Privacy policy
Effective from 7 October 2026
SpaDesk is a web application for spa, massage and wellness businesses (the “Companies”), available at app.spadesk.pl, together with the website spadesk.pl. This policy explains what personal data we process, why, who we share it with and what rights you have. The Polish version is the binding one.
1. Data controller
Alex Maher Netskyes
ul. Telefoniczna 23D, 91-728 Łódź, Poland
NIP (tax ID) 7272820962
Email: kontakt@spadesk.pl
We are the controller of the data described in section 3. For anything about personal data, write to kontakt@spadesk.pl.
2. Two roles: controller and processor
We process the data of the people who use SpaDesk (Company owners and staff) and the Companies' own data as a controller — section 3. We process the data of a salon's clients and employees, which the Company enters into the app, on behalf of that Company, which is its controller — section 4.
3. Data we process as controller
What data
- Account: name, email address, a hash of your password — we never know the password itself —, your chosen language and theme, and when you were last active.
- Sign-in: sign-in sessions, including the IP address and browser details.
- Company: name, country, currency, time zone, location names and addresses, logo and settings; the roles and access of the people in the Company, and invitations (the invited person's email address).
- Contacting us: your message and the address you write from.
- Technical data: server logs (such as IP address, time and type of request), needed to run and protect the service.
Purposes and legal bases
- creating your account and providing the service — signing in, running the app, account emails (address confirmation, password reset, sign-in links, invitations, notifications) — Art. 6(1)(b) GDPR (contract);
- securing the service, preventing abuse, and establishing, pursuing or defending legal claims — Art. 6(1)(f) GDPR (our legitimate interests);
- answering your messages — Art. 6(1)(f) GDPR;
- meeting legal obligations, such as tax and accounting ones, where they apply — Art. 6(1)(c) GDPR.
Providing data is voluntary, but an account can't be created without an email address and a password.
4. Data Companies entrust to us
A Company using SpaDesk enters data about:
- its clients — such as name, phone, email, date of birth, gender, notes (including preferences and allergies), tags, marketing consent, the history of messages sent, vouchers, and form answers, including health questionnaires and signatures;
- its employees — such as contact details, position, schedule and time off, contracts and documents, salary, and also date of birth, address, national ID (PESEL) or ID card number, bank account number and emergency contact;
- its finances and stock — income, expenses, till days, stock levels.
The Company is the controller of this data. We process it only on the Company's behalf and instructions, to provide the service, and never for our own purposes. If you are a client or an employee of a salon and want to exercise your rights, please contact the salon. If your request reaches us, we will pass it on to the right Company.
5. Who we share data with
We use service providers that process data on our behalf:
- Vercel — app hosting and file storage; the application servers run in Frankfurt (EU);
- Neon — the database, in the Frankfurt region (EU);
- Resend — sending email;
- SMSAPI — sending text messages, when a Company texts its clients;
- OpenAI — drafting ad copy, when a Company uses that feature; we send a description of the advertised service, its price, the Company's name and its town — not client data;
- Meta (Facebook, Instagram) and Google (Google Ads) — when a Company connects its ad account to SpaDesk; we then publish ads and fetch their results on its behalf (see section 10).
Some providers are based outside the European Economic Area, including in the United States. Data is transferred to them on the basis of a European Commission adequacy decision (the EU-U.S. Data Privacy Framework) or standard contractual clauses. Public authorities may also receive data where the law requires it. We don't sell personal data.
6. How long we keep data
- account data — until the account is deleted;
- a Company's data, including the data it entrusts to us — until the Company is deleted: the owner can delete it in Settings → Company → Delete company; after 30 days all of the Company's data and files are permanently deleted, and until then the deletion can be cancelled;
- database backups — for a short time, after which they are automatically replaced;
- server logs — for a short time, under our hosting provider's settings;
- correspondence — as long as it is needed to deal with the matter and any claims.
7. Your rights
You have the right to:
- access your data and get a copy of it,
- have it corrected,
- have it erased,
- restrict its processing,
- data portability,
- object to processing based on our legitimate interests.
Write to kontakt@spadesk.pl — we reply within one month. A Company's owner can also download all of the Company's data themselves: Settings → Company → Export all data. How to delete data is described on the Data deletion page.
You also have the right to complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or to the authority where you live.
8. Cookies and browser storage
- The spadesk.pl website sets no cookies and uses no analytics tools.
- The app at app.spadesk.pl sets only the session cookies needed to keep you signed in, and keeps your language and theme and the last company and location you chose in your browser's storage (localStorage).
- We use no advertising or analytics cookies.
9. Security
Connections to the app are encrypted (HTTPS). Passwords are stored only as hashes. Each Company's data is kept apart in the database itself. Access tokens for ad platforms and employees' national ID and bank account numbers are encrypted in the database. Access depends on a person's role and locations, and changes are recorded in an audit log.
10. Data from Facebook, Instagram and Google
When someone at a Company connects SpaDesk to their Facebook or Google account, with their permission we receive an access token and the information needed to run the Company's ads: the name on the Facebook profile or the Google account's email address, the list of ad accounts, Facebook Pages and Instagram accounts they manage, and campaign data — budgets, ad copy, targeting area and results.
We use it only to create and change the Company's ads and to show their results in SpaDesk. We don't sell it or share it with anyone else. The connection can be removed at any time — see Data deletion.
11. Changes to this policy
We may change this policy, for example when we add a feature or a provider. The current version is always at this address; we will tell you about important changes in the app or by email.