Privacy Policy
1. Who we are
Hair Atelier AI is operated by:
Nostro box j.d.o.o.
Jurja Ves III odv. 5, 10000 Zagreb, Croatia
OIB: 58661874766
Brand: Nostro Box AI
Privacy contact:
sales@nostroboxai.app
2. Scope and our privacy roles
This Policy explains how personal data is processed in connection with Hair Atelier AI (“Service”), including Free Trial access, authentication, account administration, generation usage/credits, security, support and related business communications.
When Nostro box j.d.o.o. acts as controller
Nostro box j.d.o.o. generally acts as an independent controller for personal data processed for its own purposes, such as business contact details, Demo/Trial requests, account administration, authentication, security, support, service management, evidence of acceptance of legal terms, billing/commercial administration and compliance with legal obligations.
When Nostro box j.d.o.o. acts as processor
Where a salon or other professional Customer uploads a photograph of its client or otherwise submits client personal data through the Service for a salon consultation, the Customer generally acts as the controller and Nostro box j.d.o.o. acts as processor on the Customer's behalf.
In that situation, the Customer is responsible for determining the lawful basis for the processing, providing any required privacy information to the client and obtaining any permission or consent required by applicable law. Processing by Nostro box j.d.o.o. as processor is governed by the applicable Data Processing Agreement, including the Trial Data Processing Terms in Annex A of the Terms of Use for Free Trial Customers.
3. Personal data we process
| Category | Examples and purpose |
|---|---|
| Business, Demo and Trial request data | Company/salon name, address, country, tax/VAT number, business email, contact person, phone number and request type, used to respond to Demo/Trial requests and manage the business relationship. |
| Account and authentication data | Email address, account identifier, account status, authentication/session metadata and password-reset activity used to provide and secure the account. Plain-text passwords are not intentionally stored in the Hair Atelier application database. |
| Legal acceptance records | User/account identifier, date and time of acceptance, and accepted Terms/Privacy/DPA version used to document electronic acceptance and manage compliance. |
| Uploaded photographs | A photograph selected for upload or captured with the device camera, processed to assess visible hair characteristics and to generate the requested hairstyle/color preview. |
| AI output | The generated hairstyle/color preview displayed in the browser and made available for download by the authorised user. |
| Plan, credit and usage data | Assigned plan or Trial status, billing/credit-cycle data where applicable, included credits, credits used, remaining credits, one-time extra credits and generation/usage records. |
| Technical and security data | IP address, browser/device information, request metadata, timestamps, session/security events, diagnostic data and logs processed by us or our infrastructure providers to operate, secure and troubleshoot the Service. |
| Support and business communications | Information you provide if you contact us regarding account, privacy, technical, Trial or commercial matters. |
4. How photographs and generated images are handled
Hair Atelier AI is designed not to persist client photographs or generated hairstyle images in its own application database as a photo library after the relevant generation process is completed. Photographs are temporarily processed by the application and transmitted to contracted infrastructure and AI providers as necessary to perform the requested function.
We do not use uploaded photographs for biometric identification, identity verification or facial-recognition purposes. The Service is intended to create a visual hairstyle/color consultation preview.
Third-party infrastructure and AI providers may apply limited technical retention, logging or backup periods under their applicable contracts and data-control settings. Where Nostro box j.d.o.o. acts as processor, those providers are engaged subject to the applicable processor/subprocessor arrangements.
OpenAI is currently used as an AI model/API provider for relevant image-processing and generation functions. Data submitted through the API is handled in accordance with OpenAI's applicable business/API data controls and contractual terms. Those controls and retention settings may evolve, so the current provider documentation and contractual settings should be consulted where a precise retention period is required.
5. Purposes and legal bases when we act as controller
Where Nostro box j.d.o.o. acts as controller, we may process personal data for the following purposes and legal bases under the GDPR:
- Demo/Trial requests and steps before a business relationship: to respond to a request and take steps requested before entering into a contract (Article 6(1)(b) GDPR where applicable) and/or our legitimate interest in responding to genuine B2B enquiries (Article 6(1)(f) GDPR).
- Providing and administering a business account or Service: processing necessary to perform the applicable agreement with the Customer (Article 6(1)(b) GDPR).
- Authentication, password recovery and account security: performance of the Service and our legitimate interests in protecting accounts and systems (Articles 6(1)(b) and 6(1)(f) GDPR, as applicable).
- Recording electronic acceptance: performance of the applicable Trial/Service terms and our legitimate interests in demonstrating which legal terms were accepted and when (Articles 6(1)(b) and 6(1)(f) GDPR).
- Service security, misuse prevention, diagnostics and troubleshooting: our legitimate interests in maintaining a secure, reliable and functional service (Article 6(1)(f) GDPR).
- Billing, accounting and legal compliance: performance of the commercial agreement and compliance with applicable legal obligations (Articles 6(1)(b) and 6(1)(c) GDPR).
- Support and ordinary business communications: performance of the Service and/or our legitimate interest in responding to users and customers (Articles 6(1)(b) and 6(1)(f) GDPR, as applicable).
- Consent-based optional processing: where we specifically ask for consent for a separate optional purpose, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time for future processing.
6. Processing of salon-client data when we act as processor
When a Customer uses Hair Atelier AI to process a client's photograph for a salon consultation, Nostro box j.d.o.o. does not determine the Customer's legal basis for that client processing. The Customer, as controller, is responsible for determining and documenting the appropriate legal basis and meeting its transparency obligations.
