Privacy Policy

Last updated: October 2026

1. Controller

[Full name]
Beauty by Negin
[Street and number, postcode, city, country]
Email: [Email address]
Phone: [Phone number]

This policy explains which personal data we process when you visit this website and use our services. It applies to all language versions and to visitors from Germany and the EU, Turkey, Iran and all other countries. It is based in particular on the EU General Data Protection Regulation (GDPR) and German data protection law; additional information for Turkey and Iran is given in sections 15 and 16.

2. Hosting

The website is operated by Render Services, Inc., 525 Brannan St, San Francisco, California, USA. The server is located in a data centre in Frankfurt am Main (Germany), where the website, the database and uploaded images are stored. A data processing agreement (Art. 28 GDPR) is in place with Render. As Render is a US company, access from the USA (e.g. for maintenance and support) cannot be ruled out. Render is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR); the EU Standard Contractual Clauses (Art. 46 GDPR) apply in addition. The legal basis is our legitimate interest in operating the website securely and reliably (Art. 6(1)(f) GDPR).

3. Server log files

Each visit automatically records technically necessary data: IP address, date and time, page requested, amount of data transferred, status code, browser and operating system. These data are used for security (e.g. preventing attacks and spam) and troubleshooting (Art. 6(1)(f) GDPR). They are not combined with other data and are deleted automatically after 30 days at the latest.

4. Cookies

We only use technically necessary cookies (Art. 6(1)(f) GDPR, § 25(2) TDDDG); no consent is required for them. There are no analytics, marketing or tracking cookies.

  • bbn.af – protects forms against misuse (session)
  • bbn.customer – keeps you logged in to your customer account (only after logging in, at most 180 days or until you log out)
  • bbn.auth and bbn.panel-lang – only for staff in the admin area (login and language)

5. No analytics or tracking, no external content

We do not use analytics or tracking services (e.g. Google Analytics), advertising networks or social media plugins. Fonts, scripts and images are loaded from our own server; visiting the website does not transfer any data to third parties such as Google. Links to Instagram, WhatsApp or map services are plain links: only when you click them do you leave our website, and the privacy policy of that provider applies.

6. Contact form and appointment requests

When you write to us via the contact or booking form, we process the data you provide (name, phone number, email address, requested treatment, preferred date, message) solely to handle your request and arrange an appointment (Art. 6(1)(b) GDPR). Required fields are marked. Please do not send us health information beyond what is needed to plan the appointment; we are happy to discuss your skin in person.

7. Customer account

You can choose to create a customer account. For this we process your email address, your name, optionally your phone number and the time of your last login. Login works without a password using a 6-digit code that we send to you by email; the code is valid for 15 minutes and is stored only in encrypted (hashed) form. In your account you can see your appointment requests and your chat history. The legal basis is the use of the account at your request (Art. 6(1)(b) GDPR). You can delete your account yourself at any time under "My account"; the data are then removed from the account and permanently deleted within 30 days, unless statutory retention obligations apply.

8. Chat

Logged-in customers can write to us directly via the chat. We store the messages with date and time so that the conversation remains visible to both sides (Art. 6(1)(b) GDPR). The chat history is deleted when you delete your account or ask us to.

9. Reviews

If you write a review, we store your name (or the short name you choose), the rating and the text. Reviews are only published after we have checked them; the name given and the text are then visible to all visitors. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time – we will then remove the review.

10. Newsletter

For the newsletter we store your email address, optionally your name, the chosen language and the time of sign-up on the basis of your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time – a short message to us is enough.

11. Sending emails

Emails (login codes, replies, notifications) are sent via the email service we use for our address. If this is Gmail or Google Workspace, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as a processor; transfers to the USA are based on the EU-US Data Privacy Framework and the Standard Contractual Clauses. The legal basis is Art. 6(1)(b) or (f) GDPR.

12. Notifications via Telegram

If enabled, we receive a short notification about new requests (e.g. name and type of request) via the Telegram messenger (Telegram Messenger Inc. / Telegram FZ-LLC, Dubai, UAE) so that we can reply quickly (Art. 6(1)(f) GDPR). Data may be transferred to a country outside the EU for which there is no adequacy decision. We keep the content of these notifications to the minimum necessary.

13. Storage period and data security

We store personal data only for as long as necessary for the respective purpose or as required by statutory retention periods (e.g. under commercial and tax law). Deleted entries remain in an internal trash for 30 days and are then permanently removed. For reliability, daily backups are made and overwritten after 7 days. The connection to the website is encrypted with TLS (https); credentials for email and notification services are stored encrypted, and the admin area is protected by a password and a lock after failed attempts.

14. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the EU member state of your residence or of our establishment. An email to the address above is enough.

15. Information for users in Turkey (KVKK)

For persons in Turkey, Law No. 6698 on the Protection of Personal Data (KVKK) applies in addition. This policy also serves as the information notice under Art. 10 KVKK. Your data are stored on servers in Germany; the transfer abroad takes place within the framework of Art. 9 KVKK (in particular to fulfil the contract or request you asked for). You can exercise your rights under Art. 11 KVKK (including access, rectification, erasure and objection) by emailing us, and you may also contact the Turkish Personal Data Protection Authority (Kişisel Verilerin Korunması Kurumu).

16. Information for users in Iran

Visitors from Iran enjoy the same principles and rights as described above. Your data are stored on servers in Germany and are not passed on to Iranian or other authorities unless we are legally obliged to do so. Please note that Instagram, WhatsApp and Telegram may be restricted in Iran; you can always reach us by phone or email as well.

17. No automated decision-making, changes

There is no automated decision-making, including profiling (Art. 22 GDPR). We update this policy when the website or the law changes; the version published here applies.