Legal

Privacy Policy

Information on the processing of personal data pursuant to Art. 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and the Italian Data Protection Code (Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018, “Codice Privacy”).

1. Controller (Titolare del trattamento)

Claudia Hofer, Le Clou | cosmetic artist
Strada Riva di Sotto 21/B, I-39057 San Paolo / Appiano (BZ)
VAT no. 03182110217 · Tax code HFRCLD99L66A952V
Email info@leclou.bz · PEC claudiahofer@pec.it
Phone +39 338 194 5746

No data protection officer (Responsabile della protezione dei dati, DPO) has been appointed, as the requirements of Art. 37 GDPR are not met.

2. Principles

Protecting your data matters to us. We process personal data exclusively in accordance with the GDPR and the Codice Privacy: lawfully, fairly, transparently, for specified purposes and limited to what is necessary (Art. 5 GDPR).

This website uses no cookies, no analytics or tracking tools and no advertising services. Our social media icons (Instagram and WhatsApp) are simple links: they are not embedded as plugins and only transfer data to the respective provider once you click them (see 3.3). Fonts are loaded locally from our own server; visiting the website therefore does not transfer any data to Google or other third parties, unless you actively load the Google Maps map or click an external link (see 3.3).

3. What data we process

3.1 Visiting the website (server log files)

Our website is served via the GitHub Pages service of GitHub, Inc. (see 4 and 5). When you visit the website, GitHub’s servers automatically record technical data transmitted by your browser:

Purpose: providing the website, ensuring stability and security, detecting and preventing misuse.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and error-free operation of the website).
Retention period: log files are stored by GitHub only for as long as necessary for these purposes and then deleted, unless they are needed to investigate a specific security incident. We ourselves have no access to these log files and do not evaluate them.

3.2 Contact by email, PEC, phone or WhatsApp

If you contact us, for example to book an appointment, a consultation or to request a gift voucher, we process the data you provide (e.g. name, email address, phone number, content of your message, preferred appointment).

Purpose: handling your enquiry, booking appointments, processing gift voucher orders.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract at your request); otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
Retention period: data is deleted once your enquiry has been fully dealt with. If a contract is concluded (e.g. purchase of a voucher or products), we keep tax and accounting records for the statutory period of 10 years (Art. 2220 Italian Civil Code, Art. 22 Presidential Decree No. 600/1973); the legal basis is then Art. 6(1)(c) GDPR.

WhatsApp: If you write to us via WhatsApp, your message, your phone number and your profile name are transmitted via the WhatsApp service of WhatsApp Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland). The content is end-to-end encrypted, but WhatsApp processes metadata (e.g. time of the message, phone number) and may transfer it to its parent company Meta Platforms Inc. in the USA. Using WhatsApp is voluntary; you can always reach us by email or phone as well. WhatsApp’s privacy policy applies to its processing: www.whatsapp.com/legal/privacy-policy-eea.

Note on health data: please do not send us health data by email, WhatsApp or phone (e.g. allergies, skin conditions, medication). Information required for a safe beauty treatment or Hypoxi session is recorded in person at the studio. We will inform you separately there about this processing of special categories of personal data (Art. 9 GDPR) and obtain your explicit consent where required.

3.3 Links to external services

On the contact page, our address links to Google Maps (route planning). A Google Maps map can also be displayed there. The map is not loaded automatically but only once you click “Show map”; it is then loaded from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). In particular, your IP address and technical data from your browser are transferred to Google, and Google may set cookies; a transfer to the USA is possible. The legal basis is your consent given by clicking (Art. 6(1)(a) GDPR), which you can withdraw at any time by reloading the page or not clicking. The same applies if you click the linked address and are redirected to Google’s website. Google is responsible for the data processing there; Google’s privacy policy applies: policies.google.com/privacy.

If you click on our phone number or email address, the corresponding app on your device opens. Processing by your phone or email provider is outside our control.

Instagram and WhatsApp: The footer of every page links to our Instagram profile and our WhatsApp contact. Both services are operated by Meta (Meta Platforms Ireland Limited or WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland). These are simple links, not embedded plugins: merely visiting our website does not transmit any data to Meta. Only when you click one of these links are you redirected to Instagram or WhatsApp; from then on Meta is responsible for the data processing, and a transfer to the USA is possible. Instagram’s privacy policy applies: privacycenter.instagram.com/policy.

Google reviews: In the footer of every page we link to our reviews on Google. The rating shown is written into our website and is not loaded from Google: simply visiting our website does not transfer any data to Google. Only when you click the link are you redirected to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); from then on Google is responsible for the data processing, and a transfer to the USA is possible. Google’s privacy policy applies: policies.google.com/privacy.

4. Recipients of data

Your data is not sold or passed on to third parties for advertising purposes. Only the following have access:

5. Transfers to third countries

Our hosting provider GitHub, Inc. is based in the USA. Data generated when you visit the website (see 3.1) may therefore be transferred to the USA. GitHub is certified under the EU-US Data Privacy Framework; this transfer is covered by the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR). Our email provider Namecheap, Inc. is also based in the USA. For emails to us (see 3.2), the basis is the EU standard contractual clauses (Art. 46(2)(c) GDPR), which form part of the data processing agreement (Data Processing Addendum) with Namecheap. Beyond that, a transfer to the USA is only possible if you use an external service yourself: if you load the Google Maps map, click a link to Google Maps, Instagram or WhatsApp, or write to us via WhatsApp. Google and Meta are certified under the EU-US Data Privacy Framework; these transfers are covered by the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR).

6. Obligation to provide data

Providing your data is voluntary. However, without contact details we cannot answer your enquiry or book an appointment.

7. No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

8. Data security

The website is transmitted over an encrypted connection (HTTPS/TLS). We take appropriate technical and organisational measures in accordance with Art. 32 GDPR to protect your data against loss, misuse and unauthorised access.

9. Your rights

You have the following rights towards the controller at any time:

To exercise your rights, an informal message to info@leclou.bz or by PEC to claudiahofer@pec.it is sufficient. We will respond within one month (Art. 12(3) GDPR).

Right to lodge a complaint

If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the Italian data protection authority (Art. 77 GDPR, Art. 141 et seq. Codice Privacy):

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma
www.garanteprivacy.it

10. Cookies

Information on the use of cookies can be found in our Cookie Policy.

11. Changes

We update this privacy policy when the website, our data processing or the legal situation changes. The version published here applies.

Last updated: 25 September 2026

Back to the home page