Privacy Policy

Last updated: 30 June 2026

1. Who We Are

Scisso is an appointment coordination and SMS notification system developed by KodeKind S.R.L. (CIF: RO54603957, Reg. Com.: J2026028952000), with registered office at Str. Mihail Kogalniceanu, Camera 1, Bl.C8, Et.4, Ap.16, Timisoara, Timis, Romania. This privacy policy explains how we collect, use, and protect personal data when you use Scisso.

This policy applies to all users of the system: business owners, employees (including receptionists), clients of those businesses, and visitors who interact with Scisso (for example, by joining a waitlist or submitting a data request).

For questions about this policy or your personal data, contact us at: [email protected]

KodeKind is not required to appoint a Data Protection Officer under GDPR Article 37 (our processing does not involve large-scale monitoring or special categories of data). For any data protection inquiries, you can reach us at the email address above.

2. Data Controller and Data Processor

Under the GDPR, the business owner who operates Scisso is the Data Controller for all client personal data processed through the system. The business owner determines the purposes and means of processing their clients' data.

KodeKind (the developer) acts as a Data Processor on behalf of the business owner, processing data only according to the owner's instructions and our Data Processing Agreement (DPA). The DPA is accepted when the business owner agrees to the Terms of Service.

For waitlist signups, data subject requests submitted directly through Scisso, the maintenance of SMS opt-out records (to honour communication preferences as required by law), and sending operational platform SMS to business owners (such as a welcome message upon signup), KodeKind acts as an independent Data Controller for those limited purposes.

3. What Data We Collect and Why

We collect and process the following categories of personal data:

Client data (collected and stored by the business)

  • First name and last name - to identify the client and personalise SMS messages
  • Phone number - to send SMS appointment notifications (encrypted at rest)
  • Email address (optional) - for matching Google Calendar events to client records (encrypted at rest)
  • Birthday (optional, encrypted at rest) - to send birthday greetings via SMS, if enabled by the business
  • Profile notes (optional) - service preferences or other remarks, recorded by staff on the client record or submitted by the client via an online booking request
  • Language preference - to format dates and times in SMS messages according to the client's language
  • Last appointment date - to identify inactive records for data retention review
  • Appointment history - dates, times, services, and status of past and future appointments
  • SMS notification history - type, status, delivery provider used (Android relay or third-party gateway), and timestamp of each SMS sent (message content and phone number are deleted immediately once the message is sent)
  • Appointment comments (optional) - internal staff comments on individual appointments, which may contain personal data. Encrypted at rest using AES-256-GCM. Included in data exports and permanently deleted upon customer erasure

Employee data

  • First name, last name, and nickname (optional) - for identification and personalising SMS messages sent on their behalf
  • Email address - for account management, login, and receiving invitations and notifications
  • Date of birth - collected once at account creation for age verification (18+); never editable afterward; nulled on account anonymisation
  • Password - stored as a one-way hash (bcrypt); the original password is never stored
  • Google OAuth refresh token - to sync appointment calendars (encrypted at rest using AES-256-GCM)
  • Google Calendar ID and Google account email - to identify and sync the employee's calendar
  • Job title and biography (optional) - displayed publicly on the booking page to help clients choose a service provider. You can object to this display under GDPR Article 21.
  • Booking slug (optional) - a URL-friendly identifier derived from your name, used for personalised booking URLs. Publicly accessible when online booking is enabled.
  • TOTP secrets and backup codes - encrypted at rest (AES-256-GCM) and used for two-factor authentication. Deleted when MFA is disabled or the account is anonymised.
  • Push notification subscriptions - browser endpoint URLs and encryption keys, or a mobile device push token, stored to deliver real-time notifications to staff about bookings, billing and system health. Delivery uses the push service of your own browser for web notifications and Google Firebase Cloud Messaging for the mobile apps, which relays to Apple on iOS. Web notification contents are encrypted end to end and cannot be read by the push service; mobile notification contents are visible to Google and Apple in transit. Deleted when you unsubscribe, log out, when the device stops accepting notifications, or when your account is anonymised. There is currently no time-based expiry.

Organisation data

  • Business name, phone number, and address - displayed in SMS messages and used for service identification
  • Shop hours/schedule - included in SMS messages so clients know when the shop is open
  • Logo images - displayed in the application interface and in client-facing registration forms
  • Price-list images uploaded for service-catalogue import - sent for AI analysis to produce a draft catalogue, then discarded. These are never stored, and camera metadata is removed before they are sent

Signup and abuse prevention (business owners)

  • IP address at signup - recorded once when a business account is created. It serves as evidence of your place of establishment for EU VAT (One Stop Shop) purposes, and is used to prevent a suspended account from immediately signing up again.
  • Email verification timestamp - records when you last proved control of your email address by entering the code we sent you. We keep the timestamp, not the code.
  • Abuse prevention list - if an account is suspended for abuse, we may record the email address and IP address it was created with, so that the same identifiers cannot be used to open another account. Values are stored encrypted and as a keyed one-way hash, never in readable form in the lookup used to check them.
  • Phone verification - if you verify the phone number on your account to receive free SMS credits, we keep the date you did so, and a one-way keyed hash of the number. The hash records that this number has already received its free credits, so the same number cannot claim them again through another account. We do not keep the number itself in that record.

