Data processing agreement
Last updated: 5 October 2026
1. Parties and scope of the agreement
The salon identified in its professional account is the controller of the data it entrusts to Bookelya. Its representative declares that they are authorised to bind it. The processor is KURT Brûsk, an individual trading as NOWAVE, enterprise number 0803.438.231, VAT BE 0803.438.231, established at Rue T. Marcotty 5A, 4101 Seraing, Belgium. Contact: contact@bookelya.com. Telephone: +1 646 208 2714.
This agreement and its annexes supplement the professional terms under Article 28 GDPR. They cover operations carried out for the salon throughout their provision and until the data are returned or deleted. This is an original agreement, not the European Commission’s official standard contractual clauses.
The agreement already accepted for online payments remains specific to that module, in its accepted version. It does not cover marketing campaigns or health data in treatment forms, which fall under this general agreement. The specific agreement takes precedence for payment operations; for other salon processing, this agreement takes precedence over conflicting commercial provisions.
2. Documented instructions and own purposes
The features used, the salon’s settings and its written requests constitute documented instructions. Bookelya processes data only on these instructions, including for international transfers, unless legally required otherwise. It then informs the salon before processing unless prohibited by law, and immediately informs it if an instruction appears to infringe data protection law.
Bookelya does not sell the salon’s client database or use it to train an artificial intelligence model. Its own processing for account management, billing for its services, general security, the public directory and moderation is subject to its separate responsibility, described in the privacy policy. Retaining data after the agreement ends does not permit unrestricted reuse.
3. Salon obligations and health data
The salon determines purposes, legal bases, authorised persons and necessary retention periods. It informs clients, establishes the lawful origin of imports, respects objections and responds to rights requests. It limits notes, questions and attachments to what is necessary for treatments and checks the rules applicable to minors.
Custom forms may collect allergies or contraindications where necessary. The salon must have a legal basis under Article 6 and a valid condition under Article 9 GDPR. Where explicit consent is required, it obtains it separately, freely, specifically, on an informed and demonstrable basis, and allows withdrawal. Accepting the terms or making a booking does not constitute such consent.
Refusing or withdrawing consent to health data processing must not prevent a treatment for which that information is unnecessary. Withdrawal does not affect the lawfulness of earlier processing. If relying on another condition under Article 9, the salon must be able to justify it and inform the client.
The salon restricts access to persons who need it, keeps health data out of campaigns, notifications and public content, and sets a limited retention period. Current forms do not have a dedicated mechanism for explicit consent to health data processing. The salon must arrange and retain this evidence before collecting such data; otherwise it must not ask these questions.
4. Confidentiality and security
Bookelya binds persons authorised to process data to confidentiality and limits their access to their duties. The salon protects its team accounts, removes unnecessary permissions and does not share private download links. Existing technical measures are described in Annex III.
Bookelya applies measures appropriate to the risks under Article 32 GDPR and develops them without reducing contractual protection. This agreement makes no claim of security or health data hosting certification, encryption of all files at rest or uninterrupted availability.
5. Assistance and personal data breaches
Taking account of the nature of processing and available information, Bookelya assists the salon with rights requests, security, required impact assessments and prior consultations, and compliance with Articles 32 to 36 GDPR. It forwards requests concerning the salon’s processing and does not decide on its behalf unless instructed or legally required. Requests should be sent to contact@bookelya.com.
Bookelya notifies the salon of any breach of data processed on its behalf without undue delay after becoming aware of it. It progressively provides the nature of the incident, the categories and approximate numbers of affected persons and records, likely consequences, measures taken or proposed and a contact. It does not wait for a complete file; the controller’s 72-hour deadline for notifying the authority is not a waiting period for Bookelya.
6. Subprocessors and transfers
The salon gives general authorisation for the subprocessors in Annex IV solely for the functions described. Bookelya imposes equivalent data protection obligations on them and remains responsible to the salon for their performance.
Before adding or replacing a subprocessor, Bookelya informs the salon in writing of its identity, role, processing countries and proposed safeguards. The salon has at least fifteen days before the new processing to raise a reasoned data protection objection. The parties seek a solution; failing that, the affected processing or service ends without imposing the disputed provider.
A transfer outside the European Economic Area requires a valid safeguard under Chapter V GDPR: an adequacy decision whose scope has been checked, or appropriate transfer clauses with the necessary assessment and supplementary measures. European hosting does not remove the need to check other providers’ data flows. Documents and safeguards applicable to the Bookelya account are available on request; assumed certification is insufficient.
7. Compliance information and audits
Bookelya provides information necessary to demonstrate compliance with this agreement and allows audits, including inspections, by the salon or its appointed auditor. The parties arrange their scope, confidentiality and access to protect other salons and service continuity without removing audit rights. An incident or an authority’s request may justify an urgent or additional review. Charges for specific work require prior agreement and must not obstruct statutory obligations.
8. End of service, return and deletion
At the end of the service, the salon chooses the return or deletion of data processed on its behalf. It exports its data before deleting the account and sends any additional instructions to contact@bookelya.com. Bookelya deletes the data and active copies on instruction within thirty days, except where retention is legally required; the legal basis, data and period are explained to the salon. Backup copies follow the cycle in Annex II and remain isolated from routine use. Data protection obligations continue for as long as data is retained.
The current self-service export is limited to the client list in CSV or XLSX, including available contact details, client record notes, visit statistics and consent information. It excludes the detailed calendar, separate notes and their attachments, form answers and photos, campaigns, website and reviews. The salon may request the complete return of data processed on its behalf at contact@bookelya.com. Bookelya provides it free of charge within thirty days of the request, in CSV or JSON format, together with the associated files and attachments. No automatic account access is provided after deletion.
