Client Terms of Use
Last updated: 21 May 2026
1. What This Document Covers
These Client Terms of Use ("Terms") explain how Scisso works and what to expect when a business uses the platform to manage your appointments and communicate with you.
Scisso is a software platform developed by KodeKind S.R.L. (CIF: RO54603957), Timisoara, Romania. It is used by your barbershop, salon, or other service business to coordinate appointments and send you SMS notifications. KodeKind is a technology provider. Your service relationship (the appointment, the haircut, the treatment) is with the business, not with KodeKind.
How these Terms apply to you:
- If you submit an online booking request or complete a self-registration form, you are asked to accept these Terms and the Privacy Policy before submitting. By checking the acceptance box and submitting, you agree to be bound by these Terms.
- If the business added your contact details on your behalf (without your direct interaction with Scisso), these Terms serve as an information notice under GDPR Article 14. They explain how your data is processed through the platform and what your rights are. The business is responsible for informing you that your data is managed through Scisso.
2. Who Controls Your Data
The business (barbershop or salon) that manages your appointments is the Data Controller under the EU General Data Protection Regulation (GDPR). The business decides what data is collected about you and why.
KodeKind acts as a Data Processor, operating the Scisso platform on the business's behalf. KodeKind processes your personal data only on the business's instructions and does not use it for its own purposes.
In limited cases, KodeKind acts as an independent Data Controller: specifically, when you submit a data subject request directly to KodeKind, when maintaining SMS opt-out records to honour your communication preferences as required by law, and when collecting anonymised website usage statistics via Google Analytics (only with your consent, if you click "Accept all" in the cookie banner).
3. What Data Is Collected
Depending on how the business uses Scisso, the following data may be collected:
- Your first name and last name
- Your phone number (used for SMS notifications)
- Your email address (optional, used for record identification)
- Your date of birth (optional, used for birthday greetings if enabled by the business)
- Your language preference (used to format SMS messages in your language)
- Profile notes about your service preferences (entered by the business staff on your client record)
- A free-text note you submit with an online booking request (visible to the business staff)
- Your appointment history (dates, times, and services)
- Internal staff comments on your individual appointments (encrypted at rest). These may contain notes about service details or follow-up actions. They are included in any data export and permanently deleted if your data is erased.
- Your billing address (street, city, county/state, postal code, country), when collected during a booking with online payment (encrypted at rest)
- Your company details (company name, tax ID, trade register number), if you identify as a company during a payment booking (encrypted at rest)
- Payment information: payment status, payment amount, and Stripe reference identifiers on your appointment. Card details (card number, expiry, CVC) are collected directly by Stripe and are never stored on the business's or {{appName}}'s servers.
Phone numbers and email addresses are encrypted at rest using AES-256-GCM. They are never stored in plain text in the database.
4. SMS Notifications
Scisso may send you the following types of SMS on behalf of your business:
- Appointment confirmation when a new appointment is booked for you
- Appointment reminder approximately 24 hours before your appointment
- Rescheduling notice if the time or date of your appointment changes
- Cancellation notice if your appointment is cancelled
- Booking received confirming that your online booking request has been received and is pending review by the business
- Booking rejected notifying you that the business has declined your booking request
- Follow-up message after your appointment (for example, to encourage rebooking)
- Promotional message sent only if you explicitly opted in to promotional messages from the business (for example, during online booking). You can withdraw this consent at any time by opting out of SMS.
- Birthday greeting on your birthday, if enabled by the business and your date of birth is on file
Each of these SMS types can be individually enabled or disabled by the business. SMS messages may be sent from the business's own mobile phone number (via an on-premises Android device) or from a short code number (via a third-party SMS gateway), depending on how the business has configured its delivery settings. In both cases, the message content identifies the business by name.
The first transactional SMS you receive from each sender number will include an opt-out link. Promotional messages (such as follow-up messages or birthday greetings) always include the opt-out link. Once the message has been sent, the message content and your phone number are immediately deleted from the Scisso system.
