STUDIO COREBack

Revision: 28 Apr 2026

Privacy

OPERATOR & DATA CONTROLLER

STUDIO CORE is operated by The White Whale sas, a company incorporated in Italy with registered office at Via Tadino 20, 20124 Milan, Italy — VAT no. IT 13571300964 (the "Operator"). GDPR roles. The Operator acts as a data processor for personal data entered into the platform by each studio (its clients, artists, bookings). Each studio that uses STUDIO CORE acts as the data controller for the personal data it collects from its own clients. The Operator is the data controller only for account-level data (login email, role, payment metadata). Contact for privacy matters and data subject requests: privacy@studio-core.app — or write to the registered office above.

1. DATA COLLECTED

STUDIO CORE processes the following categories of personal data, strictly for studio management and internal analytics: • Practitioner data: name, email, role, payment parameters, calendar tokens. • Client data collected per appointment: full name, email address, phone number, city, country, year of birth. • Financial data: session prices and deposits. • Consent form data (when signed by the client): tax code, home address, ZIP code, province, ID document type and number, digital signature, and health-related confirmations. • Appointment metadata: date, time, workstation, appointment type, session notes, reference files.

2. HOW DATA IS USED

Data is used exclusively for: • Managing bookings and workstation allocation. • Internal analytics and performance tracking. • Sending automated email communications to clients (booking confirmations and aftercare instructions). • Artist-specific client history: each artist can view an aggregated history of their own clients to facilitate repeat bookings. This data is private to the individual artist and is not shared with other artists or studio administrators. • Guest artist tracking: monitoring external artist sessions and social media posting compliance for partnership agreements.

3. ECOSYSTEM INTEGRATION

Our integration with Google Services utilises OAuth2 protocols. STUDIO CORE requests restricted access to manage a dedicated calendar created by the application. Tokens are encrypted and stored securely within our Cloud Infrastructure. Users maintain full control and can revoke access via their Personal Parameters.

4. PERSISTENCE & COOKIES

We utilise LocalStorage technology to maintain UI preferences such as language selection. No tracking cookies are used for marketing purposes. All operational data is stored via Firebase (Google Cloud) with encryption at rest and in transit.

5. AI PROCESSING

STUDIO CORE integrates AI services (Google Gemini via Genkit) to perform automated tasks such as Google Calendar synchronisation and daily operational recap generation. These processes access appointment data solely to complete the requested operation. No personal data is retained or used to train AI models. Processing occurs within Google Cloud infrastructure under standard data processing agreements.

6. DATA SUBJECT RIGHTS

In accordance with GDPR (EU Regulation 2016/679), every data subject — including clients whose data is recorded during appointments — has the right to access, rectify, restrict processing, or request the deletion of their personal data. Data retention is limited to the duration of the professional relationship with the studio, or as required by applicable law for fiscal documentation. Requests may be submitted via the feedback channel within the application or by contacting the studio directly.

SUB-PROCESSORS

To deliver the service the Operator engages the following sub-processors, all bound by GDPR-compliant data processing agreements: • Google LLC (Firebase / Google Cloud) — hosting, authentication, database, file storage. EU/US. • Resend (Resend.com Inc.) — transactional email delivery. EU/US. • PayPal (Europe) S.à r.l. et Cie, S.C.A. — recurring subscription billing. EU. • Google LLC (Genkit / Gemini) — AI-assisted features (calendar sync, daily recap). EU/US. The list is reviewed periodically; material changes are communicated to studio admins by email at least 30 days in advance.

STUDIO CORE // PRIVACY