Few tools have transformed the day-to-day of hair and beauty salons as much as online booking apps. Fresha, Treatwell, Booksy, Planity and similar providers have moved in a few years from being a complement to becoming the operational backbone of many salons: diary, client file, reminders, loyalty, automated marketing, payments, review collection.
That centrality requires a sound understanding of the legal position those platforms occupy in relation to the centre and to the clients, under the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018). Knowing this avoids operational confusion and, above all, enables the centre to respond confidently if a client asks about the destination of their data.
Controller and processor: the split of roles
The GDPR distinguishes two key figures:
- Controller (art. 4(7) GDPR): who determines the purposes and means of the processing. Typically, the centre decides why it processes client data (manage the appointment, build loyalty, send reminders) and chooses which tools to use.
- Processor (art. 4(8) GDPR): who processes data on behalf of the controller, under documented instructions. SaaS booking platforms, in the standard configuration, take this role in relation to the centre.
Art. 28 GDPR regulates the relationship. At its core, the processor may only handle data for the controller's purposes, must apply adequate security measures, cannot subcontract without authorisation, assists the controller with client rights and, on termination, returns the data to the controller or allows it to be exported so the centre can comply with its own retention periods, only proceeding to destruction after that.
The processing agreement (DPA): minimum content
Every controller-processor relationship must be set out in writing (or in an equivalent electronic format). In the beauty sector the leading platforms offer a Data Processing Agreement that can be signed from the centre's admin panel. The minimum content under art. 28(3) GDPR includes:
| Clause | What it must say |
|---|---|
| Subject matter, duration, nature and purpose | Why the platform is contracted and for as long as the main contract runs. |
| Categories of data and data subjects | Identifiers, contact, appointment history, possible health-related data if the centre stores it with explicit consent. |
| Confidentiality obligations | Authorised staff of the processor, formally committed. |
| Security measures (art. 32 GDPR) | Encryption, access control, backups, periodic assessment. |
| Sub-processors | Accessible list and procedure for notifying changes. |
| Assistance with data subject rights | Access, rectification, erasure, portability, objection. |
| Breach notification | Timing and procedure to notify the centre as controller. |
| Return or export of data on termination | The controller must be able to recover its data before any destruction. |
International data transfers
Many leading platforms in the sector have their parent or technological infrastructure outside the EEA, typically in the United States or the United Kingdom. The transfer of the centre's clients' data to those territories is an international transfer and must rely on a Chapter V GDPR tool:
- Adequacy decision (art. 45 GDPR): exists for the United Kingdom. For the US, the current framework is the Data Privacy Framework (DPF): the European Commission adopted a specific adequacy decision for US entities certified to the DPF. The specific provider's certification must be checked against the DPF public list.
- Standard Contractual Clauses (SCCs) (art. 46(2)(c) GDPR): where there is no adequacy decision or the provider is not certified to the DPF, the updated SCCs are the most common tool, accompanied where appropriate by a transfer impact assessment.
- Binding Corporate Rules (BCRs): for multinational groups that have obtained them.
The centre must identify, for each platform it uses, where the data sits and which tool legitimises the transfer. This information is found in the platform's privacy notice, in its DPA or in its public compliance documentation.
The information notice to the client
Art. 13 GDPR requires the centre to inform the client, at first contact, about the processing of their data. When a booking platform is used, the notice must specifically include:
- Identity of the controller (the centre) and contact details.
- A mention that appointment management is carried out through a technology platform (name of the provider) acting as processor.
- Specific purposes (booking management, reminders, loyalty if activated by the centre).
- Legal basis (typically performance of contract for the booking itself, consent for additional commercial uses).
- If there is an international transfer, its existence, the countries or territories and the legitimising tool (adequacy decision, DPF, SCCs).
- Retention periods.
- Client rights and how to exercise them, including whether they can be exercised through the platform itself.
- Right to lodge a complaint with the AEPD.
