ATELIER
KHAYBAR
EST. 1447

Privacy Policy & GDPR Terms

Last updated: August 18, 2026 | GDPR & ISO 27001 Aligned

1. Introduction & Data Controller

KHAYBAR ("Company") operates a luxury hotel uniform platform that processes personal data from hotel employees, guides, and business contacts. We are committed to transparent, lawful data handling under GDPR and applicable data protection laws.

Data Controller (Hotel): When a Hotel uploads employee data to KHAYBAR, the Hotel is the Data Controller (responsible for lawfulness). KHAYBAR acts as a Data Processor on behalf of the Hotel.

Data Controller (KHAYBAR): For guide registrations, guide metrics, and business communications, KHAYBAR is the Data Controller.

2. What Personal Data We Collect

A. Hotel Employee Data (Hotel is Controller)

Hotels upload on our Platform:

  • Full name
  • Department & position title
  • Email & phone number
  • Body measurements (chest, waist, hips, shoulders, sleeve length, inseam, etc.)
  • Professional photograph (with explicit GDPR consent)
  • Hire date & employment status
  • Special notes (fit preferences, allergies, etc.)

B. Guide Registration Data (KHAYBAR is Controller)

  • Full name, email, phone
  • Professional biography & portfolio
  • Years of experience, credentials
  • Specializations & industries served
  • Professional headshot
  • Bank details (for commission payments)
  • Performance metrics (ratings, projects completed)

C. Business Contact Data

  • Hotel contact person name, email, phone
  • Supplier/partner contact information
  • Communication logs & inquiries

3. Lawful Basis for Processing

Employee Data (Hotel Employees)

Lawful Basis: Explicit Consent (Article 6(1)(a) GDPR) + Contract Performance (Article 6(1)(b))

Hotels MUST obtain written GDPR consent from each employee BEFORE uploading their data to KHAYBAR. Consent must specifically cover:

  • Measurement taking & data storage on KHAYBAR
  • Professional photography & storage
  • Sharing data with production partners (e.g., Bernhardt) for manufacturing
  • Retention period & deletion rights

Guide Data

Lawful Basis: Consent (registration) + Contract (guide agreement) + Legitimate Interest (fraud prevention, platform improvement)

Business Contacts

Lawful Basis: Consent + Legitimate Business Interest + Performance of Contract

4. Purpose of Processing

We process personal data only for:

  • Design & manufacturing of custom uniforms
  • Fit & size calculations
  • Quality assurance & defect management
  • Guide performance evaluation & payments
  • Order tracking & delivery coordination
  • Fraud prevention & platform security
  • Impact reporting (anonymized: total suits, meals generated)
  • Service improvement & analysis

We do NOT use personal data for marketing, profiling, automated decision-making, or third-party selling without explicit consent.

5. Who We Share Data With

Sub-Processors (Art. 28): Employee names, measurements, photos, and customization codes are shared with our sub-processors to manufacture garments. All sub-processors are bound by Data Processing Agreements (DPA) with KHAYBAR. Our sub-processor register — including processing purposes, locations, transfer safeguards, and DPA status — is maintained internally and available to data subjects and regulators on request.

Active Sub-Processors include: Base44 (BaaS hosting), Stripe (payments), Resend (email), AssemblyAI (audio transcription), Google Places (business data), and KVK (business registry). A full register with DPA status for each processor is maintained under GDPR Art. 28.

Internal KHAYBAR Team: Designers, operations staff, and support team access data as needed to fulfill services.

No Third-Party Selling: We do NOT sell or share employee data with marketers, data brokers, or third parties for profit.

Legal Requirements: We may disclose data if required by law (court order, regulatory authority).

6. Data Retention & Deletion

KHAYBAR maintains a formal Data Retention Schedule (GDPR Art. 5(1)(e) — storage limitation) covering all platform entities. Each data category has a defined retention period, trigger event, and end-of-life action (delete, anonymize, archive, or review).

Employee Measurements: Retained for 3 years from last order (to enable reordering). Hotels may request earlier deletion by contacting KHAYBAR.

Employee Photos: Retained for 3 years or until employee revokes GDPR consent. Deleted upon employee request.

Guide Data: Retained while guide is active + 2 years after account termination (for dispute resolution & tax records).

Order Data: Retained for 7 years (legal/financial record-keeping requirements).

Data Classification (Art. 30): All platform entities are classified into four sensitivity tiers — public, internal, confidential, and special category — with access controls matching each tier. Body measurements are classified as special category data (biometric-adjacent) and receive the highest level of protection.

Right to Erasure: Employees can request deletion of their data at any time by contacting their Hotel HR or KHAYBAR directly, or by exercising their right to erasure through our self-service portal. We will erase data within 30 days unless legal obligations require retention.

7. GDPR Data Subject Rights

Hotel employees have the following rights under GDPR:

Right of Access (Article 15)

Employees can request a copy of all personal data KHAYBAR holds about them. We will respond within 30 days.

Right of Correction (Article 16)

Employees can request corrections to inaccurate data (e.g., wrong name, outdated measurements).

Right to Erasure (Article 17)

Employees can request deletion of their data. We will comply unless legal obligations require retention (e.g., active orders, tax records).

Right to Restrict Processing (Article 18)

Employees can request that we limit use of their data while disputes are resolved.

Right to Data Portability (Article 20)

Employees can request their data in a structured, machine-readable format (JSON, CSV) to transfer to another service.

Right to Object (Article 21)

Employees can object to processing for legitimate interest purposes.

Right to Withdraw Consent

Employees can withdraw GDPR consent at any time. This does not affect the lawfulness of processing before withdrawal.

How to Exercise Rights: You can submit any of these requests directly through our Privacy Rights Portal, or by contacting your Hotel HR department, or by emailing privacy@khaybar.com. We will respond within 30 days per GDPR Art. 12.

8. Data Security & Protection

KHAYBAR implements industry-standard security measures aligned with ISO 27001 controls:

  • Encryption in transit (TLS/HTTPS) & at rest
  • Row-Level Security (RLS) — users can only access data within their own hotel or their own records; cross-tenant access is enforced at the database level
  • Role-based access controls (employees, guides cannot access each other's data)
  • Regular security audits & penetration testing
  • Staff data protection training & confidentiality agreements
  • Audit logging (ISO 27001 A.12.4) — all data access and modifications are logged with actor, timestamp, and change details
  • Incident response plan for data breaches
  • GDPR-compliant Data Processing Agreements with all sub-processors

Breach Notification Protocol (Art. 33-34): In the event of a personal data breach, KHAYBAR will notify the Autoriteit Persoonsgegevens (Dutch supervisory authority) within 72 hours of becoming aware, and notify affected data subjects without undue delay where the breach is likely to result in high risk. All breaches are recorded in our internal breach register with root cause, containment, and post-incident review.

9. International Data Transfers

KHAYBAR and production partners operate in multiple countries. When employee data is transferred outside the EU/EEA, we ensure compliance through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions (where applicable)
  • Explicit Hotel & Employee consent for international transfer

10. Children's Data

KHAYBAR does not knowingly collect data from individuals under 18. If we become aware that we have collected data from a minor, we will delete it immediately.

11. Data Protection Officer & Complaints

KHAYBAR Data Protection Officer: dpo@khaybar.com

Supervisory Authority: If you believe KHAYBAR has violated GDPR, you have the right to lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France).

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to affected parties. Your continued use of the Platform constitutes acceptance of updated terms.

13. Contact Us

For GDPR requests, data access, or privacy concerns:

  • Email: privacy@khaybar.com
  • DPO: dpo@khaybar.com
  • Mailing Address: [KHAYBAR Legal Address]