Skip to content

Trust & security

Your clients' data, handled with care.

Hosted in the EU, encrypted with a key unique to your business, and built around Croatian and EU rules.

Where your data lives. Three places, all in the EU.

  • App and database

    Hetzner, in the EU. Bookings, client records, stock and your settings are stored here.

  • Photos and files

    Scaleway, Amsterdam. Before-and-after photos, sealed consent PDFs and your exports, served through links that expire.

  • Email

    Scaleway, Paris. Confirmations, reminders and receipts to your clients are sent from here.

Where personal data is involved, we choose sub-processors for EU data residency.

Encrypted, per salon. One key for your business, and no one else's.

  • A key of your own

    Client data is encrypted with a key unique to your business, field by field, so the sensitive details are encrypted inside the database itself.

  • Encrypted in transit

    Every connection — the app, your booking page, the client portal — runs over TLS, and photos and exports are served through links that expire.

  • When a business closes

    Erasure is done by destroying the keys, so personal data can no longer be read. Records Croatian fiscal law requires us to keep stay, without readable personal details.

GDPR, built into the work. Not a folder of paperwork.

  • You are the controller

    You decide what goes into your records; we process it on your instructions. The data processing agreement is part of sign-up, accepted at the version you were shown.

  • Clients export their own data

    From the client portal, a client downloads their own data as an archive, without asking you for it (Art. 20).

  • Clients ask to be forgotten

    When a client asks to be forgotten, their identity is erased after a 30-day cooling-off period; your treatment records follow your retention policy (Art. 17).

  • Consents are sealed

    A signed consent keeps the exact text the client agreed to, sealed in a PDF record — a simple electronic signature under eIDAS.

Who can see what. You decide, down to the permission.

  • Custom roles

    Build roles from 60 permissions, so staff see only what you allow — the front desk need not see the money.

  • An audit log

    A log of who changed what, visible to administrators.

  • PIN on a shared tablet

    One shared tablet: staff switch with a PIN, and every sale is attributed to the right person.

Available on the Pro+ plan

Fiscal compliance. Receipts, cash book and JOPPD.

Receipts are fiscalised automatically with the Tax Administration (Porezna uprava): ZKI, JIR and QR code. You need your own FINA certificate. The cash book covers the blagajnički maksimum, the Odluka and the daily cash journal, and tips come out as a JOPPD file for your accountant.

How checkout works

Sub-processors.

We engage sub-processors for infrastructure, storage, email delivery and payment processing. They are bound by equivalent data-protection obligations and chosen for EU data residency where personal data is involved; payments are handled by Stripe and Revolut.

The current list is maintained as part of the data processing agreement, and you are told of intended changes before they happen.

Read the data processing agreement

Report a security issue.

Found something that looks wrong? Write to us with what you found and how to reproduce it, and we will come back to you by email.

info@f9.contact

Questions we get. Short answers.

See it on your own salon. Thirty days, no card.

Support in Croatian and English, from real people.