This policy explains how we handle personal data across all Daviana products. It applies to the Daviana web platform, the DavianaGo staff app, the GA Lounge client booking app, any other white-label client apps built on Daviana, and the SalonForge marketing website. Product-specific differences are called out inline.
1. Who we are
Daviana is a salon management software platform (“Daviana”, “we”, “us”, “our”) operated by Evera Ltd, a company registered in England and Wales (company number 09649356), with registered office at 154 Arthur Road, London SW19 8AQ, United Kingdom.
We provide salon management software to salon businesses (“our Salon Customers”). Current Salon Customers include GA Salons (London) and other salons across the UK. Any salon business can become a Salon Customer by subscribing at daviana.salonforge.com.
2. Products this policy covers
- Daviana platform (web) — used by salon owners, managers, and staff
- DavianaGo (iOS / Android) — staff and owner mobile app
- GA Lounge (iOS / Android) — appointment booking app for clients of GA Salons
- Other white-label client booking apps built on Daviana, used by clients of specific Salon Customers
- The SalonForge marketing website at salonforge.com
Where a product collects different data, this policy notes it explicitly.
3. Our role under UK GDPR
We act in two capacities depending on the data subject:
- Data controller — for personal data of (a) salon owners, managers, and staff who use Daviana / DavianaGo directly, and (b) prospective customers who contact us through salonforge.com or daviana.salonforge.com.
- Data processor — for personal data of a Salon Customer's clients collected through the Daviana platform or a client-facing app (including GA Lounge and other white-label apps). The Salon Customer is the controller of their client records; we process that data on their instructions under a data processing agreement.
When you use a client-facing app such as GA Lounge, the salon whose app you are using is the controller of your booking, payment, and visit data. We act solely as processor.
4. Information we collect
From salon staff, owners, and managers (we are the controller)
- Identity and contact: name, email, mobile number, job title / role, assigned salon and branch
- Account credentials: email and password (passwords are hashed; we never store plaintext). Optional biometric unlock (Face ID, Touch ID, fingerprint) is handled on-device only — biometric templates never leave your device.
- Staff PIN (hashed) for in-app quick switching between staff
- Usage and audit logs: actions taken in the app, timestamps, salon context
- Device and technical data: IP address, device type, operating system, app version, crash and diagnostic data
- Payment and billing data (for salon subscription): handled by Stripe; we see only the last four digits and card brand
From salon clients, via the Daviana platform or a client-facing app (the Salon Customer is the controller; we process on their behalf)
- Identity and contact: name, email, phone
- Booking data: appointments, services booked, visit history, preferences, no-show/cancellation records
- Consultation notes and treatment plans, including (where the salon collects it) special category data under UK GDPR Article 9 — e.g. skin-type history or medical disclosures for aesthetic clinics. The salon is responsible for obtaining appropriate consent.
- Photographs uploaded by the salon (before / after portfolio, client reference images)
- Payment method data: handled by Stripe; we never see raw card details. Tip amounts and payment metadata are recorded for the salon's accounting.
- Push notification tokens (where the client app supports push reminders)
- Device and technical data as above
From prospective customers contacting us through the marketing site
- Name, email, phone, salon name (where provided), message content, page visited
Device permissions requested by our mobile apps
The following OS permissions are requested only when you use the relevant feature:
- Face ID / Touch ID / fingerprint (DavianaGo) — local biometric unlock; no biometric data transmitted
- Camera (DavianaGo, client apps) — scan barcodes for inventory; capture before / after photos
- Photo library (DavianaGo, client apps) — attach photos to client records
- Push notifications (DavianaGo, client apps) — appointment reminders, confirmations, schedule changes
- Location — not currently used. Will be disclosed here if added.
We do not use the iOS App Tracking Transparency framework to track users across apps or websites owned by other companies.
5. How we use this information
For staff, owner, and prospect data (as controller)
- Create and maintain user accounts and salon subscriptions
- Authenticate users and secure access
- Provide customer support and respond to enquiries
- Send service-related communications (account alerts, billing, security notices)
- Improve platform reliability, performance, and security
- Comply with legal, accounting, and tax obligations
For salon client data (as processor)
- Solely to provide the salon management platform and associated apps to the controlling Salon Customer, under that salon's instructions
- We do not use salon client data for our own marketing, analytics across salons, or any purpose outside the scope of our processing agreement
6. Lawful basis (UK GDPR Article 6)
- Contract — processing necessary to deliver Daviana to Salon Customers and their authorised users
- Legitimate interest — platform security, abuse prevention, product improvement, responding to enquiries. We have carried out balancing tests and these interests do not override your rights.
