Journal
Product5 min read

GDPR without the panic: what Bookatu handles for your salon

Clients serve themselves a copy of their data, deletion requests run on rails with a 30-day countdown in your dashboard, and you can export your whole business any day. GDPR when the software does its share.

BTThe Bookatu team

If you run a salon in the EU, and in Germany more than anywhere, GDPR is not an abstract worry. Clients ask about their data. Some ask for a copy of it. Occasionally one asks you to delete it, and that is the moment most booking software leaves you alone with a legal obligation and a search box. This post is the plain-language tour of what Bookatu actually does for you. No badges and no absolutes, just how it works.

The right of access, served instantly

GDPR gives every client the right to a copy of the data you hold about them. In Bookatu they do not have to ask you for it. Signed into their account on your booking page, they tap Download my data and receive one readable file with their profile, appointments, invoices, payments and consents. It arrives instantly. There is no ticket to us and no task for you, and the right that most tools turn into paperwork becomes a button.

01Right of access, self-service: a client downloads everything the salon holds about them as one file, straight from their account.

Deletion requests arrive on rails

The right to erasure is the one owners worry about, so we built it as a lifecycle rather than an inbox. A client requests deletion from their own account and types their name to confirm it. Then they tap a link we email to the address on their file, so the person asking is provably the person who holds the account. After that comes a 48 hour cooling-off window with a cancel button for changed minds. Only then does anything run.

Your dashboard shows every request from the moment it is raised, on the Privacy and security screen. Each one carries its status and a countdown, because the law expects a response within a month and you should not have to remember that yourself. Most requests complete on their own. The ones that reach you are held for a stated reason, such as an upcoming appointment or an unpaid balance, and once that is settled you review and complete them. Before anything is erased you see exactly what will be deleted and what will be kept in anonymized form, and you type the client's name to make it final.

02The deletion queue in your dashboard: status, the honest reason a request is waiting, and the 30-day response countdown.

We only erase what we can prove is theirs

Here is a rule we treat as non-negotiable: Bookatu only erases records it can provably link to the person asking. An appointment tied to their account. An invoice with their client record behind it. What we never do is guess by name. If your books contain a walk-in called Anna M. and we cannot prove she is the Anna M. who asked, that record stays, and the completed request says so plainly instead of hiding it.

That can sound less impressive than a promise to delete everything. It is also the only honest way to do it. Deleting by name-matching means one day erasing the wrong person's history, which is its own data-protection failure. When a request cannot be met in full, the right answer is a truthful report, not a quiet guess.

The same honesty applies to money. Financial records are not deleted, because tax law requires you to keep them, usually for about seven years. Instead they are anonymized: the invoice survives for your accountant, and the person it pointed to does not.

Your own data has an exit door too

GDPR thinking should not stop at your clients. As the owner you can download your entire business from the same Privacy and security screen: profile and settings, services, products, team, clients, appointments, campaigns, posts and forms, in one file. Payment credentials and connected-account keys are never in it. You can run it once per day, and a confirmation email goes out each time, so an export can never happen without your knowledge.

It is your business. A platform that believes that should hand you the whole copy without making you ask a human for permission.

What stays your responsibility

None of this makes GDPR someone else's problem. We build the controls, but you decide what you collect, how long you keep it, and how you answer your clients. Bookatu is not a certification and this post is not legal advice. What the software can do is make the mechanical part run properly, the requests, the deadlines, the deletions themselves and the records of them, without you building a process from scratch. That is the part a booking platform should own, so we do.

Honesty is the feature. A salon that can say exactly what happens to a client's data has an answer most competitors do not.

gdpr salon softwaregdpr germanybooking software euright of accessdata deletion queue
Ready to put this to work?

Bookatu gives you a branded booking page, deposits, memberships, gift cards and reminders, with 0% commission on your bookings.

Start free