Data processing agreement

Updated 2026-09-10

The LT version is the legally binding one.

1. Parties and when this agreement applies

This agreement is between the salon using the edapi system (the Controller) and edapi (edapi.io), an individual engineering practice in Lithuania (the Processor).

It is an annex to the Terms of service and takes effect together with them when the salon signs up. No separate signature is needed — GDPR Art. 28(9) allows written form in electronic form. At sign-up we record which version of the terms the salon accepted.

It applies for as long as the Processor processes personal data on behalf of the Controller.

2. Roles

The Controller decides whose data and what data goes into the system and for what purpose — so it is the controller with respect to its own clients.

The Processor processes the data only to make the system work and only on the Controller instructions. We do not use the Controller client data for our own purposes: no profiling, no offering it to other salons, no shared client directory (a matter of principle, not a temporary state).

For salon account data (the owner and staff) the Processor acts as an independent controller — described in the Privacy policy.

3. Subject matter, nature, purpose and duration

Subject matter and purpose: taking and managing salon bookings, client records, email reminders and confirmations, deposit collection, review collection, messages and campaigns.

Nature: collecting, storing, displaying to persons authorised by the Controller, sending by email, deleting and anonymising on the Controller instruction, and backups.

Duration: for as long as the service is used, plus the deletion period set out in this agreement.

4. Types of data and categories of data subjects

Data subjects: salon clients, people a booking is made for (when someone else books) and salon staff.

Types of data: name, phone number, email address, salon notes, allergy and health notes, visit history with services, times, prices and statuses, deposit payment facts, consents and their history, email delivery records, message content, reviews and no-show counts.

Special category data: allergy and health notes (GDPR Art. 9). The lawful basis for them is the Controller responsibility; the system offers the field but does not require it.

5. Processor obligations

To process the data only on the documented instructions of the Controller. Using the system itself is an instruction (the records, sends and deletions the Controller performs), as are requests received in writing.

To inform the Controller without delay if, in our view, an instruction infringes the GDPR or other data protection law (Art. 28(3)).

To ensure confidentiality: only people who need it to provide the service have access to system data, and they are bound by a duty of confidentiality.

To assist the Controller in fulfilling data subject rights (Art. 12-23). In the system the Controller can do it directly: a client data copy (JSON and CSV) and erasure of personal data are one button each in the client record.

To assist the Controller with its Art. 32-36 obligations: providing information about security measures, breaches and, where needed, facts for an impact assessment.

On termination, to delete or return the data as set out below.

6. Security measures (GDPR Art. 32)

All traffic is encrypted over HTTPS. Passwords are stored only as cryptographic hashes.

Every database query is mandatorily scoped to a single salon in the application layer — a query without a salon context does not run. This protects against salon data mixing.

Server access is protected by an SSH key with no password login; the database is not reachable from the internet.

Destructive actions are written to an action log with author and time. Access rights are checked on the server against a role matrix, not by hiding buttons.

The booking form is protected by a Cloudflare Turnstile check and rate limits.

A database backup is taken automatically every night and kept in encrypted Cloudflare R2 storage; copies older than 30 days are deleted.

The system carries no analytics or advertising scripts — no data leaves to third parties for tracking.

7. Sub-processors

The Controller gives general authorisation to use sub-processors. Each is used under its published data processing terms (a GDPR Art. 28 compliant DPA) imposing obligations no lower than those in this agreement; we provide the links on request.

Contabo GmbH (Germany) — server and database hosting.

Cloudflare, Inc. — domain, traffic protection (Turnstile), R2 photo storage and nightly database backups.

Resend, Inc. — system emails (confirmations, reminders) and campaign emails.

Stripe, Inc. / Stripe Payments Europe Ltd. — the salon subscription and client deposits. Card data is handled only by Stripe.

Google (Gemini API) — text draft generation when the Controller asks for it. Only text the Controller typed is sent; client data is not.

We give 30 days notice by email before replacing or adding a sub-processor. If the Controller objects it may end the agreement within that time without paying for the remaining period.

8. Personal data breach notification

If we identify a personal data breach we inform the Controller without undue delay and no later than 48 hours after becoming aware of it.

The notice states what happened, which data and how many subjects are affected (as far as known), the measures we took and what we recommend. Notifying the supervisory authority and the data subjects is the Controller duty; we supply the facts needed for it.

9. Deletion and return of data

The Controller can download a copy of the whole salon data in a machine-readable format from the admin area at any time — no separate request is needed for return.

After termination we delete the data within 30 days of a written request from the Controller, sent from the account email address. Data disappears from backups according to the backup rotation cycle.

Automatic retention periods after an account is closed will be published together with the account closing feature; until then data is not deleted by itself, so that no salon loses it unexpectedly.

We do not delete what the law requires us to keep (for example accounting documents) or data from which personal data has already been removed (visit times and amounts without personal data).

10. Information and audit

At the Controller written request we provide the information needed to verify compliance with this agreement: a description of security measures, the sub-processor list and answers to data protection questionnaires.

If that is not enough, an audit is possible at a pre-agreed time, no more than once a year (or after a breach), without disrupting the service for other salons and without disclosing their data.

11. Transfers outside the EEA

The server and database are in the European Union. Some sub-processors (Cloudflare, Resend, Stripe, Google) are US-based and may process data outside the EEA — such transfers rely on the European Commission standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

12. Final provisions

This agreement prevails over the Terms of service on matters concerning personal data processing. The terms apply to everything else.

The version and date of this agreement are shown at the top of the page; changes follow the same 30 day notice rule as the terms. Questions: [email protected].