Legal
Data processing agreement
The UK GDPR Article 28 terms under which BeautyZilla processes your clients' data on your behalf — part of the terms of service, in force from the day you sign up.
Data processing agreementv1.0effective
How this agreement applies
This Data Processing Agreement ("DPA") is between the business that holds a BeautyZilla salon account (the "Customer", "you") and BeautyZilla ("BeautyZilla", "we", "us"). It forms part of, and is incorporated into, the BeautyZilla terms of service. It takes effect automatically on the day you create your account, or on the effective date shown at the top of this page if your account already existed — whichever is later. No signature, counter-signature or upload is needed: accepting the terms of service accepts this DPA.
If anything in this DPA conflicts with the terms of service on a data-protection point, this DPA prevails. If you and BeautyZilla have signed a separate written data processing agreement, that signed agreement prevails over this page for as long as it is in force.
Definitions
Words used with a capital letter have the following meanings; anything not defined here has the meaning given in the Data Protection Laws.
- Data Protection Laws — the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), and, where it applies to you, the EU GDPR (Regulation (EU) 2016/679), each as amended or replaced from time to time.
- Customer Personal Data — personal data about your clients, your staff and any other individual that you enter into, upload to, or collect through BeautyZilla, and that we process on your behalf.
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing have the meanings given in the UK GDPR.
- Sub-processor — a third party we engage to process Customer Personal Data on our behalf in order to provide the Service.
- Service — the BeautyZilla booking, point-of-sale, messaging and marketplace software described in the terms of service.
- Standard Contractual Clauses — the EU Commission's standard contractual clauses for international transfers (Decision (EU) 2021/914), and the UK International Data Transfer Agreement or Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
Roles of the parties
You are the Controller of Customer Personal Data. Your clients are your clients: you decide why their details are collected, what is recorded about them, how long it is kept, and what they are told about it. You are responsible for having a lawful basis for that processing and for giving your clients your own privacy notice.
BeautyZilla is your Processor for Customer Personal Data. We process it only to provide the Service to you and only on your documented instructions, as set out in this DPA.
BeautyZilla is a Controller in its own right for a narrower set of data: the account data of the salon owners and staff who sign in to the platform, billing records, usage and security logs, and the accounts of consumers who register directly with the BeautyZilla marketplace. That processing is governed by our privacy policy, not by this DPA.
Subject matter, duration, nature and purpose
- Subject matter — the personal data you store in BeautyZilla to run your business: client records, appointments, staff rotas, sales and the messages the Service sends on your behalf.
- Duration — for as long as you hold an active BeautyZilla account, plus the deletion period described under "Deletion and return of data" below.
- Nature — storage, retrieval, organisation, transmission (appointment confirmations, reminders and replies by email, SMS and WhatsApp), backup, search indexing and deletion, all carried out by automated means within the Service.
- Purpose — providing the Service to you: taking and managing bookings, running your till, keeping client histories, sending the messages you configure, and publishing the listing you choose to publish on the marketplace.
Categories of data subjects and personal data
Data subjects
- Your clients and prospective clients, including people who book with you through the marketplace.
- Your staff, contractors and anyone else you give a login or a rota slot to.
- Anyone else whose details you record in a client note, a booking or a message.
Personal data
- Names, email addresses, mobile numbers and postal addresses.
- Appointment history: services booked, dates, times, the staff member seen, attendance and no-shows.
- Client notes you write, which may include information about allergies, patch tests or sensitivities. Where such a note is health data, it is special category data under Article 9 of the UK GDPR and you must have an Article 9 condition for recording it.
- Payment status, deposit and refund records, and the last four digits and card brand of a stored card.
- Message history: the reminders, confirmations and replies sent through the Service.
Card numbers are never Customer Personal Data held by BeautyZilla. Full card details are collected directly by Stripe and never pass through our servers.
Instructions and confidentiality
We process Customer Personal Data only on your documented instructions. Your instructions are: this DPA, the terms of service, the settings you choose in the Service, and any further written instruction you give us that is consistent with the Service. We will tell you promptly if, in our opinion, an instruction infringes Data Protection Laws, and we may suspend that instruction until the point is resolved.
Where a law of the United Kingdom, or of a country whose law applies to us, requires us to process Customer Personal Data in a way you have not instructed, we will tell you before doing so unless that law forbids us from telling you.
Every member of our staff and every contractor who can access Customer Personal Data is bound by a written confidentiality obligation, has access only to the extent their role requires, and is trained in data protection before being given that access.
Security measures
Taking into account the state of the art, the cost of implementation and the risks to the individuals concerned, we maintain the following technical and organisational measures for Customer Personal Data, as required by Article 32 of the UK GDPR:
- Encryption in transit — every connection to the Service, and every connection between our servers and our sub-processors, uses TLS.
- Encryption at rest — the database volume that stores Customer Personal Data is encrypted at rest, as are backups of it.
- Tenant isolation — each salon is a separate tenant, and row-level security policies in the database itself prevent one tenant's queries from ever returning another tenant's rows, in addition to the checks in the application.
