Privacy Policy

Zolmi Privacy Notice

Last updated: 17 August 2026

This Privacy Notice explains how Umov sp. z o.o. ("Umov", "Zolmi", "we", "us" or "our") collects, uses, discloses and protects personal information in connection with the Zolmi websites, mobile applications and salon and appointment-management services (together, the "Services").

This Notice applies to Zolmi business customers, their authorised users, visitors to Zolmi websites and people who contact Zolmi. It also explains how we process information that a business customer stores in Zolmi about its clients and staff.

This Notice is not a contract, and use of the Services is not treated as consent to every type of processing described below. Where consent is required, we request it separately.

This Notice covers Zolmi-branded Services. The Belliata consumer marketplace and consumer application involve different processing activities and are covered by the applicable Belliata privacy notice.

1. Who we are

The operator of Zolmi is:

Umov sp. z o.o.
ul. Nowogrodzka 31/220
00-511 Warsaw, Poland
Email: support@zolmi.com

For privacy enquiries, please contact the Umov Privacy Team using the email address above.

2. Our role and the business customer's role

Zolmi performs different roles depending on the information and the purpose for which it is processed.

2.1 Umov as controller

Umov is a controller of personal information used for its own business purposes, including:

  • creating and administering Zolmi business accounts;

  • managing authorised-user access and authentication;

  • processing subscriptions, billing and invoices;

  • providing support, onboarding and training;

  • maintaining the security and reliability of the Services;

  • analysing how the Services are used and improving them;

  • communicating with business customers and authorised users;

  • marketing Zolmi, subject to applicable law and communication preferences; and

  • complying with legal obligations and establishing, exercising or defending legal claims.

2.2 Umov as processor or service provider

When a salon, spa, clinic or other business customer uses Zolmi to enter or manage information about its clients or staff ("Customer Data"), that business customer normally determines why and how the information is used. The business customer is therefore the controller or business responsible for that Customer Data, and Umov processes it as a processor or service provider on the customer's instructions.

The business customer is responsible for providing appropriate privacy information to its clients and staff and for having a valid legal basis for collecting and using Customer Data. Umov remains responsible for fulfilling its own duties as a processor or service provider, including protecting Customer Data and processing it only as permitted by our agreement with the business customer and applicable law.

If your request concerns information held in a Zolmi client record by a particular business, you should normally contact that business first. We will assist the business with the request as required by applicable law and our agreement with it.

3. Information we collect

Depending on how you interact with Zolmi, we may collect the following categories of information.

3.1 Account and contact information

  • name;

  • business email address and telephone number;

  • postal or billing address;

  • account and user identifiers;

  • authentication information and account-access records;

  • job title, role, permissions and relationship with a business customer; and

  • communication and marketing preferences.

3.2 Business and staff information

  • business name, location, contact details and operating information;

  • services, prices, working hours and appointment availability;

  • staff names, contact details, schedules, permissions and services performed; and

  • information required to configure and administer the business account.

Some staff information is Customer Data processed on behalf of the business customer. Information used by Umov to manage an authorised user's Zolmi access may also be processed by Umov as controller.

3.3 Client and appointment information

Business customers may choose to store Customer Data such as:

  • client names, email addresses, telephone numbers and other contact details;

  • appointment history, services, preferences, cancellations and attendance information;

  • notes, consultation responses, consent records and electronic signatures;

  • photographs, images and files uploaded by the business customer or its client;

  • allergies, health-related information, treatment information or other sensitive information entered into a digital form or free-text field;

  • marketing preferences and consent records; and

  • payment status, deposits, amounts and transaction references, but not complete payment-card numbers.

The exact content is determined by the business customer. Zolmi does not require business customers to collect more information than is necessary for their legitimate business and legal purposes.

3.4 Subscription and transaction information

  • subscription plan and billing cycle;

  • billing contact and address;

  • invoices, amounts, currency, tax information and payment status;

  • Stripe customer, subscription, payment or transaction identifiers; and

  • tokenised or limited card information made available by Stripe, such as card brand, expiry information or the last four digits. Umov does not receive complete card numbers or card security codes.

