Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement ("Main Agreement") between:
- The Customer: the salon business named in the order form ("Controller"); and
- SPARE CHAIR LTD, a company registered in Northern Ireland under number NI715764, of 16 Green Road, Ardglass, Downpatrick, BT30 7UA, trading as Spare Chair ("Processor").
It meets Article 28 of the UK GDPR. Where the EU GDPR applies, it meets Article 28 of the EU GDPR too.
1. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018, PECR, and, where it applies, the EU GDPR.
- Personal Data means personal data the Processor handles for the Controller under the Main Agreement.
- Sub-processor means a third party the Processor uses to handle Personal Data.
- Breach means a personal data breach as defined in Data Protection Law.
- Other terms have the meaning given in Data Protection Law.
2. Roles
2.1 The Controller decides why and how Personal Data is used. The Processor handles it only for the Controller.
2.2 The Controller confirms it has a lawful basis to share the Personal Data. It confirms its own privacy notice to clients and staff covers this use.
2.3 The Processor is a separate controller for its own account, billing and support data about the Controller's users. That use sits outside this DPA.
3. Details of processing
See Schedule 1.
4. Processor duties
The Processor will:
4.1 Process Personal Data only on the Controller's documented instructions. The Main Agreement, this DPA and the Controller's settings in the dashboard are the instructions. If law requires other processing, the Processor will tell the Controller first, unless the law forbids it.
4.2 Tell the Controller at once if it thinks an instruction breaks Data Protection Law.
4.3 Make sure everyone with access is bound by confidentiality.
4.4 Take the security measures in Schedule 3 (Article 32).
4.5 Only use Sub-processors under clause 5.
4.6 Help the Controller answer requests from people using their rights. If a person contacts the Processor directly, the Processor will pass the request to the Controller within 5 working days and will not answer it unless told to.
4.7 Help the Controller with security, breach notices, DPIAs and prior consultation with the regulator (Articles 32 to 36).
4.8 At the end of the service, delete or return all Personal Data, at the Controller's choice, within 90 days. Backups roll off within a further 30 days. This does not apply where law requires the Processor to keep data.
4.9 Give the Controller the information needed to show compliance with Article 28. Allow audits under clause 8.
4.10 Not sell Personal Data. Not use it to train models for other customers in a way that identifies any person. Aggregated, de-identified statistics that cannot identify any person or salon may be used to improve the service.
5. Sub-processors
5.1 The Controller gives general authorisation to the Sub-processors in Schedule 2.
5.2 The Processor will give at least 30 days' notice by email of any new or replaced Sub-processor. The Controller may object on reasonable data protection grounds within that time. If the parties cannot agree, the Controller may end the affected service and get a pro rata refund of prepaid fees.
5.3 The Processor will put a written contract in place with each Sub-processor with data protection terms no weaker than this DPA. The Processor stays liable for its Sub-processors.
6. International transfers
6.1 The Processor hosts Personal Data in the UK (AWS London, eu-west-2).
6.2 Some Sub-processors are outside the UK. The Processor will only transfer Personal Data out of the UK with a valid safeguard. These include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the ICO International Data Transfer Agreement, or the ICO Addendum to the EU Standard Contractual Clauses. The Processor will do a transfer risk assessment where needed.
6.3 Where the Controller is in the EU, the EU Standard Contractual Clauses (Module 2 or 3 as fits) apply to transfers to the UK, unless EU adequacy for the UK covers the transfer.
7. Breaches
7.1 The Processor will tell the Controller without undue delay, and in any case within 36 hours, after becoming aware of a Breach affecting Personal Data.
7.2 The notice will include, as far as known: what happened; the types and rough number of people and records; likely effects; steps taken and planned; and a contact point. The Processor will send more detail as it learns it.
7.3 The Controller decides whether to tell the regulator and the people affected. The Processor will not do so without the Controller's agreement, unless law requires it.
8. Audits
8.1 The Processor will answer reasonable written security questionnaires once a year.
8.2 If that is not enough, or after a Breach, or if a regulator asks, the Controller may audit on 30 days' notice, in working hours, at its own cost, with an auditor bound by confidentiality. No more than once in 12 months unless after a Breach.
9. Liability
Liability under this DPA is subject to the limits in the Main Agreement.
10. Term and order of precedence
This DPA lasts as long as the Processor handles Personal Data for the Controller. If this DPA conflicts with the Main Agreement on data protection, this DPA wins.
11. Law
This DPA is governed by the law of Northern Ireland. The courts of Northern Ireland have exclusive jurisdiction.
Schedule 1: Details of processing
| Item | Detail |
|---|---|
| Subject matter | Reading the Controller's booking calendar and writing prices to fill empty appointment slots ("autopilot"), plus reports in the dashboard |
| Duration | The term of the Main Agreement, plus up to 90 days for deletion |
| Nature | Collection via the booking platform API and webhooks, storage, analysis, automated price setting, reporting, deletion |
| Purpose | To recommend and apply prices for appointment slots, and to measure the results |
| People | (a) The Controller's clients who book appointments; (b) the Controller's staff and stylists; (c) the Controller's admin users |
| Data about clients | Booking platform customer ID (a pseudonymous ID), appointment time, service, price paid, booking and cancellation events. Names, emails, phone numbers, notes and custom fields are removed on receipt and not stored |
| Data about staff | Staff ID, staff name, work email, working hours, which appointments they deliver, how full their diary is |
| Data about admin users | Name, work email, phone, role |
| Special category data | None intended. The Controller must not send any. Free-text notes are removed on receipt |
| Automated decisions | Prices are set for time slots, not for people. No decision is made about any person that has legal or similarly significant effects |
Schedule 2: Authorised Sub-processors
| Sub-processor | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting (ECS), database (MongoDB on EC2), cache (Redis), storage (S3), secrets | All Personal Data | UK, London (eu-west-2) | None needed (UK) |
| Stytch, Inc. | Dashboard login and sessions | Admin user name, email, session data | USA | Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension) |
| Resend (Plus Five Five, Inc.) | Sending setup and service emails | Admin user email, name | USA | Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension) |
| Functional Software, Inc. (Sentry) | Error monitoring | Technical data, tenant ID | EU (Germany) | EU adequacy |
| Datadog, Inc. | Logs, metrics and traces | Technical data, IDs, and any Personal Data that reaches logs | USA (us5 site) | Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension) |
| Timify GmbH (or other booking platform) | The Controller's own booking platform. It is the source of data, chosen by the Controller | Not a Sub-processor of the Processor | Germany | Chosen by Controller |
Slack and any sales tools are used only for the Processor's own lead data. They do not receive Personal Data under this DPA.
Schedule 3: Security measures
- Encryption in transit (TLS) for all external traffic, including the booking platform API and webhooks.
- Secrets kept in AWS Secrets Manager.
- Webhook signatures checked. API keys compared in constant time.
- Names, emails, phones, notes and custom fields removed from booking payloads before storage.
- Logs do not store email addresses in clear.
- Access limited to named staff who need it, with multi-factor authentication on AWS, GitHub and other admin tools.
- Tenant isolation: each salon's data is keyed and queried by tenant.
- Written breach response plan.