← Back to Laima

Laima — Privacy Policy

Last updated: 17 August 2026

This policy explains what personal data Laima handles, why, and what your rights are. It's written to be read, not skimmed past.

1. Who we are

Laima is run by Krista Vitolska, a sole trader registered in Latvia. For data protection questions, email hello@getlaima.com — a human answers.

2. Two kinds of people, two roles

Laima handles personal data at two levels, and our legal role is different for each:

a) Salon owners and beauty professionals — our clients. If you buy Laima, we are the data controller for your data. We decide what we collect about you and why, and this policy is our promise to you directly.

b) Your clients — the people who book through your Laima page. When someone chats with your booking page, their name, contact details, messages and booking details flow through our systems. For that data, you (the salon) are the controller and we are your processor: we handle it only on your behalf, only to run your booking page, and never for our own purposes. We never market to your clients, never sell their data, and never show them anyone else's business.

If you're an end client reading this: your booking relationship is with your salon. For questions about your data, contact them first — and we'll help them help you.

3. What we collect and why

About salon owners (we're the controller)

WhatWhyLegal basis
Name, business name, email, phone, Instagram handleTo build and run your page, and to talk to youContract
Your price list, services, hours, policies, brandingIt's literally what your page is made ofContract
Payment detailsTo charge the setup fee and subscription — handled by Stripe; we never see your card numberContract
Our messages with you (email, WhatsApp, Instagram)Support, edits, and a record of what you asked us to changeContract / legitimate interest
Basic usage stats about your page (bookings made, chats handled)Your weekly summary, and to keep the service workingContract / legitimate interest

We don't buy data about you, and we don't use tracking-heavy analytics (see the Cookie Policy).

About end clients (we're the salon's processor)

Through the booking page we process, on the salon's instructions:

  • name and contact details the client provides to book;
  • the chat conversation with the assistant;
  • booking details (service, date, time, and staff member).

We use this data only to answer, book, confirm, and hand the conversation to the salon when needed — plus the salon's weekly summary. Nothing else. AI conversations are processed to generate replies, not to train AI models (see §5).

4. Who else touches the data (sub-processors)

We're a small service built on serious infrastructure. These providers process data on our behalf:

ProviderWhat they do for LaimaWhere
SupabaseDatabase — bookings, chat records, page configurationEU region hosting
VercelHosts the booking pages and websiteGlobal edge network, US company
AnthropicProvides the AI that powers the assistant (API)US company
StripePayment processing for setup fees and subscriptionsUS company, EU entities
ResendSends transactional emails — booking confirmations and summariesUS company

We have data processing agreements with each of them. We'll update this list if it changes, and salons on active plans get notified of new sub-processors before they're added.

5. The AI part, plainly

The assistant on your booking page is powered by Anthropic's API. When a client chats:

  • the conversation is sent to Anthropic's systems to generate the reply;
  • under Anthropic's commercial API terms, that data is not used to train their AI models;
  • we keep chat transcripts for 3 months — enough for weekly summaries and fixing mistakes — then delete or anonymise them, keeping only the booking records themselves.

6. Where the data lives (EU and transfers)

  • Our primary database is hosted in the EU (Supabase, EU region).
  • Some providers (Vercel, Anthropic, Stripe, Resend) are US companies, so some data is transferred to the United States. These transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses — the mechanisms EU law provides for exactly this.

7. How long we keep things (retention)

DataKept for
Your page, bookings, client recordsWhile you're a client, + 90 days after cancellation (matching the Terms of Service, §12)
Chat transcripts3 months, then deleted or anonymised (see §5)
Invoices and payment recordsAs long as Latvian tax and accounting law requires, even after you cancel
Our email/WhatsApp correspondenceUp to 2 years after your account closes, in case questions come back

Within 30 days of cancelling, you can request a free export of your bookings and client contacts — after the 90 days, the working data is gone.

8. Your rights

If you're in the EU/EEA or UK, you have the right to:

  • see the data we hold about you (access);
  • correct it;
  • delete it (where we're not legally required to keep it — e.g. invoices stay);
  • take it with you (portability — the booking export in §7 is exactly this);
  • object or ask us to restrict processing;
  • withdraw consent where consent is the basis (e.g. any marketing emails).

Email hello@getlaima.com and we'll answer within a month, as the law requires. It's free.

End clients: these rights apply to you too, but your salon is the controller — ask them first. If they send the request to us, we act on it for them.

9. Marketing

We only send marketing (news, offers) to salon owners who've said yes, and every email has an unsubscribe link that works. We never send marketing to end clients. Ever.

If we've messaged you out of the blue: sometimes we find a beauty business through its public profile (for example, Instagram) and send one message introducing Laima. We do this under our legitimate interest in telling businesses about a relevant service. We use only the public business details you've published, we don't add you to any mailing list, and if you say "not interested" — or say nothing — we don't message again. Ask us anytime what we know about you (usually: your public handle and nothing more) and we'll delete it.

10. Security

Data is encrypted in transit and at rest by our infrastructure providers. Access to client data is limited to Kris — there are no other staff. We use strong authentication on every system. No system is unbreakable; if a breach ever affects your data, we'll tell you and the regulator as the GDPR requires.

11. Cookies

The website uses only what it needs to function. Details are in the Cookie Policy.

12. Children

Laima is a B2B service and booking pages are meant for adults booking beauty services. We don't knowingly collect children's data. Salons decide their own age policies for treatments.

13. Complaints

We'd rather fix it than fight it — email us first. You can also complain to the Latvian supervisory authority, the Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv), or, if you're in the UK, to the ICO (ico.org.uk).

14. Changes

If this policy changes in a way that matters, active clients get an email 30 days ahead, same as the Terms.


Questions? hello@getlaima.com — a human answers.