Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement ("Main Agreement") between:

It meets Article 28 of the UK GDPR. Where the EU GDPR applies, it meets Article 28 of the EU GDPR too.

1. Definitions

2. Roles

2.1 The Controller decides why and how Personal Data is used. The Processor handles it only for the Controller.

2.2 The Controller confirms it has a lawful basis to share the Personal Data. It confirms its own privacy notice to clients and staff covers this use.

2.3 The Processor is a separate controller for its own account, billing and support data about the Controller's users. That use sits outside this DPA.

3. Details of processing

See Schedule 1.

4. Processor duties

The Processor will:

4.1 Process Personal Data only on the Controller's documented instructions. The Main Agreement, this DPA and the Controller's settings in the dashboard are the instructions. If law requires other processing, the Processor will tell the Controller first, unless the law forbids it.

4.2 Tell the Controller at once if it thinks an instruction breaks Data Protection Law.

4.3 Make sure everyone with access is bound by confidentiality.

4.4 Take the security measures in Schedule 3 (Article 32).

4.5 Only use Sub-processors under clause 5.

4.6 Help the Controller answer requests from people using their rights. If a person contacts the Processor directly, the Processor will pass the request to the Controller within 5 working days and will not answer it unless told to.

4.7 Help the Controller with security, breach notices, DPIAs and prior consultation with the regulator (Articles 32 to 36).

4.8 At the end of the service, delete or return all Personal Data, at the Controller's choice, within 90 days. Backups roll off within a further 30 days. This does not apply where law requires the Processor to keep data.

4.9 Give the Controller the information needed to show compliance with Article 28. Allow audits under clause 8.

4.10 Not sell Personal Data. Not use it to train models for other customers in a way that identifies any person. Aggregated, de-identified statistics that cannot identify any person or salon may be used to improve the service.

5. Sub-processors

5.1 The Controller gives general authorisation to the Sub-processors in Schedule 2.

5.2 The Processor will give at least 30 days' notice by email of any new or replaced Sub-processor. The Controller may object on reasonable data protection grounds within that time. If the parties cannot agree, the Controller may end the affected service and get a pro rata refund of prepaid fees.

5.3 The Processor will put a written contract in place with each Sub-processor with data protection terms no weaker than this DPA. The Processor stays liable for its Sub-processors.

6. International transfers

6.1 The Processor hosts Personal Data in the UK (AWS London, eu-west-2).

6.2 Some Sub-processors are outside the UK. The Processor will only transfer Personal Data out of the UK with a valid safeguard. These include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the ICO International Data Transfer Agreement, or the ICO Addendum to the EU Standard Contractual Clauses. The Processor will do a transfer risk assessment where needed.

6.3 Where the Controller is in the EU, the EU Standard Contractual Clauses (Module 2 or 3 as fits) apply to transfers to the UK, unless EU adequacy for the UK covers the transfer.

7. Breaches

7.1 The Processor will tell the Controller without undue delay, and in any case within 36 hours, after becoming aware of a Breach affecting Personal Data.

7.2 The notice will include, as far as known: what happened; the types and rough number of people and records; likely effects; steps taken and planned; and a contact point. The Processor will send more detail as it learns it.

7.3 The Controller decides whether to tell the regulator and the people affected. The Processor will not do so without the Controller's agreement, unless law requires it.

8. Audits

8.1 The Processor will answer reasonable written security questionnaires once a year.

8.2 If that is not enough, or after a Breach, or if a regulator asks, the Controller may audit on 30 days' notice, in working hours, at its own cost, with an auditor bound by confidentiality. No more than once in 12 months unless after a Breach.

9. Liability

Liability under this DPA is subject to the limits in the Main Agreement.

10. Term and order of precedence

This DPA lasts as long as the Processor handles Personal Data for the Controller. If this DPA conflicts with the Main Agreement on data protection, this DPA wins.

11. Law

This DPA is governed by the law of Northern Ireland. The courts of Northern Ireland have exclusive jurisdiction.


Schedule 1: Details of processing

Item Detail
Subject matter Reading the Controller's booking calendar and writing prices to fill empty appointment slots ("autopilot"), plus reports in the dashboard
Duration The term of the Main Agreement, plus up to 90 days for deletion
Nature Collection via the booking platform API and webhooks, storage, analysis, automated price setting, reporting, deletion
Purpose To recommend and apply prices for appointment slots, and to measure the results
People (a) The Controller's clients who book appointments; (b) the Controller's staff and stylists; (c) the Controller's admin users
Data about clients Booking platform customer ID (a pseudonymous ID), appointment time, service, price paid, booking and cancellation events. Names, emails, phone numbers, notes and custom fields are removed on receipt and not stored
Data about staff Staff ID, staff name, work email, working hours, which appointments they deliver, how full their diary is
Data about admin users Name, work email, phone, role
Special category data None intended. The Controller must not send any. Free-text notes are removed on receipt
Automated decisions Prices are set for time slots, not for people. No decision is made about any person that has legal or similarly significant effects

Schedule 2: Authorised Sub-processors

Sub-processor Purpose Data Location Transfer safeguard
Amazon Web Services EMEA SARL Hosting (ECS), database (MongoDB on EC2), cache (Redis), storage (S3), secrets All Personal Data UK, London (eu-west-2) None needed (UK)
Stytch, Inc. Dashboard login and sessions Admin user name, email, session data USA Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension)
Resend (Plus Five Five, Inc.) Sending setup and service emails Admin user email, name USA Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension)
Functional Software, Inc. (Sentry) Error monitoring Technical data, tenant ID EU (Germany) EU adequacy
Datadog, Inc. Logs, metrics and traces Technical data, IDs, and any Personal Data that reaches logs USA (us5 site) Provider's data processing terms with UK transfer safeguards (UK Addendum or DPF UK Extension)
Timify GmbH (or other booking platform) The Controller's own booking platform. It is the source of data, chosen by the Controller Not a Sub-processor of the Processor Germany Chosen by Controller

Slack and any sales tools are used only for the Processor's own lead data. They do not receive Personal Data under this DPA.

Schedule 3: Security measures