Skip to main content

Privacy Policy

Last updated: August 1, 2026

How Meeti Me processes personal data under the GDPR, including purposes, legal bases, recipients, retention periods and the rights of data subjects.

Introduction

This Privacy Policy explains how DOKUMENT.PL sp. z o.o. processes personal data in connection with the use of the Meeti Me platform, available at meeti.me, including the website, mobile applications, the salon dashboard and the related notification channels.

Meeti Me operates in two roles. First, it provides a subscription service (SaaS) to salons and other beauty industry businesses, which use it to manage their calendar, bookings and client communication. Second, it operates a public marketplace where individuals (Clients) search for salons and book appointments.

The platform acts solely as an intermediary in the booking process. The beauty, hairdressing or other service covered by a booking is provided by the salon and not by DOKUMENT.PL sp. z o.o.. Clients pay the salon directly for the service. Only subscription fees charged to salons are collected through the platform.

This has a direct bearing on data protection. In relation to user accounts, the operation of the platform itself, security, subscription billing and our own marketing activities, DOKUMENT.PL sp. z o.o. is the controller. In relation to data that a salon independently collects about its own clients in the course of its business (in particular client notes, the history of visits to that salon, preferences and arrangements concerning the service), the salon is the controller and DOKUMENT.PL sp. z o.o. acts as a processor under a data processing agreement concluded with that salon. Information on how a particular salon processes personal data can be found in that salon's own privacy policy.

This Policy is aligned with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and with the national data protection and electronic services legislation applicable under law of Poland.

Document version: 2026-08-01. Effective from: 2026-08-01.

Controller and contact details

The controller of personal data within the scope described in the "Introduction" section is:

  • Legal name: DOKUMENT.PL sp. z o.o.
  • Address: Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland
  • Tax identification number (NIP): 5242982251
  • Company register number (KRS): 0001055336
  • Statistical number (REGON): 526237551

Contact for data protection matters and the exercise of rights: meetime.company@gmail.com.

Contact for the data protection officer (DPO), where one has been appointed: meetime.company@gmail.com. Where no data protection officer has been appointed, all data protection requests should be sent to meetime.company@gmail.com and are handled by the controller's designated team.

Contact for technical and account support: meetime.company@gmail.com.

We handle data protection requests without undue delay and in any event within one month of receipt. Where requests are complex or numerous, that period may be extended by a further two months, in which case we will inform you of the extension and the reasons for it.

Categories of personal data

We process the following categories of personal data:

Account data. First name, surname or display name, email address, phone number, password stored only as a cryptographic hash (we never store passwords in plain text), interface language, region, avatar if uploaded, and the verification status of the email address or phone number.

Salon data (business account). Business name and registration details, location address, contact details of the person representing the salon, staff data entered by the salon for scheduling purposes, service catalogue, pricing and opening hours. Data relating to sole traders constitutes personal data and is covered by this Policy.

Booking data. Booking and appointment history, the selected salon, service and staff member, date and time, booking status, cancellations and reschedules, and messages exchanged in connection with a booking.

Salon notes about clients. Content entered by the salon in the client record. The salon is the controller of this data and is responsible for its scope and legal basis. Salons are contractually required not to enter special categories of data (including health data) into the system without a separate valid legal basis and without informing the client.

Consents and communication preferences. Records of marketing consent given or withdrawn, selected notification channels, cookie consent settings, and the date, scope and proof of each consent.

Payment data (salons). Subscription status, plan, payment history, data required to issue invoices, and transaction identifiers assigned by the payment provider. We do not store full payment card numbers or CVV codes. Card details are entered directly in the environment of the payment provider Stripe. We receive only limited data such as the card brand, the last four digits and the expiry date.

Technical and analytics data. IP address, device and session identifiers, browser type and version, operating system, language settings, referring page, product events (for example opening a screen or completing a booking), security logs and error logs.

Correspondence. The content of support requests, complaints and data protection enquiries, together with the history of our replies.

Providing data marked as mandatory is a condition for concluding and performing the contract for the electronic provision of services. Without that data we cannot create an account or process a booking. Providing any other data is voluntary.

Legal bases for processing

Every processing purpose relies on one or more of the legal bases set out in Article 6(1) GDPR:

Article 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract):

  • creating and operating user accounts and salon accounts,
  • handling the booking process, including transmitting the booking to the salon,
  • sending transactional notifications about a booking (confirmation, reminder, change, cancellation),
  • providing and billing the SaaS subscription to salons,
  • handling support requests relating to the use of the service.

Article 6(1)(a) GDPR (consent):

  • direct marketing carried out by DOKUMENT.PL sp. z o.o. through electronic channels (email, SMS, push, Telegram),
  • cookies and similar technologies other than strictly necessary ones, including product analytics,
  • processing of optional data that is not required to perform the contract.

