Privacy policy
Last updated: 8 September 2026
This is a translation, provided for convenience. The legally binding version of this document is the Slovenian one — Politika zasebnosti. If the two differ, the Slovenian text applies.
This policy explains what personal data Dior Nail Studio collects through the dior.si website, why it collects it, and what rights you have in relation to it. It is drawn up in accordance with the General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
Who the controller is
The controller of personal data is Dior Nail Studio, Dunajska c. 13, 1000 Ljubljana. For any privacy question write to us at info@dior.si or call 064 277 047. Full details of the business are in the imprint.
What data we collect
When you book an appointment. Your name and surname, email address, telephone number, and details of the service and time chosen. Without these a booking cannot be made.
When you create an account. The same data as above, plus a password, which is stored encrypted and which we cannot read.
When you pay online. Payment data: the amount, time, status and transaction reference. We neither receive nor store your card details — you enter those directly with Stripe, which is certified to the PCI DSS standard.
When you contact us by email or phone. Whatever you tell us in your message.
Automatically when you visit. Data logged by the web server (IP address, time of visit, page viewed, browser type) and visit data through Google Analytics. Details are in the cookie policy.
Why we process data, and on what basis
Providing the service — booking, confirming and reminding you of an appointment, and running your account. The legal basis is performance of a contract (Article 6(1)(b) GDPR).
Operating and securing the website — preventing abuse, spam sign-ups and attacks. The legal basis is legitimate interest (Article 6(1)(f) GDPR).
Measuring traffic — visit statistics through Google Analytics. The legal basis is your consent, which you may withdraw at any time.
Meeting legal obligations — retention of accounting records where they arise. The legal basis is a legal obligation (Article 6(1)(c) GDPR).
Who we share data with
We do not sell personal data and do not pass it to third parties for their own purposes. Only our contracted processors, who provide technical services to us, have access to it:
- the hosting and server provider on which the website runs;
- the booking system provider (Amelia), which runs on the same server;
- the email provider used to send confirmations and reminders;
- Stripe Payments Europe, Limited (Ireland) for processing online payments by card, digital wallet or Klarna;
- Google Ireland Limited for Google Analytics, and only with your consent.
Stripe Link. When paying online you may choose Link, where Stripe saves your card and email address so you need not enter them again next time — including at other businesses that use Stripe. Using Link is your decision and the relationship is with Stripe directly; we have no access to the stored card details. You can review or delete what is stored at any time at link.com.
We may also disclose data to the competent authorities where the law requires us to.
Transfers outside the EU
Data is normally processed within the European Union. Where a service provider also processes data outside the EU, this is done on the basis of the European Commission’s standard contractual clauses.
Newsletter sign-up
If you sign up for the newsletter we store your email address, the wording of the consentyou agreed to, your IP address and the time of sign-up. We keep the last three because we must be able to demonstrate that consent was given — for no other purpose.
The legal basis is your consent (Article 6(1)(a) GDPR). Signing up is voluntary and is not a condition of booking. You may withdraw consent at any time using the unsubscribe link in every message, or by writing to us at info@dior.si; withdrawal does not affect the lawfulness of processing before it.
We keep sign-up data until you unsubscribe. After that we keep a record that you unsubscribed for as long as is necessary to avoid sending you messages again.
How long we keep data
- Appointment data: for as long as you have an account with us, or at most five years after your last appointment.
- Your account: until you delete it or ask us to delete it.
- Email correspondence: at most two years from the last message.
- Web server logs: at most twelve months.
Your rights
You may at any time request access to your data, its rectification or erasure, restriction of processing, or transfer to another controller, and you may object to processing based on legitimate interest. You may withdraw consent for traffic measurement at any time, without affecting the lawfulness of processing before withdrawal.
Send your request to info@dior.si. We reply within one month at the latest. If you believe we process your data unlawfully, you may complain to the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si.
Security
The website runs exclusively over an encrypted HTTPS connection. Passwords are stored encrypted, access to the booking system is restricted and protected, and the server is protected by a firewall and intrusion detection systems.
Changes
We may update this policy from time to time. The version published on this page, with the last-updated date at the top, is always the one that applies.