Privacy Policy
1. Controller and privacy contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is: Sala Thai Massage & Spa, proprietor Nut Karch, Stievestraße 15, 80638 Munich, Germany. Phone: 089 / 926 585 60. Email: info@sala-thai-massage.com.
Please use the contact details above for privacy enquiries and to exercise your rights. Following an assessment of Article 37(1) GDPR and section 38(1) of the German Federal Data Protection Act (BDSG), there is currently no statutory duty to designate a Data Protection Officer: fewer than 20 persons are regularly and continuously engaged in automated processing of personal data, and the salon’s core activities involve neither large-scale regular and systematic monitoring nor large-scale processing of special-category or criminal-offence data. The documented processing does not require a data protection impact assessment; nor do we process personal data commercially for transmission or anonymised transmission, or for market or opinion research. No DPO has therefore been designated. Privacy responsibility remains with the controller.
2. Principles, recipients and international transfers
We process personal data only for the purposes described below, under the legal basis stated there and only to the extent necessary. Recipients are authorised staff and the processors or independent controllers specifically named below. We do not carry out solely automated decision-making or profiling.
For transfers that we as controller initiate outside the EU or EEA, where no adequacy decision under Article 45 GDPR applies, we use appropriate safeguards under Article 46 GDPR, in particular the EU Standard Contractual Clauses, and assess supplementary measures where required. Participation in the EU-US Data Privacy Framework is relied on only if the specific US recipient is actively certified at the time of transfer. Independently responsible third-party providers explain their own transfer mechanisms in the privacy policies linked below. You may request a copy of the relevant safeguards agreed by us from our privacy contact.
3. Website, hosting, server logs and transport encryption
When the website is requested, the web server processes technically necessary connection data: IP address, date and time, requested URL and HTTP method, response status and volume of data transferred, referrer, and browser/device or user-agent information. The purposes are delivery, stability, error analysis and defence against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are secure, available and technically reliable website operation. Logs are not used for advertising or user profiles and are deleted automatically after 14 days.
The website, CMS, database and self-hosted Redis run on infrastructure supplied by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as processor. Hosting takes place in Germany. Connections to our website are encrypted using TLS.
Application logs additionally contain the time, affected technical function, status or error code, aggregate job counters and, where necessary, an internal record identifier, but no contact-form fields or message text. They are used solely for operation, troubleshooting and security evidence, are also based on Article 6(1)(f) GDPR and are deleted after 14 days like the web-server logs.
4. Contact form and abuse prevention
Name and email address are required fields in the contact form; phone number and message are optional. The form language, handling status, technical delivery metadata and any internal organisational note are also stored. We use the information to handle your enquiry and answer organisational follow-up questions. If an enquiry concerns an appointment or potential contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries it is Article 6(1)(f) GDPR; our legitimate interest is orderly business communication. There is no statutory duty to provide the data. Without a name and email address the form cannot be sent; you may instead contact us by telephone or email.
We do not ask for and do not wish to receive health data or any other special-category data through the contact form. In particular, do not enter diagnoses, symptoms, medication, pregnancy information or other health information in the message field. If such information nevertheless reaches us unsolicited and is identified, we will not use it to respond through this channel and will delete it immediately unless a legal obligation prevents immediate deletion. The optional free-text field is not analysed by an automated health-data classifier.
To prevent spam and abuse, each full IP address is limited to ten contact attempts within 60 minutes. Only a counter and reset time are stored in our self-hosted, non-persistent Redis. The corresponding key is a keyed hash of the IP address and a function identifier computed with a server-side secret; the IP address itself is not stored there and cannot be reconstructed from the key. The key expires automatically after no more than 3,601 seconds. If Redis is temporarily unavailable, process memory enforces the same 60-minute window; the entry disappears when the process ends or the period expires. The IP address is not forwarded to Payload and is not stored with the contact submission. A hidden honeypot field provides additional bot protection. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are security, availability and spam prevention.
