Data Processing Agreement
Last updated: [DATE]
This Data Processing Agreement ("DPA") forms part of the Terms of Service between [COMPANY NAME] Ltd (company number [TBC]) ("BarberDesk", "we", "us", "our", the "Processor") and the barbershop or business using BarberDesk ("you", "your", the "Shop", the "Controller"). It governs how BarberDesk processes personal data relating to your customers on your behalf.
Where this DPA and the Terms of Service conflict on data protection matters, this DPA takes precedence.
1. Roles
1.1 In relation to the personal data of your customers processed through BarberDesk ("Customer Personal Data"), you are the Controller and BarberDesk is the Processor.
1.2 You are responsible for ensuring you have a lawful basis to collect and use Customer Personal Data and for meeting your own obligations as Controller under UK data protection law.
1.3 This DPA does not cover data for which BarberDesk is itself the controller (such as your account and billing data); that data is handled under our Privacy Policy.
2. Definitions
"UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any other applicable data protection laws of England and Wales, as amended.
"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in UK Data Protection Law.
"Sub-processor" means any third party engaged by BarberDesk to process Customer Personal Data.
3. Scope and details of processing
3.1 Subject matter: provision of the BarberDesk booking and shop-management platform.
3.2 Duration: for as long as you use BarberDesk, plus any retention period described in this DPA.
3.3 Nature and purpose: hosting, storing, organising, transmitting, and otherwise processing Customer Personal Data so that you can take bookings, take deposits and no-show charges, and communicate with your customers.
3.4 Types of Personal Data: customer names, contact details (such as email and phone number), appointment and booking history, payment-related records (such as whether a deposit or no-show charge was made), and any notes or messages you or your customers add.
3.5 Categories of Data Subject: your customers and prospective customers.
4. Our obligations as Processor
BarberDesk will:
4.1 process Customer Personal Data only on your documented instructions, which include your use of the platform's features and this DPA, unless we are required to process it by law (in which case we will inform you, unless the law prohibits it);
4.2 ensure that people authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
4.3 implement appropriate technical and organisational measures to protect Customer Personal Data, including measures that keep each shop's data logically separated from every other shop's data (see Section 5);
4.4 not sell Customer Personal Data and not use it for our own purposes;
4.5 assist you, taking into account the nature of the processing and the information available to us, in responding to Data Subject requests and in meeting your security, breach-notification, and data-protection-impact-assessment obligations;
4.6 make available information reasonably necessary to demonstrate our compliance with this DPA;
4.7 tell you without undue delay if, in our opinion, one of your instructions infringes UK Data Protection Law.
5. Security
5.1 We maintain appropriate technical and organisational security measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
5.2 These measures include access controls that separate each shop's data so that one shop cannot access another shop's Customer Personal Data, encryption of data in transit, use of reputable infrastructure providers, and controls over who within BarberDesk can access data.
5.3 We keep data within the UK or EU where reasonably possible, and where data is processed elsewhere we apply the safeguards described in Section 7.
6. Your obligations as Controller
6.1 You must have a lawful basis for collecting and processing Customer Personal Data and must provide your customers with the privacy information required by UK Data Protection Law.
6.2 You must only use Customer Personal Data, and only give your barbers and staff access to it, for the legitimate operation of your business. You must not use Customer Personal Data, and must not permit your staff to use it, for any unlawful, fraudulent, deceptive, or otherwise improper purpose. You are solely responsible for any such misuse by you or your staff.
6.3 You are responsible for the accuracy of the instructions you give us and for the lawfulness of the Customer Personal Data you put into the platform.
6.4 You must configure and use the platform's access controls responsibly, including managing which of your barbers and staff have access to Customer Personal Data.
7. Sub-processors
7.1 You give general authorisation for BarberDesk to engage Sub-processors to help provide the platform. Our current Sub-processors are listed in our Privacy Policy and include our hosting, database, payment, email, messaging, and (where used) AI providers.
7.2 We impose data protection obligations on our Sub-processors that are no less protective than those in this DPA, and we remain responsible for their processing of Customer Personal Data.
7.3 We will give you a way to be informed of changes to our Sub-processors (for example, by updating the list in our Privacy Policy). If you have a reasonable objection to a new Sub-processor on data protection grounds, you may raise it with us, and if we cannot resolve it you may terminate the affected service.
7.4 Where a Sub-processor processes Customer Personal Data outside the UK, we ensure an appropriate transfer safeguard recognised under UK Data Protection Law is in place, such as an adequacy decision or standard contractual clauses.
8. Data Subject requests
8.1 If we receive a request from one of your customers to exercise their data protection rights, we will, where lawful, direct them to you, since you are the Controller.
8.2 We will provide reasonable assistance to help you respond to such requests, using the features of the platform and the information available to us.
9. Personal Data Breaches
9.1 We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 Our notification will include the information reasonably available to us to help you meet any obligation you have to report the breach to the ICO or to affected individuals.
9.3 We will take reasonable steps to mitigate the breach and prevent recurrence.
10. Return and deletion
10.1 On termination of your use of BarberDesk, we will, at your choice, make Customer Personal Data available to you for export for a reasonable period, and then delete or anonymise it, unless we are required by law to retain it.
10.2 We may retain limited data as required for legal, tax, or accounting purposes, protected in line with this DPA and our Privacy Policy.
11. Audit
11.1 We will make available to you information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (unless required by a regulator), allow for and contribute to a reasonable audit, conducted so as not to disrupt our operations or compromise the security of other shops' data.
12. Liability and general
12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12.2 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
12.3 If any part of this DPA is found to be unenforceable, the rest remains in force.
13. Contact
Data protection queries relating to this DPA can be sent to support@barberdesk.co.uk.
[COMPANY NAME] Ltd [REGISTERED ADDRESS] Company number [TBC]
This document is a template prepared for BarberDesk and is not legal advice. It should be reviewed by a qualified solicitor before publication, particularly the security measures, sub-processor, and international transfer provisions.