BeautiDock
Start for free

Data Processing Addendum

· Creative Current LLC

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Business using BeautiDock ("Business", "you") and Creative Current LLC, a New Mexico limited liability company that operates BeautiDock ("Creative Current", "we"). It applies automatically when you accept the Terms, and covers the personal data of your Clients and team members that we process on your behalf.

It is written to meet Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the Swiss data protection act and US state privacy laws such as the California Consumer Privacy Act ("CCPA"). If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data.

1. Roles

  • You are the controller (or "business" under the CCPA) of your Clients' personal data.
  • We are your processor (or "service provider"/"processor" under US state laws).
  • For our own account, billing and security data, we act as an independent controller under our Privacy Policy.

2. Details of the processing

Item Description
Subject matter Providing the BeautiDock service: booking site, online booking, calendar, client list, emails, deposits, loyalty card
Duration For as long as you use the Service, then until deletion under section 10
Nature and purpose Hosting, storing, organizing, displaying and transmitting data so you can take and manage appointments and communicate with Clients
Categories of data subjects Your Clients and prospective Clients; your team members
Categories of personal data Name, email, phone number, postal code, appointment details, booking notes, private notes you add, visit history, loyalty stamps, deposit and refund status; for team members: name, email, photo, bio, working hours
Special categories Not required by the Service. Booking notes may contain health information (such as allergies) if a Client or you write it; you decide whether to collect it

3. Your instructions

We process personal data only on your documented instructions. These Terms, this DPA and your use of the Service's settings and features are your instructions. We will tell you if we believe an instruction breaks data protection law. We do not process your Clients' data for our own purposes, and we do not sell or share it for cross-context behavioral advertising, or combine it with data from other sources except as needed to provide the Service.

You are responsible for the lawfulness of the data you collect and of your instructions, and for giving your Clients the information the law requires (for example, a privacy notice in your booking confirmation or on your site).

4. Confidentiality

Everyone at Creative Current who can access personal data is bound by confidentiality and accesses it only when needed to provide or support the Service.

5. Security

We implement appropriate technical and organizational measures, described in Annex 1, taking into account the state of the art, the costs, and the nature and risks of the processing. We may update these measures as long as the overall level of protection is not reduced.

6. Subprocessors

You give us general authorization to use subprocessors. Our current subprocessors are listed in Annex 2. We impose data protection obligations on each subprocessor that are at least as protective as this DPA, and we remain responsible for their performance.

We will update Annex 2 and notify the account owner by email at least 30 days before a new subprocessor starts processing your data. You may object on reasonable data protection grounds within that period. If we cannot address the objection, you may close your account and we will refund any prepaid fees for the unused period.

7. International transfers

Creative Current is in the United States, and some subprocessors are outside the European Economic Area, the UK and Switzerland. Where a transfer of personal data requires a safeguard:

  • for transfers from the EEA, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated by reference. For clause 7, the docking clause applies; for clause 9, option 2 (general authorization) applies with the notice period in section 6; for clause 11, the optional language does not apply; for clauses 17 and 18, the law and courts of Ireland apply. Annex I of the clauses is completed with section 2 of this DPA, Annex II with Annex 1, and Annex III with Annex 2;
  • for transfers from the UK, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies;
  • for transfers from Switzerland, the Standard Contractual Clauses apply with the necessary adaptations, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

We ensure that our subprocessors' transfers are covered by an appropriate mechanism as well.

8. Assistance

Taking into account the nature of the processing, we will help you:

  • answer requests from data subjects. Most requests can be handled directly in the Service (you can view, edit and delete Client records). If we receive a request directly, we will forward it to you without undue delay and will not answer it ourselves unless you ask us to;
  • carry out data protection impact assessments and prior consultations, by providing the information we reasonably have;
  • meet your security and breach notification obligations.

9. Personal data breaches

We will notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting your data. Our notice will describe, as far as we know, the nature of the breach, the data and people concerned, the likely consequences and the measures taken or proposed. We will take reasonable steps to contain and remedy the breach.

10. Return and deletion

You can export your data at any time on request. When your account is closed, we delete your personal data within 90 days, unless the law requires us to keep it. Data in backups is deleted when the backups are overwritten under our normal cycle, and is protected under this DPA until then.

11. Audits

We will make available the information reasonably needed to show compliance with this DPA, including answers to security questionnaires and, where available, our subprocessors' certifications and audit reports. If that is not enough, you may ask for an audit once a year with at least 30 days' written notice, at your cost, during business hours, by an auditor bound by confidentiality, in a way that does not disrupt the Service or expose other customers' data. Supervisory authorities may audit as the law allows.

12. US state privacy laws

As a service provider, we will not: sell or share your Clients' personal information; retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship with you; or combine it with personal information we receive from others, except as the CCPA allows. We will comply with the applicable obligations of the CCPA and notify you if we can no longer meet them. You may take reasonable steps to stop and remedy unauthorized use.

13. Liability and term

Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow it. This DPA applies for as long as we process personal data on your behalf.

Annex 1: Security measures

  • Encryption: all traffic is encrypted in transit (HTTPS/TLS). Our database and file storage providers encrypt data at rest.
  • Access control: each Business's data is separated by database-level access rules (row-level security). Team members only see the account they belong to. Administrative access is limited to authorized staff.
  • Authentication: passwords are stored hashed by our authentication provider; sessions use secure, HTTP-only cookies.
  • Abuse prevention: rate limiting on public endpoints, bot protection (Cloudflare Turnstile), honeypot fields, and email confirmation for bookings without a deposit.
  • Payments: card data is handled by Stripe (PCI DSS Level 1). We never store full card numbers.
  • Availability and resilience: managed infrastructure with automated backups by our database provider and a global network for delivery.
  • Data minimization: the Service asks for the data needed to manage appointments; analytics are aggregate counters with no personal data; IP addresses are not stored in our database.
  • Maintenance: regular updates of the software and its dependencies.
  • Incident response: security incidents are assessed, contained, notified and remedied as described in section 9.

Annex 2: Subprocessors

Subprocessor Purpose Location of processing
Cloudflare, Inc. (USA) Hosting and delivery of the Service, file storage for photos, bot protection, rate limiting Global network
Supabase Pte. Ltd. (Singapore) Database and authentication European Union (Ireland)
Plus Five Five, Inc. (Resend) (USA) Sending booking confirmations, reminders and service emails United States
Stripe (Stripe, Inc., USA, and Stripe Payments Europe, Ltd., Ireland) Billing of BeautiDock fees. Deposits from Clients are processed by Stripe under your own agreement with Stripe, where Stripe acts as an independent controller United States, European Union

Questions about this DPA: privacy@beautidock.com.