Privacy Policy
Last updated: 2026-07-19 · Version: Beta 1.0
This privacy policy explains how personal data is processed on the DEK platform under the General Data Protection Regulation (GDPR) and the laws of the Republic of Lithuania.
1. Data controller
The data controller is Majevski, MB, legal entity code 304720404, address Smalinės g. 21-3, LT-06225, Vilnius, Lietuva. For privacy questions or to exercise your rights, contact pagalba@majevski.com.
2. Who this policy applies to
This policy applies to: (a) business users who create and use a DEK account; (b) clients who create a DEK identity account (see section 7); and (c) website visitors. When a business (User) processes its own clients' data through the Service, the User is the controller of that data and Majevski, MB acts as a processor (see section 4 and the Data Processing Agreement). In that case information about the processing is provided by the User in its own privacy notice.
3. What data we collect and on what basis
- Account data (business name, your name, email, phone): processed to perform the contract (the Terms of Service). This data is necessary to enter into the contract and provide the Service; without it, an account cannot be created or the Service used.
- DEK identity data (client's first name, last name, email, phone, image): processed to perform the contract, so the client can manage their account and bookings (see section 7). The image is optional.
- Client (business clients') data: processed as a processor on the User's instructions; the legal basis is set by the User.
- Usage and technical data (logs, device and browser info, feature usage): processed on the basis of legitimate interest, to ensure security, quality and improvement of the Service (see section 5).
- Delivery data (whether a sent email reached the recipient and whether our own link in it was clicked): processed on the basis of legitimate interest, to make sure clients receive visit information. We do not use tracking pixels and do not record whether an email was opened.
- Payment data: card data is processed directly by Stripe; we see only payment status and metadata, which we process to perform the contract and to meet a legal (accounting) obligation.
- Consents (e.g. for cookies or notifications): processed on the basis of consent.
4. Who we share data with (processors)
We share data only with trusted providers, to the extent necessary to provide the Service:
- UAB "Interneto vizija": server hosting. Data is stored on servers in Lithuania, Vilnius.
- Stripe: payment processing. Card data is processed and stored directly by Stripe, as a financial institution, not by DEK.
- 1e.lt (Mailwizz): sending emails and newsletters.
- asms.lt: sending SMS via the User's connected account and device.
- calendar.lt: public holiday and name-day data (no personal data is shared).
We do not sell data or share it with third parties for marketing. We may disclose data to competent authorities where required by law.
5. Usage analytics (during Beta)
While the Service is provided as a Beta version, we collect usage data (which features are used, error and performance information) to improve the Service, fix bugs and ensure security. This analytics is processed on the basis of legitimate interest. Because it is necessary to provide and secure the Service during Beta, we consider our interest in a functioning, secure Service to be overriding. You have the right to object to the processing (see section 10); in that case we assess whether we can meet the request without discontinuing the Service. The data is used only for internal improvement and is not sold.
6. Where data is stored and transfers
Primary data is stored on servers in Lithuania (UAB "Interneto vizija"), in the European Union. Some processors (e.g. Stripe) may process data outside the European Economic Area; in such cases transfers are made under appropriate safeguards (e.g. the European Commission's Standard Contractual Clauses). You can request a copy of those safeguards by contacting pagalba@majevski.com.
7. Client accounts and the DEK identity layer
When a client verifies a contact with a one-time code (OTP) and creates a DEK account, DEK becomes the controller of that person's basic identity data only: first name, last name, email, phone and image. We initially receive that contact (email or phone) from the salon (User) that entered your booking, in order to send the verification code; the source of that contact is the salon you visited. This lets the client reuse the same details across salons and manage their own bookings and history. We store no password: sign-in is a fresh one-time code each time.
The salon (User) remains a separate controller of its own relationship data: notes, custom fields (for example hearing-device data), visit history and consent. That data is never shared between salons. Consenting to one salon's newsletter is not consenting to another's.
A client can view, correct or delete their DEK identity from their account at any time. Deleting the identity unlinks it from the salons but does not delete the salons' own records: each salon stays a separate controller with its own retention duty.
As part of this identity layer, DEK also computes a reliability score: the share of booked visits a client actually attended, counting no-shows and last-minute (under 24 hour) cancellations as missed. Each salon always sees the score for its own bookings; premium salons additionally see a cross-salon average, shown only as a single aggregate percentage that never reveals which salons a client visited or what happened at any one of them. The client can see this score in their own account. It is provided as guidance for the salon and is not an automated decision (see section 9). The basis is our and the salons' legitimate interest in reducing no-shows; you may object under section 10.
8. Retention
- We keep account and related data while you use the Service. On account closure, data is deleted or anonymised within 30 days, unless longer retention is required by law (e.g. accounting records).
- Retention of Client (business clients') data is set by the User as controller.
- We keep usage and technical logs for up to 12 months, after which they are deleted or aggregated.
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you. The client reliability score (section 7) is an informational aid only: it does not by itself refuse or change a booking, and any decision remains with the salon.
10. Your rights
Under the GDPR you have the right to: access your data; rectify it; erase it ("right to be forgotten"); restrict or object to processing; port your data; and withdraw consent (which does not affect the lawfulness of processing carried out before withdrawal). To exercise these rights, contact pagalba@majevski.com. Note: for data controlled by a User (a business), contact that User directly.
- You can export your account and client data at any time.
- Clients can opt out of notifications via their consent settings or a link in the email.
If you believe your data is processed improperly, you have the right to lodge a complaint with a supervisory authority, in Lithuania the State Data Protection Inspectorate (VDAI, vdai.lrv.lt).
11. Security
Data is transmitted over encrypted HTTPS. Sensitive data (e.g. asms.lt keys) is stored encrypted. Access is restricted and backups are taken regularly. However, during Beta we cannot guarantee complete security or uninterrupted operation.
12. Cookies
We use essential cookies for login and language selection, and analytics or marketing cookies, if any, only with your consent. See the Cookie Policy for details.
13. Changes and contact
We may update this policy; we will notify you of material changes. For questions, contact pagalba@majevski.com.