Valid'Or Privacy Policy

Effective Date: 1.1.2026 Last Updated: 1.1.2026


1. Who We Are

ValidorAI ("ValidorAI", "we", "us", or "our") provides AI-powered hair and scalp analysis technology, including a handheld scanner device and a software-as-a-service ("SaaS") platform offered to professional salon partners ("B2B Customers") and individual consumers ("Consumers") (collectively, the "Services").

Data Controller:

  • ValidorAI, računalniško programiranje, d.o.o. (ValidorAI d.o.o.), a Slovenian limited liability company, Gosposvetska cesta 13, 1000 Ljubljana, Slovenia. Registration no. 7359578000, VAT ID SI82851433.

Contact for privacy matters:


2. Scope

This Privacy Policy describes how we collect, use, disclose, and protect Personal Data when you:

  • Visit our website at www.validorai.com (the "Website")
  • Use the Valid'Or mobile or desktop application (the "App")
  • Use the Valid'Or handheld scanner (the "Device")
  • Engage with us as a salon partner, supplier, or business contact

If you are a Consumer using the Services through a B2B Customer (e.g., during a salon visit), the salon may also process your data as an independent or joint controller. Their privacy practices are governed by their own policies.


3. Personal Data We Collect

3.1 Data You Provide Directly

  • Account information: name, email, phone number, password, professional credentials (for salon users), business details
  • Profile information: hair type, scalp concerns, age range, optional self-reported health information
  • Payment information: processed by our payment processor Stripe; we receive transaction confirmations but do not store full card numbers
  • Communications: support tickets, feedback, survey responses

3.2 Data Collected Automatically

  • Scan data: images and videos of your scalp and hair captured by the Device, plus AI-derived hair and scalp analysis results (e.g., scalp condition indicators, hair density estimates)
  • Device data: Device serial number, firmware version, usage logs
  • App and Website usage: IP address, device identifiers, browser type, pages viewed, interactions, time stamps
  • Cookies and similar technologies: see Section 11

3.3 Data from Third Parties

  • Salon partners may upload Consumer profiles and scan history on behalf of their clients
  • Authentication providers (e.g., Google, Apple) if you choose social login

3.4 Special Categories of Data (GDPR Art. 9)

Scalp and hair imagery, together with AI-derived hair and scalp analysis results, may constitute biometric data and/or health data under GDPR Article 9 and equivalent laws (e.g., BIPA in Illinois, CMIA in California). We process this data only with your explicit consent and apply heightened safeguards, including encryption, access controls, and limited retention.


4. How We Use Personal Data (Purposes & Legal Bases)

PurposeLegal Basis (GDPR)
Provide the Services and deliver scan resultsPerformance of contract (Art. 6(1)(b)); explicit consent for biometric/health data (Art. 9(2)(a))
Authenticate users, manage accountsPerformance of contract (Art. 6(1)(b))
Process paymentsPerformance of contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Improve and train AI modelsLegitimate interest (Art. 6(1)(f)); explicit consent for special category data (Art. 9(2)(a))
Customer support and communicationPerformance of contract; legitimate interest
Marketing communications (where permitted)Consent (Art. 6(1)(a)) or legitimate interest, subject to opt-out
Security, fraud prevention, abuse detectionLegitimate interest (Art. 6(1)(f))
Legal compliance, regulatory reportingLegal obligation (Art. 6(1)(c))

5. AI Analysis & Important Limitations

The Services provide cosmetic and wellness-oriented insights about hair and scalp condition. The Services are not a medical device, do not diagnose, treat, cure, or prevent any disease, and are not a substitute for professional medical advice.

