Privacy policy
Last updated 11 August 2026
Nolira processes personal data on behalf of the beauty and wellness businesses that use it. This policy explains what we collect, why, how long we keep it, and what rights people have.
Draft pending legal review. This document is a working draft written to describe how Nolira intends to operate. It has not yet been reviewed by a qualified lawyer in Malaysia and should not be relied on as a binding agreement until it has.
1. Who we are
Nolira provides operations software for beauty and wellness businesses. For data belonging to a salon's own clients, the salon is the data controller and Nolira acts as a data processor under contract. For data about our own account holders and website visitors, Nolira is the controller.
2. What we collect
From businesses using Nolira
- Account details: name, work email, phone number, role and branch.
- Organisation details: business name, outlets, operating hours, tax identifiers.
- Usage and diagnostic data: feature use, performance, crash reports.
- Billing details, processed by our payment provider rather than stored by us.
From salon clients, on behalf of the business
- Contact details: name, phone, email, preferred language.
- Appointment, visit, payment, package and membership history.
- Service notes, preferences and consultation records entered by staff.
- Before-and-after photographs, where the client has consented.
3. Sensitive information
Allergy notes, sensitivity records and treatment photographs can be sensitive. We treat them accordingly: access is restricted by role, every view is logged, they are excluded from analytics, and they are never used for marketing without separate explicit consent.
Nolira is not a medical records system and does not store diagnoses, prescriptions or clinical assessments.
4. Why we process data
- To deliver the service under our contract with the business.
- To send transactional messages such as booking confirmations and reminders.
- To secure the service, detect fraud and investigate incidents.
- To meet financial, tax and legal record-keeping obligations.
- To improve the product using aggregated, non-identifying usage data.
We do not sell personal data, and we do not use salon client data to train third-party AI models.
5. Sharing
We share data only with subprocessors needed to run the service: cloud hosting, object storage, email delivery, push notifications, payment processing and messaging providers. Each is bound by contract. A current subprocessor list is available on request.
6. Storage and retention
Data is encrypted in transit and at rest, and each organisation's data is logically isolated. Retention differs by category: operational records follow the business's configured policy; financial records are held for the statutory period; sensitive notes and media follow the shortest retention consistent with the service and applicable law.
7. Your rights
Individuals may request access, correction, deletion or export of their personal data. Where the data belongs to a salon's client, requests are directed to that salon as the controller, and Nolira supports them in fulfilling it. Some records are retained where financial, tax or fraud obligations require it; we identify these rather than deleting silently.
8. Account deletion
Account holders can request deletion from within the mobile apps under Settings, or by writing to us. Deletion revokes sessions and removes or anonymises data that we are not legally required to retain.
9. International transfers
Data is primarily hosted in a region close to Malaysia and Singapore. Where a subprocessor operates elsewhere, we rely on appropriate contractual safeguards.
10. Changes
We will update this page when our practices change and, for material changes, notify account holders directly.
11. Contact
Privacy questions and data requests: hello@nolira.my.