This Data Processing Addendum ("Addendum") forms part of the Terms of Service (the "Principal Agreement") between Belle Newco Limited, a UK private limited company with company number 10816660 doing business as Slick (the "Processor") and Processor’s Client (as defined in the Terms) that has subscribed to Processor’s Services (the “Company”) (together as the “Parties”). The terms of this Addendum supersede and govern over any conflicting or inconsistent terms in the Principal Agreement in relation to the Processing of Customer Personal Data and Data Transfers.
WHEREAS:
A. The Company acts as a Data Controller.
B. The Company wishes to subcontract certain Services, which imply the processing of Personal Data, to the Processor.
C. The Parties seek to implement a data processing agreement that complies with the requirements of current legal framework in relation to Processing and Data Transfer under applicable Data Protection Laws.
D. The Parties wish to lay down their rights and obligations.
IT IS AGREED AS FOLLOWS:
1. Definitions and Interpretation
1.1. Unless otherwise defined herein or in the Terms of Service, capitalized terms and expressions used in this Agreement shall have the following meaning:
1.1.1. "Agreement" means this Addendum and all Schedules;
1.1.2. "Customer Personal Data" means any Personal Data of Customers that may be processed by Processor on behalf of Company pursuant to or in connection with the Principal Agreement;
1.1.3. "Contracted Processor" means a Subprocessor;
1.1.4. “Customer” means a customer, as well as any employees, contractors, or other end-users of Company’s services that may provide Personal Data to the Company using the Services;
1.1.5. "Data Protection Laws" means EU Data Protection Laws, UK Data Protection Laws, US Data Protection Laws, and other applicable laws and regulations on the Transfer and Processing of Customer Personal Data;
1.1.6. "Data Transfer" means:
1.1.6.1. a transfer of Customer Personal Data from Processor to a Contracted Processor; or
1.1.6.2. an onward transfer of Customer Personal Data from a Contracted Processor to a subcontracted Processor, or between two establishments of a Contracted Processor, in each case, where such transfer would be regulated by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
1.1.7. "EEA" means the European Economic Area;
1.1.8. "EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including as amended and superseded by the EU General Data Protection Regulation 2016/679 (GDPR) and laws implementing or supplementing the GDPR;
1.1.9. “Process(ing)” means any operation or set of operations which is performed on Customer Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.1.10. "Services" means the Processor’s Services as defined and described in its Terms of Service, including without limitation websites and mobile applications that allow Company and Company’s Customers to use Processor’s Services to manage bookings and appointments, process payments, and otherwise manage and conduct Company’s business and Customer’s interactions with the Company.
1.1.11. "Subprocessor" means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Agreement.
1.1.12. “UK Data Protection Laws” means the United Kingdom General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018 (as amended);
1.1.13. “US Data Protection Laws” means all applicable federal, state, and local laws and implementing regulations of the United States of America, governing personal privacy, security and data protection, including, without limitation, the California Consumer Privacy Act (CCPA) of 2018, as amended by the California Privacy Rights Act (CPRA) of 2020.
1.1.14. The terms, "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
2. Processing of Customer Personal Data
2.1. Company hereby instructs and directs Processor to only process Personal Data for the limited purpose described herein and subject to the terms and conditions of this Agreement. Company shall at all times retain control of the Personal Data and remains responsible for its compliance obligations under applicable Data Protection Laws, including providing any required notices and obtaining any required consents, and for the processing instructions it gives to Processor.
2.2. All Customer Personal Data processed by Processor pursuant to this Agreement will only be processed by Processor for the limited and specific purpose of providing Company and its Customers with the Services, and only in accordance with Company’s instructions. In furtherance of this limited purpose, Processor may use non-sensitive, non-special categories of Customer Personal Data for its own internal performance benchmarking and analytics to monitor, maintain, improve, and upgrade the Services. Processor will not process Customer Personal Data for any other purpose. Schedule 1 attached hereto and incorporated herein by reference, describes the general categories of Customer Personal Data the Processor may Process to fulfill the limited purpose described herein. Company shall disclose Customer Personal Data to the Processor only for the limited and specified purposes in Schedule 1.
