrypted (HTTPS/TLS) — both on the website and on the API.
- Stored secrets (passwords, API keys, integration tokens) are stored encrypted.
- Access is role-based, and each salon’s data is kept separate.
- We take regular backups, and the system is logged and monitored.
- A data processing agreement is in place with every external provider.
What happens in the event of a data breach?
A personal data breach means the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. We investigate and record such events.
- If the breach is likely to result in a risk to your rights, we report it to the supervisory authority (NAIH) without undue delay and at the latest within 72 hours of becoming aware of it.
- If the breach is likely to result in a high risk to you, we also inform you — clearly and plainly, together with the measures taken and recommended.
- If we become aware of a breach affecting salons’ Guests’ data (where CalmReserve is the processor), we notify the affected salon as controller without delay.
What rights do you have?
Under the GDPR you may request the following from us at any time:
- Access (Art. 15): information about what data of yours we process and how.
- Rectification (Art. 16): correction of inaccurate or incomplete data.
- Erasure (Art. 17): deletion of your data where processing is no longer necessary or you have withdrawn your consent.
- Restriction (Art. 18): restriction of processing in the cases set out in law.
- Data portability (Art. 20): provision of your data in a structured, machine-readable format.
- Objection (Art. 21): objection to processing based on legitimate interest.
- Withdrawal of consent (Art. 7): at any time and without giving reasons, for processing based on consent.
We accept requests at info@calmreserve.com and respond within one month at the latest.
Where can you complain?
If you feel that our data processing infringes your rights, please tell us first — we will try to resolve it quickly. You may also lodge a complaint with the supervisory authority or go to court:
- Authority:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address:
- 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address:
- 1363 Budapest, Pf. 9, Hungary
- Phone:
- +36 (1) 391-1400
- E-mail:
- ugyfelszolgalat@naih.hu
- Web:
- naih.hu
Other information
We do not use automated decision-making or profiling that would produce legal effects concerning you.
We may update this notice from time to time (e.g. when engaging a new provider). The version in force at any time is available on this page; we notify you of material changes through the platform.