PRIVACY POLICY

1. Responsible body

Natalia Drews
beautician
Am Mitterfeld 27a
81829 Munich
Germany
Telephone: +49 162 2604856
E-mail: natalia@drews.beauty


2. General information on data processing

The protection of your personal data is very important to us. We process your data exclusively in accordance with the legal requirements of the GDPR and the BDSG (German Federal Data Protection Act). Personal data is any information that can be used to personally identify you.


3. Hosting and server log files (INWX)

Our website will be used at INWX – InterNetworX GmbH & Co. KG hosted.

INWX automatically collects server log files:

• IP address (shortened/anonymized)
• Browser type and version
• Date and time of access
• Visited pages
• Referrer URL
• Operating system

Legal basis: Article 6 paragraph 1 letter f GDPR
(Legitimate interest in security, stability, and error analysis.)


4. Contact form (Elementor Forms)

When you contact us via the contact form, we process:

• Name
• E-mail address
• Phone number (if provided)
• Your message

Purpose: Processing your request
Legal basis: Article 6 paragraph 1 letter b GDPR (pre-contractual measures)

Your data will not be shared without your consent.


5. Online appointment booking via Amelia

We use the booking system Amelia.

Data collected:

• Name
• E-mail address
• Telephone number
• Date and time of the appointment
• Selected service
• Optional: Customer notes

Legal basis: Article 6 paragraph 1 letter b GDPR

5.1 Payment processing (Stripe, PayPal, Klarna)

The following providers can be used for online payments via Amelia:

Stripe
PayPal
Klarna

These payment service providers process, among other things:

• Name
• Billing address
• E-mail address
• Payment information

The processing is carried out exclusively via the respective providers.

Legal basis:
• Article 6 paragraph 1 letter b GDPR (contract)
• Article 6 paragraph 1 letter f GDPR (fraud prevention)


6. Cookies & Consent Manager

We use a cookie consent manager.
Cookies that are not technically necessary are only after your consent set.

These include, for example:

• Statistics cookies
• Marketing cookies
• Google services (maps, fonts)

Legal basis: Article 6 paragraph 1 letter a GDPR

You can withdraw your consent at any time via the cookie banner.


7. Google Maps

Our website uses Google Maps to display locations or as a link.

Google can process the following data:

• IP address
• Device information
• Browser data

Legal basis:
• Article 6 paragraph 1 letter a GDPR (consent) for embedded map
• Article 6 paragraph 1 letter f GDPR for a simple link

Further information:
https://policies.google.com/privacy


8. Google Fonts (loaded online)

We use [this method] to ensure a consistent display of fonts. Google Fonts, which are integrated via Google servers.

The following data can be transmitted:

• IP address
• Browser information

Legal basis: Article 6 paragraph 1 letter a GDPR (consent)

Further information:
https://developers.google.com/fonts/faq


9. Before & After Photos

We publish treatment photos on our website.

9.1 With written consent

Legal basis: Art. 6 para. 1 lit. a GDPR

9.2 Only verbal consent / informal permission

Since verbal consent is legally weaker, we obtain written consent if necessary.

Those affected can at any time:

• Revoke
• Request deletion


10. Social Media (Instagram)

We've linked to our Instagram profile:
https://www.instagram.com/drews.beauty/

Only when you click will personal data be processed. Meta Platforms Ireland Ltd. processed.

No data transfer takes place., before you click the link.

Instagram Privacy Policy:
https://help.instagram.com/519522125107875


11. Rights of data subjects

You have the following rights:

• Right of access (Art. 15 GDPR)
• Rectification (Art. 16 GDPR)
• Erasure (Art. 17 GDPR)
• Restriction (Art. 18 GDPR)
• Data portability (Art. 20 GDPR)
• Right to object (Art. 21 GDPR)
• Withdrawal of consent (Art. 7 para. 3 GDPR)

Contact for inquiries:
natalia@drews.beauty


12. Storage duration

• Contact requests: until completed
• Appointment data: according to statutory retention periods
• Photos: until further notice
• Cookies: depending on the provider


13. Data security

We implement technical and organizational measures to protect your data against loss, misuse or unauthorized access.


14. Changes to this Privacy Policy

We reserve the right to amend this privacy policy in the future to reflect current legal requirements or changes to our services.