3.5 Support and communications information

We collect communications sent through email, Zolmi support channels and live chat, including contact information, message content, attachments, support history, onboarding information and feedback. We use User.com and other communication tools to manage business contacts, consultations and support conversations.

3.6 Device, log and usage information

When you use the Services, we may automatically receive:

  • IP address and approximate location derived from it;

  • browser, operating system, device type and device identifiers;

  • application version, language and time-zone settings;

  • login times, pages or screens viewed, features used and interactions with the Services;

  • error, diagnostic, performance and security logs; and

  • cookie and similar-technology information described in our Cookie Policy.

We do not collect precise device location unless a particular feature requires it and you have enabled the relevant permission.

4. How we obtain information

We obtain personal information:

  • directly from business customers and authorised users;

  • from a business customer about its staff and clients;

  • from a client who completes a form or interacts with an online-booking function provided by a business customer;

  • automatically through websites, applications, cookies, logs and similar technologies;

  • from payment, communication and integration providers; and

  • from other people or organisations where they are authorised to provide the information or where collection is otherwise lawful.

5. How and why we use personal information

Where the GDPR, UK GDPR or similar law applies, our principal purposes and legal grounds are:

Purpose

Principal legal basis

Create and administer business accounts and provide the Services

Performance of a contract; legitimate interests in providing the Services to authorised users

Authenticate users and manage roles and permissions

Performance of a contract; legitimate interests in access control and account administration

Process subscriptions, payments and invoices

Performance of a contract; compliance with tax, accounting and other legal obligations

Provide customer support, onboarding and training

Performance of a contract; legitimate interests in assisting customers and improving service quality

Deliver appointment emails, SMS messages and other communications configured by a business customer

Processing on the business customer's instructions; performance of the Services

Secure, troubleshoot and maintain the Services

Legitimate interests in preventing misuse, fraud and security incidents and maintaining reliable Services; legal obligations where applicable

Analyse use and improve Zolmi

Legitimate interests in understanding and improving the Services; consent where required for cookies or similar technologies

Send Zolmi marketing communications

Consent where required; otherwise legitimate interests, subject to the right to object and applicable direct-marketing law

Comply with law and handle disputes or claims

Compliance with legal obligations; legitimate interests in protecting our legal rights

When Umov processes Customer Data as a processor or service provider, the business customer determines the applicable legal basis. We process the information according to the customer's documented instructions and the applicable Data Processing Addendum.

We do not use salon Customer Data for third-party behavioural advertising.

6. Digital forms, photographs and sensitive information

Zolmi enables business customers to create digital forms and upload photographs, documents and other information of their choice. These fields may contain health information, allergy information or other information treated as sensitive or specially protected under applicable law.

The business customer decides which fields to create, which information to request and how the information will be used. The business customer must ensure that the collection is necessary, proportionate and supported by an appropriate legal basis and, where required, an additional condition for processing sensitive information.

Umov processes this information only to provide, secure and support the Services, on the business customer's instructions, unless we are required by law to do otherwise. Business customers should not enter complete payment-card details, government identification numbers or information that is unnecessary for the services they provide.

7. Payments

Zolmi subscriptions are paid in advance on a monthly or annual basis and are processed by Stripe. Payment-card details are entered into Stripe's payment environment. Umov receives a token and limited billing and transaction information necessary to administer the subscription, reconcile payments, issue invoices and manage payment failures. Umov does not receive or store complete payment-card numbers or card security codes.

Stripe processes information under its own contractual and privacy terms and may act as an independent controller for some activities required by financial, anti-fraud or regulatory law.

8. When we disclose personal information

We may disclose personal information in the following circumstances.

8.1 Infrastructure and service providers

We use providers that process information for hosting, backup, payment processing, transactional email, SMS delivery, customer support, analytics, security and related operational purposes. Our principal providers include:

  • Hetzner for primary server and database infrastructure in Germany;

  • Amazon Web Services (AWS) for backup storage in the United States;

  • Stripe for subscription and payment processing;

  • Mailgun for transactional email delivery;

  • Sinch for SMS and communications delivery; and

  • User.com for business-contact management, consultations, live chat and customer support.