Contact submissions are held in the access-controlled CMS and hard-deleted 90 days after receipt, regardless of status, by a deletion task that runs daily at 03:00. Authorised staff may delete them sooner. A notice of a new enquiry is sent over TLS through IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, acting as processor. The notice contains no name, email address, phone number or message text, only a generic alert under the fixed subject “Neue Kontaktanfrage im geschützten CMS” and a technical delivery identifier. Its retention in the mailbox follows the same period as other mailbox correspondence under section 5. Because it carries no form data, deletion of the submission itself is unaffected.
5. Contact by email and telephone
If you contact us directly by email or telephone, we process the information you provide and the connection and metadata generated by that communication channel. Article 6(1)(b) GDPR applies to appointment or contract-related communication; Article 6(1)(f) GDPR applies to other business enquiries, based on our interest in responding. We retain mailbox correspondence until the end of the third calendar year after the last exchange and delete it thereafter. That period follows the ordinary limitation period under sections 195 and 199 BGB: until then, claims may still arise from an appointment or enquiry, or be brought against us, and we need the correspondence to assess them. Longer statutory retention obligations under section 11 are unaffected.
Please do not provide health or treatment data by email or telephone either. We do not document unsolicited health information communicated orally; unsolicited health information received digitally is deleted immediately once identified in accordance with section 4.
Our business mailbox is supplied by IONOS SE as processor. No separate IONOS email archiving is booked for this mailbox, so there is no additional archive copy independent of the mailbox itself. The period above applies equally to the inbox, the sent folder and the trash; deleted messages are purged from the trash on a regular basis. Commercial correspondence and accounting records are subject to the longer statutory periods and are kept separately and with restricted access for that purpose under section 11. For telephone calls, the telecommunications providers involved process the traffic and subscriber data needed to establish the connection under the rules applying to them and on their own responsibility.
6. Online appointment booking with Salonized
We use Salonized for online appointment booking. The current provider is Treatwell Salonized NL B.V. (trading as Salonized), Vijzelstraat 79, 1017 HG Amsterdam, Netherlands. Salonized processes booking data for us under Article 28 GDPR; we remain the controller for customer data in our Salonized account. As part of our regular vendor review, we check the current data processing agreement actually accepted in the salon account, the legal entity identified in it and the current subprocessor list.
Every booking action on this website first opens our own notice. No connection to the Salonized widget is made before you confirm. When loaded, Salonized necessarily receives in particular the IP address, time, requested widget address, referrer, and browser/device data. The booking flow processes location, service, any staff preference, date and time, and first and last name, email address and phone number. Salonized creates a customer profile for a new booking based on the email address and may handle confirmations, reminders, amendments, cancellations and appointment history. We may also enter appointments arranged by telephone or at the salon in the same calendar. Where a sale or receipt is created for an appointment, service, price, payment-status and invoice details are added. We do not keep health or treatment notes in Salonized. Address, date-of-birth and newsletter fields are disabled for online booking. Do not enter health data there either.
Your prior consent under Article 6(1)(a) GDPR governs the initial loading of the third-party widget and, where information is stored on or read from your device, section 25(1) TDDDG applies. Once you start a specific booking, the details you enter and appointment administration are based on Article 6(1)(b) GDPR. Security and abuse prevention and a customer history limited to what is necessary are based on Article 6(1)(f) GDPR; the legitimate interests are secure booking operation and traceable appointment administration. Accounting information subject to statutory retention is processed under Article 6(1)(c) GDPR in conjunction with section 257 HGB and section 147 AO.
Technical data is needed to load the widget. Under the current configuration, first and last name, email and phone number and the selected appointment details are required for an online booking; without them Salonized cannot create or confirm the appointment. For either location, you can book online through this website’s Salonized booking function or by phone: Maxvorstadt at +49 89 958 755 22 and Neuhausen-Nymphenburg at +49 89 926 585 60. Closing the overlay immediately removes the widget and prevents further transfers through our site; it cannot reverse transfers already made. Consent may be withdrawn at any time for the future. Once a booking has been submitted, the statutory data-subject rights apply to contractually necessary processing instead.