- Role-based access — owner, manager and staff roles limit what each login can see and do; you control who holds each role.
- Audit log — sensitive actions (exports, deletions, permission changes, refunds) are written to a tamper-evident audit log you can review in the console.
- Backups and restore drills — the database is backed up daily, backups are retained on a rolling schedule, and we periodically restore a backup to confirm it can actually be recovered.
- Operational controls — least-privilege access to production for our own staff, two-factor authentication on infrastructure accounts, dependency and vulnerability monitoring, and a documented incident-response procedure.
We may update these measures as technology and threats change, provided the overall level of protection does not fall.
Sub-processors
You give us general written authorisation to engage Sub-processors to help provide the Service. The current list, with what each one does and where it processes data, is Schedule 3 of this DPA and is published at /legal/subprocessors.
- Notice — before we add a new Sub-processor, or change what an existing one does with Customer Personal Data, we will update that page at least 30 days before the change takes effect and show the date the change applies from.
- Right to object — you may object in writing, on reasonable data-protection grounds, within those 30 days. We will work with you in good faith to find an alternative. If none is reasonably available, you may terminate the affected part of the Service without penalty, and we will refund any subscription fees you have paid in advance for the period after termination.
- Flow-down — each Sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each Sub-processor's obligations.
Assistance with data subject requests and impact assessments
The Service is built so that you can answer most requests yourself: you can search, export, correct and delete an individual client's record from the console without asking us.
If a Data Subject writes to us directly about Customer Personal Data, we will not respond on the merits; we will pass the request to you within five working days and tell the individual we have done so. Where a request cannot be met through the console, we will provide the assistance reasonably needed for you to respond within the statutory period.
Taking into account the nature of the processing and the information available to us, we will also give you reasonable assistance with data protection impact assessments and with any prior consultation of the Information Commissioner's Office that those assessments require. We may charge a reasonable fee, agreed in advance, for assistance that goes materially beyond what the Service already provides.
Personal data breach notification
If we become aware of a Personal Data Breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it, by email to your account owner's address. The notification will include, so far as we then know it:
- the nature of the breach, the categories and approximate number of individuals and records concerned;
- the likely consequences of the breach;
- the measures we have taken or propose to take to address it and to limit its effects; and
- a contact point for further information.
Where we cannot provide all of that at once, we will provide it in phases without further undue delay. We will cooperate with you so that you can meet your own obligation to notify the Information Commissioner's Office within 72 hours and, where required, the affected individuals. We will not notify a regulator or an individual on your behalf, or name you publicly in connection with a breach, unless the law requires it.
Deletion and return of data
You can export your client list, appointment history and sales records from the console at any time while your account is open, in a structured, commonly used, machine-readable format.
When your account is closed, whether by you or by us under the terms of service:
- your export remains available for 30 days after the closure date;
- we then delete Customer Personal Data from the live Service within 30 days of the closure date, unless United Kingdom law requires us to keep specific records for longer, in which case we keep only those records and only for that period;
- copies held in encrypted backups are overwritten in the ordinary backup rotation and are gone within 90 days of the closure date; backups are never restored to a live system except to recover from a failure, and any Customer Personal Data restored that way is deleted again immediately.
We will confirm deletion in writing if you ask us to.
Audit and information rights
We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR, including this DPA, a description of our security measures, the sub-processor register, and written answers to a reasonable security questionnaire no more than once in any 12-month period.
If that information does not reasonably satisfy you, or a supervisory authority requires it, you may carry out an audit, yourself or through an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits are on at least 30 days' written notice, during business hours, no more than once in any 12-month period unless a Personal Data Breach has occurred, and conducted so as not to disrupt the Service for other customers. You bear your own costs; we bear ours unless the audit reveals a material breach of this DPA.
International transfers
The Service is hosted in the United Kingdom and European Economic Area. Some Sub-processors process data outside the UK and EEA, principally in the United States, as shown in the region column of the sub-processor register.
We will not transfer Customer Personal Data outside the UK, or outside the EEA where the EU GDPR applies to you, unless the transfer is covered by adequacy regulations made under section 17A of the Data Protection Act 2018 (or an EU adequacy decision), or by appropriate safeguards: for transfers from the UK, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; for transfers from the EEA, the EU Standard Contractual Clauses. Where we rely on such clauses with a Sub-processor, we carry out a transfer risk assessment first.
Where necessary to enable such a transfer, you authorise us to enter into the Standard Contractual Clauses with a Sub-processor on your behalf as your agent.
Liability, precedence and governing law
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the terms of service, which apply to this DPA as if set out here, save that nothing limits either party's liability to the extent it cannot be limited by law. Nothing in this DPA relieves either party of its own direct obligations under Data Protection Laws or affects a Data Subject's rights against either party.
This DPA, and any dispute or claim arising out of or in connection with it, is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, in each case as set out in the terms of service.
Questions about this DPA, or a request to sign it as a standalone document for your own records, can be sent to info.beautyzilla@gmail.com.
Version history
- Version 1.0First edition.