Laima — Privacy Policy
Last updated: 17 August 2026
This policy explains what personal data Laima handles, why, and what your rights are. It's written to be read, not skimmed past.
1. Who we are
Laima is run by Krista Vitolska, a sole trader registered in Latvia. For data protection questions, email hello@getlaima.com — a human answers.
2. Two kinds of people, two roles
Laima handles personal data at two levels, and our legal role is different for each:
a) Salon owners and beauty professionals — our clients. If you buy Laima, we are the data controller for your data. We decide what we collect about you and why, and this policy is our promise to you directly.
b) Your clients — the people who book through your Laima page. When someone chats with your booking page, their name, contact details, messages and booking details flow through our systems. For that data, you (the salon) are the controller and we are your processor: we handle it only on your behalf, only to run your booking page, and never for our own purposes. We never market to your clients, never sell their data, and never show them anyone else's business.
If you're an end client reading this: your booking relationship is with your salon. For questions about your data, contact them first — and we'll help them help you.
3. What we collect and why
About salon owners (we're the controller)
| What | Why | Legal basis |
|---|---|---|
| Name, business name, email, phone, Instagram handle | To build and run your page, and to talk to you | Contract |
| Your price list, services, hours, policies, branding | It's literally what your page is made of | Contract |
| Payment details | To charge the setup fee and subscription — handled by Stripe; we never see your card number | Contract |
| Our messages with you (email, WhatsApp, Instagram) | Support, edits, and a record of what you asked us to change | Contract / legitimate interest |
| Basic usage stats about your page (bookings made, chats handled) | Your weekly summary, and to keep the service working | Contract / legitimate interest |
We don't buy data about you, and we don't use tracking-heavy analytics (see the Cookie Policy).
About end clients (we're the salon's processor)
Through the booking page we process, on the salon's instructions:
- name and contact details the client provides to book;
- the chat conversation with the assistant;
- booking details (service, date, time, and staff member).
We use this data only to answer, book, confirm, and hand the conversation to the salon when needed — plus the salon's weekly summary. Nothing else. AI conversations are processed to generate replies, not to train AI models (see §5).
4. Who else touches the data (sub-processors)
We're a small service built on serious infrastructure. These providers process data on our behalf:
| Provider | What they do for Laima | Where |
|---|---|---|
| Supabase | Database — bookings, chat records, page configuration | EU region hosting |
| Vercel | Hosts the booking pages and website | Global edge network, US company |
| Anthropic | Provides the AI that powers the assistant (API) | US company |
| Stripe | Payment processing for setup fees and subscriptions | US company, EU entities |
| Resend | Sends transactional emails — booking confirmations and summaries | US company |
We have data processing agreements with each of them. We'll update this list if it changes, and salons on active plans get notified of new sub-processors before they're added.
5. The AI part, plainly
The assistant on your booking page is powered by Anthropic's API. When a client chats:
- the conversation is sent to Anthropic's systems to generate the reply;
- under Anthropic's commercial API terms, that data is not used to train their AI models;
- we keep chat transcripts for 3 months — enough for weekly summaries and fixing mistakes — then delete or anonymise them, keeping only the booking records themselves.
6. Where the data lives (EU and transfers)
- Our primary database is hosted in the EU (Supabase, EU region).
- Some providers (Vercel, Anthropic, Stripe, Resend) are US companies, so some data is transferred to the United States. These transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses — the mechanisms EU law provides for exactly this.
7. How long we keep things (retention)
| Data | Kept for |
|---|---|
| Your page, bookings, client records | While you're a client, + 90 days after cancellation (matching the Terms of Service, §12) |
| Chat transcripts | 3 months, then deleted or anonymised (see §5) |
| Invoices and payment records | As long as Latvian tax and accounting law requires, even after you cancel |
| Our email/WhatsApp correspondence | Up to 2 years after your account closes, in case questions come back |
Within 30 days of cancelling, you can request a free export of your bookings and client contacts — after the 90 days, the working data is gone.
8. Your rights
If you're in the EU/EEA or UK, you have the right to:
- see the data we hold about you (access);
- correct it;
- delete it (where we're not legally required to keep it — e.g. invoices stay);
- take it with you (portability — the booking export in §7 is exactly this);
- object or ask us to restrict processing;
- withdraw consent where consent is the basis (e.g. any marketing emails).
Email hello@getlaima.com and we'll answer within a month, as the law requires. It's free.
End clients: these rights apply to you too, but your salon is the controller — ask them first. If they send the request to us, we act on it for them.
9. Marketing
We only send marketing (news, offers) to salon owners who've said yes, and every email has an unsubscribe link that works. We never send marketing to end clients. Ever.
If we've messaged you out of the blue: sometimes we find a beauty business through its public profile (for example, Instagram) and send one message introducing Laima. We do this under our legitimate interest in telling businesses about a relevant service. We use only the public business details you've published, we don't add you to any mailing list, and if you say "not interested" — or say nothing — we don't message again. Ask us anytime what we know about you (usually: your public handle and nothing more) and we'll delete it.
10. Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to client data is limited to Kris — there are no other staff. We use strong authentication on every system. No system is unbreakable; if a breach ever affects your data, we'll tell you and the regulator as the GDPR requires.
11. Cookies
The website uses only what it needs to function. Details are in the Cookie Policy.
12. Children
Laima is a B2B service and booking pages are meant for adults booking beauty services. We don't knowingly collect children's data. Salons decide their own age policies for treatments.
13. Complaints
We'd rather fix it than fight it — email us first. You can also complain to the Latvian supervisory authority, the Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv), or, if you're in the UK, to the ICO (ico.org.uk).
14. Changes
If this policy changes in a way that matters, active clients get an email 30 days ahead, same as the Terms.
Questions? hello@getlaima.com — a human answers.