Who is who: The salon using the system is the Controller of its clients' data. BeautyForms is the Processor, which processes that data solely to the extent necessary to provide the service.
1Definitions
GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
Controller — the Customer, i.e. the salon, studio or other entity using the Service, which decides on the purposes and means of processing its clients' data.
Processor — the operator of the BeautyForms service.
Data — personal data of the Controller's clients entered into the Service.
2Subject and purpose of processing
2.1 The Controller entrusts the Processor with processing the Data solely for the purpose of providing the electronic client-card and consultation-form service, within the scope and for the time specified in the Terms of Service.
2.2 The Processor processes the Data solely on the documented instruction of the Controller, which consists in particular of using the Service's functions.
3Scope of entrusted data
| Category of persons | Categories of data |
| Clients of the Controller |
First and last name, date of birth, phone number, e-mail address, data entered by the Controller in the form fields, including health data (Art. 9 GDPR) to the extent defined by the Controller itself, image in the form of treatment photographs, electronic signature, content and date of consents given. |
| The Controller's staff |
First and last name, e-mail address, login credentials, activity log in the Service. |
The scope of health data results from the content of forms designed by the Controller itself. The Processor does not decide what information the Controller asks its clients for.
4Obligations of the Processor
The Processor undertakes to:
- process the Data solely on the documented instruction of the Controller;
- ensure that persons authorised to process the Data have committed themselves to confidentiality;
- apply technical and organisational measures appropriate to the risk, including encryption of transmission and data at rest, access control, authentication and regular backups;
- assist the Controller in responding to requests from data subjects (the right of access, rectification, erasure, restriction, portability and objection) by providing the appropriate functions of the Service;
- assist the Controller in fulfilling the obligations under Art. 32–36 GDPR;
- notify the Controller of a Data breach without undue delay after becoming aware of it, no later than within 24 hours;
- make available to the Controller the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allow for audits on the terms set out in §6;
- delete or return the Data after the provision of the service has ended, in accordance with §7.
5Sub-processing
5.1 The Controller gives general consent for the Processor to use further processors (sub-processors) in the area of server infrastructure, sending SMS and e-mail messages, and payment handling.
5.2 The Processor ensures that each sub-processor is bound by data-protection obligations corresponding to those under this agreement, and bears full liability towards the Controller for the performance of their obligations.
5.3 The Processor will inform the Controller in advance of any intended changes concerning the addition or replacement of a sub-processor, allowing the Controller to object.
6Audit
6.1 The Controller has the right to carry out an audit of the processing of the entrusted Data, subject to prior notice of at least 14 days, no more than once per calendar year, during working hours and in a manner that does not disrupt the Processor's ongoing operations.
6.2 The Processor may first present current documents or reports confirming compliance, if they sufficiently correspond to the scope of the audit.
7Term and termination
7.1 The agreement remains in force for as long as the Controller uses the Service.
7.2 After the service agreement is terminated, the Controller is able to export the Data on its own for a period of 30 days. After that period, the Data is permanently deleted, unless an obligation to retain it further results from the law.
7.3 The Controller may at any time delete the data of a selected client or the entire account on its own, using the functions of the Service.
8Location of processing
8.1 The Data is processed on servers located within the European Economic Area (EEA). The Processor does not transfer the Data to third countries outside the European Economic Area without first informing the Controller and ensuring a legal basis for such a transfer.
9Liability
9.1 Each party is liable for damage caused by processing where it has failed to comply with the obligations under the GDPR directly imposed on it, or has acted outside the lawful instructions of the other party.
9.2 The Controller bears sole responsibility for the lawfulness of collecting the Data, in particular for having the proper legal basis, the content of information clauses and the scope of questions contained in the forms it creates.
10Final provisions
10.1 In matters not regulated herein, the provisions of the GDPR, the data-protection law and the Civil Code apply.
10.2 The agreement is concluded upon acceptance of the Terms of Service and does not require written form. At the Controller's request, the Processor will make the document available in PDF format.