1. Data controller
POWERDISE SL · NIF B16529596
Calle Eusebio Estada, 81A, 07004 Palma de Mallorca, Baleares
2. Data we process
- Identification and contact data: name, telephone number and email address.
- Customer and appointment data: services, date, notes, preferences, language and basic history.
- Billing and payment data where applicable.
- Appointment communications by email or WhatsApp and their sent, delivered or read status.
- Technical and security data: IP address, session identifiers, access or security logs, browser and device.
- With consent, pseudonymous advertising identifiers, source campaign and analytics or conversion events. We do not disclose the customer name, telephone number or email address to advertising platforms.
3. Purpose and legal basis
- Manage appointments, provide services and send confirmations or reminders. Basis: contract or pre-contractual steps (Art. 6.1.b GDPR). Required data are necessary to book; without them we cannot manage the appointment
- Customer service and internal customer management. Basis: contract and legitimate interest in assisting clients and organising the customer relationship (Art. 6.1.b and f GDPR)
- Billing, accounting and legal obligations. Basis: legal obligation (Art. 6.1.c GDPR)
- Analytics, advertising measurement and personalisation Basis: consent (Art. 6.1.a GDPR)
- Fraud prevention and system security. Basis: legitimate interest in protecting the service and preventing misuse (Art. 6.1.f GDPR)
4. Recipients
We use hosting, email, WhatsApp, analytics and advertising, advisory and support providers. They act as processors or, depending on the service, as controllers or joint controllers, such as Meta and Google.
Transfers outside the EEA rely, as applicable, on adequacy decisions or standard contractual clauses. You may request a copy of the safeguards. We also disclose data where required by law.
5. Retention periods
- Customers and appointments: during the relationship and afterwards for the legal periods needed to address liabilities. WhatsApp records are retained with the appointment.
- Billing and accounting: for the periods required by applicable commercial and tax law.
- Consent and technical data: until consent is withdrawn; cookies and platforms follow the Cookie Policy and their settings. Direct click identifiers linked to a booking are retained for up to 90 days; afterwards only aggregated campaign data without direct identifiers may be retained. Technical sessions last up to 4 hours, failed login attempts 1 hour and booking anti-abuse checks up to 24 hours.
6. Your rights
You may exercise your rights to access, rectification, erasure, object, restriction and data portability free of charge by contacting Sienna Nails.
- We will request identity documents only if we have reasonable doubts about your identity.
- Indicate the right you wish to exercise and the data concerned.
You may withdraw any consent without affecting prior processing. We do not make decisions with significant effects based solely on automated processing.
7. Minors
Bookings for minors must be made or authorised by their legal representatives where required.
8. Security measures
We apply proportionate measures such as access controls, restricted permissions, session expiry and encrypted communications.
9. Contact for exercising your rights
Sienna Nails
Calle Eusebio Estada, 81A, 07004 Palma de Mallorca, Baleares
Email: info@siennanails.com
10. Right to lodge a complaint
If you believe your rights have not been properly addressed, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.