← Back to the site

Privacy policy

Cheveux & Sourires — Paola Negrete · Last updated: 22 September 2026

I come to your home to do your hair. To do that, I need to know who you are and where you are — which means data that belongs to you. This page tells you which data, why, who it passes to, how long I keep it, and what you can require of me. It is written to be read, not skimmed.

1. Who is responsible

I am, and you can reach me:

Paola Negrete Parada, self-employed hairdresser
Contact address: Institut Serenity, Rue de Lausanne 67, 1020 Renens (VD)
Email: contact@cheveuxetsourires.ch
Phone: +41 77 240 43 96

I am the "controller" under the Swiss Federal Act on Data Protection (FADP). Put plainly: I am the one who answers for this, and I am the one you write to.

For the design and technical maintenance of the site and the booking system I use Lavanchy Digital (Renens, VD), acting on my instructions.

The contracts with Resend and Stripe are in my name: they are my direct providers. Hosting with Infomaniak and the Supabase database are contracted by Lavanchy Digital on my behalf: they are its own providers, working within what it does for me. Either way, I am the one answerable to you.

2. What is active today

This site has no form yet. The booking buttons open a WhatsApp conversation or your email program. Until online booking opens, the site itself collects nothing beyond what is described in section 3.1.

When online booking opens, this page will be updated before, not after.

The site sets no cookies, uses no analytics, no advertising pixel, no social media button that would follow you. Only two things are kept by your browser, on your device, and they never reach me:

3. What I collect

3.1 When you simply browse the site

My host automatically records, for technical and security reasons, the IP address, the date and time of the visit, the page requested and the browser type. These logs are not linked to your name, and I do not use them to identify you.

3.2 When you contact me

By WhatsApp, email or phone: your name, your number, your email address and whatever you choose to write to me — often your address, since I travel to you.

3.3 When online booking opens

This section describes the system being prepared. It does not apply yet.

Your address does not travel. It is used to come to you and to calculate the travel supplement, nothing else. It appears neither in the confirmation or reminder emails, nor in the calendar files (.ics) you receive. This is a rule checked automatically every time the site is published, not an intention.

4. Why

I sell nothing to anyone, I run no targeted advertising, and I do not use your data for anything other than what is written here.

5. Who I entrust the data to

Running a site and a calendar takes providers. Here are mine, what they do, and where. I checked each line at the source rather than assuming it.

ProviderWhat it doesWhere data is processed
Infomaniak Network SA
Geneva, Switzerland
Hosts the site and the server logs Switzerland only. No transfer abroad.
Supabase
Supabase Pte. Ltd., Singapore
Appointment database Zurich, Switzerland for the database itself. Technical support may access it from the United States, and technical logs are processed outside Switzerland.
Resend
Plus Five Five, Inc., San Francisco
Sends the confirmation, reminder, change and cancellation emails United States. Email content is kept there for at most 30 days, then deleted.
Stripe
Stripe Payments Europe, Limited, Ireland
Collects the deposit or the payment Ireland, with transfer to Stripe, LLC in the United States.
WhatsApp
WhatsApp Ireland Limited, Dublin
Contact channel, if you use it Ireland, with transfer to WhatsApp LLC in the United States.

About payment

I never see your card number or its security code: they go straight to Stripe and do not pass through me. All that reaches me is your name, your email address, the amount, the date and the last four digits.

About WhatsApp, and I would rather be straight with you

WhatsApp applies its own privacy policy, over which I have no control. The content of our messages is end-to-end encrypted, but WhatsApp sees who writes to whom and when. I remain responsible, however, for what you send me from the moment I receive it.

If you would rather avoid WhatsApp, email me or call me: the result is exactly the same for you.

6. Transfers outside Switzerland

The law requires me to tell you which countries your data goes to, and on what conditions. Here they are.

DestinationWhoOn what basis
Ireland (European Union) Stripe, WhatsApp The Federal Council recognises that European Economic Area countries provide adequate protection (art. 16 para. 1 FADP).
United States Stripe, LLC · WhatsApp LLC These companies are certified under the Swiss-U.S. Data Privacy Framework, which the Federal Council has recognised as providing adequate protection since 15 September 2024.
United States Resend · Supabase support These companies are not certified under that framework. The transfer therefore rests on the European Commission's standard contractual clauses, adapted to Swiss law and signed with each of them (art. 16 para. 2 let. d FADP).
Singapore Supabase Pte. Ltd. The same standard contractual clauses adapted to Swiss law.

7. How long I keep it

Here is how long I keep each thing, and why. Once the period is over, I delete — that is a rule, not an intention.

DataProposed periodWhy
The appointment address 12 months after the appointment It is the most sensitive item and the least useful afterwards. Twelve months is enough to recognise you from one season to the next without keeping it indefinitely.
The appointment (service, date, amount) 10 years These are accounting records: the period is set by law (art. 958f CO).
Your contact details (name, phone, email) 3 years after the last appointment So I do not have to ask you the same thing every time. After that, with no news from you, I delete.
Your free-text notes 12 months They may contain anything, including things you would not want kept.
Server logs Managed by Infomaniak Kept for at least seven days for technical diagnosis.

8. Your rights

At any time you may:

Who to write to: me, directly, at contact@cheveuxetsourires.ch or on +41 77 240 43 96. I answer within thirty days. It is free. I may ask you to prove your identity — that is to protect you, not to buy time.

If my answer does not satisfy you, you may contact the Federal Data Protection and Information Commissioner (FDPIC) in Bern.

9. Security

Exchanges with the site are encrypted (HTTPS). The database is only accessible once authenticated. Access to my dashboard is password-protected. None of these measures is perfect, and I will not tell you otherwise: if an incident affected your data and posed a high risk to you, I would tell you, and I would report the case to the FDPIC as the law requires (art. 24 FADP).

10. Changes

If this policy changes, the date at the top of the page changes too. Significant changes — a new provider, a new category of data — will be announced before they take effect, never after.

← Back to the site · Français · Español