1. Who we are

AuraZenix is a product of Indicio IT Solutions B.V., Overwegwachter 4, 3034 KG Rotterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 69195951. AuraZenix is an online platform (web application and mobile app) for salon and clinic management: appointments, client management, invoicing, treatments, packages and loyalty.

For privacy questions or to exercise your rights, contact us at support@aurazenix.nl.

2. Two roles: controller and processor

AuraZenix is used by salons and clinics (our customers). Under the General Data Protection Regulation (GDPR) we therefore act in two different roles:

  • Controller — for the data of salon owners and their staff who hold an AuraZenix account, and for the data required to provide and invoice our service.
  • Processor — for the data of the salon's clients (such as appointments, treatment history and contact details). The salon decides which client data is recorded and is the controller for that data; we process it solely on the salon's instructions.

Are you a client of a salon that uses AuraZenix? Please contact your salon for questions about your data (access, correction or deletion). We support the salon in handling such requests.

3. What data do we process?

From account holders (salon owners and staff)

  • Name, email address and role within the salon;
  • Password (stored only as an encrypted hash) and two-factor verification codes sent by email;
  • Login and security data, such as IP address, login timestamps and device information;
  • When using the mobile app: a push notification token for your device, only if you enable notifications yourself;
  • The salon's business and billing details for the subscription.

On behalf of the salon (as processor)

  • Client profiles: name, contact details, address and any notes the salon records;
  • Appointments, treatment history and treatment records;
  • Photos the salon takes with the client's consent (for example before/after treatment photos);
  • Invoices, payments and refunds;
  • Loyalty and package data;
  • Communication such as appointment confirmations and reminders by email or SMS.

4. Purposes and legal bases

  • Performance of a contract — providing the platform: accounts, agenda, client management, invoicing and the mobile app.
  • Legal obligation — retaining invoices and records under Dutch tax retention rules (7 years).
  • Legitimate interest — securing the platform, such as logging login attempts, blocking suspicious IP addresses and preventing abuse.
  • Consent — push notifications on your phone (opt-in via iOS) and any marketing communication. You can withdraw consent at any time.

5. Who do we share data with?

We never sell personal data. We only share data with service providers that are necessary to run AuraZenix:

  • Hosting provider — our servers and database run in a data centre within the European Union;
  • Payment providers — Mollie and Stripe, for processing payments;
  • Email and SMS providers — for sending login codes, confirmations and reminders;
  • Apple — for delivering push notifications to iOS devices.

We conclude data processing agreements with parties acting as our processors. Some providers (such as Apple and Stripe) may process data outside the European Economic Area; where that happens, appropriate safeguards apply, such as the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework.

6. How long do we keep data?

  • Account data is kept for as long as the account is active. After an account is deleted, personal data is removed or anonymised;
  • Invoices and records are kept for 7 years under Dutch tax law;
  • Security and login logs are kept only for a limited period, unless needed for an incident investigation;
  • Client data we process on behalf of a salon is retained according to that salon's instructions and retention policy.

7. How do we protect data?

  • All connections are encrypted via HTTPS/TLS;
  • Passwords are stored only as hashes and login uses two-factor authentication;
  • Sensitive data is stored encrypted;
  • Data of different salons is strictly separated (tenant isolation);
  • Access within a salon is limited through roles and permissions: staff only see what they need.

8. Your rights

You have the right to access, correct, delete and port your personal data, and the right to object to or restrict processing. Account holders can delete their account and data directly in the app (Settings → Delete account) or send a request to support@aurazenix.nl. We respond within the statutory period of one month.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

9. Cookies

The AuraZenix web application uses only functional cookies required for logging in and keeping the application secure (such as session and security cookies). We do not use tracking or advertising cookies.

10. Changes

We may update this privacy policy, for example when we add new features or when legislation changes. The current version is always available on this page; we will actively inform account holders of significant changes.