Privacy policy

Your privacy and the security of your personal data are our top priorities.

1. Introduction

S Lift obrt za kosmetiskej usluge (hereinafter referred to as: “Salon”, “we” or “controller”) respects the privacy of its clients and website users and processes personal data in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR),
  • Act on the Implementation of the General Data Protection Regulation,
  • other applicable regulations of the Republic of Croatia and the European Union.other applicable regulations of the Republic of Croatia and the European Union.

The purpose of this Privacy Policy is to explain clearly and transparently what personal data we collect, for what purposes we process it, on what legal basis, how long we keep it, with whom we share it and what rights you have as a data subject.

By using this website, you confirm that you are familiar with the content of this Privacy Policy.

2. Data controller

S Lift trade for cosmetic services

Kačićeva ulica 10

10000 Zagreb, Republic of Croatia

OIB: 70146195679

E-mail for protection of personal data and exercise of rights:

admin@slift.hr

3. What personal data we process

We only process personal data that is necessary for providing our services, communicating with users, booking appointments, performing professional cosmetic treatments and fulfilling legal obligations.

3.1. Contact form

If you contact us via the contact form on the website, we process:

  • name and surname (if you specify it),
  • e-mail address,
  • message content.

Purpose of processing

  • answering inquiries,
  • communication with users,
  • taking actions before entering into a service contract.

Legal basis

  • Article 6(1)(b) GDPR – taking action at the request of the data subject before entering into a contract,
  • Article 6(1)(f) GDPR – legitimate interest in efficient business communication.
3.2. Newsletter

When subscribing to the newsletter, we process:

  • your email address.

Purpose of processing

  • sending news,
  • promotional offers,
  • information about services,
  • educational content.

Registration is carried out via a double opt-in system, i.e., the subscription becomes active only after confirmation of the registration via e-mail.

Legal basis

Article 6(1)(a) GDPR – consent.

You can withdraw your consent at any time by clicking on the unsubscribe link in each message or by sending a request to:

admin@slift.hr

3.3. Online appointment booking

Online appointment booking is carried out via the external application Zoyya.

On this occasion, the following can be processed:

  • name and surname,
  • phone number,
  • e-mail address,
  • selected service,
  • date and time of reservation.

The data is used exclusively to organise the appointment, communicate with the client, and provide the contracted service.

Legal basis

Article 6, paragraph 1, point (b) of the GDPR - execution of the contract, i.e. taking actions before concluding the contract.

3.4. Forms for skin analysis and treatment

Before carrying out certain facial care treatments, the Salon collects data through professional forms that may contain special categories of personal data under Article 9 of the GDPR.

This includes:

  • Skin Code analysis,
  • AI skin analysis using the View Skin device,
  • general client questionnaire,
  • data on skin condition,
  • information about allergies,
  • information on contraindications,
  • other health circumstances important for safe treatment.

The data provided is used exclusively for the following purposes:

  • assessing the suitability of the treatment,
  • preventing allergic reactions and other undesirable effects,
  • selecting appropriate products,
  • individual treatment planning,
  • monitoring the progress of the skin over time.

Legal basis

Article 9(2)(a) GDPR – explicit consent of the data subject.

Providing this data is not a legal obligation, but without it it may not be possible to provide certain cosmetic treatments safely.

You can withdraw your consent at any time, and withdrawal does not affect the lawfulness of the processing carried out before withdrawal.

4. Automated skin analysis

AI analysis via the View Skin device uses algorithms to assess the condition of the skin and is an auxiliary tool in making professional recommendations for skin care.

The results of the AI ​​analysis:

  • do not constitute a medical diagnosis,
  • serve exclusively as an aid to professional staff,
  • are not used to make automated decisions that produce legal effects or similarly significantly affect the data subject within the meaning of Article 22 GDPR.

A professional at the Salon always makes the final assessment and treatment recommendation.

5. Processors and recipients of personal data

To provide services, we use trusted business partners who process personal data exclusively according to our instructions and in accordance with the GDPR.

This includes:

  • Zoyya – online appointment booking system,
  • Hostinger – a web hosting provider,
  • Logobox – technical website maintenance,
  • Microsoft OneDrive – secure storage of digital documentation,
  • WordPress and related plugins, including navigation plugins (Breadcrumbs),
  • Google Analytics – traffic analytics,
  • Meta Pixel – measuring the effectiveness of marketing campaigns.
Use of artificial intelligence (AI)

The Salon uses artificial intelligence (AI) technology through the View Skin system for digital analysis of skin condition in the provision of certain cosmetic services.

