Privacy Policy

Website haircutexpress.eu, payment machines and the HAIRCUT EXPRESS Club programme

Version effective from 05.10.2026

This is a translation provided for information purposes. In case of any discrepancy, the Polish version prevails.

1. GENERAL PROVISIONS

1.1. This Privacy Policy sets out the rules for processing personal data collected and used in connection with:

  • a) the use of the website haircutexpress.eu, hereinafter the “Website”;
  • b) the use of Payment Machines, i.e. devices located in salons operating under the HAIRCUT EXPRESS brand, used in particular to select services, register and manage an Account in the Programme and make payments;
  • c) registration and participation in the HAIRCUT EXPRESS Club loyalty programme, hereinafter the “Programme”;
  • d) the handling of contact forms, correspondence, cookies and analytical and marketing tools used on the Website.

1.2. The controller of personal data processed in connection with the operation of the Website and participation in the Programme is RAVIS Sp. z o.o. with its registered office in Warsaw, ul. Sarmacka 16 lok. 138, 02-972 Warszawa, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw, 13th Commercial Division of the National Court Register, under KRS number 0000665548, REGON 366654169, NIP (tax ID) 5472173621, share capital PLN 100,000, hereinafter the “Central Controller”.

1.3. In matters concerning the processing of data by the Central Controller, you can contact us by e-mail at pr@haircutexpress.eu or in writing at the address given in section 1.2.

1.4. The controller of personal data processed in connection with the performance and settlement of a hairdressing service in a specific salon is the entity operating that salon, hereinafter the “Salon Operator”.

1.5. The current list of salons is available at https://haircutexpress.eu/mapa-salonow/. The details of the Operator of a specific Salon are available in that Salon, on the receipt or invoice and in other information provided to the customer in connection with the service.

1.6. The Central Controller and the Salon Operator may process the data of the same person, but for different purposes and on different legal bases: the Central Controller – primarily to run the Website and the Programme, and the Salon Operator – primarily to perform and settle the hairdressing service provided in a specific Salon.

1.7. Data related to the Programme are processed in a central CRM system run by the Central Controller. Salon Operators have access to these data only to the extent necessary to operate the Programme and in this respect act on behalf of the Central Controller.

1.8. Personal data are processed in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter the “GDPR”.

1.9. Providing personal data is voluntary; however, providing a telephone number, accepting the Programme Rules and providing the data necessary to identify the Account are required to participate in the Programme. Providing your month of birth and giving marketing consent are voluntary.

2. SOURCES AND SCOPE OF PROCESSED DATA

2.1. Personal data may be obtained:

  • a) directly from the data subject;
  • b) via a Payment Machine, the Website, contact forms, e-mail, telephone or other communication channels;
  • c) during registration for and use of the Programme;
  • d) from the Salon Operator and the Salon’s sales system – only to the extent necessary to operate the Programme;
  • e) via cookies, similar technologies and technical logs;
  • f) from service providers supporting the Controller, where the transfer of data is lawful and necessary to achieve a specific purpose.

2.2. In connection with participation in the Programme, the Central Controller may process in particular:

  • a) the telephone number used to create and identify the Account;
  • b) the optionally provided month of birth – solely for the purpose of granting the Birthday Bonus;
  • c) information on acceptance of the Rules, including the date and time of acceptance, the version of the Rules, the Salon and device identifier and the method of acceptance;
  • d) information on marketing consents given and withdrawn, including the exact wording of the consent, its version, date, time, place and channel of giving or withdrawing it;
  • e) the history of visits and transactions in Participating Salons to the extent necessary for the Programme, in particular the date, Salon, number and category of Qualifying Haircuts and the information needed to apply the daily limit;
  • f) the history of awarding, deducting, correcting and expiry of CutCoins, including the Welcome Bonus and the Birthday Bonus;
  • g) the current CutCoins balance and the data needed to determine its validity;
  • h) information on the Membership Level: Club Member, Club Gold or Club VIP, and the data used to determine that Level automatically;
  • i) information on Reward thresholds reached, decisions to postpone collection, Rewards issued and CutCoins deducted;
  • j) data contained in complaints, requests and correspondence concerning the Programme;
  • k) logs of operations performed in the CRM and on Payment Machines, identifiers of users, Salons and devices and other technical data necessary for security, access control and investigating irregularities;
  • l) in connection with SMS communication: the recipient’s telephone number, the content of the message, the message identifier, the date and time of sending, the delivery status, the error code and information on withdrawal of consent or objection.

