Privacy Policy
Last updated 18 July 2026This policy explains what personal data Roo SalonOS (operated by Olircore Solutions (Pvt) Ltd, registered office Kegalla, Sri Lanka) collects, why, how it's protected, and what rights you have over it — under Sri Lankan, UAE, and EU/UK law.
1. Who is responsible for your data
For account and billing data (the people who sign up and log in to Roo), Olircore is the data controller. For your salon's customer data (the clients, appointments, and sales you record inside Roo), Olircore is a data processor acting on your instructions as the business — you remain the controller of your own customers' data, and are responsible for having a lawful basis to collect it from them.
2. What we collect
- Account data — name, email, phone, role, for each user your business creates.
- Business operational data — sales, appointments, customer records, inventory, staff, and financial data entered while using Roo.
- Technical data — IP address, device/browser information, and login timestamps, collected for security, fraud prevention, and audit-log purposes.
- Support communications — anything you send us via email or WhatsApp when requesting help.
We do not collect payment card data directly — during the free period, no payment details are collected at all.
3. Why we process it (legal basis)
- Performance of a contract — providing the Service you signed up for.
- Legitimate interest — securing the platform (tenant isolation, audit logging, abuse/rate-limit protection), improving reliability.
- Legal obligation — retaining records where Sri Lankan, UAE, or other applicable law requires it.
- Consent — for anything not covered above (e.g. optional marketing communications), which you can withdraw at any time.
4. Subprocessors and sharing
We do not sell personal data. It's shared only with:
- infrastructure/hosting providers needed to run the Service,
- email-delivery providers for transactional email (verification, password reset, receipts),
- authorities, where required by law or a valid legal process.
A current list of named subprocessors is available on request.
5. International data transfers
Because Roo's infrastructure, your salon, and your customers may be in different countries, personal data may be transferred across borders. Where we transfer personal data out of the EU/EEA/UK, we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard. Where required by the Sri Lanka PDPA or UAE PDPL, we apply the safeguards those laws require for cross-border transfer.
6. Data retention
Data is retained for as long as your account is active, plus 30 days after voluntary termination to allow export, after which it is deleted or irreversibly anonymized. For accounts suspended for non-payment, data is instead retained for 2 months from the date of suspension (see Terms of Service, Section 4), after which it is deleted. Either window may be extended where a longer retention period is required by law (e.g. financial records under Sri Lankan or UAE tax law).
7. Security
Passwords are hashed, never stored in plaintext. Sessions and devices can be reviewed and revoked from within the app. Multi-factor authentication is available. Data in transit is encrypted (TLS). Access to production data is restricted to staff who need it to operate the Service.
8. Your rights
If you are in Sri Lanka (PDPA No. 9 of 2022): you have the right to access, rectify, erase, and object to processing of your personal data, and to lodge a complaint with the Data Protection Authority of Sri Lanka.
If you are in the UAE (Federal Decree-Law No. 45 of 2021): you have the right to access, correct, erase, and restrict processing of your personal data, to data portability, to object to processing for direct marketing, and to file a complaint with the UAE Data Office.
If you are in the EU/EEA or UK (GDPR / UK GDPR): you have the right to access, rectify, erase ("right to be forgotten"), restrict, port, and object to processing of your personal data, and to lodge a complaint with your local supervisory authority.
To exercise any of these, contact us at the address below — we'll respond within the timeframe the applicable law requires (typically 30 days).
9. Children's data
Roo is a business tool. It is not directed at, and we do not knowingly collect personal data from, individuals under 18.
10. Breach notification
If a personal data breach occurs that's likely to result in risk to affected individuals, we will notify affected customers and, where legally required, the relevant supervisory authority (Sri Lanka Data Protection Authority, UAE Data Office, or an EU/UK authority as applicable) without undue delay.
11. Changes to this policy
We'll post material changes here with an updated "Last updated" date, and notify active accounts by email or in-app notice for significant changes.
12. Contact
Privacy questions or rights requests: [email protected]
