Pretty Pooches

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the grooming business (the "Controller", "you") and Preson Limited, trading as Pretty Pooches — a company registered in England & Wales, company number 17477430, registered office 6 Riverside Court, Croft, Leicester, England, LE9 3HG — (the "Processor", "we", "us"). It governs our processing of personal data on your behalf and is designed to satisfy Article 28 of the UK GDPR. Where the Terms of Service and this DPA conflict on data protection, this DPA prevails.

Version 1.1, last updated 25 September 2026. It explains our processing commitments in plain terms and is not legal advice. What changed in 1.1: section 9 now describes exactly what happens when a customer deletes their account, and the sub-processor list in section 8 is updated.

1. Definitions

"UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018. "Personal data", "controller", "processor", "processing", "data subject", "personal data breach" and "sub-processor" have the meanings given in the UK GDPR. The "Customer Personal Data" means the personal data of your customers and their pets that we process on your behalf through the platform.

2. Roles + scope

For the Customer Personal Data, you are the controller and Pretty Pooches is the processor. Each party will comply with its obligations under the UK GDPR. This DPA does not apply to data for which Pretty Pooches is the controller (for example operator account and platform-usage data), which is covered by our Privacy notice.

3. Subject-matter, duration, nature + purpose

  • Subject-matter: processing of Customer Personal Data to provide the booking, payments and communications platform.
  • Duration: for as long as you have an active account, and thereafter only as needed to return or delete the data and to retain anonymised booking records as set out below.
  • Nature: collection, storage, organisation, retrieval, use, transmission to sub-processors, anonymisation and deletion, by automated means.
  • Purpose: creating and managing bookings, taking deposits and payments, scheduling and travel planning, sending booking reminders and service messages, and supporting the service — all on your documented instructions.

4. Types of personal data + categories of data subjects

Categories of data subjects: your customers (pet parents) and, where relevant, the people they list on a booking.

Types of personal data: name, email address and phone number; postal address and geolocation / latitude-longitude (for collect-and-return and mobile bookings); pet records (name, breed, size, coat, temperament, vaccination status, photos and care notes); booking history; marketing preferences; push-notification tokens; and reminder / delivery logs. Card numbers are not processed by us — they are handled directly by Stripe. We do not intend to process special-category data; any health-style notes are limited to the pet's grooming care.

5. Processing only on documented instructions

We will process Customer Personal Data only on your documented instructions — including the instructions embodied in the platform's configuration and in the Terms of Service — unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes the UK GDPR.

6. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are limited to those who need access to provide the service.

7. Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: row-level multi-tenant isolation so one business's data is not accessible to another; encryption in transit; access controls and least-privilege; secrets held in a secrets manager rather than plain columns; separated operator / consumer / public API surfaces with their own authorisation; rate limiting and webhook signature verification; and logging and error monitoring. PCI-scope card data is handled by Stripe.

8. Sub-processors

You give general authorisation for us to engage sub-processors to provide the service. We impose data-protection terms on each sub-processor that are no less protective than this DPA ("flow-down"), and we remain responsible to you for their performance. Our current sub-processors are:

Sub-processorPurposeRegion
StripeCard payments, deposits, payouts (Connect) and plan billingUK / EU / US
Amazon Web Services (RDS, S3, SES, CloudFront)Hosting, database, file storage, transactional email (SES) and our public-asset CDNEU (eu-west-1, Ireland); CloudFront edge is global
Amazon Bedrock (AWS)AI drafting assistance for our own outreach messages and, where enabled, in-product suggestions; prompts are not used to train the underlying modelsEU (eu-west-1)
TwilioSMS sign-in codes, booking reminders and notificationsUK / EU / US
Meta — WhatsApp Cloud APIWhatsApp messaging and sign-in codes (where enabled — feature-flagged off by default)EU / US
postcodes.ioKeyless UK postcode geocoding for travel planning (postcodes only — no names or contact details)UK
Google Maps PlatformTravel-time (Distance Matrix) and geocoding, only where a business enables it with its own keyEU / US
Google PlacesFinding businesses for our own outreach (search terms and area only — no customer or operator account data)EU / US
Push notifications — Apple (APNs), Google (FCM), ExpoDelivering push notifications to the mobile apps (device token + notification payload), where enabledUS
Umami (self-hosted)Cookieless product analytics — page views and named funnel events with no personal identifiers, on our own servers; nothing is shared with an analytics vendorOur own AWS infrastructure (eu-west-1)
PostHogOptional product analytics — funnels, heatmaps and session replay (replay masks all form input by default). Not currently active; loads only after analytics consent.EU (eu.i.posthog.com)
SentryError monitoring and diagnostics for the websites, apps and API (error reports carry technical details of the request that failed)EU / US
EntriSearching for and buying a new web domain, only if a business buys one through us (not currently active; connecting a domain a business already owns does not use Entri)US
Google Business ProfilePosting updates and reading reviews on a business's Google Business Profile, only where the business connects itEU / US
Meta — Facebook and InstagramPosting to a business's Facebook and Instagram accounts, only where the business connects themEU / US
TikTokPosting to a business's TikTok account, only where the business connects it (not yet available)US / EU

We will give you advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.

9. Assisting with data-subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools for this: operators can export and delete data from the back-office, and your customers can export their own data and delete their account from the customer app or booking site. A deleted account is closed at once and can be restored by the customer signing in again within 30 days. After that we erase their identity from the platform (name, contact details, address, sign-ins, saved card reference and photos) and keep the remaining records in pseudonymised form. Your own records about that customer — their appointments and payments, your notes, and the pet-care and safety records you hold, such as vaccination, consent and intake records — stay with you as controller: we do not delete them on the customer's instruction to us, and you decide whether to erase them. Where a request reaches us directly, we will refer it to you unless you instruct otherwise.

10. Personal data breach notification

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, so far as known, the nature of the breach, likely consequences and the measures taken or proposed, so that you can meet your own notification obligations to the ICO and affected data subjects.

11. Assisting with your obligations

Taking into account the nature of processing and the information available to us, we will assist you in meeting your obligations under Articles 32–36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation).

12. Deletion or return on termination

Before you delete your account you can download the Customer Personal Data from the back-office (Settings → Close account); that is how we return it. We then delete it, and existing copies on the platform, 30 days after your deletion request (you can cancel until then), unless retention is required by law. As that exception, we keep minimised financial records (amounts, currency, dates, payment status and Stripe references, with no customer names, contact details or pet data) for 7 years from the transaction to meet UK tax and accounting obligations, then delete them. Customers you imported or entered yourself, who never signed in and have no other business on the platform, are erased with your account. Any other customer's own account and pet profiles are not deleted; only your link to them and your notes are. Deleted data can remain in our encrypted database backups for up to 35 days, after which it is gone for good; we never restore a backup except to recover from a disaster.

13. Audit + records

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (save where required by a regulator or after a breach), and subject to confidentiality. We may satisfy audit requests by providing relevant third-party certifications or reports where available.

14. International transfers

Our primary hosting and storage of Customer Personal Data is in the EU (AWS region eu-west-1, Ireland), which the UK recognises as adequate. Where a sub-processor processes Customer Personal Data outside the UK and EU, we ensure an appropriate safeguard is in place under the UK GDPR — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — and we will provide details on request.

15. Liability + governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the laws of England & Wales.

16. Contact

For any question about this DPA or our processing, contact our data-protection contact Lewis Preson, Director at privacy@prettypooches.app.
Data Processing Agreement — Pretty Pooches