Data processing agreement

Last updated: 17 July 2026

Introduction and scope

This Data Processing Agreement ("DPA") forms part of our agreement with business customers on a Salon or Schools team plan who act as a data controller for personal data of their own staff or students processed through the Service, for example when a salon owner adds team members to their plan.

If you're an individual subscriber, this DPA doesn't apply to you — see our Privacy Policy instead. Terms used in this DPA have the meaning given in UK GDPR unless defined otherwise below. If there is any conflict between this DPA and our Terms of Service in relation to the processing of Personal Data, this DPA prevails.

Definitions

  • "Controller" and "Processor" have the meanings given in UK GDPR.
  • "Data Subject" means an identified or identifiable individual whose personal data is processed under this DPA, such as one of your team members.
  • "Personal Data" means any information relating to a Data Subject that we process on your behalf through the Service.
  • "Sub-processor" means a third party we engage to help process Personal Data on your behalf, as listed below.
  • "UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018.

Roles and responsibilities

Where this DPA applies, you are the controller of personal data belonging to your team members that you submit to, or that is generated through, the Service, and we are the processor, acting only on your documented instructions as set out in our Terms of Service and this DPA. We'll tell you if, in our opinion, an instruction infringes UK GDPR or other applicable data protection law.

Details of processing

  • Subject matter: provision of the Service to your team members.
  • Duration: for as long as your Subscription is active, plus any further period described in our Privacy Policy.
  • Nature and purpose: account management, course access, progress tracking, and support.
  • Categories of data subjects: your team members.
  • Categories of personal data: as described in the "Information we collect" section of our Privacy Policy.

Sub-processors

We use the following sub-processors to provide the Service. You authorise us to engage them, subject to the safeguards described below:

  • Amazon Web Services, Inc. — Cloud hosting, database, file storage, transactional email delivery, and push notification delivery (United Kingdom and Ireland).
  • Stripe, Inc. — Payment processing for web subscriptions (card details are tokenised by Stripe and never reach our servers) (United States).
  • RevenueCat, Inc. — Subscription management for iOS and Android in-app purchases (United States).
  • Google LLC — "Sign in with Google" authentication and Android push notification delivery (Firebase Cloud Messaging) (United States).
  • Apple Inc. — "Sign in with Apple" authentication and iOS push notification delivery (APNs) (United States).
  • PostHog Inc. — Product analytics on the public website and native app (event analytics only — no session recording) (European Union (EU Cloud, Frankfurt)).

We'll give you reasonable notice before adding a new sub-processor that will process your team members' personal data, so you can object on reasonable data protection grounds.

Confidentiality

We ensure that the people we authorise to process Personal Data are subject to an appropriate duty of confidentiality, whether contractual or statutory, and are made aware of the confidential nature of the data.

Security measures

We use appropriate technical and organisational measures to protect Personal Data, including encryption in transit and at rest, access controls limiting who can view it, and regular review of our security practices.

Assistance with data subject rights

Where one of your team members asks us directly to exercise a data subject right, for example to access or delete their data, we'll either direct them to you or assist you in responding, as appropriate. We'll help you respond to any request you receive, taking into account the nature of the processing.

Personal data breaches

If we become aware of a personal data breach affecting your team members' personal data, we'll notify you without undue delay, and provide the information reasonably available to us to help you meet your own notification obligations.

International transfers

Some of our sub-processors are based outside the UK, or may access Personal Data from outside the UK, including from the United States (see the list above). Where we transfer Personal Data outside the UK, we put appropriate safeguards in place, such as Standard Contractual Clauses approved for use in the UK, reliance on the UK–US Data Bridge, or another adequacy mechanism recognised under UK GDPR. Details of the specific safeguard used for a given transfer are available on request at .

Return and deletion of data

When your Subscription ends, we'll delete or return your team members' personal data in line with the retention practices described in our Privacy Policy, except where we're required to retain it for longer by law.

Audits

We'll make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for audits, including inspections, conducted by you or an auditor you appoint, on reasonable notice and subject to reasonable confidentiality and security requirements.

Governing law

This DPA is governed by the laws of England and Wales, in line with our Terms of Service.

Contact us

Questions about this Data Processing Agreement? Contact us at .

Questions? Email

Get the app