PRIVACY POLICY

Last updated: July 10, 2025



English Version - Version Française



This privacy policy describes how WOODY SAEIÉ , located at 8 bis rue Pecquay, 75004 Paris , collects, uses, protects, and shares your personal data in accordance with the General Data Protection Regulation (GDPR) .


1. Data Controller

The data controller is:
WOODY SAEIÉ
Email: [email protected]


2. Data Collected

We only collect data necessary for managing our business and delivering quality services. This includes:

  • Identification data : first name, last name
  • Contact information : email, phone number
  • Browsing data : IP address, browser type, pages visited
  • Booking data : selected services, date and time of appointment
  • Client preferences : visit history, specific requests
  • Hair diagnostics : scalp and hair condition, concerns, chemical or medical treatment history

3. Purpose of Processing

Your data is used for the following purposes:

  • Appointment management (online or by phone)
  • Hair evaluation and personalized advice
  • Client relationship tracking and improvement
  • Sending reminders and confirmations
  • Responding to contact form requests
  • Statistical analysis and service improvement
  • Compliance with legal obligations

4. Legal Basis for Processing

Our processing is based on:

  • Your explicit consent (appointment booking, diagnosis)
  • Performance of a contract (hair or diagnostic services)
  • Compliance with a legal obligation
  • Our legitimate interest (quality control, improving customer experience)

5. Data Retention Period

  • Client data : 3 years after last contact
  • Diagnostic data : 5 years from the last appointment
  • Accounting data : 10 years (legal requirement)

6. Access and Recipients

Access to your data is strictly limited to:

  • The authorized Woody Saeïé team
  • Partner service providers ( Treatwell , hosting services, booking tools) acting under confidentiality agreements

No data is sold or shared with unauthorized third parties.


7. Data Transfer Outside the EU

No data is transferred outside the European Union without appropriate safeguards.


8. Security

We implement strict technical and organizational measures to protect your data (encryption, secure access, internal privacy policy).


9. Your Rights

You may exercise the following rights at any time:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability
  • Withdrawal of consent

To exercise your rights, contact us at: [email protected]
Or by mail at WOODY SAEIÉ – 8 bis rue Pecquay, 75004 Paris

In case of dispute, you may contact the CNIL : www.cnil.fr


10. Use of Data from Facebook, Instagram, or WhatsApp

As part of our presence on Facebook, Instagram, and WhatsApp, certain interactions (notably messages sent to our page, our professional Instagram account, or our WhatsApp Business number) may be processed by a connected application, solely for the following purposes:

  • Managing incoming conversations
  • Automating certain responses (appointment confirmations, FAQs, etc.)
  • Improving responsiveness and customer service

The data collected through these platforms is used only to respond to your messages and requests. It is not sold, used for external marketing, or combined with other data sources.

This data is processed in accordance with Meta’s platform terms and privacy policy. No unauthorized access to your data from Facebook, Instagram, or WhatsApp is permitted. Only strictly necessary data is used to support communication on these platforms.


11. Use of Third-Party Automation Tool

To facilitate message management from Facebook, Instagram, and WhatsApp, we use the tool Make , which acts as a technical processor.

Make is used only to:

  • Connect our business accounts with internal tools (booking, CRM, notifications)
  • Automate simple actions (e.g., sending confirmation messages or forwarding messages to a team member)
  • Process incoming and outgoing messages securely and in a controlled manner

Make does not have access to the full message content, does not store data beyond the technical processing, and complies with current security and privacy standards, including GDPR.