Waitlist data

  • Name, email address, and shop name (optional) - collected when you sign up for the waitlist before the service is available in your region. Used solely to notify you when Scisso becomes available.

Data subject request data

  • Name, phone number, and/or email address - collected when you submit a data access, erasure, or portability request. Encrypted at rest and permanently deleted once your request has been actioned.

Client self-registration data

  • When a business shares a registration link with a client, the client may voluntarily provide their first name, last name, phone number, email, birthday, and language preference. The client must explicitly consent to this privacy policy and the terms of service before submitting the form. SMS notifications are opt-in during self-registration.

Online booking data

  • When a business enables online booking, visitors to the booking page may provide their first name, last name, phone number, email address (optional, but required when the selected service has online payment enabled), and an optional free-text note to submit a booking request. The visitor must explicitly consent to the Privacy Policy and Client Terms before submitting.
  • The booking form offers separate, optional checkboxes for SMS appointment notifications and promotional messages from the business. These consents are independent of each other and can be withdrawn at any time.
  • Booking requests are stored as pending appointments and are subject to confirmation or rejection by the business. Rejected or expired bookings are cancelled automatically.
  • If the visitor's phone number matches an existing client record at the business, the booking is linked to that record.
  • The booking form is protected by Cloudflare Turnstile, which processes a verification token to distinguish humans from bots. No personal data is shared with Cloudflare beyond this token. See Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/ for details on Turnstile data processing.
  • Employee names, titles, biographies, service names, descriptions, and pricing are displayed publicly on the booking page when online booking is enabled.

Client billing and payment data (collected during online booking with payment)

  • Billing address (street, city, county/state, postal code, country), encrypted at rest using AES-256-GCM. Collected when the selected service requires payment. Saved on the client record for pre-fill on future bookings (pre-filled only after phone OTP verification).
  • Company details (company name, tax identification number, trade register number), encrypted at rest using AES-256-GCM. Collected when the client identifies as a company during payment booking.
  • Stripe customer identifier on the business's connected Stripe account, linking the client to Stripe for payment processing. This is an opaque identifier, not card details.
  • Phone and email verification timestamps, recording when the client verified ownership via a one-time code (OTP) during booking or appointment management.
  • Payment metadata on appointments: payment status (e.g., captured, refunded), payment amount, Stripe reference identifiers (opaque IDs used for refund and dispute workflows, not card details), a secure manage token for client self-service, and a card-on-file consent timestamp.
  • Card details (card number, expiry, CVC) are collected directly by Stripe via the embedded payment form and never pass through or are stored on the business's or {{appName}}'s servers.

Technical data

  • Authentication cookie (httpOnly JWT) - keeps you signed in for up to 7 days; not accessible to JavaScript; cleared on logout
  • Theme preference (localStorage) - remembers your light/dark mode setting; stays on your device
  • Cookie consent choice (localStorage) - remembers that you have acknowledged this notice; stays on your device
  • Calendar UI preferences (localStorage/sessionStorage) - remembers calendar display settings such as collapsed/expanded state and selected filters; stays on your device and is cleared on logout

Billing data

  • Billing type (company or individual), company name, tax identification number, and VAT number (if applicable). Used to generate invoices that comply with local tax regulations.
  • Billing address (street, city, region, postal code, country). Required for invoice generation and tax compliance.
  • IP address at sign-up. Recorded as a second piece of location evidence alongside your billing address, as required by EU VAT rules for digital services (Council Implementing Regulation 282/2011, Article 24f). Not used for any other purpose.
  • Payment method details (card number, expiry, CVC) are collected directly by Stripe and never pass through or are stored on Scisso servers.
  • SMS credit purchase history (pack size, price, payment reference, withdrawal waiver consent timestamp). Used for billing records, credit balance reconciliation, and to document compliance with the consumer withdrawal waiver (Article 16(m) of the Consumer Rights Directive).

Platform communications (sent by KodeKind as independent controller)

  • When you create a business account, KodeKind may send operational SMS messages to the account owner's phone number from KodeKind's own phone number. Currently this includes a welcome message upon signup. These are transactional platform communications, not marketing. The phone number is encrypted at rest and the message content is deleted immediately after sending, in the same manner as client SMS.

Inferred data

  • When Google Calendar events are synced, Scisso may infer a client name from the event title or attendee information. These inferred names are stored to help staff match events to existing client records. They are deleted if the client record is erased.

