Legal notice and privacy policy
In Spanish: aviso legal y política de privacidad — the details identifying the operator of christine.one, a description of what happens to your data when you open this website, and how we handle the data of Christine One Panel users.
Effective: 24 September 2026
1. The operator
Pursuant to Article 10 of Spanish Law 34/2002 (LSSI-CE):
- Company name
- CHRISTINES BEAUTY SL (sociedad unipersonal)
- Registered office
- Calle Hermosilla 48, Planta 1,
Puerta DC
28001 Madrid, Spain - CIF
- B26685115
- Commercial registry
- Registro Mercantil de Madrid, Hoja M-876395
- Telephone
- +34919939888
- hello@christine.one
The company above trades as Christine One. For the processing described in sections 3 and 4, the company is the data controller; the conversations with salons' clients are a different matter (see below).
2. What this website is for
The christine.one website presents the Christine One platform. It is not an online shop: you cannot buy or pay here, and no contract is concluded here. The prices shown on the website are for information only and do not constitute an offer.
3. What data this website processes
The short answer: as little as possible. The longer answer:
Cookies — none
This website does not place any cookies on your device, and does not use any identifier stored in your browser. That is also why no cookie banner appears: there is nothing for you to consent to.
Your browser remembers one thing only, and only if you ask it to: if you
choose a language in the language selector, it saves that one setting
(c1-lang) so that you see the website in that language next time
too. It does not identify you, it is not sent anywhere, and you can remove it
at any time by clearing your browser data.
Third parties
The website loads all of its resources (fonts, images, styles) from its own server. There is no embedded tracking code, no social media button, no advertising pixel.
If you submit the enquiry form, your browser connects to our own server (api.christine.one). Until you submit it, not even that happens.
Server logs
The hosting provider keeps a technical log of requests: IP address, timestamp, requested path, browser type (user agent). This is inherent in the operation of any web server, and serves to operate the service securely and to detect abuse.
- Legal basis: legitimate interest — operating the service securely (Article 6(1)(f) GDPR).
- Processor: Render Services, Inc.
If you contact us
The enquiry form is received by our own server, which forwards it by email to our mailbox. If you write directly to hello@christine.one, your email arrives in the same place.
- What data: what you provide — your name, the name of your business, email address and/or phone number, the booking system you currently use, and whether you are requesting a demo, asking a question or pre-registering.
- What we use it for: solely to reply to you and to arrange a demo. We do not send newsletters, and we do not pass your data on to any third party.
- Legal basis: replying to your enquiry, or taking steps prior to entering into a contract (Article 6(1)(b) GDPR).
- How long we keep it: for as long as our discussions continue, and for no more than one year after that. If a contract is concluded, for the period required by accounting legislation. On our server, the content of the form only waits in a queue until it is delivered, and is then deleted from there.
- Processors: our server runs in the European Union (Frankfurt, Germany) and is operated by Render Services, Inc.; our mailbox is provided by Namecheap, Inc. (United States). Your email therefore reaches a provider outside the European Union.
What this website does not do: it does not profile you, it does not take automated decisions about you, and it does not link your visit to any other data. Whatever you send in an email or through the form arrives in the mailbox described above.
4. Panel users
Salon staff work in the Christine One Panel: that is where they see the conversations and edit the knowledge base and the settings. We process the data this requires in our own right, as controller — it is not part of the processing we carry out on the salon's behalf.
- What data: the email address you sign in with through your Google account, and what Google passes on at sign-in (name, profile picture); the time, IP address and browser of each sign-in; and what you did in the Panel and when — for example taking over or answering a conversation, or changing the knowledge base. The content of messages does not go into this log.
- What we use it for: so that only people the salon has given access can sign in; so that it can be established afterwards who handled a conversation; and to prevent misuse.
- Legal basis: legitimate interest — running the service securely, keeping human interventions traceable and preventing misuse (Article 6(1)(f) GDPR).
- How long we keep it: your sign-in access and the Supabase account that goes with it while the access is active, and for up to 24 months afterwards; the log of actions in the Panel for 24 months. The session Supabase opens at sign-in is closed straight away; the time, IP address and browser of each sign-in are recorded in Supabase's technical log, which is available to us for up to 1 day. Exception: where an action is part of a record that has to be kept longer — recording a client's consent, for example — the email address of the person who recorded it is kept with that record.
- Who else processes it: sign-in is checked by Supabase, as our processor (SUPABASE PTE. LTD., Singapore; the service runs in the EU, in Frankfurt; the contract follows the EU's standard contractual clauses). When you sign in with Google, Google acts as an independent controller under its own terms. The Panel and the database are run by Render Services, Inc. in the EU (Frankfurt, Germany). Render keeps a technical log of every Panel request (IP address, time, requested path); Render also processes this data as an independent controller under its own terms, it is available to us for 14 days, and Render does not publish where it stores it. The nightly database backup is stored by Cloudflare, Inc., in a bucket held in the EU, encrypted with a key that stays with us.
- Who else receives it: the salon — it can download the Panel action log, including the email address of the person who performed each action, from the Panel.
5. Conversations with salon clients
An important distinction. In the Christine One service, the data from conversations with salons' clients is not processed by us in our own right: the controller of that data is the salon, and we act as a processor.
If you are a salon's client and want to know what happens to your data, that is described in the salon's own privacy notice — ask the salon for it, or look for it on the salon's own channels.
6. Your rights
In relation to data concerning you, you may request access, rectification, erasure and restriction of processing, object to processing, and request data portability (Articles 15–22 GDPR).
Write to hello@christine.one. We will reply within one month.
If you feel we have not acted properly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD, C/ Jorge Juan 6, 28001 Madrid, aepd.es), or with the supervisory authority of the country where you live.
7. Deleting your data
You can ask for deletion by email: hello@christine.one.
Tell us whose data it is: if you use Christine One as a salon, the salon's name and the WhatsApp number or Meta page you connected; if you work in the Panel, the email address you sign in with; if you wrote to us through the form on this website, the address you wrote from. Without that we cannot establish whose data is being asked about.
What we delete: the data belonging to your account and the conversations we handled on your behalf; and if you connected your WhatsApp through Meta's Embedded Signup, the access token we received that way. If we have to keep something — because the law requires it (invoices we have issued, for example), or because we keep the log of actions in the Panel for the period set out in section 4 — we will tell you what it is and for how long.
In backups, deleted data may still appear for up to 30 days; after that it is gone from there too.
If you connected through Meta's Embedded Signup, you can also withdraw our access yourself: in your Meta Business settings, disconnect Christine One. If we set the connection up by hand, ask us to end it at the address above. Disconnecting does not delete the data held here — that takes the email above.
If you are a salon's client: the controller of your conversation data is the salon, not us — we process it on the salon's behalf, as its processor. Ask the salon to delete it; if the salon asks us, we carry it out.
8. Intellectual property
The text, design, logo and images of this website are the property of CHRISTINES BEAUTY SL, or are used under a valid licence. Their use requires prior written permission.
9. Changes
If this notice is amended, the effective date above will change. We will send you the previous version on request.