2.3. Where one telephone number is used by a family, the Programme may record the number and category of services assigned to the Participant’s Account. The Programme does not require the first names, surnames or other data identifying family members or other persons for whom a Qualifying Haircut was performed.

2.4. In connection with the use of the Website, the Central Controller may process in particular data provided in a form or correspondence, the IP address, device and browser data, cookie identifiers, information on activity on the Website and data on cookie consents given.

2.5. The Controller does not require special categories of data referred to in Article 9 of the GDPR. A person contacting the Controller should not provide such data unless this is necessary to handle their matter.

3. PURPOSES AND LEGAL BASES OF PROCESSING

3.1. The Central Controller may process personal data for the following purposes:

  • a) to conclude and perform the Programme participation agreement, including registering the Participant, identifying the Account, awarding, deducting, correcting and expiring CutCoins, granting Bonuses, determining the Membership Level, handling thresholds and issuing physical Rewards – on the basis of Article 6(1)(b) GDPR;
  • b) to send technical and organisational messages necessary for registration, securing the Account or performing the participation agreement, including verification codes, confirmations of operations, information on changes requiring action by the Participant and security messages – on the basis of Article 6(1)(b) GDPR;
  • c) to handle enquiries and correspondence concerning the Website or the Programme – on the basis of Article 6(1)(b) GDPR where the enquiry aims at concluding or performing an agreement, or Article 6(1)(f) GDPR in other cases;
  • d) to handle complaints and requests concerning the Programme – on the basis of Article 6(1)(b) and (f) GDPR;
  • e) to ensure the security of the Website, Payment Machines, the CRM and Accounts, prevent abuse, detect errors, keep logs and investigate irregularities – on the basis of Article 6(1)(f) GDPR;
  • f) to carry out statistical analyses, measure the performance of the Programme and improve the quality of services, where possible using aggregated, pseudonymised or anonymised data – on the basis of Article 6(1)(f) GDPR;
  • g) to establish, pursue or defend claims and demonstrate compliance with the law – on the basis of Article 6(1)(f) GDPR;
  • h) to fulfil obligations under the law – on the basis of Article 6(1)(c) GDPR;
  • i) to send commercial and marketing information by SMS, e-mail, telephone or other communication channels – on the basis of voluntary consent, i.e. Article 6(1)(a) GDPR, and the consents required by electronic communications law;
  • j) to carry out analyses and marketing activities using cookies or similar technologies – on the basis of consent, i.e. Article 6(1)(a) GDPR, to the extent consent is required;
  • k) to ensure the technical operation of the Website using strictly necessary cookies – on the basis of Article 6(1)(f) GDPR and the applicable electronic communications law.

3.2. The legitimate interests of the Central Controller include in particular ensuring the security of systems and data, preventing abuse, handling enquiries not directly related to an agreement, analysing the operation of the Programme, improving the quality of service and establishing, pursuing and defending claims.

3.3. Marketing consent is not a condition for using the hairdressing service or participating in the Programme. Not giving marketing consent does not affect the ability to collect CutCoins, obtain a Membership Level or collect a Reward.

3.4. Consent may be withdrawn at any time in the manner indicated in the message received, in a Participating Salon or by contacting the Central Controller. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

3.5. The Salon Operator may process personal data as a separate controller, in particular for the purpose of:

  • a) concluding, performing and settling the hairdressing service agreement – on the basis of Article 6(1)(b) GDPR;
  • b) handling complaints concerning the service – on the basis of Article 6(1)(b) and (f) GDPR;
  • c) fulfilling tax, accounting and other legal obligations – on the basis of Article 6(1)(c) GDPR;
  • d) establishing, pursuing or defending claims – on the basis of Article 6(1)(f) GDPR;
  • e) conducting its own marketing – only on an appropriate legal basis and after obtaining the required consents.