Web analytics data (collected with your consent)

  • A pseudonymous client identifier stored in a browser cookie (_ga, _ga_<container-id>), used by Google Analytics to distinguish returning visitors. This identifier cannot identify you personally.
  • Page URLs and page titles visited within the application
  • General usage data: session duration, session count, browser type, device type, screen resolution, and approximate geographic location (city-level, derived from IP address). IP addresses are not stored by Google Analytics 4.
  • Interaction events: page views, navigation patterns, and feature usage. These events do not contain personal data such as names, phone numbers, or email addresses.

4. Legal Basis for Processing

We rely on the following legal bases under GDPR Article 6:

  • Legitimate interest (Art. 6(1)(f)) - Processing client contact details to send appointment confirmations, reminders, rescheduling notices, and cancellation notices is a legitimate and expected business practice. These are transactional messages, not direct marketing, and do not require consent under the ePrivacy Directive. Displaying employee names, titles, and biographies on the booking page is also based on the employer's legitimate interest in enabling clients to identify and select their service provider.
  • Legitimate interest + ePrivacy soft opt-in - Follow-up SMS messages (e.g., post-appointment messages) may contain re-engagement content. Where they do, they are classified as direct marketing under the ePrivacy Directive (2002/58/EC) and Romanian Law 506/2004. These messages rely on the "soft opt-in" exception under Article 13(2) of the ePrivacy Directive (Article 12(2) of Law 506/2004): the contact details were obtained in the context of a service, the messages promote similar services from the same business, the client was given a clear opportunity to opt out at collection, and every message includes an opt-out mechanism. As an additional safeguard beyond the minimum legal requirement, the opt-out link is included in every follow-up message. The underlying data processing relies on GDPR Art. 6(1)(f) (legitimate interest).
  • Consent (Art. 6(1)(a)) - When clients self-register via a registration link or submit an online booking request, they provide explicit consent by accepting this privacy policy and the terms of service before submitting their data. SMS notifications are separately opt-in. Promotional messages and birthday greetings are only sent to clients who have provided separate, explicit opt-in consent. This consent can be withdrawn at any time by opting out of SMS. Waitlist signups are based on your consent, provided when you voluntarily submit the waitlist form. You may request deletion of your waitlist data at any time.
  • Contract (Art. 6(1)(b)) - Processing employee personal data is necessary to provide the Scisso service under the employee's relationship with the business, including push notification subscriptions when the employee enables them via the browser permission prompt. Processing billing data (company name, tax ID, VAT number, billing address) is necessary for the performance of the subscription contract and invoice generation. Sending operational platform SMS to the account owner (such as a welcome message upon signup) is necessary for the performance of the subscription contract.
  • Legal obligation (Art. 6(1)(c)) - Maintaining SMS opt-out records is required to honour opt-out requests and comply with electronic communications regulations. Audit logs are maintained for accountability under GDPR Article 5(2). Billing data is retained for the duration required by applicable tax law.
  • Consent (Art. 6(1)(a)) for analytics and advertising measurement - We use Google Analytics 4 to understand how the application and website are used, identify usability issues, and improve the service. On our public marketing and sign-up pages we also use the Meta Pixel and the OpenAI (ChatGPT Ads) Pixel to measure which advertising campaigns lead to a sign-up. Neither pixel is loaded on the client booking pages, on the customer self-service links, or anywhere in the signed-in application. Analytics and marketing cookies are only placed on your device after you click "Accept all" in the cookie banner. If you choose "Essential only", no analytics or advertising measurement data is collected. You can change your preference at any time by clearing your browser's local storage for this site, which will re-display the cookie banner. This processing is based on your explicit, informed, freely given, and specific consent under Article 6(1)(a) GDPR, Article 5(3) of the ePrivacy Directive (2002/58/EC), and Article 4(2) of Romanian Law 506/2004.
  • Legitimate interest (Art. 6(1)(f)) - security and abuse prevention - We verify that a business owner controls the email address used at signup, and we keep a limited record of identifiers used by accounts suspended for abuse. The interest is preventing our service from being used to send messages under a false identity, which harms the recipients of those messages, the businesses whose good name the service depends on, and our own ability to deliver messages at all. GDPR Recital 49 recognises processing strictly necessary for network and information security as a legitimate interest. Only the minimum is kept, entries expire or are deleted on the schedule in Section 6, and no automated decision with legal effect is made about anyone (see Section 9).

