Effective date: 16 September 2026 • Platform: https://cyb-shop.com
This Privacy Policy informs professional users (hairdressers, barbers, salon managers) and visitors to the showcase website of how their personal data is collected, processed, hosted and secured, in accordance with the General Data Protection Regulation (GDPR 2016/679) and the French Data Protection Act (Loi Informatique et Libertés).
1. Data Controller (account and management data)
For personal data relating to Salons' professional accounts, billing, customer relations and connection logs, the Data Controller is:
DEVOXIS
Registered office address: [ADRESSE_POSTALE]
DPO / Personal Data Officer contact: [EMAIL_CONTACT]
2. Personal data collected and purposes
DEVOXIS only collects the data strictly necessary for the operation and performance of its SaaS services:
| Data category | Legal basis | Purposes |
|---|---|---|
| Salon account data: Surname, first name, business name, SIRET number, business email, phone number, hashed password. | Performance of a contract (Art. 6.1.b GDPR) | Account creation and authentication, access to the CRM dashboard, granting of staff access. |
| Billing data: Subscription history, SEPA direct debit / card mandate via Stripe. | Legal accounting obligation (Art. 6.1.c GDPR) | Billing of CYB plans, payment collection, tax compliance (French Commercial Code). |
| Support & Telephony: Support tickets, communication history, voice agent logs. | Legitimate interest (Art. 6.1.f GDPR) | Resolving issues, user support, training and proper operation of the voice switchboard. |
| Technical logs: IP addresses, timestamps, browser type. | Legitimate interest & Security | Intrusion protection, fraud detection, access traceability. |
3. Special status of the Salon's End Customers' data
With regard to all customer records hosted by the Salon in CYB (contact details of the salon's customers, appointment history, hair preferences, inspiration photos, loyalty balances and tabs):
- The operating Salon is the sole legal DATA CONTROLLER;
- DEVOXIS acts exclusively as a technical DATA PROCESSOR (Art. 28 GDPR).
DEVOXIS formally undertakes not to reuse, transfer or sell the data of the salon's end customers to third parties. The detailed terms governing this processing are set out in the Data Processing Agreement (DPA).
4. Recipients and trusted processors
Data is shared exclusively with trusted technical providers bound to comply with the GDPR:
- Infrastructure and database hosting: Hosting on high-security servers located in France / the European Union ([NOM_HEBERGEUR, ex : Hetzner / OVHcloud]).
- Secure card payments: Stripe Payments Europe Ltd (PCI-DSS Level 1 certified).
- Communication gateways: Compliant SMS operators (Twilio) for transactional notifications and automatic reminders.
- Artificial Intelligence services: CMS content generation APIs and telephone voice agent operating with encryption of data in transit and no reuse of data for public training purposes.
5. Data retention periods
- Salon account data: Retained for the entire active term of the contract, then for 3 years from termination for B2B prospecting purposes or as evidence in the event of a dispute.
- Accounting and billing data: 10 years in accordance with Article L.123-22 of the French Commercial Code and Article L.102 B of the French Book of Tax Procedures.
- Connection and security logs: 12 rolling months maximum.
- Customer photos and temporary tokens: Upload tokens expire automatically after use or once their validity period has elapsed.
6. Infrastructure security and integrity
DEVOXIS implements enterprise-grade security measures to protect your data:
- SSL/TLS encryption of all data transfers;
- Strict logical multi-tenant isolation of databases by salon identifier (Tenant ID);
- Strong hashing and salting of user passwords;
- Automated daily encrypted backups.
7. Your rights over your personal data
In accordance with the provisions of the GDPR, you have the following rights:
- Right of access and to a copy (Art. 15 GDPR): Obtain confirmation of processing and a copy of your data.
- Right to rectification (Art. 16 GDPR): Correct inaccurate or incomplete information.
- Right to erasure (Art. 17 GDPR): Request the deletion of your personal data, subject to legal retention obligations.
- Right to restriction and to object (Art. 18 and 21 GDPR): Object to processing or request that it be suspended.
- Right to data portability (Art. 20 GDPR): Export your customer data in a structured format (CSV/JSON) directly from your CRM area.
To exercise these rights, contact our DPO by email at: [EMAIL_CONTACT]. You may also lodge a complaint with the CNIL (French Data Protection Authority) at www.cnil.fr.