Consent is voluntary and may be withdrawn at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Article 6(1)(c) GDPR (legal obligation):

  • keeping accounting and tax records relating to subscriptions,
  • responding to data subject requests and maintaining records of processing activities,
  • obligations arising from anti-abuse legislation and reporting obligations towards competent authorities.

Article 6(1)(f) GDPR (legitimate interests of the controller):

  • securing the platform, detecting abuse, preventing spam and attacks, and maintaining security logs,
  • establishing, exercising or defending legal claims,
  • internal statistical analysis and service improvement on aggregated data,
  • measuring satisfaction and handling complaints,
  • contacting salons about the ongoing business relationship and service maintenance.

Wherever processing is based on Article 6(1)(f) GDPR we carry out a balancing test, and you have the right to object as described in the section "Your rights".

To the extent that a salon enters data about its own clients into the system, the legal basis is determined by the salon as controller and DOKUMENT.PL sp. z o.o. processes that data solely on the salon's documented instructions in accordance with Article 28 GDPR.

Purposes of processing

We process personal data for the following purposes:

  1. Account management and authentication. Creating accounts, signing in, maintaining sessions, resetting passwords, verifying email addresses and phone numbers.
  2. Booking intermediation. Presenting salon offerings, accepting bookings, transmitting them to the selected salon, handling changes and cancellations, and maintaining the user's booking history.
  3. Transactional notifications. Informing users about booking status, reminding them of upcoming appointments, notifying them of changes made by the salon, and sending account security messages.
  4. Salon subscription management. Registering subscriptions, collecting payments through Stripe, handling renewals, plan changes, cancellations and refunds, and issuing accounting documents.
  5. User support. Answering enquiries, handling complaints and diagnosing technical issues.
  6. Security and abuse prevention. Detecting unauthorised access attempts, rate limiting, identifying fraudulent bookings and fake accounts, and maintaining logs.
  7. Product analytics. Understanding how the platform is used, measuring feature effectiveness and removing friction in the interface. Product analytics is activated only after consent has been given.
  8. Direct marketing. Informing users about new features, promotions and educational content, exclusively through channels covered by a separate consent.
  9. Legal obligations and claims. Retaining accounting records, defending against claims and cooperating with competent authorities to the extent required by law.

Notifications and marketing consent

Notifications fall into two mutually exclusive groups.

Transactional (service) notifications relate to the performance of the contract and to a specific booking or to account security. They include booking confirmations, appointment reminders, notices that a salon has changed or cancelled an appointment, alerts about sign-in from a new device, password change confirmations, and notices about changes to the terms of service or to this Policy. We send them on the basis of Article 6(1)(b) GDPR. They do not require marketing consent and cannot be switched off while the account remains active, because the service cannot be performed properly without them. You may, however, choose the channel through which they are delivered.

Marketing notifications cover commercial information, product news, promotions and educational content. We send them only after obtaining a separate, explicit consent, given individually for each channel. Marketing consent is never pre-ticked, is not a condition for creating an account or making a booking, and is not bundled with acceptance of the terms of service.

Available notification channels:

  • Email - delivered through Amazon SES.
  • SMS - delivered through a third-party SMS provider.
  • Push notifications - in the mobile application, after permission has been granted at operating system level on the device.
  • Telegram - an optional channel, activated only if you connect your account to the Telegram bot yourself. Once connected, we transmit the chat identifier and the notification content to Telegram.

You may withdraw marketing consent at any time, with the same ease with which it was given: in the notification settings of your account, using the unsubscribe link included in every marketing email, by using the relevant command in the Telegram bot, by disabling push notifications in your device settings, or by writing to meetime.company@gmail.com. We action withdrawals promptly and in any event within 72 hours. After withdrawal we retain only the record of the consent having been given and withdrawn, as evidence of compliance with a legal obligation.

Salons may send their own communications to their clients to the extent permitted by law. In such cases the salon is the controller and DOKUMENT.PL sp. z o.o. merely provides the technical tool. The salon is responsible for having an appropriate legal basis for such communications.

Recipients and processors

We disclose personal data only where necessary and only to the following categories of recipients:

Salons. Once a booking is made, we transmit to the salon the data necessary to fulfil it: first name and surname or display name, phone number, email address, the selected service, the appointment time and any notes added to the booking. The salon is a separate controller in respect of that data.

