1. Definitions
"UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018. "Personal data", "controller", "processor", "processing", "data subject", "personal data breach" and "sub-processor" have the meanings given in the UK GDPR. "Client Personal Data" means the personal data of your clients that we process on your behalf through the platform.
2. Roles + scope
For the Client Personal Data, you are the
controller and Beatrice is the
processor. Each party will comply with its obligations under the UK GDPR. This DPA does not apply to data for which Beatrice is the controller (for example your operator account and platform-usage data), which is covered by our
privacy notice.
3. Subject-matter, duration, nature + purpose
- Subject-matter: processing of Client Personal Data to provide the booking, payments and communications platform.
- Duration: for as long as you have an active account, and thereafter only as needed to return or delete the data and to retain anonymised booking records as set out below.
- Nature: collection, storage, organisation, retrieval, use, transmission to sub-processors, anonymisation and deletion, by automated means.
- Purpose: creating and managing appointments, taking deposits and payments, scheduling and travel planning, sending reminders and service messages, and supporting the service — all on your documented instructions.
4. Types of personal data + categories of data subjects
Categories of data subjects: your clients, and where relevant the people they book on behalf of.
Types of personal data: name, email address and phone number; postal address and geolocation (for mobile or at-home appointments); appointment history; the notes you keep about a client's treatments; photos you or the client attach to an appointment record; marketing preferences; push-notification tokens; and reminder / delivery logs. Card numbers are not processed by us — they are handled directly by Stripe.
4a. Special category (health) data
Unlike some booking platforms, we expect special category data under Article 9 to be in scope here: several Beatrice trades must ask a client about allergies, medications, skin conditions or pregnancy, must record a patch-test outcome, or must take informed consent for a procedure such as laser, tattooing, piercing, electrolysis or permanent makeup.
We process that data only to store it against the appointment and make it available to you. We do not use it for any purpose of our own, do not use it to train anything, and do not disclose it to any sub-processor beyond the hosting and storage listed in §8.
Identifying the Article 9(2) condition for collecting it, and keeping the records for as long as your insurer or your local-authority licence requires, are your responsibilities as the controller. We will not delete a record you are required to keep without telling you.
5. Processing only on documented instructions
We will process Client Personal Data only on your documented instructions — including the instructions embodied in the platform's configuration and in the Terms — unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes the UK GDPR.
6. Confidentiality
We ensure that personnel authorised to process Client Personal Data are bound by confidentiality obligations and are limited to those who need access to provide the service.
7. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: row-level multi-tenant isolation so one business's data is not accessible to another; encryption in transit; access controls and least-privilege; secrets held in a secrets manager rather than plain columns; separated operator / client / public API surfaces with their own authorisation; rate limiting and webhook signature verification; and logging and error monitoring. PCI-scope card data is handled by Stripe.
8. Sub-processors
You give general authorisation for us to engage sub-processors to provide the service. We impose data-protection terms on each that are no less protective than this DPA ("flow-down"), and we remain responsible to you for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Region |
|---|
| Stripe | Card payments, deposits, payouts (Connect) and plan billing | UK / EU / US |
| Amazon Web Services (RDS, S3, SES, CloudFront) | Hosting, database, file storage, transactional email (SES) and our public-asset CDN | EU (eu-west-1, Ireland); CloudFront edge is global |
| Amazon Bedrock (AWS) | AI drafting assistance for our own outreach messages and, where enabled, in-product suggestions; prompts are not used to train the underlying models | EU (eu-west-1) |
| Twilio | SMS sign-in codes, booking reminders and notifications | UK / EU / US |
| Meta — WhatsApp Cloud API | WhatsApp messaging and sign-in codes (where enabled — feature-flagged off by default) | EU / US |
| postcodes.io | Keyless UK postcode geocoding for travel planning (postcodes only — no names or contact details) | UK |
| Google Maps Platform | Travel-time (Distance Matrix) and geocoding, only where a business enables it with its own key | EU / US |
| Google Places | Finding businesses for our own outreach (search terms and area only — no customer or operator account data) | EU / US |
| Push notifications — Apple (APNs), Google (FCM), Expo | Delivering push notifications to the mobile apps (device token + notification payload), where enabled | US |
| Umami (self-hosted) | Cookieless product analytics — page views and named funnel events with no personal identifiers, on our own servers; nothing is shared with an analytics vendor | Our own AWS infrastructure (eu-west-1) |
| PostHog | Optional product analytics — funnels, heatmaps and session replay (replay masks all form input by default). Not currently active; loads only after analytics consent. | EU (eu.i.posthog.com) |
| Sentry | Error monitoring and diagnostics for the websites, apps and API (error reports carry technical details of the request that failed) | EU / US |
| Entri | Searching for and buying a new web domain, only if a business buys one through us (not currently active; connecting a domain a business already owns does not use Entri) | US |
| Google Business Profile | Posting updates and reading reviews on a business's Google Business Profile, only where the business connects it | EU / US |
| Meta — Facebook and Instagram | Posting to a business's Facebook and Instagram accounts, only where the business connects them | EU / US |
| TikTok | Posting to a business's TikTok account, only where the business connects it (not yet available) | US / EU |
We will give you advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.
9. Assisting with data-subject requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools for this: you can export and delete data from the back office, and your clients can export their own data and delete their account from the booking site. A deleted account is closed at once and can be restored by the client signing in again within 30 days. After that we erase their identity from the platform (name, contact details, address, sign-ins, saved card reference and photos) and keep the remaining records in pseudonymised form. Your own records about that client — appointments, payments, treatment notes, and consent, patch-test and intake records — stay with you as controller: we do not delete them on the client's instruction to us, and you decide whether to erase them. Where a request reaches us directly, we will refer it to you unless you instruct otherwise.
10. Personal data breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Client Personal Data. The notification will describe, so far as known, the nature of the breach, likely consequences and the measures taken or proposed, so that you can meet your own notification obligations to the ICO and affected data subjects.
11. Assisting with your obligations
Taking into account the nature of processing and the information available to us, we will assist you in meeting your obligations under Articles 32–36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation).
12. Deletion or return on termination
Before you delete your account you can download the Client Personal Data from the back office (Settings → Close account); that is how we return it. We then delete it, and existing copies on the platform, 30 days after your deletion request (you can cancel until then), unless retention is required by law. As that exception, we keep minimised financial records (amounts, currency, dates, payment status and Stripe references, with no client names, contact details or treatment data) for 7 years from the transaction to meet UK tax and accounting obligations, then delete them. A client's own Beatrice account is not deleted; only your link to them and your notes are. A client account that exists only because you imported it is erased along with yours. Deleted data can remain in our encrypted database backups for up to 35 days, after which it is gone for good; we never restore a backup except to recover from a disaster.
13. Audit + records
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (save where required by a regulator or after a breach), and subject to confidentiality. We may satisfy audit requests by providing relevant third-party certifications or reports where available.
14. International transfers
Our primary hosting and storage of Client Personal Data is in the EU (AWS region eu-west-1, Ireland), which the UK recognises as adequate. Where a sub-processor processes Client Personal Data outside the UK and EU, we ensure an appropriate safeguard is in place under the UK GDPR — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — and we will provide details on request.
15. Liability + governing law
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. This DPA is governed by the laws of England & Wales.
16. Contact
For any question about this DPA or our processing, contact our data-protection contact
Lewis Preson, Director at
hello@heybeatrice.com.