6. How We Share Personal Data

We do not sell your Personal Data. We share it only with:

  • Salon partners — when you receive Services through a salon, scan results and related data are shared with that salon

  • Service providers (processors) acting on our instructions, including:

    • Hosting and infrastructure: Vercel (website and web app), Amazon Web Services (file and image storage, United States), Hetzner (content management, Finland)
    • Authentication: Clerk
    • Payment processing: Stripe
    • AI analysis of scan images: Google (Gemini models, via the Vercel AI Gateway) and Lushair
    • Email delivery: Resend; business email: Google Workspace
    • Webhook delivery: Svix
  • Professional advisors (lawyers, accountants, auditors) under confidentiality

  • Authorities when legally required (e.g., subpoena, court order, regulatory investigation)

  • Corporate transactions in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections


7. International Data Transfers

We operate globally. Personal Data may be transferred to and processed in countries outside the EEA, UK, or your country of residence, including the United States. Where required, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Addendum (IDTA) where applicable
  • Adequacy decisions where available
  • Supplementary measures (encryption in transit and at rest, pseudonymization where feasible)

You may request a copy of the safeguards in place by contacting us at privacy@validorai.com.


8. Data Retention

We retain Personal Data only as long as necessary for the purposes described in this Policy:

Data CategoryRetention Period
Account dataDuration of account + 12 months after closure
Scan and biometric dataUntil consent is withdrawn, or 24 months of inactivity
Payment records7 years for tax and accounting (Slovenia & US requirements)
Marketing dataUntil opt-out
Support communications3 years
Anonymized / aggregated dataIndefinitely (no longer Personal Data)

When data is no longer needed, it is deleted or irreversibly anonymized.


9. Your Rights

Depending on your jurisdiction, you have the following rights:

9.1 EEA / UK / Switzerland (GDPR / UK GDPR)

  • Access, rectification, erasure ("right to be forgotten")
  • Restriction of processing, objection to processing
  • Data portability
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with your supervisory authority — for Slovenia: Informacijski pooblaščenec (www.ip-rs.si)

9.2 United States (CCPA / CPRA and other state laws)

  • Right to know, access, delete, and correct
  • Right to opt out of sale or sharing of Personal Data (we do not sell Personal Data)
  • Right to limit use of sensitive Personal Data (including biometric and health data)
  • Right to non-discrimination for exercising rights

9.3 Other Jurisdictions

We honor equivalent rights under applicable laws (e.g., LGPD in Brazil, PIPL in China, POPIA in South Africa).

To exercise any right, contact us at privacy@validorai.com. We will respond within the timeframes required by law (generally 30 days under GDPR, 45 days under CCPA).


10. Children's Privacy

The Services are not intended for, nor knowingly directed to, individuals under 18 years of age. We do not knowingly collect Personal Data from children. If you believe a child has provided us Personal Data, contact us and we will delete it.


11. Cookies & Similar Technologies

We use cookies and similar technologies on the Website and App for:

  • Strictly necessary functions (authentication, security)
  • Analytics and performance
  • Preferences and personalization
  • Marketing (where permitted and consented)

12. Security

We implement technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and least-privilege principles
  • Logging and monitoring
  • Regular security testing and vulnerability management
  • Vendor due diligence

No system is 100% secure. In the event of a personal data breach affecting your rights, we will notify you and the relevant authority within the timeframes required by law (e.g., 72 hours under GDPR).


13. Automated Decision-Making

Our AI generates hair and scalp analysis results based on scan data. These outputs are informational and do not produce legal or similarly significant effects on you within the meaning of GDPR Art. 22. You always have the option to discuss results with a qualified professional and to request human review.


14. California-Specific Disclosures (CCPA / CPRA)

In the past 12 months, we have collected the following categories of Personal Data: identifiers, commercial information, internet activity, geolocation (general), sensory data (scalp/hair imagery), inferences, and sensitive Personal Data (biometric information). We do not sell or share Personal Data for cross-context behavioral advertising.

To exercise CCPA/CPRA rights, submit a request at privacy@validorai.com. You may designate an authorized agent.


15. Changes to This Policy

We may update this Policy. Material changes will be notified via the App, Website, or email at least 30 days before they take effect. Continued use of the Services after the effective date constitutes acceptance.


16. Contact

Email: privacy@validorai.com Data Protection Officer: Primoz Erjavec, primoz@validorai.com Representative: ValidorAI d.o.o., Gosposvetska cesta 13, 1000 Ljubljana, Slovenia