Processors acting on our instructions, under data processing agreements compliant with Article 28 GDPR:

| Provider | Purpose of processing | Scope of data | | --- | --- | --- | | Stripe | Processing salon subscription payments, invoicing, payment fraud prevention | Salon billing data, transaction amount and status, card details processed exclusively on Stripe's side | | Amazon Web Services (S3 and infrastructure) | Application hosting, file storage and backups | All platform data, stored in encrypted form | | Amazon SES | Delivery of transactional and marketing email | Email address, first name, message content, delivery status | | SMS provider | Delivery of SMS notifications | Phone number, message content, delivery status | | PostHog | Product analytics and platform usage statistics, only after consent has been given | Pseudonymised user identifier, product events, device data, truncated IP address | | Telegram | Delivery of notifications through the Telegram channel, only where the account has been connected by the user | Telegram chat identifier, notification content |

Professional advisers and service providers. Law firms, accounting firms and auditors, to the extent necessary for the services they provide to us and subject to confidentiality obligations.

Public authorities. Only on the basis of a legally binding request and within the scope of that request. We assess every request for its legal basis and proportionality.

We do not sell personal data. We do not share it with data brokers or advertising networks. Google Analytics, Facebook Pixel and Google Ads are not installed on the platform.

PostHog product analytics runs on infrastructure hosted within the European Union.

Transfers outside the EEA

We aim to store and process data within the European Economic Area. Application infrastructure, backups and PostHog product analytics are located in European regions.

To a limited extent, however, data may be transferred outside the EEA, in particular in connection with payment processing by Stripe, with technical support provided by supplier teams located outside the EEA, and in connection with the optional Telegram channel.

Every such transfer takes place only where an instrument ensuring an adequate level of protection under Chapter V GDPR is in place, namely:

  • a European Commission adequacy decision (Article 45 GDPR), where such a decision covers the country or certification mechanism concerned, or
  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Article 46(2)(c) GDPR), supplemented by a transfer impact assessment and by additional technical and organisational measures, including encryption of data in transit and at rest and minimisation of the scope of transferred data.

A copy of the safeguards in place, including the text of the Standard Contractual Clauses with commercially confidential information redacted, is available on request sent to meetime.company@gmail.com.

Retention periods

We retain personal data no longer than is necessary for the purpose for which it was collected:

| Category of data | Retention period | | --- | --- | | User account data | For as long as the account remains active. After account deletion, for 3 years and only to the extent necessary to establish, exercise or defend legal claims, after which the data is deleted or irreversibly anonymised | | Salon account data | For the term of the subscription agreement and thereafter for 3 years from its termination, for the purpose of defending against claims | | Booking history | For as long as the account exists and, after deletion, for 3 years limited to the data necessary to defend against claims. The copy of the booking held in the salon's own records is subject to the retention period determined by the salon as controller | | Salon notes about clients | Determined by the salon as controller. When the salon stops using the platform, the data is deleted or returned to the salon in accordance with the data processing agreement, and in any event within 90 days | | Accounting and tax records (subscriptions) | 5 years counted from the end of the calendar year in which the tax payment deadline fell, in accordance with the tax legislation applicable under law of Poland | | Evidence of marketing consent given and withdrawn | Until consent is withdrawn and thereafter for 3 years as evidence of compliance | | Analytics data (PostHog) | 14 months from the event, after which data is aggregated into statistical form that does not permit identification | | Technical and security logs | 12 months, unless a specific log is the subject of an ongoing investigation | | Support correspondence | 24 months from closure of the request | | Cookies | As set out in the Cookie Policy |

Once the applicable period has expired, data is deleted or irreversibly anonymised. Anonymised data may be used for statistical purposes without a time limit, as it no longer constitutes personal data.

Your rights

In connection with the processing of your personal data you have the following rights:

Right of access (Article 15 GDPR) - you may obtain confirmation as to whether we process your data and receive a copy of it, together with information about the purposes, categories, recipients and retention periods.

Right to rectification (Article 16 GDPR) - you may request correction of inaccurate data and completion of incomplete data. Most account data can be corrected directly in your settings.

Right to erasure, the right to be forgotten (Article 17 GDPR) - you may request deletion of your data, in particular where it is no longer necessary for the purposes for which it was collected, where you withdraw the consent that was the sole basis for processing, or where you successfully object to processing. This right does not apply to the extent that processing is necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

Right to restriction of processing (Article 18 GDPR) - you may request that operations on your data be suspended, for example while its accuracy is verified or while an objection is being considered.

Right to data portability (Article 20 GDPR) - for data processed on the basis of consent or a contract and by automated means, you may receive it in a structured, commonly used, machine-readable format (we provide exports in JSON and CSV) and transmit it to another controller. Where technically feasible, you may request that we transmit the data directly to another controller.

Right to object (Article 21 GDPR) - you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. In relation to direct marketing you may object at any time and without giving reasons, and we will then stop such processing entirely.

Right to withdraw consent (Article 7(3) GDPR) - you may withdraw consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right not to be subject to a decision based solely on automated processing (Article 22 GDPR) - described in the section below.

Right to lodge a complaint with a supervisory authority - described in the final section of this Policy.