The payment module separately provides financial CSV exports and dispute evidence, subject to its permissions and specific documents. They are not an export of the entire client record or salon activity.
Cancelling a subscription does not delete the account. Account deletion removes the member from their salons; a salon is deleted only when it has no remaining member. Protected financial operations or disputes may prevent deletion until they are closed. Technical retention periods and backup limitations are described in Annex II.
Annex I — Subject matter, nature and purposes
Operations include collection, import, recording, organisation, consultation, updating, hosting, necessary transmission, export and deletion for features selected by the salon: calendar and bookings; client profiles, notes and attachments; custom forms; reminders and email/SMS campaigns; imports; the salon website; management of reviews and responses on its behalf; available exports. Publication of the directory and moderation determined by Bookelya are its own processing.
No artificial intelligence tool processes data at present. This agreement does not authorise training a model on the salon’s data.
Annex II — Data subjects, data and retention
Data subjects: clients, prospects and imported contacts, reviewers, salon members and staff, and support contacts. Data: identity, contact details, preferences and consent evidence, appointments and treatments, history and statistics, notes, files and photos, form answers that may reveal health information, campaign content, delivery and unsubscribe information, website content and reviews, and necessary identifiers and technical records. Only categories necessary for the feature used are processed.
Answers to salon forms, including health data and associated photos, are deleted twenty-four months after the client’s last appointment at the salon. Reviews are published and retained for three years after publication, then deleted. Client accounts with no login or booking are deleted after three years of inactivity, following a warning email sent thirty days beforehand. Professional accounts are not automatically deleted for inactivity: they follow termination and the salon’s exit instructions. Other business data remains linked to the service until deletion on the salon’s instructions or effective deletion of the salon, subject to necessary legal retention. The salon arranges deletion of data that is no longer needed without waiting for these deadlines.
Unattached form photos normally expire after 24 hours. The daily purge deletes them after an additional one-hour buffer; orphaned files without an expiry become eligible after 24 hours. A pending payment checkout prevents this purge. Timing depends on scheduled tasks actually running.
Backups follow a normal thirty-day cycle: all copies are retained for seven days, followed by daily copies for twenty-three days. The last recoverable copy may remain longer if new backups fail. Deleting data from the database does not instantly remove old copies. Deletion instructions remain applicable if a backup is restored; deleted data must not be returned to routine use.
Annex III — Existing technical measures
Business data are attached to an establishment, with salon filtering and server-side permission checks. Passwords are hashed; sessions and tokens can be revoked on account deletion. Service secrets are supplied through server configuration. Authentication protections and request limits do not replace the salon’s permission management.
New note attachments and form photos are stored on a private disk. Download uses a short-lived signed URL, fifteen minutes by default; a person holding the link can use it while valid. Form photos are validated, size-limited and re-encoded as WebP to remove original file metadata. Older attachments may still use public storage until their migration is completed.
A database backup is scheduled daily and a file backup weekly, with daily cleanup and failure monitoring. These tasks and private storage reduce risks but are neither a guarantee of tested restoration nor evidence of comprehensive encryption. The salon retains exports needed for business continuity.
Annex IV — Providers and transfer safeguards
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: hosting of the application, database and backups in Germany. The provider’s data processing agreement, incorporated into its terms of service, applies. The main service is provided within the EEA, with no transfer outside the EEA for that service.
Resend / Plus Five Five, Inc., United States: transactional emails and salon email campaigns, including recipient address, content and delivery metadata. Processing may take place in the United States and by its subprocessors. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
Twilio Ireland Limited, Ireland: reminder texts and enabled SMS campaigns, including recipient number, content and routing metadata. Its entities, carriers and providers may process data outside the EEA, including in the United States. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
OneSignal, Inc., United States: push notifications relating to appointments and salon activity, including device or user identifiers, content and necessary technical data. Processing may take place in the United States and by its subprocessors. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
OVH, France: management of custom domains for the salon’s website when that option is used, including contact details required for registration. The provider’s data processing agreement, incorporated into its terms of service, applies. The main service is provided within the EEA, with no transfer outside the EEA for that service. Domain registries may receive necessary data according to the chosen extension; this agreement does not place their own obligations under the salon’s instructions.
Crisp, France: chat support when enabled, including the contact’s identity, messages and session information. The provider’s data processing agreement, incorporated into its terms of service, applies. The main service is provided within the EEA, with no transfer outside the EEA for that service. If support receives data processed for the salon, that assistance falls within this processing agreement; the salon must not send health data through this channel.
Slack: technical alerts if the channel is enabled, containing only information needed to monitor an incident. Processing may take place in the United States. Health data and client files must not be copied into alerts. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
Google Tag Manager / Google Analytics / Google Ads and Microsoft Clarity, when enabled, support audience measurement or advertising subject to applicable consent. Adobe Fonts / Typekit loads the site’s fonts and transmits the IP address to Adobe in the United States. These tools are not used to process the salon’s client files or health forms. Their separate purposes and consent choices are described in the privacy and cookie policies. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).
Stripe for subscriptions and payments, RevenueCat for tracking mobile purchases, Apple and Google for their stores and sign-in, Facebook for sign-in and Apple MapKit for maps have the roles and purposes explained in the privacy policy. They are not all subprocessors of the salon’s client files. This annex does not authorise sending health forms to them. Processing may take place outside the EEA, including in the United States. The provider’s data processing agreement, incorporated into its terms of service, applies. Transfers outside the European Economic Area are governed by the EU–US Data Privacy Framework where the provider is certified under it and, otherwise, by the standard contractual clauses adopted by the European Commission (Decision 2021/914).