4. THE HAIRCUT EXPRESS CLUB PROGRAMME AND THE ROLE OF SALON OPERATORS

4.1. The Central Controller is the controller of the personal data of Programme participants throughout the HAIRCUT EXPRESS network. The Programme is based on a single Account identified by a telephone number, and CutCoins, Membership Levels and Reward entitlements are honoured in Participating Salons in accordance with the Rules.

4.2. Salon Operators have access to Programme data only to the extent necessary to:

  • a) identify the Account by telephone number;
  • b) check the current balance, Membership Level and available Reward threshold;
  • c) transmit data on Qualifying Haircuts and other events relevant to awarding or correcting CutCoins;
  • d) register the issue of a physical Reward and deduct the corresponding number of CutCoins;
  • e) accept a request or complaint concerning the Programme;
  • f) fulfil obligations related to security and access control to the system.

4.3. With respect to the activities referred to in section 4.2, the Salon Operator processes data on behalf of the Central Controller under a data processing agreement and in accordance with the documented instructions of the Central Controller.

4.4. The Salon Operator may not use data obtained from the central Programme database for its own purposes, in particular for its own marketing, unless it has a separate legal basis for such processing.

4.5. Regardless of the role indicated in section 4.3, the Salon Operator remains a separate controller of data relating to the hairdressing service it provides. Use of a common system does not change the scope of responsibility of each entity.

4.6. Where an Account is used by a family, the telephone number identifies the Participant’s Account. CutCoins may be awarded for actual Qualifying Haircuts of several persons in accordance with the Rules, but the Central Controller does not create separate profiles of those persons unless they have joined the Programme themselves.

4.7. Telephone numbers held in sales systems before a person joins the Programme are not automatically treated as Programme Accounts. An Account is created and CutCoins start to be awarded after acceptance of the Rules. CutCoins are not awarded for visits made before joining the Programme.

5. PROFILING AND AUTOMATED DETERMINATION OF THE LEVEL

5.1. Within the Programme, the Central Controller uses profiling consisting in automated analysis of the Participant’s activity and CutCoins data in order to determine the Membership Level.

5.2. Club Gold status is determined on the basis of the number of CutCoins awarded to the Participant over a rolling period of the last 12 months and is periodically reviewed in accordance with the Rules. Club VIP status is granted once the required balance has been reached before collecting the XL Reward and remains assigned to the active Account in accordance with the Rules.

5.3. The result of profiling may affect the number of CutCoins awarded for an adult haircut and access to Rewards or the Catalogue appropriate for the given Membership Level.

5.4. The profiling described above does not constitute automated decision-making within the meaning of Article 22 GDPR, as it does not produce legal effects concerning the Participant or similarly significantly affect them.

5.5. The Participant may ask the Central Controller to explain how the Level was determined, verify the data or correct the result if they believe that the data or the automated calculation are incorrect.

6. RECIPIENTS OF DATA

6.1. Personal data may be disclosed or entrusted to entities supporting the Central Controller or the Salon Operator, in particular:

  • a) Salon Operators – to the extent necessary to operate the Programme;
  • b) providers of IT systems, CRM, hosting, servers, backups, cloud and maintenance services;
  • c) providers of Payment Machines, software operating Payment Machines and integrations with sales systems;
  • d) providers of SMS communication services, including Twilio Ireland Limited;
  • e) providers of analytical, statistical and marketing tools and cookie consent management systems;
  • f) entities providing legal, audit, accounting, advisory, insurance or debt collection services;
  • g) payment service providers, where necessary in connection with a transaction carried out on the Website or via a Payment Machine;
  • h) competent public authorities, courts or other authorised entities, where the obligation to disclose data arises from the law.