5. How We Use Your Data

Scisso sends the following types of SMS notifications to clients, each of which can be individually enabled or disabled by the business owner:

  • Confirmation - sent when a new appointment is created, confirming the date, time, and service
  • Reminder - sent approximately 24 hours before the appointment
  • Updated - sent when an existing appointment is rescheduled to a different date or time
  • Cancelled - sent when an appointment is cancelled
  • Follow-up - sent a configurable number of days after an appointment. May contain re-engagement content (e.g., encouraging rebooking), which is classified as direct marketing under the ePrivacy Directive and sent under the soft opt-in exception (see Section 4)
  • Booking received - sent when a client submits an online booking request, confirming receipt and pending review
  • Booking rejected - sent when the business rejects an online booking request
  • Promotional - sent only to clients who have explicitly opted in to receive promotional messages from the business. This consent is collected separately (e.g., via the online booking form) and can be withdrawn at any time.
  • Birthday - sent on the client's birthday (if a birthday is on file and the feature is enabled by the business)

In addition to SMS notifications, we use your data for:

  • Synchronising appointments with Google Calendar to reduce manual data entry
  • Matching Google Calendar events to existing client records using email addresses, calendar colour codes, or event title keywords
  • Displaying appointment history and aggregated statistics (using anonymised counts per month, not personal details)
  • Allowing staff to manage client records, appointments, and recurring appointment series
  • Detecting and merging duplicate client records when the same person is entered more than once
  • Processing data subject requests (access, erasure, portability)
  • Generating QR codes in the browser for booking pages, registration links, and client update links. QR codes are created client-side and are not transmitted to or stored on our servers.
  • Offering visitors the option to download the business contact details as a vCard file (.vcf) when the business is outside its shop hours. vCard files are generated in the browser and contain only the business name and phone number.
  • Processing online booking requests, including matching booking visitors to existing client records by phone number
  • Sending email notifications to employees about new online booking requests and other account-related events (via Resend)
  • Sending push notifications to employees about bookings, billing events, SMS credit levels and relay health, delivered via your browser's push service or via Google Firebase Cloud Messaging on mobile
  • Analysing aggregated, anonymised usage patterns (via Google Analytics 4) to improve the application's interface, identify performance issues, and prioritise feature development. Analytics data is collected only with your consent (see Section 4).
  • Processing online payments during booking (deposits, prepayments, card-on-file storage) via Stripe Connect on the business's own Stripe account. This includes creating payment objects, managing refunds, and facilitating client self-service cancellation via secure manage links.

We do not use client personal data for advertising or profiling. Client records, appointments, phone numbers, and SMS content are never shared with advertising networks and are never used for any purpose beyond managing appointments, the business relationship, and improving the service. Separately, and only on our public marketing and sign-up pages, we measure which advertising campaigns lead to a sign-up. That measurement runs only if you accept marketing cookies, and is described in Sections 8 and 11. We do not engage in automated decision-making or profiling as defined in GDPR Article 22.

6. Data Retention

  • Client records - retained for the period configured by the business owner (default: 2 years after the last appointment). Inactive records are flagged for owner review; no automatic deletion occurs without owner action.
  • SMS message content and phone number - deleted from the system immediately once the message has been sent, and equally if it is cancelled or if all retry attempts are exhausted without a send. They are never retained while awaiting a delivery report. A daily cleanup job also runs as a safeguard to remove any data that was not cleared in real time.
  • SMS opt-out records - the opted-out phone number (encrypted) is retained indefinitely to ensure we never send another message to that number, even if the number is later re-entered.
  • Employee records - fully anonymised (all personal fields nulled, Google tokens revoked and deleted) when the employee leaves the business. Appointment history is retained with anonymised references for statistical integrity.
  • Audit logs - retained for legal compliance and accountability. They contain no personal data, only event types, record IDs, and timestamps.
  • Waitlist entries - retained until you are notified and onboarded, or until you request deletion.
  • Data subject requests - the personal data you provide in a request (name, phone, email, notes) is encrypted at rest and permanently deleted once the request has been actioned. The request record (type, status, timestamp) is retained for audit purposes.
  • Authentication cookie - expires after 7 days or when you log out, whichever comes first.
  • Billing data - company name, tax ID, VAT number, billing address, and sign-up IP address are retained for the duration of your subscription and for the period required by applicable tax law thereafter. Payment method details are managed entirely by Stripe and subject to Stripe's retention policies.
  • SMS credit purchase history - purchase records (pack size, price, payment reference, withdrawal waiver timestamp) are retained for the duration of your subscription and for the period required by applicable tax law thereafter.
  • Aggregated statistics - anonymised, aggregate appointment counts (per service category at the organisation level, not attributable to any individual employee or client) are retained indefinitely under GDPR Article 89(1). Per-employee statistics are aggregated to organisation-level totals when an employee account is anonymised or the business terminates its subscription. These aggregated counts do not constitute personal data under GDPR Recital 26.
  • Encrypted backups - personal data in encrypted database backups is deleted in accordance with the standard backup rotation schedule, not to exceed 90 days after deletion from active systems. During this period, backup data remains encrypted and access-restricted, and will not be restored to active systems.
  • Web analytics data - Google Analytics data retention is set to 14 months for user-level and event-level data. After this period, data is automatically deleted by Google. Aggregated reports (which are not personal data) are retained indefinitely. Analytics cookies (_ga) expire after 13 months of inactivity. You can delete analytics cookies at any time by clearing your browser data.
  • Client billing data - billing address, company details, and Stripe customer identifier are retained on the client record for as long as the client record exists (see item 1). All billing fields are encrypted at rest and are permanently nulled upon customer erasure.
  • Appointment manage tokens - secure one-time links for client self-service expire 7 days after the appointment ends and are nulled upon customer erasure.
  • Stripe payment references - opaque Stripe identifiers (PaymentIntent IDs, SetupIntent IDs, Invoice IDs) on appointments are retained even after customer erasure, as they are needed for refund workflows and dispute evidence. They are not personal data (they cannot identify an individual without access to Stripe's systems).
  • AI usage records - non-content telemetry about each AI request (which feature, which employee, token counts, cost, status, timestamp). No titles, names, images, or other content are recorded. Detailed records are deleted after 13 months; an aggregated daily summary is kept for the lifetime of the business account and deleted when the account is closed.
  • Abuse prevention records - an IP address recorded at signup is kept for as long as the business account exists, and is deleted with it. An entry on the abuse prevention list is deleted 30 days after it stops applying, 90 days after it is withdrawn, and in any case no later than 4 years after it was created. Nothing on that list is kept indefinitely.
  • Phone verification records - the hash that records a number has already claimed its free SMS credits is kept for as long as that protection is needed, and is not deleted when an account is erased. Deleting it would restore the entitlement and defeat the purpose. It contains a one-way hash and a date, nothing else. Ask us and we can tell you whether your number appears in it.

