UltraGuru CRM protects your personal data in accordance with the Swiss Federal Act on Data Protection (nFADP/nDSG) that entered into force on September 1, 2023, as well as international data protection standards.
This policy applies to all personal data processed by UltraGuru CRM for beauty and service professionals in Switzerland and internationally. We work in compliance with nFADP, GDPR (for EU clients), and other relevant data protection laws.
Data Controller & Processing Purposes
Who we are & why we process data
UltraGuru CRM (data controller) processes personal data to provide business management services: client management, appointment scheduling, payment processing, analytics and AI insights. We determine the purposes and means of processing in accordance with Art. 31 nFADP.
Legal basis for processing:
Contract performance (Art. 31 nFADP) - processing necessary to provide services
Legitimate interest (Art. 31 nFADP) - service improvement and security
Explicit consent (Art. 31 nFADP) - for marketing communications
Data Collection & Categories
What data we collect
We collect and process the following categories of personal data in accordance with the principle of data minimization (Art. 6 nFADP):
Account data
Name, email, phone, password (hashed), salon ID
Client data
Contact information, visit history, preferences, color formulas
In accordance with the Swiss Federal Act on Data Protection (nFADP), you have the following rights:
Right to information (Art. 19)
Obtain confirmation of processing and a copy of the data
Right to data portability (Art. 20)
Export data in a structured, machine-readable format
Right to rectification/erasure (Art. 21)
Request correction or deletion of inaccurate data
Right to restriction of processing (Art. 22)
Object to or limit the processing
Right to withdraw consent
Withdraw previously given consent at any time
Security Measures (Art. 7, 8 nFADP)
How we protect your data
We implement technical and organizational measures in accordance with Art. 7 (Data protection by design) and Art. 8 (Data protection by default) of nFADP:
Data encryption
AES-256 for data at rest, TLS 1.3 for transmission
Access control (RLS)
Row Level Security in PostgreSQL for tenant isolation
Audit logging
⚠ legalPages.privacy.sectionFour.message3Desc
Data Retention (Art. 6 nFADP)
Data retention periods
We retain personal data only for as long as necessary for the purposes of processing, in accordance with the principle of data minimization (Art. 6 nFADP):
Account data
Contract duration + 10 years
Client data
Until deletion + 3 years
Event logs
24 months
Financial documents
10 years (per Swiss CO)
International Transfers (Art. 16 nFADP)
International data transfers
In accordance with Art. 16 nFADP, we ensure an adequate level of protection when transferring data outside Switzerland:
Protection safeguards:
✓Transfer only to countries with adequacy decisions (EU/EEA, UK, Japan)
✓Standard contractual clauses (SCCs) for other countries