"Using a booking app does not relieve the centre of any obligation: responsibility for the processing remains its own. What changes is that part of the technical work is done by the platform. The professional centre signs the DPA, verifies international transfers, includes the platform in the RoPA and ensures the client is properly informed. Once that is done, the tool stops being a grey area and becomes what it should be: a well-fitted technology provider."
Mario P. Talamillo · Managing Partner, Certix®
When the platform wants to be more than a processor
Some platforms in the sector offer the end client their own account from which they can book at any participating centre and receive communications from the platform itself with offers, suggestions or recommendations. In that part of the processing the platform acts as an independent controller for the user account, not as the centre's mere processor.
The practical consequence is that two distinct relationships with the client coexist: the centre as controller of the aesthetic service, and the platform as controller of the user account in its marketplace. Each must deliver its own information notice. The centre, in its notice, must be clear about this duality and should not assume what the platform tells the client as information delivered on its behalf.
Sub-processors and supplier chain
Modern platforms rely on cloud infrastructure, payment gateways, email marketing tools and SMS services for reminders. Each of these providers is a sub-processor of the platform in relation to the centre. Art. 28(2) GDPR requires the controller's prior specific or general authorisation for sub-processors, with the right to object to changes. Most standard DPAs contain a general authorisation accompanied by a public list of sub-processors and a commitment to notify additions.
The centre's due diligence is to know where that list lives, review it periodically and, if a new sub-processor with a sensitive profile appears, assess whether to object.
Security breaches and the centre's role
If the platform suffers a breach affecting the centre's client data, the platform must notify the centre as controller. The centre will then assess whether the breach requires it to notify the AEPD within 72 hours (art. 33 GDPR) and, where appropriate, communicate it to affected clients (art. 34 GDPR). The DPA must contain a clear commitment to prompt notification and cooperation. The centre, for its part, must have an internal mini-protocol to manage the notice when it arrives, avoiding improvisation.
Minimum checklist for the centre
- Inventory of SaaS platforms used (booking, payments, email marketing, SMS, cloud).
- DPA signed and archived with each one.
- Identification of international transfers and verification of the legitimising tool (DPF, SCCs, adequacy decision).
- RoPA with an entry for each platform as processor, mentioning international transfers and categories of data.
- Art. 13 GDPR information notice delivered to the client, with specific mention of the platform and the international transfer.
- Operational procedure for client rights (access, rectification, erasure, portability) from the platform's admin panel.
- Breach notification procedure with the platform's technical contact.
- Periodic verification of the sub-processor list.
- Exit plan: if the centre changes platform, database export before deactivation.
Frequently asked questions
Are booking apps processors?
In the standard configuration, yes: they handle the client's data on behalf of the centre. The relationship is formalised in an art. 28 GDPR DPA, which the leading platforms (Fresha, Treatwell, Booksy) make available for signature from their admin panel. The centre remains the controller.
Can the platform use the data for its own purposes?
In that case it ceases to be a mere processor and becomes a joint or independent controller, which changes the regime. When the platform offers the end client their own account, two relationships coexist: the centre as controller of the service and the platform as controller of the account. Both must inform the client.
Do they involve international transfers?
Frequently yes. For US-based providers, the usual basis is certification to the Data Privacy Framework (DPF). Where there is no DPF, Standard Contractual Clauses are required and, where appropriate, a transfer impact assessment. The centre must verify and document each provider's tool.
What documentary obligations does the centre take on?
DPA signed and archived, RoPA entry per platform with mention of international transfers, information notice to the client identifying the platform and the transfer, and an internal procedure for client rights and breach notification.
This content is for general information purposes only and does not constitute specialist legal advice. The application of the rules to each specific case requires individual analysis. Spanish regional sector-specific rules may extend or modify timeframes and requirements.
Want to fit your booking app and SaaS providers properly into your centre's compliance?
At Certix we assign you an expert in compliance for the beauty sector. No commercial intermediaries, no generic templates.
Talk to an expert