5. How to Opt Out of SMS
You can stop receiving SMS messages at any time:
- Click the opt-out link included in the SMS message. For transactional messages, this link appears in the first message from each sender number. For follow-up, promotional, and birthday messages, it appears in every message. You will be taken to a confirmation page before your preference is saved. This method works regardless of how the message was delivered.
- Reply STOP to the business phone number. This works when the message was sent from the business's own phone number (Android relay). It does not work for messages sent from a short code number (third-party gateway); for those, use the opt-out link in the message.
- Ask the business directly to disable SMS notifications for your record.
Once you opt out, Scisso will never send you another SMS from that business, even if your phone number is re-entered into the system. Your opt-out preference is stored securely and indefinitely.
Opting out of SMS does not delete your personal data. To request data deletion, see Section 7.
6. Self-Registration and Online Booking
If the business shares a registration link with you, you may complete a form to provide your contact details. When you register:
- The registration link expires after 15 minutes for security
- SMS notifications are opt-in (not enabled by default)
- You must accept the Privacy Policy and these Terms before submitting your data
- You may provide as little or as much information as you choose. Only your first and last name are required.
If the business has enabled online booking, you may visit the booking page to request an appointment. When you submit an online booking:
- You provide your first name, last name, phone number, and optionally your email address (email is required when the selected service has online payment enabled). You may also include an optional note for the business. You must accept the Privacy Policy and these Terms before submitting.
- Submitting a booking request does not create a confirmed appointment or any contractual obligation on the part of Scisso. It is a request that the business may accept or reject. When the selected service requires a deposit or prepayment, the payment is a transaction between you and the business (not Scisso). The business's cancellation and refund policy, displayed before payment, applies if the booking is rejected or cancelled.
- Your booking request is submitted as pending. It is not confirmed until the business explicitly accepts it.
- If the business does not respond within the configured expiry period (typically 8 business hours), your booking request is automatically cancelled.
- The business may reject your booking request at its sole discretion and without providing a reason.
- If your phone number matches an existing client record at the business, your booking will be linked to that record.
- You may separately opt in to receive SMS notifications for appointments and/or promotional messages from the business. These consents are optional and independent of each other. You can withdraw either consent at any time.
- The booking form is protected by Cloudflare Turnstile, a bot verification service. No personal data is shared with Cloudflare beyond a verification token.
- When the business is outside its shop hours, the booking page may offer you the option to save the business contact details as a vCard file (.vcf) containing the business name and phone number. This file is generated in your browser and is not sent to or stored on any server.
- The booking page may display promotional pricing on services (shown as a discounted price alongside the original price). Promotions are defined by the business and may be time-limited. The price shown at the time of booking is the price that applies to your appointment.
- When the selected service requires payment (deposit, prepayment, or card-on-file), additional steps appear in the booking form: billing details (address, optional company information), a Stripe payment form, and the business's cancellation/refund policy. Your billing details are encrypted and saved for future bookings at the same business (pre-filled only after phone verification via a one-time code).
- Card details are collected directly by Stripe's secure payment form embedded in the booking page. They are never transmitted to or stored on {{appName}}'s servers or the business's servers. For card-on-file bookings, you must explicitly consent (via an unticked checkbox) to your card being stored and potentially charged in case of no-show or late cancellation.
- After a successful booking with payment, you receive a secure manage link (via SMS and/or email) that allows you to view your appointment details and, after phone verification, cancel the appointment subject to the business's refund policy. The manage link expires 7 days after the appointment ends.
- Payments are processed on the business's own Stripe account. The business is the merchant of record. {{appName}} (KodeKind) is a technology provider that facilitates the payment process but is not a party to the payment transaction between you and the business. Any payment disputes, refund requests, or chargebacks are between you and the business (and their payment processor, Stripe).
7. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data under the General Data Protection Regulation:
- Access (Art. 15) - request a copy of the personal data held about you
- Rectification (Art. 16) - have inaccurate or incomplete data corrected
- Erasure (Art. 17) - request deletion of your personal data. All personal fields will be removed and your phone number will be added to the opt-out list.
- Restriction (Art. 18) - request temporary restriction of processing
- Data portability (Art. 20) - receive your data in a structured, machine-readable format (JSON)
- Object (Art. 21) - object to processing of your data. For SMS, use the opt-out link, reply STOP, or ask the business to disable notifications.
