Skip to content

Lysté Studio · Wrocław

Privacy policy

Effective 8 September 2026.

We take care of your personal data and process it under the GDPR and Polish law. This page explains what we do with information you give on lyste.studio, when booking a visit, and when you contact the studio.

If something is missing or you want to use your rights, email lystestudio@gmail.com or call +48 573 667 025.

1. Data controller

The controller is Lysté Studio (lysté STUDIO), ul. Jedności Narodowej 224/8, 50-260 Wrocław, Poland.

Contact: lystestudio@gmail.com, tel. +48 573 667 025. Website: https://lyste.studio

2. What data we collect

Booking data: name, phone number, optional email and comment, selected treatments, date and time, specialist.

Promo form on the site: name (optional) and phone number so we can call you back.

Account (if you sign in): email, optional phone, and data from Google or Facebook (e.g. name and profile photo) provided by that login service.

Technical data: IP address, browser type, language, approximate location from analytics, pages you visit on our site.

We do not ask in forms for special-category data (e.g. health). Details about a treatment or your skin may be given in person at the visit and are used only to provide the service.

3. Purposes and legal bases

Contract / steps before a contract (GDPR art. 6(1)(b)): booking and delivering the visit, confirmations, contact about the appointment.

Legitimate interest (art. 6(1)(f)): handling enquiries and leads, site security, aggregated statistics, establishing or defending claims.

Consent (art. 6(1)(a)): marketing (e.g. a promo reminder if you asked), analytics and ads (Google Analytics, Google Ads, Meta Pixel) when those scripts load.

Legal obligation (art. 6(1)(c)): accounting documents if we issue a receipt or invoice.

You may withdraw consent at any time. That does not affect processing that already happened.

4. Who receives data

Providers we need to run the site and bookings (processors or independent controllers for their own services):

Altegio — online booking (visits, staff, price list).

Supabase — user accounts and related data.

Netlify — website and serverless hosting.

Google (Analytics, Ads, Gmail, Maps after you click the map) and Meta (Pixel, Facebook login) — analytics, ads, email, login.

Telegram — staff alerts about a new enquiry (we do not post your data on a public channel).

Booksy — only if you click through to the Booksy profile; their policy then applies.

We do not sell your data. A public authority may receive data if the law requires it.

5. Cookies and tracking

The site uses what it needs to work (e.g. language, login session).

Google Analytics (G-RJR2X7P7SH) and the Meta Pixel load after a delay or after you interact with the page, so they do not block first paint. They are used for statistics and — for Pixel / Ads — to measure bookings and ads.

The Google Map on the contact section loads only after a click, so map cookies are not set on every visit.

You can limit cookies in the browser (settings / private mode). Blocking analytics does not stop booking, but it can make it harder for us to improve the site.

6. Transfers outside the EEA

Some providers (Google, Meta, Supabase, Netlify) may process data on servers outside the European Economic Area. They use standard contractual clauses or other GDPR tools. Details are in their privacy policies.

7. How long we keep data

Enquiries and leads: until we handle the request and for a reasonable time after (usually up to 12 months), unless you ask us to delete sooner and we have no other duty to keep them.

Bookings: for as long as needed to deliver the visit and meet accounting duties (often up to 5 years for tax records, if any were created).

Account: until you delete the account or ask us to erase data, except what we must keep by law.

Technical logs and analytics: according to the tools’ settings (usually 14–26 months).

8. Your rights

You have the right to access, rectify, erase, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent.

Send requests to lystestudio@gmail.com. We will reply without undue delay, within the GDPR deadline (as a rule one month).

You may lodge a complaint with the Polish DPA (UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl

9. Security

We use HTTPS, limited access to booking / mail / alert panels, and providers with processing agreements or their own GDPR safeguards. No system is 100% secure. If we suspect an incident, we will act as required by law.

10. Minors

The studio and this site are aimed at adults. We do not knowingly collect children’s data. If you are a parent and think a child sent us data, write to us — we will delete it.

11. Changes

The current version is at https://lyste.studio/polityka-prywatnosci. The date at the top is when it takes effect. Material changes will be announced on the site.

This is an informational GDPR template for a small service studio. It is not legal advice.