6.2. Entities processing data on behalf of the Controller act under an appropriate agreement, process data only in accordance with its documented instructions and are obliged to apply appropriate safeguards.

6.3. Personal data are not sold or transferred to other entities for their own marketing purposes without an appropriate legal basis.

7. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

7.1. The Central Controller seeks to use providers that process data within the European Economic Area. However, in connection with the use of certain cloud, analytical, marketing, communication or maintenance services, data may be transferred or accessed from a country outside the EEA.

7.2. If data are transferred outside the EEA, this will take place only on the basis of a mechanism provided for in Articles 45–49 GDPR, in particular a European Commission adequacy decision, standard contractual clauses or another legally permissible mechanism, and, where necessary, after applying additional safeguards.

7.3. Information on the providers currently used, the location of processing and the safeguards applied can be obtained by contacting the Central Controller. Detailed information on cookie providers is available in the consent management tool on the Website.

7.4. When Twilio services are used, data may be processed by Twilio Ireland Limited, 70 Sir John Rogerson’s Quay, Dublin 2, D02 R296, Ireland. Depending on the technical configuration, telecommunications route, maintenance access and subcontractors, data may also be processed outside the EEA.

7.5. For transfers related to Twilio services, standard contractual clauses, binding corporate rules or the relevant Data Privacy Framework mechanism may apply, depending on the recipient and the basis of the transfer. The Controller confirms the mechanism appropriate for the actual configuration before sending begins.

8. DATA RETENTION PERIOD

8.1. Personal data are kept no longer than necessary to achieve the purpose for which they were collected, taking into account legal obligations, the need to demonstrate the lawfulness of processing and limitation periods for claims.

8.2. Participant data used for the ongoing operation of the Programme are kept in operational mode for the period of active use of the Programme. The end of ongoing operation is, as a rule, determined by the later of the following dates: the date of the last Visit assigned to the Account or the date of expiry of the last CutCoins.

8.3. After the end of the operational period, data necessary for evidential, complaint and settlement purposes and for establishing, pursuing or defending claims may be kept in archive mode until 31 December of the sixth year following the year in which the later of the events referred to in section 8.2 occurred.

8.4. In archive mode, the scope of data is limited to the information necessary to demonstrate the course of participation, the awarding and deduction of CutCoins, the issue of Rewards, the content and history of consents, complaints, protection against abuse and the defence of claims.

8.5. After the relevant period, data are deleted or anonymised, unless further retention is required by law or necessary in connection with pending proceedings.

8.6. Data concerning marketing consents are used until they are withdrawn, an appropriate objection is lodged, it is established that the data are out of date, or marketing activities end. After consent is withdrawn, the Controller may keep a limited record of the consent given and withdrawn in order to demonstrate the lawfulness of earlier processing and to prevent the data from being used again for the contested purpose.

8.7. Data concerning the performance of the hairdressing service are kept by the Salon Operator for the period necessary to perform and settle the service, handle complaints, fulfil tax and accounting obligations and until the relevant limitation periods for claims expire.

8.8. Data processed in order to reply to an enquiry are kept for the duration of the correspondence and then for the period necessary to demonstrate its course and until the relevant limitation period for claims expires.

8.9. Technical data and system logs are kept for the period resulting from the Controller’s retention and security policy, no longer than necessary to detect irregularities and handle incidents. If a log is related to an incident, complaint or claim, it may be kept until the matter is finally resolved and the relevant periods expire.

8.10. Data related to sending SMS messages are kept for the period necessary to send the message, handle delivery, complaints and security and demonstrate compliance with the law. The detailed retention periods at the SMS provider depend on the actual configuration of the service. Until it is confirmed, the Controller does not declare in this Policy that individual retention, redaction of message content or processing exclusively in the European region are enabled.

8.11. The retention period of data obtained using cookies depends on the type of file, its purpose and the settings indicated in the consent management tool.

8.12. A request to delete data does not result in their deletion to the extent that further processing is necessary to fulfil a legal obligation or to establish, pursue or defend claims.

