KRI

Privacy Policy

Last updated: 15 July 2026

Who we are

KRI is a booking and website platform for beauty businesses — barbershops, nail studios, spas, brow and lash artists, and independent practitioners. This policy explains what personal data we handle, why, and what rights you have.

KRI is operated by Iurii Rogulia, registered in Finland at Vanhanpellonkatu 5, 53850 LAPPEENRANTA, Finland (Business ID 2984587-5). For anything about your data, contact us at mail@kri.rocks.

This policy covers two different situations, and it matters which one applies to you. If you run a salon on KRI, we are the data controller for your account. If you booked an appointment at a salon that uses KRI, the salon is the controller and we handle your booking on its behalf.

The two roles — whose data is whose

KRI wears two hats, and this changes who is responsible for your data.

When you are a salon (our customer), we decide how your account information is used, so we are the controller. This whole policy applies to you.

When you book an appointment with a salon through KRI, the salon — not KRI — decides why it collects your details and how long it keeps them. The salon is the controller; we are only its processor, providing the software. We do not use salon customers' booking details for our own purposes, and we do not sell or share them. For questions about your booking data — how long it is kept, whether the salon contacts you, or deletion of your record — please contact the salon directly. They should have their own privacy information.

What we collect if you run a salon (we are the controller)

  • Account and sign-in: your name and email address. We use passwordless sign-in ("magic links"), so we do not store passwords. We use your email to send you the sign-in link and essential service messages.
  • Salon profile: your business details, services, team members, opening hours, and page content you add — used to build and run your public booking page.
  • Billing: subscription status and payment information. Card payments are handled by our payment provider; we do not store full card numbers. We keep records of your plan, invoices, and country for pricing and legal accounting.
  • Technical data: your session, functional preferences (such as language and country), and server logs (including IP address) generated when you use the service. We use these to keep you signed in, show the right language, keep the service secure, and diagnose problems.

What we collect if you booked an appointment (the salon is the controller)

When you book with a salon through KRI, the salon collects your name and phone number, and may collect your email, the language you booked in, and notes related to your appointment, together with the service, time, and price of your booking. We store this on the salon's behalf so it can manage its bookings.

Some information a salon records — for example notes about treatments — may be more sensitive. The salon is responsible for how it collects and uses that information, and we do not use it for our own purposes.

Legal bases

As controller, we rely on the following legal bases under the GDPR:

  • Performance of a contract — to provide the KRI service to salons who have an account, and to handle billing.
  • Legitimate interests — to keep the service secure, prevent abuse and fraud, keep basic logs, and communicate with salon owners about their account and service-critical changes. We balance these against your rights.
  • Legal obligation — to keep accounting and tax records for the period the law requires.
  • Consent — where we ask for it explicitly, for example if in future we offer optional marketing emails. You can withdraw consent at any time.

We do not send marketing to salon customers on our own behalf, and we do not use a salon customer's phone or email for our marketing simply because they made a booking. Where KRI acts as a processor for salon-customer booking data, the salon is responsible for having a legal basis for that processing.

Sub-processors and third parties

We use a small number of trusted providers to run the service. They process data on our instructions, under contract, only to provide their part of the service:

Our database (PostgreSQL) and cache (Redis) run on our own server, which we manage ourselves using Coolify; they are not operated by a separate third-party database provider. The server is hosted in a European Union data centre.

  • Vultr — the cloud infrastructure provider whose European Union data centre hosts our server.
  • Resend — sending essential emails, currently the sign-in ("magic link") email.
  • Cloudflare — DNS, content delivery, and security for our domains.

We may add or change sub-processors as the service grows (for example, providers for SMS reminders, background jobs, or media storage). When we make a material change we will update this list. A current list is always available on request.

Cookies

We use strictly necessary cookies to run the service (such as keeping you signed in and remembering your language and country), and — only with your consent — analytics and marketing cookies to understand site usage and measure our advertising. You can accept or reject the optional categories at any time.

For the full list of cookies, their purpose and duration, and to change your choices, see our Cookie Policy at /legal/cookies.

How long we keep data

  • Account data — for as long as you have a KRI account, and for a short period after you close it, then we delete or anonymise it. In practice we remove account data within 90 days of account closure.
  • Billing and accounting records — for the period required by law (in Finland this is generally several years for accounting records). We keep accounting vouchers and invoices for 6 years, and financial statements and ledgers for 10 years, from the end of the accounting year, as Finnish law requires.
  • Server logs — for a limited period for security and troubleshooting, then deleted. We normally keep server logs for up to 90 days.
  • Salon-customer booking data — the salon decides the retention period, as the controller. We delete or return this data on the salon's instruction, and when a salon closes its account we delete the associated data after 30 days. Backups are cycled out on a rolling basis.

International transfers

We keep personal data within the European Union / European Economic Area wherever we can. Our own server — including the database and cache that hold your data — is hosted in a European Union data centre.

Some of our sub-processors are established in the United States and may process limited personal data there: Cloudflare (DNS, CDN and security), Resend (email) and Vultr (the infrastructure provider for our EU-based server). For those transfers we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU–U.S. Data Privacy Framework. You can ask us for more detail at mail@kri.rocks.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete your data ("right to be forgotten"), where applicable;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent where we relied on it; and
  • lodge a complaint with a supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto). You may also contact the authority in your own EU country. If you are a salon customer, exercise these rights with the salon you booked with, since it is the controller. If you contact us instead, we will pass your request to the relevant salon and help where we can.

How to exercise your rights

Email us at mail@kri.rocks. We may need to verify your identity before acting, to protect your data. We will respond within one month, as the law requires; if a request is complex we may extend this and will tell you if so. We do not charge for this, unless a request is clearly unfounded or excessive.

Children

KRI is a tool for businesses and is not directed at children. We do not knowingly collect data from children through our own services. Where a salon books appointments involving minors, the salon is responsible as the controller.

Changes to this policy

We may update this policy as the service evolves or the law changes. We will post the new version here with an updated date, and for significant changes we will make a reasonable effort to tell account holders.

Contact

Questions, requests, or complaints about your data:

Iurii Rogulia

Vanhanpellonkatu 5, 53850 LAPPEENRANTA, Finland

mail@kri.rocks