2.3. Processor shall, to the extent reasonably practicable, promptly delete (or return to Company, at Company’s election) any Customer Personal Data received under this Agreement: (i) upon written request by Company; or (ii) upon termination of this Agreement. Notwithstanding the foregoing, Processor may retain Customer Personal Data where required by applicable law, regulatory obligations, backups, security logs, dispute preservation, or similar legitimate business needs as may be allowed by applicable law.
2.4. Processor shall:
2.4.1. comply with all applicable Data Protection Laws in the Processing of Customer Personal Data; and
2.4.2. not Process Customer Personal Data other than on the Company’s documented instructions.
2.4.3. Processor shall respond promptly to all enquiries from Company relating to Processor’s processing of Customer Personal Data.
2.5. Company shall, to the extent not provided under the Principal Agreement or otherwise accomplished by Processor as part of the Services:
2.5.1. give Data Subjects sufficient notice and disclosure regarding Company’s use of (and if applicable disclosure of) Customer Personal Data, pursuant to GDPR Article 13 and comparable Data Protection Laws;
2.5.2. obtain Data Subjects’ consent to use of (and if applicable disclosure of) Customer Personal Data by Company and disclosure of Customer Personal Data to Processor for the purpose of providing the Services.
3. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Customer Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Customer Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with applicable Data Protection Laws in the context of that individual's duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
4. Security
4.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Customer Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. Such measures shall include all reasonable security procedures and practices.
4.2. In assessing the appropriate level of security, Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
5. Subprocessing
5.1. Processor may permit Subprocessors to process Customer Personal Data, but only for the same limited and specific purpose as Processor and for no other purpose. Processor represents and warrants to Company that such Subprocessors will be directed by Processor to comply with all of Processor’s obligations under the Agreement regarding processing of Customer Personal Data, including security measures. Upon Company’s written request, Processor will provide Company with a list of all Subprocessors, and copies of the relevant provisions of Processor’s agreements with Subprocessors relating to Processor’s obligations pursuant to this Agreement. Processor will notify Company in writing promptly upon becoming aware of any breach by a Subprocessor of the terms of this Agreement regarding processing of Customer Personal Data. Notwithstanding anything to the contrary in the Agreement, if Company raises any privacy or data protection concerns with any Subprocessors, Company shall have the right to either: (a) terminate the Agreement immediately upon providing written notice to Processor, or (b) prohibit the particular Subprocessor from accessing Customer Personal Data. Except as expressly provided in this Agreement, there are no other warranties of Processor, express or implied, including the implied warranties of merchantability or fitness for a particular purpose, all of which are hereby disclaimed. Company hereby expressly authorizes Processor to appoint its affiliated entity, Daysmart Software LLC, a Delaware, USA, limited liability company, as a Subprocessor under this Agreement. Company reserves the right to revoke Subprocessor’s authorization upon notice to Processor.
6. Data Subject Rights
6.1. Taking into account the nature of the Processing, Processor shall assist the Company by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Company’s obligations under Data Protection Laws, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws. Company shall promptly notify Processor of any requests or demands from a Data Subject regarding Customer Personal Data.
6.2. Processor shall:
6.2.1. provide Company with information reasonably necessary to satisfy Company’s notice and disclosure requirements to Data Subjects under Data Protection Laws;
6.2.2. promptly notify Company if it receives a request from a Data Subject under any Data Protection Law in respect of Customer Personal Data; and
6.2.3. ensure that it does not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Processor is subject, in which case Processor shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Processor responds to the request.
7. Personal Data Breach
7.1. Processor shall notify Company without undue delay upon Processor becoming aware of a Personal Data Breach affecting Customer Personal Data, providing Company with sufficient information to allow the Company to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws, provided however that under no circumstances will such notice be deemed an admission of liability or responsibility for the Personal Data Breach that is the subject of any such notice.