7. Data Security

  • Client phone numbers and email addresses are encrypted at rest using AES-256-GCM with unique initialisation vectors per record
  • Google OAuth refresh tokens are encrypted at rest using AES-256-GCM
  • SMS job phone numbers are encrypted at rest and permanently deleted immediately after sending
  • Data subject request contact details are encrypted at rest and deleted after the request is actioned
  • Employee passwords are hashed using bcrypt (12 rounds); the original password is never stored or recoverable
  • Two-factor authentication (TOTP) is available for all users. TOTP secrets and backup codes are encrypted at rest using AES-256-GCM.
  • Changing your password or modifying MFA settings invalidates all existing sessions on other devices immediately.
  • All data is transmitted over HTTPS/TLS between browser and server
  • Servers are EU-hosted to comply with GDPR data residency requirements
  • Access to client records is role-restricted. Employees can only view and edit clients they have a direct working relationship with. Owners and receptionists have broader access within their organisation.
  • Personal data is automatically redacted from application logs. Phone numbers, names, email addresses, and other sensitive fields are never written to log files.
  • When sent via the Android relay, SMS messages are transmitted from the server to the on-premises device over an encrypted WebSocket connection. The phone number and message body exist in the device's memory only for the duration of delivery and are never stored on the device. When sent via a third-party SMS gateway, the phone number and message body are transmitted over HTTPS/TLS to the gateway API for delivery. Only the recipient phone number and message body are shared with the gateway. No internal identifiers, client profile data, or organisation metadata is transmitted.
  • Android relay authentication uses a unique API key per device, stored as a one-way bcrypt hash on the server. The plaintext key is shown once at pairing time and is never stored or retrievable afterward.
  • Staff comments on appointments are encrypted at rest using AES-256-GCM. They are included in customer data exports and permanently deleted upon customer erasure.
  • Client billing details (address, company name, tax ID) collected during payment-enabled bookings are encrypted at rest using AES-256-GCM. They are pre-filled on subsequent bookings only after phone OTP verification. All billing fields are permanently nulled upon customer erasure.

8. Data Sharing

We do not sell your personal data. We share data only with the following processors, under contractual data protection obligations:

  • Google LLC - Google Calendar API is used for two-way appointment synchronisation. Scisso has read and write access to the connected calendar: it creates events when appointments are booked, updates events when appointments are rescheduled or confirmed, deletes events when appointments are cancelled, and sets private extended properties on events to link them to Scisso records. Scisso also reads events from the connected calendar (via webhook notifications) to detect changes made directly in Google Calendar. Only appointment data (times, titles, descriptions, attendee emails, and extended properties) is exchanged. Your Google account email is used to identify your account. Your Google OAuth refresh token is encrypted at rest and is revoked at Google when you disconnect your calendar from your profile or when your account is anonymised. You can disconnect Google Calendar at any time from your profile settings. We strongly recommend connecting a dedicated work calendar rather than a personal calendar. Covered by Google's Standard Contractual Clauses. See Google's Privacy Policy.
  • Resend - used to deliver transactional emails: staff invitations, password reset links, email change confirmations, and internal admin notifications (such as new waitlist signups and data subject requests). Only the recipient's email address is shared. See Resend's Privacy Policy.
  • Stripe - used in two capacities: (1) to process KodeKind's subscription billing and SMS credit purchases (business owner's billing data shared); (2) via Stripe Connect (Standard), to process online payments on the business's own connected Stripe account during booking (client billing details, email, and card data collected directly by Stripe's embedded payment form). In both cases, card details are collected directly by Stripe and never pass through Scisso servers. Stripe acts as a data processor for payment execution and as an independent data controller for its own fraud prevention and regulatory compliance purposes. For Stripe Connect payments, the business is the merchant of record. KodeKind does not collect any platform fee or commission on payment transactions. Covered by Stripe's Standard Contractual Clauses. See Stripe's Privacy Policy.
  • Cloudflare, Inc. - used in two capacities: (1) Cloudflare Turnstile on the online booking form verifies that submissions come from real visitors and not automated bots, exchanging only a verification token, with no personal data (name, phone number, email) shared; and (2) Cloudflare R2 object storage and CDN delivery host the images the business uploads (logos, staff avatars, and public booking-page gallery photos), which may contain personal data of the business's clients, such as faces. The R2 storage bucket is located in the European Union. See Cloudflare's Privacy Policy.
  • SMSAdvert (S.C. SMSAdvert S.R.L.) - used as a fallback SMS delivery provider when the business's Android relay device is unavailable, or as a primary provider if configured by the business. The recipient's phone number and the SMS message body are transmitted to SMSAdvert's API over HTTPS for delivery. No other personal data (client name, email, appointment details beyond what is in the message body, or internal identifiers) is shared. SMSAdvert is based in Romania (EU). See SMSAdvert's Terms.
  • VPS provider - the server infrastructure hosting Scisso is EU-located. The provider processes data only as necessary to run the server and has no access to application-layer encryption keys.
  • Google Analytics (Google LLC) - used to collect anonymised website and application usage statistics to improve the service. Only pseudonymous identifiers (the _ga cookie value), page URLs, and general device/browser information are shared with Google. No personal data (names, email addresses, phone numbers, appointment details, or client records) is sent to Google Analytics. Google processes this data under its Data Processing Amendment and Standard Contractual Clauses. We have configured Google Analytics 4 with the following privacy settings: IP anonymisation is enabled by default in GA4; data sharing with Google products is disabled; Google Signals is disabled; user-level data retention is set to 14 months; no User-ID feature is enabled (we do not link analytics data to authenticated user accounts). Google Analytics data may be processed in the United States under the EU-U.S. Data Privacy Framework. See Google Analytics' Privacy Policy.
  • SmartBill (S.C. Intelligent IT S.R.L., Visma group) - used to generate and deliver invoices for subscription payments and SMS credit purchases. We share the billing entity name, tax identification number, VAT number (if applicable), billing address, and invoice line items with SmartBill. No client personal data is shared. SmartBill stores data in AWS datacentres in Ireland and Germany (European Union). SmartBill acts as a data processor under its own DPA. See SmartBill's Privacy Policy.
  • Scaleway SAS - used for two optional AI-assisted features. The first classifies Google Calendar event titles to detect likely client appointments: only the event title (which may contain a client's first name) and the business's own service-catalogue labels are sent. No client lists, phone numbers, or email addresses are sent. The second lets a business build its service catalogue from photographs of its own price list: those images contain the business's own commercial information (service names, durations, prices), not client data, and camera metadata including any recorded location is removed before transmission. In both cases the data is processed transiently in France (EU) on the Mistral Small 3.2 model; the model's author does not receive it. Inputs are not used to train models, and no prompt content, response content, or image is stored. The business can disable both features at any time in Settings. See Scaleway's Generative APIs data-privacy documentation.
  • Meta Platforms Ireland Limited - the Meta (Facebook) Pixel runs on our public marketing website and sign-up pages only, to measure how effective our advertising is and to attribute a sign-up to the campaign that produced it. It is never loaded on the client booking pages, on the customer self-service links sent by SMS or email, or anywhere in the signed-in application. It receives the page address, a pseudonymous browser identifier, and a sign-up event carrying the chosen plan name and its price. It never receives client records, appointments, phone numbers, email addresses, or SMS content. It is loaded only after you click "Accept all" in the cookie banner, and never if you choose "Essential only". See Meta's Privacy Policy.
  • OpenAI Ireland Limited - the OpenAI (ChatGPT Ads) Pixel runs on our public marketing website and sign-up pages only, to measure which ChatGPT advertising campaigns lead to a free trial. It is never loaded on the client booking pages, on the customer self-service links sent by SMS or email, or anywhere in the signed-in application. It receives the page address, a pseudonymous browser identifier, and a trial-started event carrying the chosen plan name and its price. It never receives client records, appointments, or SMS content. The pixel additionally performs automatic matching: it detects contact details present on the page you are viewing, hashes them in your browser using SHA-256, and includes those hashes with the event to improve attribution. On our sign-up page this can include the email address, phone number, and name you are entering to create your own account. It is loaded only after you click "Accept all" in the cookie banner, and never if you choose "Essential only". See OpenAI's Privacy Policy.

When the Android relay is used, SMS messages are delivered via the business's own phone using the native SMS system. The phone number is decrypted on the server and transmitted directly to the on-premises device over an encrypted connection. No third-party service processes the phone number or message content for relay-delivered messages.

