Privacy policy
Last updated: May 25, 2026.
Your privacy matters to us. This Privacy Policy explains what data we collect through the bukiraj.app Service, for which purposes, on which legal basis, with whom we share it, and what your rights are. The policy is aligned with the Personal Data Protection Act of the Republic of Serbia and the EU General Data Protection Regulation (GDPR).
1. Data controller
The controller of personal data is bukiraj.app, operated by TEOS IT, registered at Koste Sokice 35, company number 68222052, tax ID 115256321 (the "Operator", "we").
For data that a Salon enters about its clients within its own backoffice account, the Operator acts as a data processor on behalf of the Salon (the controller). Details are set out in the Data Processing Agreement concluded with each Salon.
For data protection questions: support@bukiraj.app
2. Data we collect
We collect only the data that is necessary to provide the Service:
- Booking data (Clients): first name, last name, email, phone number, optional note, selected service, team member, date and time of the appointment.
- Account data (Salons): contact person details, salon name, address, working hours, team data, prices, gallery content, branding elements.
- Newsletter data: email and optionally first name, consent to receive marketing emails.
- Communications: content of messages you send us (email, contact forms).
- Technical data: IP address, device and browser type, language, usage data.
We do not collect special categories of data (e.g. health data, political or religious beliefs) and we do not request them through the booking form. Please do not enter such data into the "note" field.
3. Purposes of processing
We process data for the following purposes:
- booking, confirming and sending reminders for appointments;
- verifying email addresses (OTP);
- cancelling appointments and related communication;
- providing the backoffice service to salons (calendar, clients, services);
- sending the newsletter and marketing communications (only with your consent);
- billing subscriptions to salons, issuing invoices and keeping accounting records;
- monitoring errors and performance, troubleshooting;
- protection against abuse and fulfillment of legal obligations.
4. Legal bases for processing
We rely on the following legal bases:
- Performance of a contract (Art. 12 PDPA, Art. 6(1)(b) GDPR) — for appointment booking, providing the backoffice service and subscription billing.
- Consent (Art. 15 PDPA, Art. 6(1)(a) GDPR) — for receiving newsletter and marketing communication. Consent can be withdrawn at any time.
- Legitimate interest (Art. 12 PDPA, Art. 6(1)(f) GDPR) — for service security, error monitoring, abuse prevention.
- Legal obligation (Art. 12 PDPA, Art. 6(1)(c) GDPR) — for tax and accounting records.
5. Sharing of data
We do not sell your data. We only share it with carefully selected processors that help us provide the Service:
- The Salon where you booked an appointment — receives the data necessary to perform the appointment.
- Supabase (PostgreSQL database, EU hosting) — data storage.
- Vercel — hosting of the web application.
- Resend (or other email provider) — sending of transactional and marketing emails.
- Sentry — error monitoring and, optionally, user session replay only on errors (anonymized, no personal data).
- Accounting service — for issuing invoices to salons.
With each processor we have a contract in place that obliges confidentiality and appropriate technical and organizational security measures.
In cases provided for by law, we may disclose data to competent authorities (court, police, tax administration).
6. Transfers outside Serbia / EEA
Our primary servers are located in the European Union. When data is processed outside the EU/EEA (e.g. certain US-based providers), the transfer is performed with appropriate safeguards — Standard Contractual Clauses of the European Commission or other mechanisms provided by the GDPR and PDPA.
7. Data retention
We keep data for as long as is necessary for the purposes for which it was collected:
- Appointment data: up to 24 months after the appointment (for history and repeat bookings), after which it is deleted or anonymized.
- Client contact data (email, phone): for as long as the salon is an active user of the service, or until a deletion request is submitted.
- Salon account data: for as long as the account is active, plus 30 days after subscription cancellation (a grace period for reactivation), after which it is deleted.
- Accounting records (invoices): 10 years, in accordance with the Accounting Act.
- Newsletter data: until consent is withdrawn (unsubscribed).
- Technical logs and Sentry data: up to 90 days.
8. Your rights
In accordance with the PDPA and GDPR, you have the following rights:
- right to be informed and to access your data;
- right to rectification of inaccurate or incomplete data;
- right to erasure of data ("right to be forgotten");
- right to restriction of processing;
- right to data portability in a common machine-readable format;
- right to object to processing based on legitimate interest;
- right to withdraw consent at any time (without affecting the lawfulness of processing prior to withdrawal);
- right to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs).
You can submit a request by sending an email to support@bukiraj.app. We respond within 30 days.
9. Data deletion
How to request deletion:
- Clients — send an email to support@bukiraj.app from the email address you used when booking, or contact the salon directly.
- Salons — cancel the subscription and submit a request for account deletion. All salon data, including data about its clients, is deleted within 30 days, except for data that we are required to keep by law (accounting).
10. Cookies and tracking technologies
The Service uses only essential cookies and technical mechanisms:
- language cookie (sr/en);
- theme cookie (light/dark);
- localStorage for temporary booking flow state;
- Sentry session replay — only in production and only on errors, with masking enabled for personal data.
We do not use third-party advertising tracking cookies.
11. Data security
We apply technical and organizational protection measures, including encryption of data in transit (HTTPS/TLS), encryption at rest (database), access control based on the principle of least privilege, regular security reviews, and error monitoring.
Despite these measures, no method of data transmission over the internet is 100% secure. In the event of an incident that could pose a risk to the rights and freedoms of users, we will notify the Commissioner and affected users within the deadlines prescribed by the PDPA/GDPR.
12. Minors
The Service is not intended for persons under 16 years of age. If we become aware that we have unintentionally collected data of a child under 16 without parental/guardian consent, we will delete such data without delay.
13. Changes to the Privacy Policy
We may update this Policy from time to time. Material changes will be published on this page with a new "Last updated" date. For users with an account, we also send an email notification about material changes.
14. Contact
For any questions, requests to exercise your rights, or complaints regarding data processing, contact us at:
- Email: support@bukiraj.app
- Web: https://bukiraj.app
You may also contact the Commissioner for Information of Public Importance and Personal Data Protection — www.poverenik.rs.