These providers receive only the information reasonably required for the relevant service and are subject to contractual and confidentiality obligations as applicable. More information about providers that process Customer Data may be provided in our Subprocessor List or Data Processing Addendum.

8.2 Business customers and authorised users

Information may be made available to the business customer that controls the relevant venue and to its authorised staff according to the permissions configured within Zolmi.

8.3 Integrations and customer instructions

If a business customer enables an integration or directs us to transmit information to another service, we may disclose the information required to provide that integration. The third party's own terms and privacy notice may also apply.

8.4 Professional advisers, authorities and legal disclosures

We may disclose information to professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies or other authorities where reasonably necessary to comply with law, respond to a valid legal request, protect the Services or establish, exercise or defend legal claims.

8.5 Business transactions

Information may be disclosed in connection with a proposed or completed merger, financing, restructuring, acquisition or sale of all or part of our business or assets. We will take reasonable steps to require the recipient to protect the information and use it consistently with applicable law.

8.6 Aggregated or anonymised information

We may use and disclose information that has been aggregated or irreversibly anonymised so that it no longer identifies an individual. Anonymised information is not personal information under many privacy laws.

9. International processing and transfers

Zolmi's primary application and database infrastructure is hosted by Hetzner in Germany. Backup copies are also stored using AWS infrastructure in the United States. Other providers may process information in the European Economic Area, the United Kingdom, the United States or other countries in which they or their approved subprocessors operate.

When personal information protected by European data-protection law is transferred to a country that has not been recognised as providing adequate protection, we use an approved transfer mechanism where required, such as the European Commission's Standard Contractual Clauses. For restricted transfers governed by UK or Swiss law, we use the corresponding approved addendum or other lawful safeguard where required.

For information originating in Canada, Australia, New Zealand, the United Arab Emirates or another jurisdiction with cross-border requirements, we take reasonable contractual and organisational measures intended to maintain appropriate protection and comply with applicable transfer or overseas-disclosure requirements.

You may contact the Umov Privacy Team for more information about the safeguards relevant to your information.

10. Data retention and deletion

We retain personal information only for as long as reasonably required for the relevant purpose, our contractual obligations and applicable legal requirements.

10.1 Active and dormant venue accounts

  • Customer Data is retained while the venue account is active.

  • If a subscription ends or payment stops without the venue being deleted, the account may be placed into dormant or blocked status. Customer Data may be retained in recoverable form for up to 12 months so the business customer can reactivate the account, unless earlier deletion is requested or longer retention is required by law.

  • After the dormant period, Customer Data is deleted or irreversibly anonymised, subject to limited legal records and backup rotation.

10.2 Venue deletion requests

A business customer may request deletion through its Zolmi profile. Following a valid deletion request, we delete the venue's Customer Data from active systems within seven days, unless particular information must be retained by law or is reasonably required for the establishment, exercise or defence of legal claims.

Residual copies may remain temporarily in restricted backup systems until they are overwritten through the applicable backup cycle. Backups are maintained for security and disaster recovery, are not used for ordinary business purposes and, if restored, remain subject to the original deletion request.

10.3 Other retention periods

  • Subscription, invoice, tax and accounting records are generally retained for up to six years, or longer where required by applicable law.

  • Support communications are retained for the time needed to resolve the request and afterwards for a limited period where required for service history, complaints, security or legal claims.

  • Security and technical logs are retained for a limited period based on their purpose, sensitivity and operational need.

  • Marketing suppression records may be retained for as long as necessary to ensure that an opt-out continues to be respected.

  • Irreversibly anonymised statistical information may be retained indefinitely.

11. Cookies, analytics and marketing communications

Zolmi websites use cookies and similar technologies for essential operation, preferences, analytics and, where enabled, marketing. Non-essential technologies are used only according to the choices presented through our consent-management tool and as required by applicable law. Further information is available in our Cookie Policy.

You may opt out of Zolmi marketing emails by using the unsubscribe link in the message or contacting us. Service, billing, security and support communications are not marketing and may still be sent where necessary.

Business customers are responsible for ensuring that marketing messages sent to their clients through Zolmi comply with applicable consent, opt-out and direct-marketing rules. Umov processes the relevant contact and preference information on the business customer's instructions.

