Information on the GDPR

29. März. 2018 | von Anna-Lena Lewerenz

On May 25, 2018, the new data protection regulation will come into force and will replace the EU Data Protection Directive.
This regulation contains provisions for the protection of natural persons in the processing of personal data and for the free movement of such data.

We provide you with important information regarding the use of Belbo software as well as information about the measures and adjustments we have implemented. Please note that you should also obtain comprehensive information about the possible impact of the new General Data Protection Regulation on your business. You can find detailed information from the Federal Commissioner for Data Protection and Information Security (BfDI).

Belbo Measures:

Processing of Your Data by Belbo

Belbo Business Software GmbH processes customer data. These are users of the administration and cash register software. In your calendar's account settings, you will soon find the updated data processing agreement, which you can consent to electronically.

Data Requests by End Customers

  1. Every customer has the option to download all data stored about them using their email address or mobile number (Art. 15 GDPR). This includes not only name and contact information but also images, uploaded documents, and note fields. The form for downloading data will be accessible via the website https://belbo.com and in the online booking.
  2. If a customer requests data access, you will receive a notification at the location email address.
  3. If the customer has not provided an email address or mobile number and still wishes to retrieve their data from you in person, you can add a mobile number or email address with the customer's consent. The customer can then perform a data request via the website. If the customer does not wish to provide an email address or mobile number, you can also print the data in the Belbo calendar via the customer file and give it to the customer.
  4. The customer receives a ZIP file with all stored data. It is important that additionally created fields are also retrieved and the customer has access to all data belonging to their customer profile.

    Exception: You can mark additional fields as "trade secrets." These may only contain information that does not uniquely identify the customer and is performance-related. Examples include: color formulas (hairdresser), machine configurations (cosmetics), current strengths (EMS fitness).
    In the export, these fields are mentioned, but their content is not displayed.

  5. If you wish, you can also disable direct data requests by your customers. In this case, customers can express their desire for a data request in the online booking via a form. However, you must fulfill this request yourself. In this context, please strictly observe the legally prescribed processing period to avoid legal consequences.

Complete Deletion of Customer Data

  1. An important part of data protection regulations is the ability for customers to have their own data completely deleted. Any customer who has their own access can do this themselves in the online booking.
  2. Even if customers ask you as a service provider to delete their customer data, you have the option to perform a GDPR-compliant deletion in the respective customer file.
  3. If the cash register system is used, the data will continue to be stored in tax-relevant exports. However, additional, non-tax-relevant information such as date of birth and customer notes will be permanently removed.
  4. If you wish, you can also disable direct deletion by your customers. In this case, customers can express their desire for data deletion in the online booking via a form. However, you must fulfill this request yourself. In this context, please strictly observe the legally prescribed processing period to avoid legal consequences.

Approval for Data Storage Capture

  1. As of May 25, 2018, appointment entries with an email address will always trigger an email in which the customer is informed that their data is being stored digitally. The customer has the option to consent to this storage and will be informed that they can object to it at any time in the future.
  2. The fact that existing customers will also be notified when new appointments are stored as of May 25, 2018, complies with the legal basis.
  3. As long as the customer has not consented to storage, they will not receive any (further) reminder, confirmation, or marketing emails.

Approval for Sending Marketing Messages

  1. If you are unsure whether all marketing approvals collected by you so far comply with legal requirements, you can use the setup wizard in your Belbo calendar to request consent again. From May 25, customers will receive the consent-required storage information described above.
  2. SMS campaigns will also contain a link in the future allowing unsubscription. Since each SMS can only contain 160 characters, this means you will have approximately 30 fewer characters available and the campaign can become correspondingly expensive.
  3. In the future, marketing messages will only be possible through active customer acceptance: For customers without an email address, SMS campaigns will therefore not be possible in the future.
  4. For customers without an email address, we will provide a form from May 25 that must be signed by the customer. The scan can be uploaded in the respective customer profile. Only then can the customer receive marketing SMS.

Changes to Online Registration

Registration and appointment booking forms will be expanded by 2 fields:

  1. An expanded data protection field will be added and must be actively checked during registration and appointment booking (without registration) as before.
  2. Another field for receiving marketing messages will be established. You can generally disable this if you do not plan to send advertising messages.