7.2. Processor shall co-operate with the Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
8. Data Protection Impact Assessment and Prior Consultation
8.1. Processor shall provide reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervisory Authorities or other competent data privacy authorities, which Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Customer Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
9. Deletion or return of Customer Personal Data
9.1. Processor shall only process Customer Personal Data for the duration of Company’s Agreement with Processor and as required to perform any post-termination obligations as directed by Company. In case of cessation of any Service involving the Processing of Customer Personal Data, Processor shall delete all Customer Personal Data to the extent permitted by Data Protection Laws (or other applicable law) and in accordance with our Terms and Conditions and Privacy Policy. Should Company or any Data Subject require a copy of any Customer Personal Data, Company or the Data Subject must request such data before the deletion of Company’s account; requests to return data made after Company’s account has been deleted can no longer be considered.
9.2. Subject to this section 9, Processor shall promptly and in any event within 10 business days of Company’s request or the date of cessation of any Services involving the Processing of Customer Personal Data (the "Cessation Date"), delete and procure the deletion of all copies of Customer Personal Data or return all Customer Personal Data at Company’s election. If Processor retains Customer Personal Data beyond the Cessation Date as may be allowed by applicable law, Processor will continue to manage and protect such data pursuant to this Agreement.
10. Audit rights
10.1. Subject to this section 10, Processor shall make available to the Company on reasonable request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company in relation to the Processing of the Customer Personal Data by Processor and/or Contracted Processors. Any such audit shall be at Company’s expense, upon reasonable advance written notice, during normal business hours, and no more than once per calendar year unless Company reasonably suspects violation of Processor’s obligations. The results of any such audit or investigation shall remain confidential, subject to applicable law and compulsory legal disclosures.
10.2. Information and audit rights of the Company only arise under section 10.1 to the extent that the Agreement does not otherwise give Company such information. Such audit rights are expressly limited to the extent necessary to satisfy Company’s rights and obligations under Data Protection Laws and to meet relevant requirements of Data Protection Laws.
11. International Data Transfer
11.1. Processor may subject Customer Personal Data to Data Transfer(s) outside the UK and/or the EEA provided that such Data Transfer is made in compliance with applicable Data Protection Laws and further provided that the Data Transfer is to a country or territory recognized to have an adequate level of protection pursuant to Article 45 GDPR or Processor implements appropriate safeguards such as an International Data Transfer Agreement pursuant to UK Data Protection Laws and/or Standard Contractual Clauses adopted by the European Commission (as amended, replaced, or superseded from time to time) pursuant to EU Data Protection Laws, which the parties agree shall be incorporated by reference and deemed executed between the Processor (or relevant Subprocessor) and the recipient upon transfer.
11.2. Without limiting the foregoing, Company acknowledges and agrees that the Processor's affiliated companies, including Daysmart Software, LLC, a Delaware, USA, limited liability company and Subprocessors may be located outside the UK and/or EEA, and consents to such transfers on the basis set out in this Section, without requiring separate prior authorization for each Data Transfer.
11.3. Where guidance, decisions, or regulatory developments (including from the UK Information Commissioner’s Office, European Commission, the EDPB, or a competent supervisory authority) require execution of updated transfer documentation or additional safeguards, the Parties shall cooperate in good faith to implement such changes, and the Processor may make such updates unilaterally where necessary to maintain a valid transfer mechanism, notifying the Company of any material change.
12. General Terms
12.1. Limitations. The terms and conditions of this Agreement shall only apply to the extent required by Data Protection Laws applicable to Company and Processor in the jurisdiction in which Company is located. Processor’s liability under this Agreement shall be limited to the extent provided in the Principal Agreement.
12.2. Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
(a) disclosure is required by law;
(b) the relevant information is already in the public domain.
12.3. Notices. All notices and communications given under this Agreement must be in writing and will be delivered personally, sent by post, or sent by email to the address or email address set out in Processor’s Terms & Conditions and if to Company at Company’s address provided to Processor at the time of Company’s registration for the Services, or at such other address as notified from time to time by the Parties changing address.
