Privacy Policy & Data Processing Agreement (DPA)

This document explains which data Keep-Them processes, for which purposes, how long it is retained, and which providers may participate in operating the Service.

1. INTRODUCTION AND SCOPE

1.1. This Privacy Policy and Data Processing Agreement applies to the Keep-Them account, dashboard, billing, support, integrations, and the appointment-reminder processing configured by a Customer.

1.2. Account and subscription data is processed to perform the service agreement. Security data and limited audit records are processed for the legitimate interests of protecting the Service, preventing fraud, and resolving disputes. Required financial records are processed to comply with legal obligations. Consent is used only where applicable law requires it. The Customer remains responsible for a lawful basis to notify its own clients.

2. JURISDICTIONAL STATUS (DATA PROCESSING ROLES)

2.1. Keep-Them as an independent Controller: Keep-Them determines the purposes and means of processing needed for account registration, authentication, account and Service security, subscription and billing administration, support, abuse prevention, and legal compliance. This includes email address, password hash, login and session metadata, language settings, support requests, and subscription and payment identifiers.

2.2. Customer as Controller; Keep-Them as Processor: The Customer controls its client and appointment data in the CRM. When Keep-Them fetches that data from Altegio to prepare and deliver reminders configured by the Customer, Keep-Them processes it on the Customer's instructions.

2.3. Keep-Them does not use Customer client or booking data for advertising, profiling, or resale. The Customer must configure the Service and its connected channels in accordance with applicable law and the rights of its clients.

3. CATEGORIZATION OF PROCESSED DATA FIELDS

3.1. Account and administrative data: email address, password hash, verification, authentication and session state, language, support data, Service settings, integration credentials, and subscription and payment identifiers.

3.2. Appointment payload data: when a notification is due, the Service fetches current client, staff, service, and appointment details from Altegio and uses them for that delivery. The Service does not build a PostgreSQL client directory containing client names and phone numbers. The source payload is discarded after the operation except for the limited fields listed in Section 4.2.

3.3. Connected-channel data: the salon's connected Telegram account phone number, high-value integration tokens, an application-encrypted Telegram session string, and isolated persistent WhatsApp connection state needed to operate the channels connected by the Customer. The connected account phone is salon account data, not a client-directory entry.

4. DATA STORAGE & RETENTION

4.1. Keep-Them applies data minimization. Source payloads are used for the requested notification, while only the operational state needed for delivery safety, opt-out handling, synchronization, and history is kept.

4.2. Storage boundary: PostgreSQL retains HMAC phone hashes for opt-out and channel suppression; numeric provider record and client identifiers; appointment time, state, and revision metadata; delivery history; service titles; and a short appointment link. Service titles and the link are an appointment snapshot, not a client directory. A WhatsApp availability lookup associated with a phone number may also remain in an isolated, disk-backed cache for up to seven days.

4.3. Logging is minimized: HTTP request bodies and frame-local variables are disabled for error monitoring, and recognized sensitive structured fields are redacted. Technical logs may retain limited identifiers, status codes, and timestamps.

4.4. The active retention schedule is:

  • Routine processing audit records: 90 days.
  • Terminal notification history: 365 days.
  • Detailed security, ownership, billing, and lifecycle audit records: 730 days, after which known personal-data fields are redacted while a pseudonymous action footprint may be retained for abuse prevention and dispute resolution.

5. SERVICE PROVIDERS AND RECIPIENTS

5.1. Keep-Them uses the following providers where necessary to operate the Service. A provider marked optional processes data only when the relevant integration is enabled.

Provider / recipientPurposeData processedLocation / transfer
Hetzner Online GmbHServer infrastructure & databasesAll stored Service dataDeployment region selected for the Service
Cloudflare, Inc.Optional CDN, static-site delivery & WAFSite request data, IP addressesGlobal network; provider transfer safeguards apply
ResendTransactional email (verification, password reset, contact form)Recipient email address, message contentPrimarily United States; SCCs where required
SentryOptional application error monitoringDiagnostic and operational metadataConfigured organization region: US or EU
Lemon SqueezyOptional payment provider and Merchant of RecordEmail, internal salon and subscription identifiers, plan and location quantity; payment details are collected by the providerProvider DPA and applicable transfer safeguards

5.2. High-value integration tokens and the Telegram session string are encrypted at the application layer. WhatsApp connection state is kept in isolated, access-restricted infrastructure. Passwords are stored only as modern password hashes. External connections use HTTPS/TLS where supported, while internal services are separated by private network boundaries.

5.3. Customer-selected platforms. Appointment data comes from the Customer's Altegio connection. Reminders are delivered through messaging accounts the Customer connects with its own credentials — Telegram (the salon's own account, over MTProto) and WhatsApp (the salon's own connected number). Personal data is transmitted through these platforms to reach the intended recipients; they operate under their own terms as the source or destination platforms selected by the Customer.

5.4. Optional sign-in. If the Customer chooses Google sign-in and that feature is enabled, Google processes the authentication data necessary to complete the sign-in.

6. CUSTOMER CONTROLS & DATA RIGHTS

6.1. The Customer can pause reminders, disconnect messaging accounts, and remove the Marketplace integration. If the Service cannot confirm a remote Telegram or WhatsApp sign-out, the Customer must finish removing the linked session in that messenger's device settings.

6.2. Salon deletion can be initiated from the account dashboard. Reminders stop immediately and the salon can be restored for 14 days. After that period, primary salon data is removed from the working database. Residual copies may remain in disaster-recovery sets until automatic rotation, for no more than 30 days. Those sets are not used for routine processing. Security, billing, audit, and opt-out records may remain for the periods above or as required by law. Data requests may also be sent to info@keep-them.com.

7. MODIFICATIONS

7.1. Keep-Them may revise this document to reflect changes in the Service, providers, security controls, or applicable law.

7.2. Material changes will be published before they take effect in the manner described in the Terms.