To exercise any of these rights, write to meetime.company@gmail.com or use the relevant functions in your account settings. Exercising your rights is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee covering administrative costs or refuse to act, giving reasons in each case. To protect your data we may ask for additional information to confirm your identity where we have reasonable doubts as to the identity of the person making the request.

Automated decision-making and profiling

We do not take decisions in relation to you that are based solely on automated processing, including profiling, and that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

We do not carry out automated profiling of users for marketing purposes, we do not build behavioural profiles for advertising, and we do not transmit data to advertising networks.

The platform uses only simple, deterministic automated mechanisms, such as sorting salon search results by distance, availability or rating, sending appointment reminders at a fixed interval, and applying security rules that limit the number of requests from a single IP address. These mechanisms do not produce legal effects and do not constitute automated decision-making within the meaning of Article 22 GDPR.

If in the future we introduce a solution falling within Article 22 GDPR, we will inform you in advance, explain the logic involved and provide the right to obtain human intervention, to express your point of view and to contest the decision.

Security

We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR, in particular:

  • encryption of data in transit using TLS and encryption of data at rest, including backups,
  • storage of passwords solely as salted hashes generated with a modern hashing function,
  • role-based access control and the principle of least privilege, with multi-factor authentication for administrative access,
  • separation of production, staging and development environments, with no real personal data used in non-production environments,
  • regular backups together with restore testing,
  • logging and monitoring of security events, anomaly detection and rate limiting,
  • periodic access reviews, staff training and confidentiality undertakings,
  • due diligence on processors before entrusting data to them, and data processing agreements compliant with Article 28 GDPR,
  • a personal data breach management procedure.

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we notify the supervisory authority without undue delay and in any event within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we also notify the affected data subjects.

No method of transmitting or storing data is completely secure. Please use a unique, strong password, do not share your login credentials with third parties, and report any suspected unauthorised access immediately to meetime.company@gmail.com.

Children

The Meeti Me platform is intended for persons aged 16 and over. We do not direct the service to children below that age and we do not knowingly collect their personal data for the purpose of creating an account.

If a person under the age of 16 has created an account, a legal guardian may report this to meetime.company@gmail.com. Once the report has been verified, we will promptly delete the account and the associated data, except where retention is required by law.

Where the law applicable under law of Poland provides for a different, lower age threshold for the validity of consent in relation to information society services, we apply the threshold arising from that law, which will not be lower than 13 years.

An appointment for a minor may be booked by a legal guardian from the guardian's own account. In that case the guardian is responsible for the scope of the data provided in the booking.

Cookies and similar technologies

On the Meeti Me websites and applications we use cookies and technologies with similar effect, including browser local storage.

Cookies other than strictly necessary ones, including analytics cookies, are loaded only after prior consent has been given. Before consent is given, no scripts other than those necessary for the operation of the service are executed. You may withdraw consent at any time, with the same ease with which it was given, using the "Cookie settings" link available in the site footer.

A detailed list of cookies, their purposes and retention periods is set out in the separate Cookie Policy.

Changes to this Privacy Policy

We may update this Policy in response to changes in how the platform operates, changes in legislation, or changes in the set of processors we use.

We will give at least 14 days' advance notice of material changes, in particular those affecting the purposes of processing, legal bases, categories of recipients or retention periods, by email to the address associated with your account and by a notice within the service. Editorial and housekeeping changes are published without prior notice.

The current version of the Policy is always available at meeti.me. Each version is identified by the version number 2026-08-01 and the effective date 2026-08-01. Previous versions are available on request sent to meetime.company@gmail.com.

A change to this Policy does not provide a basis for processing data for purposes that require consent where such consent has not been given.

Complaint to a supervisory authority

If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority in accordance with Article 77 GDPR.

You may lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority competent for your region is:

  • Supervisory authority: Prezes Urzedu Ochrony Danych Osobowych (UODO)
  • Address: ul. Stawki 2, 00-193 Warszawa, Poland
  • Website: uodo.gov.pl

Independently of any administrative complaint, you have the right to an effective judicial remedy in accordance with Article 79 GDPR. The competent courts are courts competent for the seat of the operator, without prejudice to the consumer right to sue at their place of residence, and you may also bring proceedings before the courts of the Member State where you have your habitual residence.

We encourage you to contact us at meetime.company@gmail.com or meetime.company@gmail.com before lodging a complaint. Many matters can be clarified and resolved directly and more quickly.

Binding language version

This document has been prepared in the following language versions: Polish (pl), English (en) and Ukrainian (uk).

For the PL (Poland) region, the Polish (pl) language version of this document is binding. For the EU (other European Economic Area countries) region, the English (en) language version is binding. The Ukrainian (uk) version is provided for information and convenience only. In the event of any discrepancy, the version binding for the relevant region prevails.