Data Processing Agreement
[Insert publish date, e.g. "21 July 2026"] · Version 1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Lean Salon ("Processor", "we") and the salon using our platform ("Controller", "you"), and governs the processing of personal data of your clients and staff that you enter into Lean Salon. It reflects the requirements of Article 28 of the General Data Protection Regulation (GDPR).
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "sub-processor" and "personal data breach" have the meaning given to them in the GDPR.
- •Controller: the salon using Lean Salon — you determine the purposes and means of processing your clients' and staff's personal data.
- •Processor: Lean Salon (eenmanszaak, Pijnsweg 29, 6419 CH Heerlen, KvK 42089738) — we process that data on your instructions, to provide the service.
- •Sub-processor: a third party we engage to help deliver the service, who also processes personal data on our behalf (see the list in section 5).
2. Subject matter and duration
This DPA applies for as long as Lean Salon processes personal data on your behalf under our Terms of Service — from the start of your account until the data is deleted or returned in accordance with section 10.
3. Nature, purpose and categories of data
We process personal data solely to provide the Lean Salon service: scheduling and managing appointments, processing payments, sending reminders and confirmations, responding to WhatsApp messages, and generating business insights for you as the salon.
- •Categories of data subjects: your clients, and your staff members with a Lean Salon login.
- •Categories of personal data: name, email address, phone number, appointment history, notes you add about a client, and message content exchanged via our WhatsApp assistant. We do not require or expect you to enter special categories of personal data (e.g. health data) into free-text fields, and ask you not to do so beyond what is strictly necessary for providing your services.
4. Our obligations as processor
We will:
- •Process personal data only on your documented instructions, including regarding international transfers, unless required to do otherwise by EU or member state law.
- •Ensure that people authorised to process personal data (our own staff, where applicable) are bound by confidentiality.
- •Implement appropriate technical and organisational security measures, as described in section 6.
- •Assist you, as far as reasonably possible, in responding to requests from data subjects exercising their GDPR rights (access, rectification, erasure, restriction, portability, objection).
- •Assist you in meeting your own obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments), taking into account the nature of processing and the information available to us.
- •Delete or return all personal data at the end of the provision of services, as described in section 10.
- •Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described in section 9.
5. Sub-processors
You give us general authorisation to engage the following sub-processors to help deliver the service, each bound by their own data processing agreement with us:
- •Microsoft Azure — hosting and infrastructure (Northern Europe region).
- •Mollie — payment processing.
- •Mailgun — transactional and inbound email.
- •Meta (WhatsApp Business Platform) — WhatsApp messaging.
- •Google (Gemini) — AI processing of messages, invoices and images.
- •OpenAI — AI processing used to generate strategic salon advice and periodic business reports.
- •Anthropic (Claude) — AI processing of messages, invoices and images.
6. Adding or replacing sub-processors
If we intend to add or replace a sub-processor, we will inform you in advance (for example by email or a notice in the dashboard). You may object on reasonable data-protection grounds within a reasonable period after notice; if we cannot address your objection, either party may terminate the affected part of the service.
7. International data transfers
We aim to host and process data within the European Economic Area (EEA) — our hosting infrastructure (Microsoft Azure) runs in the Northern Europe region.
Some of our sub-processors (including OpenAI and Anthropic, both based in the United States) are located outside the EEA. For these, we rely on Standard Contractual Clauses (SCCs), approved by the European Commission. You can read more about Standard Contractual Clauses here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
8. Security measures
We use industry-standard technical and organisational measures to protect personal data, consistent with our Privacy Policy:
- •Hosting with Microsoft Azure (Northern Europe region), with encryption of data in transit (TLS) and at rest.
- •Passwords, API keys and other secrets are never stored in source code, but managed via Azure Key Vault.
- •Access to Azure resources uses Managed Identity, avoiding long-lived credentials that could leak.
- •Strict separation of data between salons at the database level (Row-Level Security), so that one salon's data is never accessible to another salon.
- •Role-based access within your own dashboard (e.g. owner versus staff member).
9. Personal data breaches
[DRAFT — for legal review.] If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 48 hours of becoming aware, so you can meet your own obligation to notify the Dutch Data Protection Authority within 72 hours where required. Our notification will include what we know at that time about the nature of the breach, the likely consequences, and the measures taken or proposed.
10. Audits
[DRAFT — for legal review.] On reasonable written request, we will make available relevant documentation to demonstrate our compliance with this DPA. We allow for an audit, including inspections, once per calendar year with reasonable advance notice, or promptly following a confirmed personal data breach. Audits are carried out in a way that avoids unreasonable disruption to our operations and other customers, and reasonable costs may be agreed in advance.
11. Deletion or return of data
Upon termination of your use of Lean Salon, we will, at your choice, delete or return all personal data processed on your behalf, and delete existing copies, unless EU or member state law requires us to retain the data (for example, invoice data under Dutch tax retention rules — see our Privacy Policy for specific retention periods).
12. Liability
Liability under this DPA is governed by the limitation of liability clause in our Terms of Service.
13. Governing law
This DPA is governed by the same law and jurisdiction as our Terms of Service.
14. Contact
Questions about this DPA? Email us at privacy@leansalon.com.