Salona Salona
Features About Contact
Login Get Started
Back to Sign Up

Privacy Policy

Last Updated: November 16, 2025

Your Privacy Matters: Salona is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with GDPR and other data protection regulations.

1. Introduction

Salona ('we', 'us', or 'our') operates the Salona platform (the 'Service'). This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.

2. Data Controller Information

For the purposes of GDPR and other data protection laws, Salona acts as the data controller for the personal information we collect from you.

  • Company: Salona OÜ
  • Address: Estonia
  • Email: privacy@salona.me

3. Information We Collect

3.1 Information You Provide to Us

Data Type Examples Purpose
Account Information Name, email, phone number, password Account creation and authentication
Business Information Business name, address, tax ID, banking details Service provision and payment processing
Customer Data Client names, contact info, appointment history Booking management and CRM functionality
Communications Support tickets, emails, chat messages Customer support and service improvement

3.2 Information Collected Automatically

When you use our Service, we automatically collect:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, time spent)
  • Cookies and similar tracking technologies
  • Log data (access times, error logs)

3.3 Information from Third Parties

We may receive information from:

  • Social media platforms (if you sign up via Google, Facebook, etc.)
  • Payment processors
  • Marketing and analytics partners
  • Third-party integrations you connect to Salona

4. How We Use Your Information

We use your personal data for the following purposes:

4.1 Service Provision (Legal Basis: Contract Performance)

  • Creating and managing your account
  • Providing booking and scheduling functionality
  • Processing payments and managing subscriptions
  • Customer relationship management
  • Sending transactional emails and notifications

4.2 Service Improvement (Legal Basis: Legitimate Interest)

  • Analyzing usage patterns and trends
  • Developing new features and improvements
  • Troubleshooting and debugging
  • Ensuring security and preventing fraud

4.3 Marketing (Legal Basis: Consent)

  • Sending promotional emails and newsletters (with your consent)
  • Displaying personalized advertisements
  • Conducting market research

4.4 Legal Compliance (Legal Basis: Legal Obligation)

  • Complying with legal requirements and regulations
  • Responding to legal requests and preventing illegal activity
  • Enforcing our Terms of Service

5. GDPR Rights for EU Users

Your Data Protection Rights

If you are a resident of the European Economic Area (EEA), you have the following data protection rights:

5.1 Right to Access

You have the right to request copies of your personal data. We may charge a reasonable fee for multiple requests.

5.2 Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data.

5.3 Right to Erasure ('Right to be Forgotten')

You have the right to request deletion of your personal data under certain conditions, such as when the data is no longer necessary or you withdraw consent.

5.4 Right to Restrict Processing

You have the right to request restriction of processing your personal data under certain conditions.

5.5 Right to Data Portability

You have the right to request transfer of your data to another organization or directly to you in a structured, commonly used format.

5.6 Right to Object

You have the right to object to processing of your personal data for direct marketing purposes or based on legitimate interests.

5.7 Right to Withdraw Consent

Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5.8 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

  • Email: privacy@salona.me
  • Through your account settings for certain rights

We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.

6. Data Sharing and Disclosure

We may share your personal data with:

6.1 Service Providers

  • Cloud hosting providers (AWS, Google Cloud, etc.)
  • Payment processors (Stripe, PayPal, etc.)
  • Email service providers
  • Analytics and monitoring services
  • Customer support tools

6.2 Business Transfers

If Salona is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will notify you before your data is transferred and becomes subject to a different Privacy Policy.

6.3 Legal Requirements

We may disclose your personal data if required by law or in response to valid requests by public authorities.

6.4 With Your Consent

We may share your information for any other purpose with your explicit consent.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures
  • Regular backups and disaster recovery plans

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy:

  • Account data: Retained while your account is active and for 30 days after deletion
  • Transaction records: Retained for 7 years for tax and accounting purposes
  • Marketing data: Retained until you unsubscribe or object
  • Usage logs: Retained for 90 days
  • Support communications: Retained for 3 years

9. International Data Transfers

Your information may be transferred to and processed in countries outside your country of residence, including countries outside the European Economic Area that may not have equivalent data protection laws.

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses approved by the European Commission
  • Privacy Shield certification (where applicable)
  • Binding Corporate Rules

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies:

10.1 Essential Cookies

Required for the website to function properly (e.g., session management, security).

10.2 Analytics Cookies

Help us understand how visitors interact with our website (Google Analytics, etc.).

10.3 Marketing Cookies

Used to deliver relevant advertisements and track campaign effectiveness.

10.4 Cookie Management

You can control cookies through your browser settings. Note that disabling certain cookies may affect website functionality.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

12. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the 'Last Updated' date
  • Sending you an email notification (for significant changes)

Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: privacy@salona.me
  • Support: support@salona.me
  • Website: www.salona.me

15. Supervisory Authority

If you are an EU resident and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.

Data Protection Commitment:

Salona is committed to transparency and accountability in our data practices. We regularly review and update our policies and procedures to ensure compliance with evolving privacy regulations and best practices.