This DPA forms part of the Terms of Use between the professional/salon workspace controller (“Controller”) and Lovely Brand Estonia OÜ (“Processor”). It applies whenever Controller enters personal data about clients, staff or other data subjects into the workspace.

Scope and instructions

Processor processes personal data only on documented instructions, including these Terms, the configured functions and lawful instructions in the service. Processor promptly informs Controller where legally required if an instruction appears unlawful. Processing duration lasts through service delivery and the documented return/deletion period.

Confidentiality and security

Processor ensures authorised personnel are bound by confidentiality, applies appropriate security under GDPR Article 32, separates salon workspaces through access controls and restricts administrative access. Technical and organisational safeguards are described in Annex B.

Assistance and data subject rights

Processor provides available tools and reasonable assistance for access, correction, export, erasure, restriction, breach assessment and DPIA or authority enquiries, considering the nature of processing and information available.

Personal data breaches

Processor notifies Controller without undue delay after becoming aware of a personal data breach affecting Controller data; it supplies available facts, likely consequences and remedial action in stages as necessary. Controller remains responsible for determining statutory notification obligations.

Subprocessors

Controller gives general authorisation for listed subprocessors in Annex C. Processor imposes suitable obligations on each relevant subprocessor, informs Controller of intended material additions or replacements with a reasonable opportunity to object, and remains accountable under applicable Article 28 obligations. An objection process and consequences of unresolved objections are provided through account notices/support.

Transfers

Processor observes GDPR Chapter V when applicable and uses appropriate safeguards for restricted transfers. Hosting region alone does not determine the location of all processing or remote access.

Return and deletion

At termination, Controller may request available exports of its data. Processor deletes or returns personal data in accordance with the Controller’s lawful instructions, unless retention is required by law. Copies in backups are removed or overwritten under the applicable backup lifecycle.

Information and audits

Processor makes available information necessary to demonstrate compliance with Article 28, including relevant assurance materials, and allows/contributes to legally required audits and inspections subject to proportionate security, confidentiality and operational arrangements. No annual frequency limit overrides statutory rights.

Responsibilities

Controller determines purposes, lawful bases, Article 9 conditions if relevant, notices, staff permissions, data minimisation and retention. Processor must not use client health records or salon data for its own advertising or marketing.

Annex A — processing details

Subject: hosting, synchronisation, access, backup, retrieval, inspection exports and deletion of workspace records. Categories of data subjects: salon clients, staff and authorised business contacts. Categories of data: names/contact details, business activity and training, visit and procedure information, consent/signatures, optional photographs, relevant health-related information, incident reports and audit trails. Nature: recording, storing, organising, retrieving, displaying, transferring to authorised devices and deleting. Duration: active service and defined exit/deletion window.

Annex B — technical and organisational measures

  • Encryption in transit and at rest; secure key management and restricted database administration.
  • Unique account authentication; role-based access to each workspace, location and user.
  • Administrative accounts protected with multifactor authentication; monitored support access and event logs.
  • Secure backups and tested restoration; documented recovery objectives and retention schedule.
  • Incident response, vulnerability management, staff confidentiality and least-privilege access.
  • Prevention of analytics/pixels collecting client records or sensitive data; protection of uploads and app diagnostics.
  • Offline-device storage protection, PIN controls where configured, and safe sign-out and sync.

Annex C — subprocessors

Refer to Document 7: Providers and Subprocessors Register. The current register will be incorporated by reference as it is updated. Not every external platform is a subprocessor: marketing platforms may act as independent or joint controllers for specific purposes.