Last updated: August 2026
Legal information
Privacy
Clear information about how servIQ processes data in day-to-day salon work.1. Controller
The controller responsible for processing personal data in connection with ServIQ is:
Miran Trocker
ServIQ
Rosengartenstraße 8
39040 Seis am Schlern (BZ)
Italy
Email: hello@serviq.me
2. General information
Protecting personal data is important to us. We process personal data solely in accordance with applicable data protection law, in particular the General Data Protection Regulation (GDPR).
The data processed depends on how ServIQ is used — for example, as a visitor to our website, as a user of a ServIQ account or as a customer of a business that uses ServIQ to manage its appointments.
3. ServIQ as controller and processor
For data processed directly to operate ServIQ — such as user accounts, contract management, billing, support requests or the security of our systems — ServIQ acts as the data controller.
Where salons, practices or other service providers use ServIQ to manage their own customers, appointments and communications, the respective business is generally the controller responsible for that personal data.
In these cases, ServIQ processes the data on behalf of and under the instructions of the respective business.
Questions about an appointment, booking or customer data stored by a particular business should therefore generally be directed to the business with which the appointment was booked.
4. Visiting our website
When you visit our website, technically necessary information may be processed, in particular:
- IP address
- date and time of access
- pages or resources accessed
- browser and device information
- technical log and security data
This processing is carried out to provide the website, ensure its stability and security and identify misuse or attacks.
The legal basis is our legitimate interest in operating our services securely and reliably under Article 6(1)(f) GDPR.
5. Contacting us
If you contact us by email or through a contact form, we process the data you provide, in particular:
- name
- email address
- business or industry, where provided
- content of your enquiry
We process this data to handle your enquiry and communicate with you.
Where an enquiry relates to a potential or existing contract, processing is based in particular on Article 6(1)(b) GDPR. In other cases, it may be based on our legitimate interest in handling enquiries under Article 6(1)(f) GDPR.
6. Registration and ServIQ user accounts
When a ServIQ account is created and used, the following data may be processed in particular:
- name
- email address
- business affiliation
- user role and permissions
- login and security information
- technical usage and log data
This data is required to authenticate users, manage access rights and provide the ServIQ platform.
Processing is carried out in particular to perform the relevant user or contractual relationship under Article 6(1)(b) GDPR and to ensure security under Article 6(1)(f) GDPR.
7. Appointment and customer data belonging to our customers
Businesses using ServIQ can manage personal data relating to their customers through the platform.
This may include in particular:
- first and last name
- email address
- phone number
- appointments and appointment times
- services booked
- assigned staff or resources
- information about the status or alteration of an appointment
- notes or other information stored by the respective business
The respective business is generally responsible for this processing.
ServIQ processes this data as a technical service provider or processor solely to provide the agreed functions.
8. Booking appointments through public ServIQ pages
Where an appointment with a business is requested or booked through a booking page provided by ServIQ, the information required for the booking is sent to that business and processed within ServIQ.
The details required depend on the respective business and its booking settings.
The business with which the booking is made is generally the controller responsible for processing customer data in connection with the appointment.
9. Email and SMS communication
ServIQ enables businesses to send appointment-related messages by email and, where enabled, by SMS.
The following data may be processed for this purpose in particular:
- recipient name
- email address or phone number
- appointment information
- message content and status
We use suitable communication providers for technical delivery.
Where a business sends messages to its customers through ServIQ, processing is generally carried out on behalf of that business.
10. Billing and contract management
For paid ServIQ contracts, data required for contract management and billing may be processed.
This may include in particular:
- business and invoicing data
- selected plan
- billing period
- agreed prices or discounts
- use of communication services relevant to billing
Processing is carried out to perform the contract under Article 6(1)(b) GDPR and to meet statutory retention and documentation obligations under Article 6(1)(c) GDPR.
11. Protection against automated access — Cloudflare Turnstile
We use Cloudflare Turnstile in certain areas of ServIQ, in particular for security-sensitive forms such as sign-in or registration.
Turnstile helps identify automated or abusive access and distinguish genuine users from automated systems.
Technical information about the browser, device, network connection and usage process may be handled in this context.
This use is based on our legitimate interest in protecting our systems, user accounts and forms against misuse and automated attacks under Article 6(1)(f) GDPR.
12. Cookies and technical storage technologies
ServIQ does not currently use marketing or profiling technologies such as advertising pixels or behavioural tracking systems.
However, technically necessary cookies or comparable storage technologies may be used for purposes including:
- sign-in and session management
- security functions
- technical delivery of the application
- storing necessary user states
Prior consent is generally not required for technically necessary cookies and comparable technologies.
If analytics, marketing or profiling technologies are introduced in future, this privacy notice will be updated accordingly and consent will be obtained where required.
13. Technical service providers and recipients
We use carefully selected technical service providers to operate ServIQ.
These include providers in the following areas in particular:
- hosting and IT infrastructure
- database and backend infrastructure
- email communication
- SMS communication
- security and misuse protection
- technical maintenance and system operation
Service providers receive personal data only to the extent required to provide their respective services.
Where service providers process personal data as processors, this is done on the basis of the relevant data protection agreements.
14. Transfers to third countries
Within the technical infrastructure we use, it cannot be ruled out that individual service providers may process data outside the European Economic Area or access data from there.
Where no adequacy decision by the European Commission exists for a third country, such a transfer takes place only with appropriate data protection safeguards, for example on the basis of standard contractual clauses or other mechanisms permitted under the GDPR.
15. Retention period
Personal data is stored only for as long as required for the relevant processing purpose or while statutory retention obligations apply.
In particular:
- Contract and billing data is stored in line with statutory retention obligations.
- User account data is generally stored for the duration of the relevant contract or user relationship.
- Contact enquiries are stored for as long as needed to handle and, where appropriate, follow up the enquiry.
- Security and technical log data is stored only for as long as required for security, fault analysis or misuse prevention.
- Data processed by ServIQ on behalf of a business is handled in accordance with the contractual relationship and the business's instructions and is then deleted or returned unless statutory obligations prevent this.
16. Data security
We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration or disclosure.
These measures are adapted in line with technical developments and the relevant risks.
17. Rights of data subjects
Subject to the statutory requirements, data subjects have the following rights in particular:
- access to the personal data processed
- rectification of inaccurate data
- erasure of personal data
- restriction of processing
- objection to certain processing
- data portability
- withdrawal of consent with effect for the future
To exercise these rights, you can contact us at hello@serviq.me.
For data that a business processes about its own customers through ServIQ, the request should generally be directed to that business.
18. Right to lodge a complaint
Data subjects have the right to lodge a complaint with a competent data protection supervisory authority.
In Italy, this is in particular:
Garante per la protezione dei dati personali
19. Automated decisions
ServIQ does not currently use decisions based solely on automated processing that have legal or similarly significant effects on website visitors or ServIQ users.
20. Changes to this privacy notice
We may update this privacy notice if functions, technical processes or legal requirements change.
The current version published on this website applies.