← Back to the blog
Security

Who can see client files when an employee leaves

August 24, 2026 · 4 min read

An employee leaves on Friday. On Monday it turns out your clients' numbers are in their private phone and you have no way to take them back. Here is how to set up access so that leaving a job is not moving out with the client base.

Parting with an employee is rarely a row. Usually it is ordinary: the employee found something closer to home, is opening their own place, is changing industry.

The problem shows up two weeks later, when your regular clients start cancelling appointments. Not because anyone "stole" them. Because their numbers sat in a private phone for three years, and the phone left the company along with the employee.

Three ways a client base walks out of a salon

A number saved in a phone. The most common and the least malicious. An employee saves a contact so they can confirm an appointment. After a year they have half your base in their phone — and nobody planned it.

A shared password. One account, one password, a sticky note by the desk. When someone leaves, you cannot take away their access without changing the password for everyone. So usually nobody changes it.

A notebook or a spreadsheet on a drive. It can be photographed in a minute and leaves no trace at all.

The common denominator: you do not know who saw what, and you have no way to revoke access.

This is not only about losing clients

A client base is personal data, and your company is its controller. So you are answerable for where that data sits — including when it got there without anyone meaning harm.

A number saved in an employee's private phone leaves your control. In GDPR terms that is a personal data breach, and it makes no difference that nobody intended anything bad: the employee saved the contact to confirm an appointment, not to take anything away. The responsibility still sits with the controller — with you.

If such a breach may put clients' rights at risk, the controller is obliged to report it to the supervisory authority — as a rule within 72 hours of becoming aware of it. And if the file contains health data — contraindications, allergies, treatments carried out — the bar is higher still, because that is a special category of data, protected more strictly than a plain phone number.

That is why the question "who can see the client files" is not a question about trusting a particular person. It is a question of whether you can demonstrate where your clients' data is — and that is an obligation resting on you regardless of anyone's intentions.

What you can do before anyone leaves

This is not a matter of trusting a particular person. It is a matter of setting things up so that nothing has to be negotiated at parting.

Everyone has their own account. Not "the salon's account", their own. Then taking access away from one person does not touch the rest of the team.

Everyone sees as much as they need. An employee needs the profile of the client they are serving and their own schedule. They do not need the day's takings or their colleagues' rates.

The contact belongs to the company. If appointment confirmations go out from the app rather than a private phone, nobody has to save numbers of their own.

A trace remains. Not to police anyone day to day — so that in case of doubt it is not one person's word against another's.

How it works in Kepili

Three roles: owner, manager, employee. Each sees only what belongs to them. An employee has their own appointments and their own pay; they do not see the team's settlements.

Revoking access takes effect immediately. This is a detail with very practical meaning: access disappears at once, not when someone gets around to it. Blocking an account on Friday at six means that at six nobody logs in any more.

Everyone signs in their own way. By e-mail, a Google account or a fingerprint. There is no shared password, so there is nothing to change for the whole team.

Contacts and visit history belong to the company. The base stays in Kepili, not in anyone's phone. A change in the team does not take your clients away — because there is nothing to take from a private device.

The audit log records who changed what and when — from a client card to a closed month. It also records refused access, meaning attempts to reach places someone had no rights to.

Personal and health data are secure and encrypted. This is a safeguard you cannot put in place while keeping client data in a notebook.

A checklist for the day of parting

To do in five minutes, on the last day of work:

The last point matters most commercially and is the one most often skipped. A client who gets a call with a proposed slot before they have had time to wonder where to go now usually stays.


An employee leaving is a normal part of running a salon. It does not have to be the moment you lose control of your own client base.

Create an account and use the full Business plan for 30 days — no limits, no complicated contract and no card. Set the roles once and take this worry off your list.

Try Kepili on your own business. 30 days of the full Business plan, no limits and no card required.

Start 30 days free