When a third-party SMS gateway (SMSAdvert) is used, the recipient's phone number and message body are transmitted to the gateway's API for delivery. The message is sent from a generic short code, not the business's phone number, but the message content identifies the business by name. The gateway processes this data solely for the purpose of SMS transmission.

9. Your Rights Under GDPR

Whether you are a client, employee, or business owner using Scisso, you have the following rights regarding your personal data under the General Data Protection Regulation:

  • Right of access (Art. 15) - you can request a copy of all personal data held about you, including your appointment history and SMS notification history.
  • Right to rectification (Art. 16) - you can ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17) - you can request deletion of your personal data. We will erase all personal fields (name, phone, email, birthday, notes) and add your phone number to the opt-out list to prevent future contact. An anonymised record shell is retained for statistical integrity.
  • Right to restriction (Art. 18) - you can ask us to temporarily stop processing your data in certain circumstances.
  • Right to data portability (Art. 20) - you can request your data in a structured, commonly used, machine-readable format (JSON).
  • Right to object (Art. 21) - you can object to processing based on legitimate interest. If you object to receiving SMS messages, reply STOP to any message or ask the business to disable SMS for your record.
  • Right to withdraw consent (Art. 7(3)) - if you provided consent during self-registration, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right regarding automated decisions (Art. 22) - you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not engage in such processing.
  • Right to lodge a complaint - you have the right to lodge a complaint with your national data protection authority. In Romania, this is the ANSPDCP (www.dataprotection.ro).

How to exercise your rights. If you are a client, you should direct your request to the business first (the Data Controller). If you cannot reach the business, you can submit a data request or email us at [email protected]. If we receive a request that should be handled by the business, we will forward it promptly. If you are a business owner or employee, you can contact us directly.

Requests will be handled within one calendar month of receipt, as required by GDPR Article 12(3). For complex requests or where multiple requests are received, this period may be extended by up to two additional months, with notification of the extension and reasons provided within the initial one-month period.

One limited exception applies to the right to object. Where we process a small amount of data specifically to stop an account that was suspended for abuse from immediately opening another one, we may decline an objection under Art. 21(1) where we can demonstrate compelling legitimate grounds. Those grounds are that the processing exists to protect other people from messages sent under a false identity, that upholding every objection would defeat the measure entirely and by design, and that the data held is minimal, is not used for any other purpose, and expires. We will tell you if we rely on this, we will explain why, and you can complain to a supervisory authority. This exception never applies to your appointment data, your marketing preferences, or anything else in this policy.

10. SMS Opt-Out

You can opt out of SMS messages at any time by clicking the opt-out link included in SMS messages. For transactional messages (confirmations, reminders, rescheduling and cancellation notices), the link is included in the first message sent to you from each sender number. For follow-up, promotional, and birthday messages, the link is included in every message. The link takes you to a confirmation page where you can review which business is contacting you before confirming your opt-out. Once confirmed, we will never send you another SMS from that business. Your opt-out preference is stored indefinitely (as an encrypted phone number) to ensure we honour your request even if your number is re-entered in the system.

You can also opt out by replying STOP to the business phone number. The relay app on the business's Android device detects exact-match keywords only (STOP, START, HELP, and common EU-language equivalents). No message content is read, stored, or logged beyond this keyword matching. When a keyword is detected, only the sender's phone number is forwarded to the Scisso server to process the opt-out, opt-in, or help request. Phone numbers from keyword processing are not retained beyond immediate processing. Replying START re-enables transactional SMS only. Promotional SMS consent must be re-granted separately.

Additionally, the business owner or staff can disable SMS notifications for individual clients at any time. Clients who self-register can choose not to opt in to SMS during registration.

11. Cookies and Local Storage

We use the following browser storage:

