Privacy Policy
Version: 2.0 | Effective date: September 5, 2026
This policy explains how personal data is handled in the aprovo.eu platform. It is based on Regulation (EU) 2016/679 („GDPR”) and applies across the European Economic Area.
1. Two roles — please read this first
Everything in this policy depends on which of two very different roles we are playing:
- For our own customers' data — the businesses that subscribe to Aprovo: salons, clinics, practices and trainers — we are the controller. We decide why and how that data is processed, for example to create an account, bill a subscription or provide support.
- For end-client data — the data of the people who visit those businesses and sign consent forms — we are only a processor. The business that entered the data is the controller. We act on its documented instructions under the Data Processing Agreement and for no other purpose.
If you signed a consent form at a salon or clinic: we are not the controller of your data and cannot act on your request directly. Please contact the business where you received the service — they control your data, and the platform gives them the tools to answer you. If you tell us, we will pass your request on and inform you that we have done so.
2. Data we process as controller
This is the data of our subscribing businesses and the people who use the panel on their behalf.
- Registration and business data: first name, last name, business email address, company name, registered address, VAT identification number and other tax identifiers, country of establishment.
- Account and security data: hashed credentials, two-factor authentication settings, session and login records, IP address, audit trail of relevant operations in the Account.
- Billing data: subscription plan, billing period, payment identifiers and invoice records. Full payment card numbers never reach our systems — they are handled by Stripe.
- Support correspondence: the content of messages you send us.
3. Why we process it, and on what legal basis
- Providing the service — giving access to the platform and its features, and supporting you: Article 6(1)(b) GDPR, performance of a contract.
- Billing, accounting and tax — invoicing and statutory record-keeping: Article 6(1)(c) GDPR, legal obligation.
- Security and abuse prevention — monitoring availability, detecting attacks, keeping audit logs: Article 6(1)(f) GDPR, our legitimate interest in a secure and reliable platform.
- Establishing or defending legal claims — Article 6(1)(f) GDPR, legitimate interest.
- Product announcements and marketing — only where you have opted in, or within the limits of an existing customer relationship. Article 6(1)(a) or 6(1)(f) GDPR; you can opt out at any time via the link in any such message.
For end-client data we do not choose the purpose or the legal basis. That is determined by the business operating the account — typically the client's explicit consent for health data under Article 9(2)(a), or the provision of healthcare under Article 9(2)(h) where a regulated professional is involved.
4. Who else is involved (subprocessors)
We use a small number of infrastructure providers. The authoritative, dated list — with processing regions and transfer safeguards — is Annex 2 to the Data Processing Agreement, and it is the version that governs. In summary:
- Render Services, Inc. — application hosting and managed database. Processing region: Frankfurt, Germany.
- Amazon Web Services, Inc. — file storage for signed PDFs and photographic documentation. Processing region: eu-central-1, Frankfurt.
- Stripe, Inc. — subscription payments. Stripe acts as a separate controller for payment data. End-client data is never sent to Stripe.
- Google LLC — the optional AI document-import feature. Processing location is pinned to the EU. Content is processed transiently and is not used to train Google's models.
We give our subscribing businesses at least 14 days' notice before adding or replacing a subprocessor, and they may object — see Section 7 of the DPA.
5. Where data is stored and transfers outside the EEA
- Data is processed within the EEA. Application, database and file storage all run in the Frankfurt region, and the AI feature is pinned to the EU.
- Several of our providers are companies incorporated in the United States even though the processing itself takes place in the EEA. Corporate ownership is not a transfer; what matters is where the data is processed and who can access it.
- Where remote access from outside the EEA cannot be excluded — for example a provider's technical support — the transfer is covered by the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914 under Article 46(2)(c) GDPR, supplemented where necessary by additional safeguards following a transfer impact assessment.
- If we ever need to move processing outside the EEA, we will update the DPA and notify affected customers in advance under the subprocessor change procedure.
6. How long we keep data
- Account and business data: for the duration of the contract, then for as long as needed to defend claims and to meet accounting and tax obligations — generally 5 years from the end of the relevant tax year.
- Security and audit logs: up to 12 months, unless a longer period is required for an ongoing investigation.
- End-client data: we keep it only as long as the controlling business instructs. After the contract ends, the business has 30 days to export, and we erase the data within 90 days — see Section 4 of the DPA. The retention periods that apply to the documents themselves are set by the law of the business's own country and profession, and are its responsibility, not ours.
7. How we protect it
A summary; the full description is in Annex 1 to the DPA.
- Encryption: AES-256 for sensitive data at rest, TLS 1.2 or higher in transit.
- Tenant isolation: every database query is scoped to a single business, so data cannot cross between accounts.
- Document integrity: signed documents carry a cryptographic hash, so any later alteration is detectable.
- Access control: role-based permissions with least privilege, optional two-factor authentication, and PIN protection on shared devices.
- Resilience: automated backups with point-in-time recovery, and continuous availability monitoring.
8. Cookies and similar technologies
- Strictly necessary cookies — session and authentication, security, load balancing and your cookie choice itself. These are required to deliver a service you have requested and are set without consent.
- All other cookies — including any analytics — are set only after you give consent through the banner. Consent is opt-in: nothing non-essential is set before you choose, refusing is as easy as accepting, and we do not treat continued browsing as consent.
- You can change or withdraw your choice at any time through the cookie settings in the banner, and you can clear cookies in your browser.
- National rules implementing the ePrivacy Directive (2002/58/EC) differ between countries. We apply the stricter standard everywhere rather than the local minimum.
9. Your rights
Where we act as controller, you have the right to:
- access your data and obtain a copy (Article 15);
- have inaccurate data rectified (Article 16);
- have data erased, where no overriding obligation requires us to keep it (Article 17);
- restrict processing (Article 18);
- receive your data in a portable format (Article 20);
- object to processing based on legitimate interest (Article 21);
- withdraw consent at any time, without affecting processing carried out before the withdrawal (Article 7(3)).
To exercise any of these, write to contact@aprovo.eu. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
Complaints. You may lodge a complaint with a supervisory authority. Because we are established only in Poland, our lead supervisory authority under the one-stop-shop mechanism (Article 56 GDPR) is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland. This does not restrict your right under Article 77 GDPR to complain instead to the supervisory authority of the EU Member State where you live, work, or where the alleged infringement took place.
10. Automated decision-making
We do not carry out automated decision-making producing legal effects or similarly significantly affecting anyone, within the meaning of Article 22 GDPR, and we do not profile individuals. The optional AI feature described in the Terms of Service only converts an uploaded document into a digital form; its output is reviewed and approved by a human before use.
11. Changes to this policy
We will publish any change here with a new version number and effective date. If a change materially affects our subscribing businesses, we will notify them by email at least 30 days in advance, in line with Section 14 of the Terms of Service.
12. Who we are
The controller is:
AMS SOFTWARE sp. z o.o.
ul. Józefa Wajzera 19/22, 41-808 Zabrze, Poland
Company registration (KRS): 0001242326 | VAT ID (NIP): PL6482836354 | Statistical number (REGON): 544821193
Contact for all privacy matters: contact@aprovo.eu, or by post to the address above. We have not appointed a Data Protection Officer; the address above reaches the people responsible for data protection.