
– Enrique Cano
VP of Security and Compliance, Fresha
– Tomasz Werema
Security, Risk & Compliance Specialist, Fresha
Introduction
London-based Fresha runs the leading marketplace platform for beauty and wellness, where millions of consumers worldwide discover, book, and pay for appointments with local businesses, and where beauty and wellness businesses and professionals manage their entire operations through an intuitive subscription-free business software and financial technology solution.
“We have over 100,000 partners using Fresha every day. We process a lot of personal data, and we want to make sure customers can trust us with that information,” Fresha’s spokesperson noted.
That pursuit of excellence shaped how Enrique Cano, Fresha’s VP of Security and Compliance, and Tomasz Werema, Fresha’s Security, Risk & Compliance Specialist, operationalized the organization’s ISO 27001, HIPAA, and GDPR compliance programs. “Friction-free is a fundamental principle,” they explained.
“We constantly strive to simplify and streamline processes for everyone. Even when addressing security questionnaires from potential clients from different markets, our aim is to meet these requirements as efficiently as possible.” Two requirements followed for the ISO 27001, HIPAA, and GDPR work: right-sizing compliance to only the changes needed to meet requirements, and automating across the existing tech stack to tear down silos.
The Problem
To operationalize its ISO 27001, HIPAA, and GDPR programs, Fresha had to figure out how various security compliances could be incorporated and audited without disrupting the operating workflow. “We’re performance-oriented, and my job is to remove performance blocks, prioritize tasks, and plan engineering deliverables in a way that results in optimal performance,” notes the spokesperson for Fresha.
That performance focus ran into the cross-team coordination compliance demands, which was the part Fresha wanted tooling to absorb. “But achieving compliance is a lot of collaborative work,” the spokesperson added. “Our resources are best spent implementing solutions, setting things up, operationalizing IT for performance, and managing it. This is where tooling is effective: it can take on the day-to-day running of compliance.”
Any new tooling also had to fit around Fresha’s patchy IT operations, where adding another system invited the disruption leadership wanted to avoid at all costs. Scope discipline mattered just as much.
“Organizations don’t think about this enough. It’s easy to fall into the trap of doing everything, often unnecessary things. As I see it, compliance is about doing the right things,” the spokesperson observes, “and we were clear we wanted to make it the easiest right thing for our people.”
The day-to-day mechanics were the tedious part: meticulously extracting data, validating systems, and capturing evidence is a process prone to errors. Fresha’s starting point for efficiency was examining those operations to identify weaknesses, an exercise its spokesperson calls “contextualizing.” As the spokesperson put it, “Compliance isn’t just about publishing policies; it’s about modifying behaviors to impact the organization positively.”
Security reviews added their own burden on engineering. “Infact, most [security] questionnaires that came my way asked for things ISO 27001 covers anyway. It was only a matter of pushing the pedal to get our certification done so that we could skate through these reviews without burdening engineering,” the spokesperson said.
The Solution
Applying the Braithwaite triangle, an academic model for devising strategies for maximum responsiveness, Fresha separated its ISO 27001, HIPAA, and GDPR work into tasks, people, and company.
“By defining clear compliance objectives, assigning tasks to everyone, and making sure team leaders were championing compliance to the rest of their teams, we could simplify compliance and eliminate a lot of the friction. This way, even the most cynical and skeptical people could do their part without breaching deadlines,” Fresha’s spokesperson explained.
To accelerate those efforts, Fresha turned to Sprinto. “The moment we saw it, we were extremely impressed—we knew that this was exactly the tool Fresha needed to help us handle compliance,” recounts Fresha’s spokesperson. Deep integration with the existing tech stack was the deciding criterion: “Integrations mattered. We wanted to automate as much as possible so people don’t know this is even happening,” the spokesperson said.
Effort was the other filter Fresha applied. “We want to right-size compliance by only making changes that would help us meet compliance. After all, we were doing this to optimize our business, not to constrain it,” the spokesperson said.
In Sprinto, Fresha found an action-oriented program manager: “Sprinto felt like painting by numbers. The ability to see how you are improving and get feedback when you make a change or do something makes it all the more easy,” the spokesperson added.
Once plugged into Sprinto, Fresha could clearly see all the tasks needed to satisfy controls against its preferred frameworks. Fresha started with security training for 330+ employees and the publication of over 30 new policies, accomplishing both as campaigns directly within Sprinto. “We launched a targeted training campaign on Sprinto and completed training for everyone in under 4 weeks!” the spokesperson said.
Keeping that momentum across a large workforce came down to prompting: “The biggest challenge is motivation and encouragement — how do you get people to do their part for compliance? Automated nudges definitely help,” the spokesperson noted.
With PeopleOps-related compliance tasks in motion, Fresha shifted its focus to access management. The access control module in Sprinto provided a robust framework for zero-trust access management that safeguards critical systems and maintains an audit log of all related events. “This helps us see who’s playing by the rules and who’s not,” shared Fresha’s spokesperson.
“Infact, Sprinto gave us a model for designing roles. We reverse-engineered all roles and access rules and updated our Notion database to paint a clear picture of how everything connects. Auditors want to see the process down to the tickets, and now, with Sprinto, everything is clearly logged.”
Building on that, Fresha used Sprinto’s change management capabilities to identify exceptions at the code level and appropriately adjust the scope of compliance, and the vendor management module to structure, evaluate, and score vendors for risk. “The dots are clearly connected: what’s critical and what’s necessary to operate within the strict confines of compliance and controls, it’s all right there,”
Fresha added, and the spokesperson summed up the effect: “Now it’s easy to get everyone to do the right thing.” Across all of it, Fresha ran a layered security program built on the common control frameworks in Sprinto to underscore control overlaps and remove unnecessary edge cases and redundancies, supported by continuous, automated testing.
Impact
Fresha achieved ISO 27001, HIPAA, and GDPR compliance and audit readiness in three months. “We accelerated to completion in a matter of weeks,” said Fresha’s spokesperson. Powered by automation and powerful connectors, Fresha created a unified view of assets, risks, and controls and implemented automated testing to validate compliance status regularly.
Sprinto reports now give Fresha summaries whenever compliance status deviates from the 100% mark, indicating the tasks it needs to complete to close the gap.
That visibility changed how Fresha’s own operations run. “Sprinto provides a lot more guidance and better visibility. Our IT team now has a clear protocol for everything, including provisioning access,” shares Tomasz Werema, Security, Risk & Compliance Specialist at Fresha.
“Compliance is rarely about adding more. It is more about improving what you already do for security. Sprinto removes complexity and eliminates too many edge cases so you can do compliance as it is intended—to improve your operations,” Fresha’s spokesperson concluded.
Got questions? Talk to our experts!



Beauty and wellness marketplace / fintech software
330+
UK





