Data Processing Agreement
Last updated: July 2026 (version 1.0)
1. Parties and scope
This Data Processing Agreement (“DPA”) is entered into between [Your company name](“Processor”) and the styling company that has an active subscription to the platform (“Controller”), and forms part of the subscription agreement between them. It applies whenever the Processor processes personal data on the Controller’s behalf and on its instructions in the course of providing the platform — in particular, personal data about the Controller’s own end clients (homeowners and households) entered into the platform. It does not cover data the Processor holds as an independent controller (see the Privacy Policy, section 2).
2. Subject matter and duration
Subject matter: hosting and processing of personal data entered into the platform by the Controller in order to provide the platform’s project, inventory, and customer-management features. Duration: for as long as the Controller has an active subscription, plus any post-termination retention period agreed in section 8.
3. Nature and purpose of processing
The Processor processes personal data solely to provide, maintain, secure, and support the platform for the Controller — including storing and displaying project/customer records, sending notifications and reminders the Controller configures, and diagnosing technical issues. The Processor does not use this data for its own purposes (e.g. marketing, analytics, or training its own products) and does not sell or share it with third parties except as described in section 6.
4. Categories of data subjects and data
- Data subjects: the Controller’s end clients (homeowners/households) and, where entered, real-estate agents/agencies.
- Data categories: name, contact details (email, phone), property address, and any notes, photos, or project details the Controller chooses to record. The Processor does not require or knowingly process special categories of data (GDPR Art. 9) and the Controller should avoid entering such data unless strictly necessary.
5. Processor obligations
The Processor shall:
- process personal data only on the Controller’s documented instructions (including as set out in this DPA), unless required to do otherwise by law;
- ensure staff and contractors authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (see section 7);
- assist the Controller, insofar as reasonably possible, in responding to data subject rights requests and in meeting its own GDPR obligations (impact assessments, prior consultation);
- notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data;
- make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Controller or an auditor it mandates, subject to reasonable notice and confidentiality.
[Add specifics: audit frequency/process, response-time commitments for breach notification and rights-request assistance, etc.]
6. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed in the Privacy Policy’s sub-processor table, under a written agreement imposing data protection obligations equivalent to those in this DPA. This currently includes infrastructure providers (hosting, storage, frontend delivery) and Anthropic, whose Claude AI assistant is used by the Processor’s engineering team and may be exposed to Controller data during platform build/support work. The Processor will notify the Controller of any intended change to this list (addition or replacement) with a reasonable opportunity to object.
7. Security measures
Encrypted connections (HTTPS/TLS) for all data in transit; bcrypt-hashed passwords; short-lived access tokens and httpOnly refresh cookies; tenant-scoped access controls preventing one Controller from accessing another’s data; rate limiting on authentication endpoints; and an internal audit log of security-relevant account events. [Add any further measures specific to your production environment — backups/disaster recovery, encryption at rest, access review cadence, employee device/security policy, etc.]
8. Data return and deletion
On termination of the subscription, the Processor will, at the Controller’s choice, delete or return all personal data processed under this DPA within [X days — fill in], except to the extent retention is required by law.
9. International transfers
Where a sub-processor is located outside the EEA (see section 6), the Processor relies on an appropriate transfer mechanism (e.g. the EU Standard Contractual Clauses) for that transfer. [Confirm and name the mechanism actually in place for each non-EEA sub-processor.]
10. Liability and governing law
[Add liability allocation and governing law/jurisdiction — typically the same as the main subscription agreement. Have this reviewed by a lawyer before publishing, as these terms carry real legal and financial consequences.]
11. Signing this agreement
An owner of your account can review and sign the current version of this DPA from within the platform (you’ll be prompted automatically the first time you log in after a new account is created, or after this document changes). See the platform’s in-app prompt for the signing form — no separate paperwork is required for this placeholder flow. If your organisation requires a countersigned PDF for its own records, use the contact form to request one.