- Withdraw consent (Art. 7(3)) - if you provided consent during self-registration or online booking, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal
Because the business is the Data Controller, you should direct your request to the business first. If you cannot reach the business or prefer to contact us directly, you can submit a data request or email us at [email protected]. If we receive a request that should be handled by the business, we will forward it promptly.
Requests will be handled within one calendar month of receipt, as required by GDPR Article 12(3). For complex requests or where multiple requests are received, this period may be extended by up to two additional months, with notification of the extension and reasons provided within the initial one-month period.
8. Data Security and Storage
- All data is stored on servers located within the European Union
- Phone numbers and email addresses are encrypted at rest (AES-256-GCM)
- SMS content and recipient phone numbers are deleted immediately after sending
- When sent via the business's own device (Android relay), SMS messages are transmitted over an encrypted connection. No third-party service handles your phone number or message content. When sent via a third-party SMS gateway, your phone number and the message body are transmitted to the gateway over HTTPS for delivery only. No other personal data is shared with the gateway.
- Access to your data within the platform is role-restricted. Only the business staff with a direct working relationship with you can view your full record.
9. Data Retention
- Your personal data is retained for as long as you have an active relationship with the business. The business owner sets the retention period (default: 2 years after your last appointment).
- If your data is erased (at your request or by the business), all personal fields are removed. An anonymised record shell (containing only dates, times, and service types, with no personal identifiers) may be retained for statistical purposes under GDPR Article 89(1). This anonymised data cannot be linked back to you.
- SMS opt-out records are retained indefinitely (as encrypted phone numbers) to ensure your preference is always honoured.
- Billing details (address, company information) are retained on your client record for as long as the record exists. They are permanently deleted upon data erasure. Card details are managed entirely by Stripe.
- Stripe payment references (opaque identifiers) on appointments are retained even after data erasure, as they are needed for refund and dispute workflows. They cannot identify you without access to Stripe's systems.
10. Data Sharing
Your personal data is not sold or shared with third parties for marketing. Data is shared only with the following, under contractual data protection obligations:
- The business and its staff - to manage your appointments and communicate with you
- EU-hosted server infrastructure - for data storage. The hosting provider has no access to application-layer encryption keys.
- Google Calendar (if used by the business) - appointment data is synced two-way. Scisso creates, updates, and deletes events in the employee's connected Google Calendar when appointments are booked, rescheduled, confirmed, or cancelled. Only appointment times, titles, descriptions, and your email address (if provided) are exchanged.
- Cloudflare, Inc. (if you use online booking) - a verification token is exchanged to confirm you are a real visitor. No personal data is shared with Cloudflare.
- SMSAdvert (if used by the business for SMS delivery) - a Romania-based third-party SMS gateway. When the business configures this provider, your phone number and the SMS message body are shared with SMSAdvert for the sole purpose of delivering the message. No other personal data (your name, email, appointment details, or internal identifiers) is shared. Messages sent via this provider come from a short code number rather than the business's phone number.
- Google Analytics (Google LLC) - if you consent by clicking "Accept all" in the cookie banner, anonymised usage data (page views, session duration, browser type, approximate location) is collected via Google Analytics 4 to help KodeKind improve the booking experience. No personal data (your name, phone number, email, or appointment details) is sent to Google Analytics. A pseudonymous cookie (_ga) is placed on your device to distinguish returning visitors. If you choose "Essential only", no analytics data is collected. Google Analytics data may be processed in the United States under the EU-U.S. Data Privacy Framework.
- Stripe, Inc. (if the business enables online payments) - when you make a payment during booking, your card details, billing address, and email are collected directly by Stripe's embedded payment form and processed on the business's own Stripe account (via Stripe Connect Standard). The business is the merchant of record. {{appName}} does not store your card details. Stripe acts as a payment processor on behalf of the business and as an independent data controller for fraud prevention. See Stripe's Privacy Policy at https://stripe.com/privacy.
11. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the national supervisory authority. In Romania, this is the Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP).