Data Processing Information

  1. In your calendar's account settings, you can enter supplementary information about your data strategy. For example, if you regularly import exports of your customer data into third-party software, you should inform your customers about this.
  2. In the "Supplement to Data Protection Agreement" field, you can add your own supplementary information.

What happens to customers who object to data storage?

In this case, the data will be deleted and is no longer accessible to you and permanently deleted.

Exception for Belbo cash register system users: Since the customer leaves data that must be retained for tax purposes, the following data will not be deleted:

  1. Gender, name, and first name of the customer, provided an appointment took place or should take place.
  2. Complete appointment history and services performed as well as the employee who performed them.

However, the data mentioned in point (1) will no longer be findable by you, but only through:

  • explicitly clicking on a past appointment in the calendar
  • printing the cash register closing or monthly closing

What happens if I unlawfully conduct marketing campaigns with existing customers whose approval I do not have in writing?

With the entry into force of the GDPR, legal violations will be penalized much more severely than before. According to Art. 83 GDPR, for serious violations of the law, fines up to 4% of a company's annual turnover, or 20 million euros, are permitted, whichever is higher.

I am unsure whether all the marketing approvals I have collected so far comply with legal conditions. How can I ensure that all campaigns sent after May 25, 2018 are lawful?

In the GDPR assistant, you have the option to contact all customers with already activated marketing permission again. In the letter, your customers will have the option to update contact information or prevent the sending of messages with advertising content. This way, you can be sure that all future campaigns are sent only to customers who have explicitly consented to receiving them.

I have a customer status "Unpunctual Customer" and I add notes in the note field to inform my colleagues about the customer's behavior. Can the customer see this data in the request?

Your customers will be able to view all information you collect about them in future data requests. If you have previously stored data in your customer files that you believe should not be viewed by the customer, you must remove it. Please note that your customers already had the right to request their own data.

I want to ensure that my employees do not misuse customer data.

In the Belbo calendar, you have the option to grant or revoke different rights to each login. If you revoke the "Customer Database" right, your employees can enter appointments and view the names of the day's customers, but cannot access the entire customer database.
More on the topic of rights management can be found here.

General Notes on Belbo Use by Your Employees:

Customer Data: In the Belbo calendar, you have the option to create customer fields yourself. These then appear in each customer file and can be filled with the desired data. Typical examples of customer fields are birthday, address data, or industry-specific data such as color formulas (hairdresser), training progress (gym), or product line used (cosmetics). When creating and filling in these fields, please consider the principles mentioned above. This includes ensuring that this data does not fall under the prohibited data in Art. 9 Para. 1 GDPR. This includes information such as the customer's ethnic origin or sexual orientation.
Furthermore, you may only make data mandatory fields if it is necessary for the provision of your services.

Learn more about customer fields and mandatory fields in the Belbo Manual chapter.

In your company, many different employees often work with the Belbo calendar. Ensure that anyone in your company who has access to customer data is also familiar with the rules of the General Data Protection Regulation. To ensure that your employees handle your customer data carefully, you can have them sign a confidentiality agreement.

Further Notes:

Create a directory of companies that further process your customers' data. These must also work in compliance with the GDPR. Such companies include, for example, digital contact directories and email service providers, as well as Belbo Business Software GmbH.

Note from Belbo: We work with data processors in data processing. Without exception, they have committed to the rules of the GDPR. A complete list of these companies and their position on the GDPR can be found in the data processing agreement.

Ensure that you also use your employees' data in accordance with regulations. This includes, for example, the use of employee photos on your website or in online booking, which may only be done with the consent of the affected employee. To be safe, have a consent form signed.

Closing Remarks

We protect your data and your customers' data carefully and in compliance with the law. We also support you through meaningful technical measures in implementing legal regulations. Nevertheless, our measures and information can only address part of your business processes. Please thoroughly inform yourself about the new General Data Protection Regulation and ensure that your customers' and employees' data is processed correctly in your company.

Interested?

Get in touch with us if you have any questions or would like to take a closer look at Belbo.

Haben Sie Fragen zu unserem Angebot?

Melden Sie sich bei uns, wenn Sie nähere Informationen wünschen!

+49 30 5770 9641