Privacy Policy & Data Protection

OUR PERSONAL DATA STATEMENT, ALLERGY GOVERNANCE & USER RIGHTS

2026.1June 23, 2026

Personal Data Statement

We are committed to creating a secure, transparent, and user-friendly experience for every client and partner salon.

Hairfora collects only personal information strictly necessary to provide our online booking, appointment scheduling, and customer communication services.

When you visit Hairfora, book an appointment, or use our mobile tools, your data is processed in full compliance with Cameroon Law No. 2024/017, the European GDPR, and international data protection laws.

What information do we gather specifically?

We collect the information you provide when creating an account, reserving an appointment, or interacting with a salon:

CategoryInformation CollectedPurposeLegal Basis
Identity & ContactFirst name, last name, phone number, email addressAccount creation & booking confirmationsPerformance of contract
AppointmentsSelected services, dates, assigned stylists, visit historySalon calendar scheduling & receptionPerformance of contract
Health & AllergiesAllergies, scalp sensitivities, ongoing hair treatmentsClient chemical & cosmetic safety at salonExplicit separate consent (Art. 9 GDPR / Law 2024/017)
TransactionsMobile Money transaction references, deposit records, receiptsStatutory invoicing & accounting complianceLegal & tax obligation (10 years)
Technical LogsIP addresses, device telemetry, session tokensPlatform security & anti-abuse protectionLegitimate interest (Security)

How do we protect health & allergy information?

Your declared hair and scalp allergies are treated as sensitive health data under strict confidentiality rules.

Allergy records are NEVER exposed publicly on marketplace profiles. They are visible solely to the stylist executing your service and the salon manager to prevent chemical burn, scalp irritation, or cosmetic injury.

Hairfora refuses automated facial biometrics for staff time-tracking. Check-in verification relies strictly on human review.

What are 'cookies' and why do we use them?

Cookies are small text files stored within your browser session to keep you authenticated, remember your language preferences, and ensure seamless booking navigation.

We do not use intrusive third-party advertising tracking cookies. Analytical telemetry is aggregated anonymously to optimize platform speed and stability.

What third parties do we share information with?

Your booking information is shared exclusively with the specific partner salon where you scheduled your appointment.

Technical hosting (ISO 27001 / SOC 2 certified cloud) and transactional notification channels (SMS / WhatsApp Business API) operate under strict Data Processing Agreements (DPA) and Standard Contractual Clauses (SCC).

We never sell, trade, or rent your personal data to advertising brokers.

How long do we retain your information?

Active user account records are retained throughout your relationship with Hairfora and archived after 3 years of continuous inactivity.

Financial transactions and official receipts are archived for 10 years in compliance with statutory commercial and fiscal regulations (OHADA / Tax Code).

Allergy entries can be deleted immediately at any time upon request from your profile.

Disclosure & Control of Your Information

You have full legal control over your personal data under applicable privacy laws:

  • Right of Access & Portability: Request an export of your complete profile and booking history in a standard electronic format.
  • Right to Rectification: Correct your contact number, email, or profile information instantly.
  • Right to Erasure ('Right to be Forgotten'): Request the permanent deletion of your account and personal identifiers.
  • Consent Revocation: Withdraw your consent for allergy tracking, portfolio photo usage, or messages with immediate effect.

How is your data secured?

Hairfora implements end-to-end TLS 1.3 transport encryption, AES-256 database encryption for sensitive records, role-based access control (RBAC), and 24/7 security monitoring.

In the event of a verified data incident, we commit to notifying competent supervisory authorities and impacted users within 72 hours.

How can you contact our Data Protection Officer?

Our dedicated DPO team is available at dpo@hairfora.com to answer all privacy questions and process data subject requests within 48 business hours.

You also maintain the statutory right to contact your national supervisory authority (APDP in Cameroon, ARTCI in Côte d'Ivoire, CNIL in France).

Updates to this Policy

Our privacy policy is reviewed periodically to reflect legal and technical evolutions. All updates will appear on this page with an updated version number and effective date.

© 2026 Hairfora SAS. Tous droits réservés.

Des questions ? Écrivez à dpo@hairfora.com