12. Data security

We use reasonable technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls, authentication controls, encrypted transmission where appropriate, backups, monitoring and restrictions on personnel access based on business need.

No internet-based service can guarantee absolute security. Business customers and authorised users are responsible for protecting their login credentials, configuring staff permissions appropriately and notifying us promptly of suspected unauthorised access.

13. Your rights and choices

Depending on your location and applicable law, you may have the right to:


  • request access to personal information about you;

  • request correction of inaccurate or incomplete information;

  • request deletion of information;

  • object to or request restriction of certain processing;

  • receive certain information in a portable format;

  • withdraw consent where processing is based on consent;

  • opt out of direct marketing;

  • request information about international transfers or recipients;

  • complain about our handling of personal information; and

  • lodge a complaint with an applicable privacy or data-protection authority.

These rights may be subject to conditions and lawful exceptions. We may request information reasonably necessary to verify your identity and protect information against unauthorised disclosure.

For information Umov controls, submit a request to support@zolmi.com. For Customer Data controlled by a salon or other business customer, contact that business first. If you contact us, we may forward the request to the relevant business and assist it in responding.

14. Additional regional information

14.1 European Economic Area, United Kingdom and Switzerland

Individuals may exercise the rights described above under the GDPR, UK GDPR or Swiss Federal Act on Data Protection, as applicable. You may complain to the supervisory authority in the country where you live or work or where you believe an infringement occurred. Umov's lead supervisory authority in Poland is the President of the Personal Data Protection Office (UODO). UK residents may contact the Information Commissioner's Office, and Swiss residents may contact the Federal Data Protection and Information Commissioner.

14.2 Canada

You may request access to and correction of your personal information, withdraw consent subject to legal or contractual restrictions and challenge our compliance through the Umov Privacy Team. You may also complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy authority. Information may be processed outside Canada, including in Germany and the United States, where it may be subject to local law.

14.3 Australia

You may request access to or correction of personal information and submit a privacy complaint to the Umov Privacy Team. We will investigate and respond within a reasonable period. If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner. Information may be disclosed to or processed by recipients located in Germany, the United States and other countries identified in our provider information.

14.4 New Zealand

You may request access to or correction of your personal information and raise a concern with the Umov Privacy Team. You may also complain to the Office of the Privacy Commissioner of New Zealand. Information may be processed outside New Zealand, including in Germany and the United States, subject to the safeguards described above.

14.5 United Arab Emirates

Subject to applicable UAE data-protection law, you may have rights to obtain information about processing, access and correct information, request deletion or restriction, object to certain processing, withdraw consent and request transfer of information. You may also complain to the competent UAE data-protection authority. Different rules may apply in the Dubai International Financial Centre or Abu Dhabi Global Market.

14.6 United States

Residents of certain US states may have additional rights concerning access, correction, deletion, portability and certain disclosures or uses of personal information. Where those laws apply to Umov, requests may be submitted to support@zolmi.com. We do not sell salon Customer Data for our own commercial purposes. Website analytics and marketing technologies are governed by the choices available through our cookie controls and applicable law.

15. Information about minors

Zolmi is a business-management service and is not directed to children as independent Zolmi account holders. A business customer may nevertheless enter information relating to a minor when providing an appointment or service, where this is lawful and appropriate.

The business customer is responsible for determining the appropriate legal basis, providing required information and obtaining parental or guardian authorisation where required. Umov processes such information as Customer Data on the business customer's instructions.

16. Changes to this Notice

We may update this Notice to reflect changes to the Services, our processing practices or applicable law. We will publish the updated Notice with a revised “Last updated” date. Where required, we will provide additional notice of material changes through the Services, by email or through another appropriate channel.

17. Contact and complaints

Questions, requests and complaints may be submitted to:

Umov Privacy Team
Umov sp. z o.o.
ul. Nowogrodzka 31/220
00-511 Warsaw, Poland
Email: support@zolmi.com


Please include enough information for us to identify the relevant account or venue and understand your request. Do not send passwords, complete payment-card information or unnecessary sensitive information by email or live chat.