Skip to main content
§ Legal / Privacy

Privacy Policy

Last updated · 2026-08-14

1. Who we are

LeoUp is a booking and operations platform for salons, operated from Vienna, Austria. This policy explains what personal data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR). Our full legal identity and postal address are listed in our Imprint.

Data controller: LeoUp — sole proprietorship (Einzelunternehmen), 1030 Vienna, Erdbergstraße 10/64, Austria. Contact: nguyenthaiduy@leoup.app.

2. What data we collect

  • Account data — name, email address, phone number, business name, and login credentials when a salon creates a LeoUp account.
  • Booking data — appointment details, services selected, customer names and contact details entered by salons or their customers.
  • Messaging data — messages exchanged through connected channels (e.g. WhatsApp Business, Instagram, Facebook Messenger) when a salon has connected these channels to LeoUp.
  • Technical data — IP address, browser type, device information, and usage logs collected automatically to keep the service secure and reliable.

3. Meta platform data

LeoUp integrates with Meta services (Facebook Login, Instagram messaging, and the WhatsApp Business Cloud API) so salons can manage bookings and customer conversations in one place. When you connect a Meta account:

  • We receive only the data you authorize (such as your page name, page ID, and messages sent to your business account).
  • We use this data solely to provide LeoUp's features — appointment reminders, booking confirmations, and customer conversation management.
  • We do not sell Meta platform data, use it for advertising, or share it with third parties beyond the service providers listed below.
  • Our use of data received from Meta APIs complies with the Meta Platform Terms and applicable Developer Policies.

4. Why we process data (legal bases)

  • Contract (Art. 6(1)(b) GDPR) — to provide the booking platform and its features.
  • Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, and service improvement.
  • Consent (Art. 6(1)(a)) — optional marketing communications and connected messaging channels; you can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — accounting and tax retention requirements under Austrian law.

5. Who we share data with

We share data only with processors needed to run the service, under data processing agreements: hosting providers (servers located in the EU), database and infrastructure providers, and Meta Platforms (for connected messaging channels). We never sell personal data.

6. International data transfers

Our core hosting and databases are located within the European Union. However, when a salon connects a Meta service (Facebook Login, Instagram, or WhatsApp Business), the associated data is processed by Meta Platforms Ireland Ltd. and may be transferred to Meta Platforms, Inc. in the United States. Such transfers are safeguarded by the EU–US Data Privacy Framework and, where applicable, the European Commission's Standard Contractual Clauses. If you do not connect a Meta service, no data is transferred to Meta through LeoUp.

7. Cookies and analytics

We use a small number of strictly necessary cookies to keep you signed in and to secure the service. For usage statistics we use privacy-friendly, cookieless analytics that do not track you across websites and do not build advertising profiles. Any non-essential tracking is loaded only after you grant consent through our cookie banner, and you can change your choice at any time.

8. How long we keep data

Account and booking data are kept for as long as the account is active. After account deletion, personal data is erased within 30 days, except where a longer retention period is required by law — for example, invoicing and accounting records, which Austrian tax law (§ 132 BAO) requires us to keep for seven years before they are erased.

9. Your rights

Under the GDPR you have the right to access, rectify, erase, and port your personal data, to restrict or object to processing, and to withdraw consent. To exercise any of these rights, email us at nguyenthaiduy@leoup.app. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).

10. Data deletion

You can request deletion of your data at any time. See our Data Deletion Instructions for the exact steps, including deletion of data connected through Facebook Login or other Meta services.

11. Children

LeoUp is a business tool intended for salon operators and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

12. Security

All traffic is encrypted in transit (TLS), access to production systems is restricted, and credentials are stored using industry-standard hashing. Data is hosted on servers within the European Union.

13. Changes to this policy

We may update this policy as the service evolves. The "last updated" date above reflects the current version. Material changes will be announced inside the app or by email.