Online store and inventory

Client records and sensitive data: GDPR in practice

Almost every business with regular customers keeps some kind of client card. In a workshop it holds the vehicle and notes from the last service; in a pet grooming salon the animal's name and temperament; in a massage or beauty studio allergies and contraindications. This data makes the service better — and some of it is special category personal data, which the General Data Protection Regulation (GDPR) treats more strictly than a name and phone number.

This article is a practical overview of how to keep customer data so that it's to hand for staff and protected at the same time. It isn't legal advice — for your specific situation, consult a data protection specialist or a lawyer.

Where customer data lives today

To be honest, often in the worst possible places: on a paper card under the counter, in an order note, in an Excel sheet in a shared folder, or in a message to a colleague. And if the business has a separate online store, booking software and till, the same customer is in three places. These are all places where the data can't be protected, where you can't see who looked at it, and where you won't find it when a customer asks for a copy of their data.

One customer register

The NUNDINAE platform has one customer register for both online store accounts and in-person customers — just as the online store and inventory management are one application there, not two. The client card holds contact details, purchases, upcoming appointments, visit history and notes. So answering a data protection request doesn't mean searching through several programs.

You can add your own fields to the card — for example vehicle, pet's name, treatment or preferences. Ready-made field sets exist for a number of sectors.

What a good client card does

A warning is visible where it's needed. A warning (an allergy, for instance) is shown in red wherever the customer appears — in the day list, next to the booking, at the till. Staff don't have to open the card separately.

Sensitive data is encrypted. The warning, the internal note, visit notes and the business's own card fields are stored encrypted in the database. If someone got hold of a copy of the database, they wouldn't be readable.

Every opening is logged. Opening a client card goes into the audit log. If the question is "who looked at this?", the answer is there.

Staff see only their own customers. Without a separate permission, a member of staff sees only the customers in their own calendar, not the whole customer base. You give permission to see all customers only to reception or a manager. Even the evening email listing tomorrow's customers contains no phone numbers or client card warnings.

Consent is recorded. If you collect health data, the card has a checkbox confirming the customer has given explicit consent to its processing, and the date is saved.

When a customer asks for their data

The GDPR gives customers the right to ask for a copy of their data, to have it corrected or erased, or to restrict its processing. You have one month to respond.

In NUNDINAE the customer page has three buttons:

  • Export data — all of the customer's data in one file.
  • Restrict processing — marketing and automated messages are switched off.
  • Anonymise — personal data, the client card and notes are removed; sales invoices remain, because the law requires them to be kept for seven years.

The admin menu has a separate page for data protection requests: you log a request straight away, and the page shows the deadline and highlights overdue ones in red.

Marketing consent is separate

An appointment reminder is part of the service. A birthday offer or "time for your next service" is marketing and needs consent. NUNDINAE keeps two separate consents — offers by email and offers by SMS — and sends a marketing message only through the channel the customer agreed to. Email consent only takes effect once the address has been confirmed. Every offer contains an unsubscribe link. I wrote about this at more length in appointment reminders and birthday offers.

How long to keep data

Retention periods should be a decision, not an accident. In NUNDINAE they're in the settings: web form enquiries 24 months by default, the content of sent emails 6 months, personal data in orders 8 years (the 7 years required for accounting records in Estonia, plus a margin), chatbot conversations 90 days. Automatic anonymisation of inactive customers is off by default — you decide that period according to your own retention policy.

Good practice that doesn't depend on software

  • Don't write health data into free-text fields (an order note, an email) — only on the client card.
  • Don't send customer data as an Excel attachment by email.
  • Disable a departing employee's account on the same day.
  • If in doubt (an unfamiliar login, a lost phone), report it straight away — a data breach must be reported to the supervisory authority (in Estonia, the Data Protection Inspectorate) within 72 hours.
  • Use two-factor authentication at least for everyone who changes users and settings.

What this looks like in a business where health data is an everyday matter is covered in a booking system for a massage and therapy studio. If you'd like to see the client card and data protection tools for real, order NUNDINAE or ask for a demo.

Keep reading

Related services

Online store and stock in one application?

NUNDINAE is the platform I built for exactly that. I'll show it to you using your own business as the example.

See NUNDINAE