Nostro box j.d.o.o. processes that personal data only to provide and secure the requested Service and in accordance with the Customer's documented instructions, the applicable Data Processing Agreement and applicable law.
7. Service providers and recipients
We use service providers necessary to operate Hair Atelier AI, including:
- OpenAI – AI image processing and generation where relevant to the requested function.
- Supabase – authentication, user accounts, database/backend functions and plan/credit/usage data.
- Vercel – web hosting, serverless/API execution and related technical infrastructure.
- Email/SMTP and hosting providers – transactional email, password-reset delivery and supporting infrastructure.
These providers may use their own subprocessors. We disclose personal data only as necessary for the relevant service, security, support, legal compliance or other purposes described in this Policy.
Where these providers process personal data on our behalf in our role as processor, the applicable subprocessor provisions in the Customer's Data Processing Agreement apply.
8. International data transfers
Some infrastructure or AI processing may involve providers or subprocessors located outside Croatia or the European Economic Area. Where GDPR Chapter V applies, an appropriate transfer mechanism and safeguards are used, such as an applicable adequacy decision, the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
9. Retention
- Client photographs and generated images: not intentionally retained as a persistent photo library in the Hair Atelier application database. They are processed transiently to provide the requested function. Limited technical retention, logging, caching or backup periods may apply at contracted infrastructure/AI providers under the applicable contractual settings.
- Demo/Trial request and business contact data: retained for as long as reasonably necessary to handle the request, manage follow-up and document the business relationship, subject to applicable legal requirements.
- Account, plan, credit and usage data: retained while the account is active and as reasonably necessary for administration, security, contractual records, legal obligations and dispute resolution.
- Legal acceptance records: retained for the duration reasonably necessary to demonstrate the applicable legal terms accepted in connection with the Trial or Service and to establish, exercise or defend legal claims.
- Technical/security logs: retained according to operational need, security requirements and provider configuration/policies.
- Support and business communications: retained for as long as reasonably necessary to handle the request and related operational, contractual or legal needs.
Where Nostro box j.d.o.o. acts as processor, deletion or return of personal data is additionally governed by the applicable Data Processing Agreement.
10. Browser storage and cookies
The Service may use strictly necessary browser/session storage mechanisms required to maintain authentication, security and account functionality. Hair Atelier AI does not currently use third-party behavioural advertising.
If non-essential analytics, advertising technologies or other non-essential cookies are introduced later, this Policy and any required consent mechanism will be updated before or when those technologies are enabled.
11. Your GDPR rights when we act as controller
Subject to the conditions and exceptions in applicable law, you may request access to your personal data, rectification, erasure, restriction of processing and data portability, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of earlier processing.
To exercise a privacy right concerning data for which Nostro box j.d.o.o. acts as controller, contact sales@nostroboxai.app. We may need to verify your identity before acting on a request.
Requests concerning a salon client's photograph
If your request concerns a photograph or other personal data submitted to Hair Atelier AI by a salon, the salon will normally be the controller responsible for handling your request. You should therefore contact the salon first.
If Nostro box j.d.o.o. receives a request relating solely to personal data processed on behalf of a Customer, we will ordinarily forward or refer the request to that Customer unless we are authorised or legally required to respond directly.
You also have the right to lodge a complaint with the Croatian supervisory authority, the Agencija za zaštitu osobnih podataka (AZOP), or another competent supervisory authority in the EU/EEA.
12. Automated processing
Hair Atelier AI uses automated AI processing to create visual hairstyle/color previews and may use automated analysis to estimate visible hair characteristics relevant to the requested consultation.
The Service does not use this processing to make decisions that produce legal effects or similarly significant effects about an individual within the meaning of Article 22 GDPR.
13. Children and photographs of minors
User accounts are intended for persons aged 18 or older and authorised professional/business users.
If a Customer uploads a photograph depicting a minor, the Customer is responsible for ensuring that it has the required parental/legal guardian authorisation, an appropriate lawful basis and any privacy information required by applicable law.
14. Security
We use technical and organisational measures designed to protect personal data in a manner appropriate to the risk, including authenticated access, access controls, credential protection, restricted administrative functions, protection of communications, service/infrastructure security controls and reasonable limitation of data retention.
No online system can guarantee absolute security. Customers are also responsible for the security of their own devices, networks, credentials and internal user-access procedures.
15. Free Trial and electronic acceptance records
A Free Trial may require an authorised user to expressly accept the Terms of Use, this Privacy Policy and the Trial Data Processing Terms before using the Service.
For that purpose, we may store the account/user identifier, acceptance timestamp and document version numbers. These records are used to administer the Trial and demonstrate the applicable terms accepted by the Customer.
16. Changes to this Policy
We may update this Privacy Policy as the Service, subprocessors, commercial model, legal requirements or processing activities change. The current version and effective date will be shown at the top of this page.
Where a material change requires renewed acceptance or additional notice under applicable law or the applicable contractual arrangement, we will provide that notice and/or request renewed acceptance.
17. Contact
Privacy questions and requests:
sales@nostroboxai.app
Nostro box j.d.o.o.
Jurja Ves III odv. 5, 10000 Zagreb, Croatia
OIB: 58661874766
This Policy describes the current Hair Atelier AI implementation and should be reviewed whenever the technical architecture, subprocessors, analytics, storage practices, account model or other material processing activities change.