Legal

Data Processing Agreement

This DPA applies when Appointso processes personal data on behalf of a salon using the platform.

1. Scope

This Data Processing Agreement forms part of the Appointso Terms of Service where a salon uses Appointso to process personal data about its own customers, employees or appointment-related contacts.

In that context, the salon is the controller and Appointso is the processor, unless mandatory law or a separate agreement says otherwise.

2. Subject matter and duration

Appointso processes data to provide appointment booking, scheduling, customer management, notifications, messaging assistant workflows, billing-related platform access and support for the duration of the salon’s use of the service.

3. Data subjects and categories of data

Data subjects may include salon customers, salon employees, salon owners and other contacts interacting with the salon through Appointso.

Data categories may include names, phone numbers, email addresses, appointment details, services, prices, employee assignment, booking history, message content, delivery metadata and support communications.

4. Processor obligations

Appointso will process personal data only according to the salon’s documented instructions through the platform and these terms, unless required by law.

Appointso will ensure that personnel authorized to process personal data are bound by confidentiality obligations, implement appropriate security measures, assist with data subject requests where reasonably possible, and notify the salon of personal data breaches without undue delay after becoming aware of them.

5. Security measures

Security measures may include TLS, access controls, role-based permissions, password hashing, audit logging, tenant isolation, operational monitoring, backup practices and restricted administrative access.

6. Subprocessors

The salon authorizes Appointso to use subprocessors needed to provide the service. Current subprocessors are listed on the Subprocessors page. We may update that list when providers change.

7. International transfers

Where subprocessors process data outside the relevant jurisdiction, Appointso will rely on appropriate transfer mechanisms where required by applicable data protection law.

8. Deletion and return

Upon termination or written request, Appointso will delete or return personal data where reasonably possible, subject to backup cycles, legal obligations, fraud prevention, accounting records and security retention.

9. Audits and information

Appointso will make reasonable information available to help salons assess compliance with this DPA. Audit requests must be reasonable, limited in scope, confidential and not disrupt the service.

10. Contact

Questions about this DPA can be sent to [email protected].