Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the grooming business (the "Controller", "you") and Preson Limited, trading as Pretty Pooches — a company registered in England & Wales, company number 17477430, registered office 6 Riverside Court, Croft, Leicester, England, LE9 3HG — (the "Processor", "we", "us"). It governs our processing of personal data on your behalf and is designed to satisfy Article 28 of the UK GDPR. Where the Terms of Service and this DPA conflict on data protection, this DPA prevails.
Version 1.1, last updated 25 September 2026. It explains our processing commitments in plain terms and is not legal advice. What changed in 1.1: section 9 now describes exactly what happens when a customer deletes their account, and the sub-processor list in section 8 is updated.
1. Definitions
2. Roles + scope
3. Subject-matter, duration, nature + purpose
- Subject-matter: processing of Customer Personal Data to provide the booking, payments and communications platform.
- Duration: for as long as you have an active account, and thereafter only as needed to return or delete the data and to retain anonymised booking records as set out below.
- Nature: collection, storage, organisation, retrieval, use, transmission to sub-processors, anonymisation and deletion, by automated means.
- Purpose: creating and managing bookings, taking deposits and payments, scheduling and travel planning, sending booking reminders and service messages, and supporting the service — all on your documented instructions.
4. Types of personal data + categories of data subjects
Categories of data subjects: your customers (pet parents) and, where relevant, the people they list on a booking.
Types of personal data: name, email address and phone number; postal address and geolocation / latitude-longitude (for collect-and-return and mobile bookings); pet records (name, breed, size, coat, temperament, vaccination status, photos and care notes); booking history; marketing preferences; push-notification tokens; and reminder / delivery logs. Card numbers are not processed by us — they are handled directly by Stripe. We do not intend to process special-category data; any health-style notes are limited to the pet's grooming care.
5. Processing only on documented instructions
6. Confidentiality
7. Security
8. Sub-processors
You give general authorisation for us to engage sub-processors to provide the service. We impose data-protection terms on each sub-processor that are no less protective than this DPA ("flow-down"), and we remain responsible to you for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Region |
|---|---|---|
| Stripe | Card payments, deposits, payouts (Connect) and plan billing | UK / EU / US |
| Amazon Web Services (RDS, S3, SES, CloudFront) | Hosting, database, file storage, transactional email (SES) and our public-asset CDN | EU (eu-west-1, Ireland); CloudFront edge is global |
| Amazon Bedrock (AWS) | AI drafting assistance for our own outreach messages and, where enabled, in-product suggestions; prompts are not used to train the underlying models | EU (eu-west-1) |
| Twilio | SMS sign-in codes, booking reminders and notifications | UK / EU / US |
| Meta — WhatsApp Cloud API | WhatsApp messaging and sign-in codes (where enabled — feature-flagged off by default) | EU / US |
| postcodes.io | Keyless UK postcode geocoding for travel planning (postcodes only — no names or contact details) | UK |
| Google Maps Platform | Travel-time (Distance Matrix) and geocoding, only where a business enables it with its own key | EU / US |
| Google Places | Finding businesses for our own outreach (search terms and area only — no customer or operator account data) | EU / US |
| Push notifications — Apple (APNs), Google (FCM), Expo | Delivering push notifications to the mobile apps (device token + notification payload), where enabled | US |
| Umami (self-hosted) | Cookieless product analytics — page views and named funnel events with no personal identifiers, on our own servers; nothing is shared with an analytics vendor | Our own AWS infrastructure (eu-west-1) |
| PostHog | Optional product analytics — funnels, heatmaps and session replay (replay masks all form input by default). Not currently active; loads only after analytics consent. | EU (eu.i.posthog.com) |
| Sentry | Error monitoring and diagnostics for the websites, apps and API (error reports carry technical details of the request that failed) | EU / US |
| Entri | Searching for and buying a new web domain, only if a business buys one through us (not currently active; connecting a domain a business already owns does not use Entri) | US |
| Google Business Profile | Posting updates and reading reviews on a business's Google Business Profile, only where the business connects it | EU / US |
| Meta — Facebook and Instagram | Posting to a business's Facebook and Instagram accounts, only where the business connects them | EU / US |
| TikTok | Posting to a business's TikTok account, only where the business connects it (not yet available) | US / EU |
We will give you advance notice of any intended addition or replacement of a sub-processor so you have the opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.