1. Controller and contact
Elaheh Ostad — Glissèa Laser, Mißler Str. 1, 28211 Bremen, +49 (0) 171 218 64 27, info@glissealaser.de. Privacy requests may be sent to info@glissealaser.de.

This notice explains how personal data is handled on the website, in customer accounts and when appointment requests are submitted.
Last updated: 30 August 2026Elaheh Ostad — Glissèa Laser, Mißler Str. 1, 28211 Bremen, +49 (0) 171 218 64 27, info@glissealaser.de. Privacy requests may be sent to info@glissealaser.de.
We process technical access and security data, your cookie/analytics choice, and—when you request an appointment—your name, telephone number, email, requested service, date, time range, preferred contact method and optional note. Customer accounts involve name, email, sign-in data, provider identifier and email-verification status. Google sign-in gives Firebase the identity data supplied by your Google account.
Website delivery and security rely on legitimate interests (GDPR Art. 6(1)(f)). Appointment data is used to answer your request and take pre-contractual steps (Art. 6(1)(b)); where the interface also asks for consent, it can be withdrawn (Art. 6(1)(a)). Account data provides the account function you requested (Art. 6(1)(b)). Google Analytics runs only with consent (Art. 6(1)(a)). Mandatory records rely on legal obligations (Art. 6(1)(c)).
Vercel hosts the website. Firebase/Google handles accounts and authentication. The configured SMTP/email provider delivers appointment requests to the studio and a receipt to you. Google processes analytics data after consent. Meta processes messages if you choose WhatsApp. Data is not sold. Providers may process data outside the EEA; the production regions, contracts and transfer safeguards still need confirmation from the controller accounts.
The website does not store an appointment request in its own database; it is delivered by email and retained according to operational correspondence, appointment and legal-record needs. Firebase account data remains until account deletion or until no longer needed. Security logs and analytics follow configured provider periods. Exact production deletion periods still require confirmation. Data no longer needed is deleted or anonymised, subject to legal duties.
We use HTTPS, server-side validation and length limits, an anti-bot field, restricted Firebase authentication and access-controlled operator accounts. Email and internet services are not risk-free, so absolute security cannot be guaranteed.
The accepted/rejected choice is stored locally in your browser as glissea_analytics_consent_v1. Google Tag Manager GTM-WXQFXX2M and Google Analytics G-SS7R3QL7BB load only after acceptance and then collect page/device information and contact-click events. You can reset the choice through Cookie settings in the footer. Firebase may use technically necessary browser storage for sign-in.
Subject to the GDPR, you may request access, correction, deletion, restriction, portability and object; withdraw consent at any time for the future; and complain to a competent data-protection authority. Contact info@glissealaser.de. We may need to verify your identity before acting.
On 30 August 2026, the following settings were checked for the Google Analytics property identified above: event data 2 months; user data 14 months. New activity resets the user-identifier retention period. These settings do not apply to standard aggregated reports and do not establish deletion periods for emails, accounts, backups or security logs; those periods still require separate confirmation.