1. Definitions
"UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018. "Personal data", "controller", "processor", "processing", "data subject", "personal data breach" and "sub-processor" have the meanings given in the UK GDPR. The "Customer Personal Data" means the personal data of your customers and their pets that we process on your behalf through the platform.
2. Roles + scope
For the Customer Personal Data, you are the
controller and Pretty Pooches is the
processor. Each party will comply with its obligations under the UK GDPR. This DPA does not apply to data for which Pretty Pooches is the controller (for example operator account and platform-usage data), which is covered by our
Privacy notice.
3. Subject-matter, duration, nature + purpose
- Subject-matter: processing of Customer Personal Data to provide the booking, payments and communications platform.
- Duration: for as long as you have an active account, and thereafter only as needed to return or delete the data and to retain anonymised booking records as set out below.
- Nature: collection, storage, organisation, retrieval, use, transmission to sub-processors, anonymisation and deletion, by automated means.
- Purpose: creating and managing bookings, taking deposits and payments, scheduling and travel planning, sending booking reminders and service messages, and supporting the service — all on your documented instructions.
4. Types of personal data + categories of data subjects
Categories of data subjects: your customers (pet parents) and, where relevant, the people they list on a booking.
Types of personal data: name, email address and phone number; postal address and geolocation / latitude-longitude (for collect-and-return and mobile bookings); pet records (name, breed, size, coat, temperament, vaccination status, photos and care notes); booking history; marketing preferences; push-notification tokens; and reminder / delivery logs. Card numbers are not processed by us — they are handled directly by Stripe. We do not intend to process special-category data; any health-style notes are limited to the pet's grooming care.
5. Processing only on documented instructions
We will process Customer Personal Data only on your documented instructions — including the instructions embodied in the platform's configuration and in the Terms of Service — unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes the UK GDPR.
6. Confidentiality
We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are limited to those who need access to provide the service.
7. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: row-level multi-tenant isolation so one business's data is not accessible to another; encryption in transit; access controls and least-privilege; secrets held in a secrets manager rather than plain columns; separated operator / consumer / public API surfaces with their own authorisation; rate limiting and webhook signature verification; and logging and error monitoring. PCI-scope card data is handled by Stripe.
8. Sub-processors
You give general authorisation for us to engage sub-processors to provide the service. We impose data-protection terms on each sub-processor that are no less protective than this DPA ("flow-down"), and we remain responsible to you for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Region |
|---|
| Stripe | Card payments, deposits, payouts (Connect) and plan billing | UK / EU / US |
| Amazon Web Services (incl. SES) | Hosting, data storage and transactional email | UK (eu-west-2) |
| Twilio | SMS booking reminders and notifications | UK / EU / US |
| Meta — WhatsApp Cloud API | WhatsApp messaging (currently dormant / feature-flagged off) | EU / US |
| Entri | Custom-domain connection and DNS / SSL | US |
| Google / Mapbox | Geocoding and travel-time (distance matrix) | EU / US |
| Fly.io + Cloudflare | Application hosting, CDN and edge networking | UK / global edge |
| Sentry | Error monitoring and diagnostics | EU / US |
| PostHog | Product analytics — usage measurement, funnels, heatmaps and session replay (replay masks all form input by default). Loaded only after analytics consent. | EU (eu.i.posthog.com) |
We will give you advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.
9. Assisting with data-subject requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools for this: operators can export and delete data from the back-office, and your customers can export their own data (GET /v1/me/export) and delete their account (DELETE /v1/me, which hard-deletes and cascades their data and anonymises related bookings) from the customer app or booking site. Where a request reaches us directly, we will refer it to you unless you instruct otherwise.
10. Personal data breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, so far as known, the nature of the breach, likely consequences and the measures taken or proposed, so that you can meet your own notification obligations to the ICO and affected data subjects.
11. Assisting with your obligations
Taking into account the nature of processing and the information available to us, we will assist you in meeting your obligations under Articles 32–36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation).
12. Deletion or return on termination
On termination of your account, at your choice we will return or delete the Customer Personal Data and delete existing copies, unless retention is required by law. As an exception, we anonymise and retain booking records for around 7 years to meet UK tax and dispute-resolution obligations; once anonymised these records no longer identify a data subject.
13. Audit + records
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (save where required by a regulator or after a breach), and subject to confidentiality. We may satisfy audit requests by providing relevant third-party certifications or reports where available.
14. International transfers
Our primary hosting and storage of Customer Personal Data is in the UK (AWS region eu-west-2, London). Where a sub-processor processes Customer Personal Data outside the UK, we ensure an appropriate safeguard is in place under the UK GDPR — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — and we will provide details on request.
15. Liability + governing law
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the laws of England & Wales.
16. Contact
For any question about this DPA or our processing, contact our data-protection contact
[[ DPO / DATA-PROTECTION LEAD NAME ]] at
privacy@prettypooches.app.