NameTypePurposeConsent required
token (httpOnly)CookieKeeps you signed in (expires after 7 days or on logout)No - essential
scisso-themelocalStorageRemembers light/dark mode preferenceNo - essential
scisso-languagelocalStorageRemembers your language/locale preferenceNo - essential
scisso-cookie-consentlocalStorageRemembers that you have acknowledged this noticeNo - essential
scisso_mini_calendar_expandedlocalStorageRemembers calendar panel collapsed/expanded stateNo - essential
scisso-calendar-zoomlocalStorageRemembers calendar time grid zoom levelNo - essential
scisso_employee_filtersessionStorageRemembers selected calendar filter within a sessionNo - essential
scisso-dashboard-daysessionStorageRemembers selected date on the dashboard within a sessionNo - essential
scisso-onboarding-queuesessionStorageTracks onboarding step progression within a sessionNo - essential
scisso-promosessionStorageApplies a promotional discount during signup (cleared after 30 minutes or on session end)No - essential
scisso_signup_draftsessionStoragePreserves signup form progress within a sessionNo - essential
scisso-booking-themelocalStorageRemembers theme preference on the booking pageNo - essential
scisso-booking-langlocalStorageRemembers language preference on the booking pageNo - essential
scisso-booking-cookie-consentlocalStorageRemembers cookie consent on the booking pageNo - essential
cf_clearanceCookie (3rd party)Set by Cloudflare Turnstile on the booking page to verify bot protection statusNo - essential (security)
_gaCookiePseudonymous visitor identifier used by Google Analytics to distinguish returning visitors and compile usage statistics (expires after 13 months of inactivity)Yes - analytics
_ga_<container-id>CookieSession-scoped cookie used by Google Analytics to maintain session state (expires after 13 months of inactivity)Yes - analytics
_fbpCookiePseudonymous identifier set by the Meta (Facebook) Pixel to measure the effectiveness of our advertising and attribute sign-ups to ad campaigns (expires after 90 days)Yes - marketing
_fbcCookieStores the Meta (Facebook) click identifier from an ad link to attribute a later sign-up to the originating advertisement (expires after 90 days)Yes - marketing
__obrefCookiePseudonymous browser identifier set by the OpenAI (ChatGPT Ads) Pixel to measure the effectiveness of our advertising and attribute sign-ups to ad campaigns (expires after 12 months)Yes - marketing
__oaiq_consentCookieRecords the consent signal given to the OpenAI (ChatGPT Ads) Pixel, so that no measurement data is sent unless you have accepted marketing cookies (expires after 30 days)Yes - marketing

The essential cookies and local storage items listed above are required for the service to function and do not require your consent. SessionStorage items are automatically cleared when you close the browser tab, and all session data is cleared on logout.

The analytics and marketing cookies (marked "Yes - analytics" or "Yes - marketing" above) are only set if you click "Accept all" in the cookie banner. If you choose "Essential only", none of these cookies are placed and no data is sent to Google Analytics, the Meta Pixel or the OpenAI Pixel. You can withdraw your consent at any time by clearing your browser's local storage for this site, which will re-display the cookie banner on your next visit.

12. International Data Transfers

All Scisso servers are hosted within the European Union. Client personal data does not leave the EU for storage or processing by Scisso itself.

Where sub-processors located outside the EU are engaged, appropriate safeguards are in place in accordance with GDPR Chapter V. Specifically: Google Calendar synchronisation is covered by Google's Standard Contractual Clauses and adequacy mechanisms. Google Analytics data is processed by Google LLC in the United States under Google's Data Processing Amendment, Standard Contractual Clauses (Module 3: processor to processor), and the EU-U.S. Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795). Resend (email delivery) processes email addresses under their Standard Contractual Clauses. Stripe (payment processing) processes billing data under their Standard Contractual Clauses and acts as an independent data controller for fraud prevention. Cloudflare Turnstile verification tokens are processed on Cloudflare's global edge network under Cloudflare's DPA with Standard Contractual Clauses. Advertising measurement is contracted with entities established in the European Union, Meta Platforms Ireland Limited and OpenAI Ireland Limited, each of which transfers data onward to its United States parent company. Both parent companies, Meta Platforms, Inc. and OpenAI, are certified under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses are in place as a fallback should that adequacy decision cease to apply. In both cases the transfer is limited to a pseudonymous identifier, the page address, and a sign-up or trial event, it happens only if you accept marketing cookies, and it stops as soon as you withdraw that consent.

For users in the United Kingdom, transfers to Google Analytics and to the advertising measurement providers named above are safeguarded under the UK International Data Transfer Agreement (IDTA) and the UK Extension to the EU Standard Contractual Clauses, in accordance with the UK GDPR and the Privacy and Electronic Communications Regulations 2003 (PECR). Analytics and advertising cookies require the same opt-in consent standard under PECR as under the EU ePrivacy Directive.

13. Children's Privacy

Scisso is a business tool. Employee accounts require the account holder to be at least 18 years of age, which is verified at account creation. We do not knowingly collect personal data from anyone under the age of 16. If client records are entered for individuals under 16, the business owner is responsible for ensuring appropriate parental or guardian consent under GDPR Article 8.

14. Changes to This Policy

We may update this policy from time to time. We will update the "Last updated" date at the top of this page. For material changes that affect how personal data is processed, we will notify business owners by email at least 14 days before the changes take effect. Business owners are responsible for informing their clients of material changes. Clients who accepted this policy during online booking or self-registration will be presented with the updated policy the next time they use those features.

Previous versions of this policy are available upon request by emailing [email protected].

15. Contact

For any privacy-related questions, data subject requests, or complaints, please contact us at:

Scisso by KodeKind S.R.L.

CIF: RO54603957 | Reg. Com.: J2026028952000

Str. Mihail Kogalniceanu, Camera 1, Bl.C8, Et.4, Ap.16, Timisoara, Timis, Romania

Email: [email protected]

We use cookies

We use essential cookies to keep you signed in and protect against bots. With your consent, we also use analytics to improve the experience, and advertising cookies to see which ads bring people here. Privacy Policy