Pretty Pooches

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the grooming business (the "Controller", "you") and Pretty Pooches Ltd (the "Processor", "we", "us"). It governs our processing of personal data on your behalf and is designed to satisfy Article 28 of the UK GDPR. Where the Terms of Service and this DPA conflict on data protection, this DPA prevails.

This is our standard documentation; last updated [[ DATE ]]. It explains our processing commitments in plain terms and is not legal advice.

1. Definitions

"UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018. "Personal data", "controller", "processor", "processing", "data subject", "personal data breach" and "sub-processor" have the meanings given in the UK GDPR. The "Customer Personal Data" means the personal data of your customers and their pets that we process on your behalf through the platform.

2. Roles + scope

For the Customer Personal Data, you are the controller and Pretty Pooches is the processor. Each party will comply with its obligations under the UK GDPR. This DPA does not apply to data for which Pretty Pooches is the controller (for example operator account and platform-usage data), which is covered by our Privacy notice.

3. Subject-matter, duration, nature + purpose

  • Subject-matter: processing of Customer Personal Data to provide the booking, payments and communications platform.
  • Duration: for as long as you have an active account, and thereafter only as needed to return or delete the data and to retain anonymised booking records as set out below.
  • Nature: collection, storage, organisation, retrieval, use, transmission to sub-processors, anonymisation and deletion, by automated means.
  • Purpose: creating and managing bookings, taking deposits and payments, scheduling and travel planning, sending booking reminders and service messages, and supporting the service — all on your documented instructions.

4. Types of personal data + categories of data subjects

Categories of data subjects: your customers (pet parents) and, where relevant, the people they list on a booking.

Types of personal data: name, email address and phone number; postal address and geolocation / latitude-longitude (for collect-and-return and mobile bookings); pet records (name, breed, size, coat, temperament, vaccination status, photos and care notes); booking history; marketing preferences; push-notification tokens; and reminder / delivery logs. Card numbers are not processed by us — they are handled directly by Stripe. We do not intend to process special-category data; any health-style notes are limited to the pet's grooming care.

5. Processing only on documented instructions

We will process Customer Personal Data only on your documented instructions — including the instructions embodied in the platform's configuration and in the Terms of Service — unless required to do otherwise by law, in which case we will tell you first unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes the UK GDPR.

6. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are limited to those who need access to provide the service.

7. Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: row-level multi-tenant isolation so one business's data is not accessible to another; encryption in transit; access controls and least-privilege; secrets held in a secrets manager rather than plain columns; separated operator / consumer / public API surfaces with their own authorisation; rate limiting and webhook signature verification; and logging and error monitoring. PCI-scope card data is handled by Stripe.

8. Sub-processors

You give general authorisation for us to engage sub-processors to provide the service. We impose data-protection terms on each sub-processor that are no less protective than this DPA ("flow-down"), and we remain responsible to you for their performance. Our current sub-processors are:

Sub-processorPurposeRegion
StripeCard payments, deposits, payouts (Connect) and plan billingUK / EU / US
Amazon Web Services (incl. SES)Hosting, data storage and transactional emailUK (eu-west-2)
TwilioSMS booking reminders and notificationsUK / EU / US
Meta — WhatsApp Cloud APIWhatsApp messaging (currently dormant / feature-flagged off)EU / US
EntriCustom-domain connection and DNS / SSLUS
Google / MapboxGeocoding and travel-time (distance matrix)EU / US
Fly.io + CloudflareApplication hosting, CDN and edge networkingUK / global edge
SentryError monitoring and diagnosticsEU / US
PostHogProduct analytics — usage measurement, funnels, heatmaps and session replay (replay masks all form input by default). Loaded only after analytics consent.EU (eu.i.posthog.com)

We will give you advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.

9. Assisting with data-subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability and objection). The platform provides self-service tools for this: operators can export and delete data from the back-office, and your customers can export their own data (GET /v1/me/export) and delete their account (DELETE /v1/me, which hard-deletes and cascades their data and anonymises related bookings) from the customer app or booking site. Where a request reaches us directly, we will refer it to you unless you instruct otherwise.

10. Personal data breach notification

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, so far as known, the nature of the breach, likely consequences and the measures taken or proposed, so that you can meet your own notification obligations to the ICO and affected data subjects.

11. Assisting with your obligations

Taking into account the nature of processing and the information available to us, we will assist you in meeting your obligations under Articles 32–36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation).

12. Deletion or return on termination

On termination of your account, at your choice we will return or delete the Customer Personal Data and delete existing copies, unless retention is required by law. As an exception, we anonymise and retain booking records for around 7 years to meet UK tax and dispute-resolution obligations; once anonymised these records no longer identify a data subject.

13. Audit + records

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (save where required by a regulator or after a breach), and subject to confidentiality. We may satisfy audit requests by providing relevant third-party certifications or reports where available.

14. International transfers

Our primary hosting and storage of Customer Personal Data is in the UK (AWS region eu-west-2, London). Where a sub-processor processes Customer Personal Data outside the UK, we ensure an appropriate safeguard is in place under the UK GDPR — UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — and we will provide details on request.

15. Liability + governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the laws of England & Wales.

16. Contact

For any question about this DPA or our processing, contact our data-protection contact [[ DPO / DATA-PROTECTION LEAD NAME ]] at privacy@prettypooches.app.
Data Processing Agreement — Pretty Pooches