9. RIGHTS OF DATA SUBJECTS

9.1. The data subject has – on the terms and with the limitations set out in the GDPR – the right to:

  • a) obtain information about the processing of data;
  • b) access the data and obtain a copy;
  • c) rectify the data;
  • d) erase the data;
  • e) restrict processing;
  • f) data portability;
  • g) object to processing based on legitimate interest;
  • h) object at any time to direct marketing;
  • i) withdraw consent at any time;
  • j) lodge a complaint with the President of the Personal Data Protection Office (UODO).

9.2. Requests concerning data processed in connection with the Website or the Programme should be sent to the Central Controller at pr@haircutexpress.eu or to the registered office address given in section 1.2.

9.3. Requests concerning data processed in connection with a service provided in a specific Salon should be sent to the Operator of that Salon. If a person is not sure which entity is the controller of their data, they may ask the Central Controller for help in identifying the appropriate entity.

9.4. The Controller responds to a request without undue delay and in any event within one month of receiving it. In cases provided for in the GDPR, this period may be extended by a further two months, of which the person making the request will be informed.

9.5. If the Controller has reasonable doubts as to the identity of the person making the request, it may ask for additional information necessary to confirm it. The scope of verification should be proportionate to the nature of the request and the risk of unauthorised disclosure of data.

9.6. Closing the Account or terminating the Programme participation agreement may result in the loss of unused CutCoins and entitlements associated with the Account on the terms set out in the Rules. This does not exclude the obligation to retain some data to the extent indicated in chapter 8.

10. COOKIES AND SIMILAR TECHNOLOGIES

10.1. The Website uses cookies and similar technologies in order to:

  • a) ensure its correct and secure operation;
  • b) remember selected settings;
  • c) analyse how the Website is used;
  • d) carry out marketing and remarketing activities and measure the effectiveness of campaigns.

10.2. The Website may use strictly necessary, functional, analytical and marketing cookies. Cookies other than strictly necessary ones are used only after obtaining the user’s consent to the extent required by law.

10.3. The user may withdraw or change the consent given at any time via the privacy settings or the consent management tool available on the Website.

10.4. Merely using the Website without making a choice in the consent management tool is not treated as consent to the use of analytical or marketing cookies.

10.5. Restricting the use of cookies may affect the availability of some functions of the Website.

10.6. Detailed information on the cookies used, providers, purposes, duration and any transfer of data outside the EEA is available in the consent management tool on the Website and in the table below.

Cookies used on the Website

11. DATA SECURITY

11.1. The Central Controller and Salon Operators apply appropriate technical and organisational measures ensuring a level of security appropriate to the risk of data processing.

11.2. These measures may include in particular encryption of transmission, access control systems, individual user permissions, multi-factor authentication for administrative accounts, backups, system updates, logging of operations, procedures for granting and revoking access, confidentiality obligations of authorised persons, periodic security reviews and limiting Salon Operators’ access to the data necessary to operate the Programme.

11.3. In the event of a personal data breach, the competent controller takes the actions required by the GDPR, including – where necessary – notifying the President of the Personal Data Protection Office and the data subjects.

12. CHANGES TO THE PRIVACY POLICY

12.1. The Privacy Policy may be updated in particular in the event of changes in the law, in the rules of operation of the Website or the Programme, the introduction of new functions, tools or providers, changes in the scope, purposes or methods of data processing and changes in the structure of the Salon network.

12.2. The current version of the Privacy Policy is published on the Website together with the date from which it applies.

12.3. Persons may be informed of significant changes affecting the rules of data processing via the Website, a notice in the Salon, a technical message or another appropriate communication channel.

13. ENTRY INTO FORCE

13.1. This Privacy Policy applies from the date of its publication on the Website, i.e. from 5 October 2026.

13.2. From 1 to 31 August 2026 the Programme operated in a pre-launch format: data were processed to register Participants, award CutCoins, grant Bonuses and determine Membership Levels, while the issue of physical Rewards was temporarily blocked. From 1 September 2026, processing also covers the full handling of the issue of Rewards.