12.4. Severability. This Agreement is intended to be enforceable according to its terms; however, to the extent any court or regulatory authority of competent jurisdiction determines that any provision of this Agreement is invalid or unenforceable, the remainder of this Agreement shall remain valid and any invalid or unenforceable provision shall be amended or interpreted as necessary to ensure its enforceability to the maximum extent allowed by law.
13. Governing Law and Jurisdiction
13.1. United States Dispute Resolution. For Companies located in the United States, this Agreement shall be governed by the laws of the State of Arizona, USA. The parties shall resolve any dispute, controversy, or claim arising out of or relating to this Agreement (each a “Dispute”), including Disputes arising from or concerning the interpretation, violation, invalidity, non-performance, or termination of this Agreement: (i) first, by good faith negotiations, and (i) second, if such negotiations do not resolve a Dispute within forty-five (45) days of their commencement, to final and binding arbitration conducted by JAMS in Maricopa County, Arizona, USA.
ANY CLAIMS BROUGHT IN ARBITRATION MAY ONLY BE IN EACH PARTY’S INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING. EACH ARBITRATION SHALL PROCEED INDIVIDUALLY AND THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE CLAIMANT’S CLAIMS IN EACH ARBITRATION PROCEEDING.
The procedures set forth herein shall be the sole and exclusive mechanisms for resolving any Dispute that may arise. Company hereby waives any and all objections to the exercise of jurisdiction over you by JAMS at such location and agree that the parties’ choice of arbitration as a dispute resolution mechanism under this Agreement is intended to be mandatory and not permissive thereby precluding the possibility of litigation in any other forum.
13.2. United Kingdom / International Dispute Resolution. For those Companies located in the United Kingdom or outside the United States, this Agreement and any non-contractual obligations arising hereunder, shall be governed by, and interpreted according to the laws of England and Wales and all disputes arising under this Agreement (including non-contractual disputes or claims) shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Schedule 1 to Data Processing Addendum
Customer Personal Data Processing Purposes and Details
A. Business Purposes:
To provide the Services described in the Agreement and the Principal Agreement, which include monitoring, maintaining, improving, and upgrading the Services.
B. Customer Personal Data Categories:
A. Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) ("California Customer Records"). A name, signature, Social Security number, physical characteristics or description, photograph, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, membership in professional organizations, professional licenses and certifications, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some Customer Personal Data included in this category may overlap with other categories.
C. Protected classification characteristics under California or federal law ("Protected Classes"). Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, reproductive health decision making, military and veteran status, or genetic information (including familial genetic information).
D. Commercial information. Records of personal property, products, or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
E. Biometric information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
F. Internet or other similar network activity. Activity on Processor’s websites, mobile apps, or other digital systems, such as internet browsing history, search history, system usage, electronic communications with us, postings on Processor’s social media sites.
G. Geolocation data. Physical location or movements, such as the time and physical location related to use of Processor’s internet website, application, or device, and GPS location data from mobile devices of consumers who visit Processor’s websites or use Processor’s mobile apps.
H. Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information, such as customer service call monitoring for quality assurance.
I. Inferences drawn from other Customer Personal Data. Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
J. Sensitive/Special Customer Personal Data. Consultation forms may include protected health information that may be regulated under applicable Data Protection Laws, including the Health Insurance Portability and Accountability Act under US Data Protection Laws. Complete account access credentials (i.e. usernames, account logins, account numbers, or card numbers combined with required access/security code or password).
C. Data Subject Types:
Prospective customers, customers, vendors, employees, prospective employees, contractors, partners, and agents of Company.
D. Processing Duration:
The duration of Processing shall be for the term of the Principal Agreement, plus any permitted retention period as provided in the Agreement.
E. Approved Subprocessors:
DaySmart Software LLC, Stripe, Twilio, BigMailer, Intercom, Segment, Sentry, Pusher, Datadog, Vercel, AWS, Expo/EAS, Apple and Google (app stores and mobile crash reporting), and Instagram/Meta CDN and Google Maps for salon microsites.