Privacy & GDPR

Your clients’ data, handled properly.

Bookatu is built for GDPR. Your clients can see and delete their own data without writing to anyone, you can see every request in your dashboard, and we are plain about the records that have to stay for tax law. No badges, no absolutes, just how it works.

The two rights, built in

Your clients don’t have to ask you for either of them.

Right of access

Self-service — no support tickets
The Privacy section of the client booking portal, with Download my data and Delete my data cards
01A client taps Download my data in their booking profile.
  • A client can download a copy of everything you hold about them.
  • Bookatu builds the file — profile, appointments, invoices, payments, consents.
  • It arrives instantly as a single readable export, no ticket and no waiting on us.

Right to erasure

Self-service — no support tickets
bookatu.com/…/admin/privacy
The deletion request queue in the salon dashboard, with a request awaiting email confirmation
02The dashboard queue tracks every request with a 30-day countdown.
  • A client can ask to be removed, from their own profile or through you.
  • Bookatu shows exactly what goes and what stays before anything runs.
  • You confirm by typing their name, and the finished request keeps its timestamps in your queue.
How deletion actually works

Five steps, including the one nobody likes to mention.

01
Request is raised

From the client’s own booking profile, where they type their name to arm it — or through you, from the client record.

02
Email confirmation

We confirm the request with the address on the account, so nobody is erased by mistake. Unconfirmed requests expire after 48 hours.

03
48-hour cooling-off

A big Cancel button for changed minds. Open appointments, unpaid balances or an active no-show agreement route the request to your queue instead.

04
What we keep, and why

Invoices stay as financial documents with the personal fields stripped. Tax law usually requires them for about seven years.

05
Erasure runs

The account is re-checked, personal data is removed, past appointments become anonymous entries, and the request keeps a timestamped record.

For salon owners

The controls sit where you already work.

Privacy request queue

Erasure requests arrive in one place in the dashboard, with where each one stands and a 30-day response countdown.

Export your whole business

Clients, services, products and appointments in one download. Your data leaves as easily as it arrived.

Deletion protection

Typed confirmations, an email double-confirm, and a preview of what goes before anything runs. Nothing permanent happens by accident.

Encryption at restConnected-account tokens and API keys are stored encrypted.
Role-based permissionsOwners, managers and staff see only what their role allows.
EU data subject rightsAccess and erasure are self-service inside the product.
Transactional email separationBooking and account email is sent separately from marketing.

This page is maintained by Bookatu to answer common privacy questions about the product. It describes features that exist today and is not a certification, an audit result, or legal advice. GDPR compliance is shared: we build the controls, you decide what you collect and how long you keep it.

Questions

The ones owners actually ask.

Try it on your own salon — free

0% commission, forever. Bookings, calendar, payments and client records in one place.

Start free