For both locations, the "Reserve with Google" feature is additionally connected to the respective Google business profile. Appointments can therefore be booked directly within Google services such as Google Search or Google Maps, without visiting our website. In that case the process begins in Google's environment: you enter your first and last name, email address and phone number as well as the desired service and appointment time with Google, and Google transmits these details to Salonized in our booking system. Our own consent notice does not apply there because the flow does not run through our site. The provider for users in the EEA is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which is an independent controller for its own processing and applies its own privacy policy to it; we remain the controller for the subsequent appointment administration in our account. The legal basis for the booking itself is Article 6(1)(b) GDPR. You can arrange appointments for either location through our website or by telephone instead.
After an appointment you attended, Salonized automatically sends a short request for feedback to your email address on our behalf, currently around one hour after the appointment and at most once within six months. Giving feedback is voluntary and has no bearing on future bookings. The purposes are quality assurance for our service and, where you release it for publication, presenting customer experience. The legal basis for the request itself and for our internal assessment is Article 6(1)(f) GDPR, with our legitimate interest in assessing and improving the quality of our treatments. You may object to this processing at any time under Article 21 GDPR; an informal message to info@sala-thai-massage.com is sufficient, after which you will receive no further feedback requests. We do not send promotional newsletters, and no newsletter field is offered in the booking form.
Feedback released for publication is additionally displayed by Salonized on a publicly accessible page belonging to our booking account. That page shows the star rating, the feedback text, your first name without a surname, an approximate time interval instead of the exact date, and any reply from the salon. The legal basis is Article 6(1)(a) GDPR; the release is given in the feedback flow and may be withdrawn at any time with effect for the future. We withdraw a publication without delay once you notify info@sala-thai-massage.com. That provider page is not embedded in our own website; the reviews shown there come exclusively from the public Google business profile under section 10.
Anonymisation is carried out by overwriting the identifying details, that is name, email address, phone number, postal address and date of birth. Merely archiving or hiding a record is not deletion. Where linked history remains in the interface or complete self-service deletion is unavailable, we instruct Salonized through support under Article 28 GDPR to delete or anonymise it and document the outcome. Longer storage occurs only for specifically required legal claims until the ordinary limitation period expires or for statutory commercial and tax records under section 11. The published Partner DPA requires the processor, at contract end, to document the erasure/destruction or return of existing copies unless a legal obligation or legal claim requires retention. The provider information describes storage in the United Kingdom and EEA and possible transfers including to the United States and Israel; the safeguards in section 2 apply. Current provider and contractual information: Treatwell/Salonized Privacy Policy and Partner DPA.
7. Google Maps
Google Maps is loaded on the contact page only after you actively confirm the notice displayed there. The provider for users in the EEA and independent controller for Google processing is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC and other Google companies may participate in technical delivery. Once loaded, Google processes in particular the IP address, time, referrer, browser/device information, the requested map and your interactions. Google may infer an approximate location from this. Our site does not request precise device geolocation; that browser permission is disabled technically.
The legal basis for loading is your consent under Article 6(1)(a) GDPR and, where device access occurs, section 25(1) TDDDG. The purpose is the interactive directions map you requested. Without consent, a placeholder remains visible; the address and directions remain available without a map. Reloading or leaving the page prevents further transfers but cannot reverse data already sent. Google may process data in third countries; section 2 and the Google Privacy Policy apply.
8. Cookies and local device storage
The public, self-operated part of this website currently sets no first-party cookies. We use no analytics, tracking or advertising cookies or advertising pixels. Third-party content from Salonized or Google can use its own cookies or comparable technologies only after the relevant consent click; sections 6 and 7 apply. Because this content is blocked in advance, a general cookie banner is not required.