ANSPDCP
Website: www.dataprotection.ro
12. Role of KodeKind and Limitation of Liability
Scisso is a software platform that facilitates appointment coordination between you and the business. KodeKind provides the technology only. It does not provide the underlying services (e.g., haircuts, beauty treatments) and has no control over the business's scheduling decisions, service quality, pricing, or availability.
Your appointment and payment relationship is with the business, not with KodeKind. KodeKind is not a party to any appointment, service agreement, or payment transaction between you and the business. When you make a payment during booking, the payment is processed on the business's own Stripe account. The business is the merchant of record. KodeKind provides the software that facilitates the payment but does not receive, hold, or control your payment. Any disputes about services, pricing, payments, refunds, or appointment fulfilment should be directed to the business.
For questions about your appointment, the service you received, a payment you made, a refund, or a cancellation, contact the business directly. KodeKind does not process refunds, handle service complaints, or resolve payment disputes on behalf of businesses. The business manages its own payments, refund policies, and client relationships. If the business believes there is a technical issue with the platform, the business can contact KodeKind directly.
Service limitations. While we work to keep the platform available and accurate, it may experience interruptions, errors, or delays. In particular:
- Submitting an online booking request does not guarantee the appointment will be confirmed, that the time slot is still available, or that the business will respond within any particular timeframe.
- SMS delivery depends on the delivery method used (the business's own device or a third-party gateway), carrier networks, and your phone. Messages may be delayed or undelivered for reasons outside our control.
- Time slot availability shown on the booking page is calculated in real time but may become outdated between display and submission.
Limitation of liability. To the extent permitted by applicable law:
- KodeKind is not liable for the actions, omissions, or conduct of the business or its staff, including service quality, pricing accuracy, appointment availability, or failure to honour confirmed appointments.
- KodeKind is not liable for indirect or consequential loss, including missed appointments, lost time, inconvenience, or travel costs, arising from the use of or inability to use the platform.
- KodeKind is not liable for payment processing failures, refund delays, chargeback outcomes, or any financial loss arising from payments processed on the business's Stripe account. Payment disputes are between you, the business, and Stripe.
- Where KodeKind is found liable to you for direct loss, its total aggregate liability shall not exceed EUR 100 (one hundred euros).
What this limitation does not affect. Nothing in these Terms excludes or limits KodeKind's liability for:
- Death or personal injury caused by KodeKind's negligence
- Fraud or fraudulent misrepresentation
- Intentional misconduct or gross negligence
- Violations of your rights under the General Data Protection Regulation (including your right to compensation under GDPR Article 82)
- Any other liability that cannot be excluded or limited under applicable law
Your statutory rights under EU and national consumer protection law are not affected by these Terms.
13. Changes to These Terms
These Terms may be updated from time to time. The "Last updated" date at the top of this page will reflect any changes.
For material changes, we will notify the businesses that use Scisso, and the businesses are responsible for informing their clients. If you accepted these Terms during online booking or self-registration, the updated Terms will be presented to you for review and acceptance the next time you use those features.
Previous versions of these Terms are available upon request by emailing [email protected].
14. Governing Law
These Terms are governed by the laws of Romania, without regard to conflict of law principles. If you are a consumer habitually resident in another EU member state, you also retain the protection of any mandatory provisions of the consumer protection law of that member state that cannot be derogated from by agreement.
Any dispute arising from these Terms may be brought before the competent courts in Romania. If you are a consumer, you may also bring proceedings in the courts of your habitual residence. You also have the right to lodge a complaint with your national data protection authority or consumer protection authority.
15. Severability
If any provision of these Terms is found to be invalid, unenforceable, or unfair by a court or competent authority, that provision will be modified to the minimum extent necessary to make it enforceable, or if that is not possible, it will be removed. The remaining provisions will continue in full force and effect.
16. Contact
For questions about these Terms, your personal data, or to exercise your rights, please contact your business directly or reach us at:
Scisso by KodeKind S.R.L.
CIF: RO54603957 | Reg. Com.: J2026028952000
Str. Mihail Kogalniceanu, Camera 1, Bl.C8, Et.4, Ap.16, Timisoara, Timis, Romania
Email: [email protected]