- Consent — where required (marketing communications to prospective customers, push notifications, non-essential cookies)
- Legal obligation — tax, accounting, and regulatory record-keeping
Where special category data is processed (Article 9), the Salon Customer is responsible for obtaining the data subject's explicit consent and retains the controller relationship for that data.
7. Third-party processors and sub-processors
We use the following sub-processors to deliver Daviana. Each is bound by a data processing agreement and appropriate international transfer safeguards.
| Provider | Purpose | Region |
|---|
| Supabase | Database, authentication, storage | EU (eu-west-2) |
| Vercel (including Vercel KV, operated by Upstash) | Application hosting, edge delivery, short-lived cache and rate limiting | Global (EU primary) |
| Stripe | Payments, Stripe Connect, Stripe Terminal | US, with UK/EU safeguards |
| Twilio | SMS, voice telephony and call recording transit | United States and Ireland |
| Resend | Transactional email | United States |
| Unipile SAS | WhatsApp messaging relay for salon-to-client conversations | France (EU) |
| Meta Platforms Ireland Ltd (WhatsApp) | WhatsApp message delivery | Ireland |
| PostHog (EU Cloud) | Pseudonymous product usage analytics (no names, contact details or notes) | EU (Frankfurt) |
| Sentry | Error and crash monitoring | United States |
| Cloudflare (Turnstile) | Bot protection on public online-booking pages | Global |
| Apple Push Notification service (APNs) | iOS push notifications | Apple-operated, global |
| Firebase Cloud Messaging (FCM) | Android push notifications | Google-operated, United States |
International transfers are covered by the UK International Data Transfer Addendum (IDTA) or Standard Contractual Clauses, as appropriate. An up-to-date sub-processor list is available on request.
8. Data retention
We retain personal data for as long as an account or subscription is active, plus the periods required by law.
- Staff and owner accounts — retained while the account is active. On deletion, personal data is removed within 30 days, except where retention is required by law.
- Salon client records — retained while the controlling Salon Customer maintains an active subscription, plus a 90-day grace period after termination. Afterwards, data is deleted or returned on the salon's request.
- Financial and payment records — retained for six years as required by HMRC.
- Support correspondence and security logs — retained for up to 24 months.
- Call recordings — where a salon enables call recording, recordings are deleted automatically after 90 days by default. Each salon brand can configure a shorter period, with a minimum of 7 days.
9. Your rights (UK GDPR)
You have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure (“right to be forgotten”), subject to legal retention obligations
- Restriction of processing in specific circumstances
- Data portability for data you provided to us
- Object to processing based on legitimate interest, or for direct marketing
- Withdraw consent at any time, where processing is based on consent
For data where Daviana is the controller (your own staff / owner account, prospect enquiries), contact us using section 14 below.
For data where a Salon Customer is the controller (your records at a specific salon that uses Daviana), contact that salon directly. We will assist the salon in responding to your request where the salon instructs us to do so.
You also have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk or 0303 123 1113.
10. Data security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (HTTPS/TLS 1.2+) and at rest
- Role-based access control and Postgres Row-Level Security for tenant isolation
- Multi-factor authentication available for all administrator accounts
- Biometric unlock handled on-device (Face ID / Touch ID / fingerprint); biometric templates never transmitted
- Regular dependency scanning, security testing, and monitoring
- Least-privilege service credentials, rotated on schedule
- Hashed passwords (bcrypt) and hashed staff PINs
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Data breach notification
If a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, we will notify the UK Information Commissioner's Office within 72 hours of becoming aware of it, and notify affected individuals without undue delay where required.
12. Cookies and similar technologies
We use only essential cookies for authentication and session management on our web applications. We do not use advertising cookies or cross-site tracking. Our mobile apps do not use web cookies.
13. Children's privacy
Our products are not intended for use by children under 16. We do not knowingly collect personal data from children. If you become aware that a child has provided personal data through our products, please contact us (section 14) and we will delete it.
Where a Salon Customer stores records for clients under 16 (e.g. children's haircuts), the Salon Customer is responsible for obtaining parental consent in accordance with UK GDPR.
14. Contact us
For privacy questions, data subject requests, or to report a concern:
Evera Ltd (company number 09649356), registered in England and Wales
Email: privacy@daviana.salonforge.com
Postal: 154 Arthur Road, London SW19 8AQ, United Kingdom
We respond to verified data subject requests within one calendar month, as required by UK GDPR.
15. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email to account holders and by updating the “Last updated” date above. Where required, we will seek fresh consent.
© 2026 Evera Ltd. Daviana is a product of Evera Ltd.