If you dismiss an announcement banner, we store in your browser only a technical key, identical for all users, for the current announcement version. It is not transmitted to us or anyone else, remains until the announcement changes or you clear it in the browser, and serves solely to implement your choice. The legal basis for this strictly necessary device access is section 25(2) no. 2 TDDDG; related processing is based on Article 6(1)(f) GDPR and our interest in unobtrusive navigation.
9. Fonts and no first-party audience analytics
Fonts used by the website itself are served locally from our hosting infrastructure. A normal page request therefore creates no connection to Google Fonts or another font provider. We use no first-party audience analytics, Google Analytics, Matomo, social-media plugins or advertising networks. Activated third-party widgets may load further resources for their own presentation; this is described in their respective sections.
10. Locally displayed Google reviews
We display a small selection of reviews published publicly on the Sala Thai Massage & Spa Google Maps business profile, served locally from our server. We process the first name or first name with surname initial, review text, star rating, review date and public source address. Merely displaying a review creates no connection to Google. Only the voluntary link to Google Maps leaves our website.
The source is the publicly accessible Google business profile; the data was not obtained directly from reviewers. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are a factual presentation of authentic customer experience and information about our services. Only already public, shortened names are used; we do not copy profile images or full surnames. You may object on grounds relating to your particular situation.
An individual Article 14 notice would require us to identify or collect contact details that we do not have and deliberately do not obtain for privacy reasons. Following a documented balancing exercise, that additional intrusion is disproportionate for this small, publicly discoverable selection within Article 14(5)(b) GDPR. As appropriate safeguards we provide this public notice, shorten names, check the source and continued publication at least quarterly, and remove a review immediately if deleted at source or following a justified objection. Continued display is reassessed no later than 24 months after inclusion. The external link is governed by the Google Privacy Policy.
11. Binding deletion and retention periods
The following standard periods apply: rate-limit IP key no more than 3,601 seconds; contact form in the CMS 90 days from receipt; email correspondence in the mailbox, including the sent folder and the trash, until the end of the third calendar year after the last exchange; web-server and application logs 14 days; access-restricted operational database, media and configuration backups 30 days; locally displayed reviews no more than 24 months without reassessment.
As exceptions, received and sent commercial correspondence is retained for six years and accounting vouchers for eight years from the end of the relevant calendar year where section 257 HGB or section 147 AO requires this. Records specifically needed to establish, exercise or defend a claim are separately restricted and retained only until the applicable limitation period expires—ordinarily three years from the end of the relevant year under sections 195 and 199 BGB—and are then deleted. These exceptions do not justify extending retention for all messages or appointments.
Backups are restricted to administrative access and are not evaluated for ordinary operation; configuration backups are additionally encrypted. All operational backups are deleted automatically after 30 days. If a backup is exceptionally restored, deletions that became due in the meantime are rerun before the restored system is released. Where possible, statutory retention is met by separating and restricting the required document instead of retaining the entire record.
12. Your rights
Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). You may withdraw consent at any time for the future under Article 7(3); prior processing remains lawful. Portability applies only to automated data processed on the basis of consent or contract.
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms or require the data for legal claims. Send a request to info@sala-thai-massage.com or the postal address in section 1. A lawful identity check may be required.
13. Right to complain
Without prejudice to other remedies, you may lodge a complaint with a data protection supervisory authority. Our competent authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, email: poststelle@lda.bayern.de, www.lda.bayern.de.
14. No automated decisions
We do not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR and do not create user profiles.
15. Minors
Our services are not directed specifically at children. We do not rely on a child’s consent under Article 8 GDPR for ordinary appointment or contact requests. Minors should coordinate bookings and personal messages with their guardians and must not send health data through digital channels.
16. Changes and version
This notice was last updated on 2 August 2026. If purposes, providers, data fields, retention periods or technical processes change materially, this notice will be updated and republished before or when the change takes effect.
Last updated : August 2, 2026