Compliance & Disclaimer
Last updated: June 15, 2026
This page summarises how Dianova Beauty Connect addresses the laws that apply to our platform, and the disclaimers that govern our AI and beauty features. It reflects our implemented practices and is not legal advice.
HIPAA — not applicable
A beauty salon is not a HIPAA “covered entity” and cosmetic hair, scalp, and allergy-preference data is not Protected Health Information. Our hair-health features are cosmetic, not medical. We therefore do not claim HIPAA compliance, because HIPAA does not govern this data. Sensitive personal data is instead protected under the privacy and biometric regimes below.
Regimes we address
| Regime | Applies to | How we address it |
|---|---|---|
| GDPR / UK GDPR | EU/UK clients | Lawful bases, consent for AI/marketing/cookies, data-subject rights incl. Art. 22, processor terms (DPA). |
| CCPA / CPRA | California clients | Notice, access/delete/correct, no sale of data, limit sensitive personal information. |
| BIPA & similar biometric laws | Face analysis (try-on, hair-health) | Explicit consent, purpose limitation, retention schedule, no sale, deletion; device biometrics never collected. |
| CAN-SPAM | Marketing email | Consent, sender identity, one-click unsubscribe. |
| TCPA | SMS/WhatsApp, AI calls | Prior express consent, STOP opt-out, calling-time rules. |
| PCI-DSS | Card payments | Card data handled by Stripe (PCI Level 1); Dianova stores no full card numbers. |
| ePrivacy / cookies | Analytics, geolocation | Essential vs. optional cookies; opt-in geolocation consent. |
| ESIGN / UETA | Electronic acceptance | Electronic consent and signatures are legally binding. |
External links are provided for reference to official sources and are not endorsements; we are not responsible for third-party content.
Data-subject & privacy requests
Submit access, correction, deletion, or opt-out requests via privacy@dianovabeauty.company or in-app account settings. We verify identity, honour authorised agents, and respond within statutory timeframes. Deletion cascades to derived analyses and images.
Security & responsible AI
Multi-tenant row-level isolation, encryption in transit and at rest, signed/expiring image URLs, least-privilege access, and audit logging. Our AI uses no protected attributes for analysis, keeps a human in the loop for service-affecting decisions, surfaces confidence as ranges, and gates vision features behind consent.
Disclaimer — cosmetic, not medical
Hair-health analysis, style recommendations, virtual try-on, and related AI features provide cosmetic and informational guidance only. They are not medical advice, diagnosis, or treatment, and do not replace a qualified professional. Suspected scalp or skin conditions should be referred to a healthcare or licensed professional.
Disclaimer — no guaranteed results & AI limits
Beauty outcomes vary by individual. AI previews, recommendations, analyses, summaries, and price quotes are illustrative, may contain errors, and do not guarantee a specific result, suitability, or price. Salon staff review and remain responsible for service-affecting decisions. Beauty services are provided by independent salons; Dianova is a technology platform and is not the provider of those services.
Controller / processor roles
For salon bookings, the salon is the data controller and Dianova is the processor / service provider. White-label tenants act as publisher and controller of their own branded app, with their own privacy policy and app-store disclosures.