The AI ​​system serves solely as an auxiliary tool in assessing skin characteristics and developing recommendations for an individual care plan. The results of the AI ​​analysis represent professional support and do not replace the assessment and professional decision of the person performing the treatment.

Based on the results of the AI ​​analysis, no automated decisions are made that produce legal effects or similarly significantly affect the client within the meaning of Article 22 of the General Data Protection Regulation (GDPR). All recommendations and decisions on the implementation of the treatment are made by a professional person at the Salon under human supervision.

The Salon strives to use AI systems that are developed and implemented in accordance with applicable European Union regulations, including Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act), to the extent applicable to the use of such systems. When using AI technology, the Salon ensures transparency towards clients, protection of personal data, and the implementation of appropriate technical and organisational security measures.

Personal data will not be sold or transferred to third parties for marketing purposes.

When necessary to comply with legal obligations or protect our rights, personal data may be provided to competent government authorities or other authorised recipients in accordance with the law.

6. International data transfers

Some digital service providers we use may process personal data outside the European Economic Area.

If such a transfer occurs, it will only be carried out with the application of appropriate safeguards prescribed by the GDPR.

When personal data is transferred to service providers based in the United States, the transfer may be based on an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework, or on other appropriate safeguards under Articles 45 to 49 of the GDPR.

7. Security of personal data

We apply appropriate technical and organisational measures to protect personal data that ensure their confidentiality, integrity and availability.

The measures implemented include:

  • SSL/TLS encryption of the website (HTTPS),
  • storage of digital forms and documentation on a Microsoft OneDrive account protected by a strong password and two-factor authentication (2FA),
  • limited access to data only to the Salon owner and, if necessary, authorised personnel who are obliged to maintain confidentiality,
  • additional encryption of documents and analyses delivered by email,
  • protection of submitted files with a four-digit password known only to the client and the Salon,
  • regular updating of information systems and security settings.

Despite the application of high security standards, no electronic data storage or transmission system can guarantee absolute security.

8. Cookies

The website uses cookies to operate properly, improve functionality and analyse site usage.

We use the following categories of cookies:

Essential cookies

Enable basic functionalities of the website and are necessary for its proper operation. They do not require user consent.

Analytical cookies

We use Google Analytics to create anonymous statistical reports on website usage. Analytical cookies are activated only after the user gives consent via the Cookie Banner.

Marketing cookies

We use Meta Pixel to measure the effectiveness of marketing campaigns and display more relevant ads. Marketing cookies are also activated only after the user's prior consent via the Cookie Banner.

Cookie consent can be changed or withdrawn at any time via the Cookie Banner settings.

9. Personal data storage periods

We only store personal data for as long as necessary to achieve the purpose of their processing or as required by applicable regulations.

The following deadlines apply:

  • data from the contact form – until the end of communication, and no longer than 12 months from the last contact,
  • data for the newsletter – until the withdrawal of consent or unsubscribe,
  • skin analysis forms, AI analysis results and client files – until the withdrawal of consent or no longer than five years from the last treatment performed, whichever comes first, unless there is a legal basis for longer retention,
  • invoices and transaction documentation – 11 years, in accordance with the tax and accounting regulations of the Republic of Croatia.

After the expiration of the specified deadlines, the data is securely deleted or anonymised, unless their further retention is required by law.

10. Rights of the data subject

In accordance with the GDPR, you have the right to:

  • request access to your personal data,
  • request correction of inaccurate or incomplete data,
  • request the deletion of personal data when the legal requirements for doing so are met,
  • request the restriction of processing,
  • exercise the right to data portability,
  • object to the processing of personal data where such processing is based on legitimate interests,
  • withdraw your consent at any time where the processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal.

To exercise your rights, you may contact us via the following email address:

admin@slift.hr

We respond to requests without undue delay and, in any event, within the deadlines prescribed by the GDPR.

11. Right to lodge a complaint with the supervisory authority

If you believe that the processing of your personal data is not in compliance with the General Data Protection Regulation (GDPR) or other applicable data protection regulations, you have the right to lodge a complaint with the competent supervisory authority in the Republic of Croatia:

Agency for Personal Data Protection (AZOP)

Ulica Metela Ožegovića 16

10000 Zagreb

Phone: +385 (0)1 4609 000

E-mail: azop@azop.hr

Web: www.azop.hr

12. Amendments to the Privacy Policy

This Privacy Policy may be updated from time to time to ensure compliance with legal changes, changes in our business operations, or technological developments that affect the processing of personal data.

Each new version will be published on this website with the date of the last update indicated and will enter into force on the date of publication.