Verwerkersovereenkomst

DATA PROCESSING AGREEMENT – LOOPPINESS SALONSOFTWARE B.V.

Definitions

GDPR: General Data Protection Regulation.

EEA: European Economic Area.

Sub-processor: A third party engaged by the Processor to process personal data.

1. Parties

Looppiness salonsoftware B.V., established in Eindhoven, the Netherlands, registered with the Dutch Chamber of Commerce under number 95210121, hereinafter referred to as the “Processor”, and

The natural person or legal entity using the services of the Processor, hereinafter referred to as the “Controller”.

2. Applicability

2.1 This Data Processing Agreement forms an integral part of the Subscription Agreement.

2.2 By using the services of the Processor, the Controller agrees to this Agreement.

3. Processing of personal data

3.1 The Processor processes personal data exclusively:

  • For the purpose of providing its services;
  • In accordance with this Agreement;
  • Based on the Controller's use of the software.

3.2 The functionalities of the software and this Agreement constitute complete and sufficient instructions within the meaning of the GDPR.

3.3 The Processor does not determine the purposes and means of the processing.

3.4 The Processor does not process personal data for its own purposes.

4. Purposes and categories of data

4.1 Personal data is processed for the following purposes:

  • Client management;
  • Appointments and scheduling;
  • Administration and invoicing;
  • Online payments and transaction processing.

4.2 Categories of personal data:

  • Names and contact details;
  • Address details;
  • Dates of birth;
  • Payment details;
  • Transaction and payment information.

4.3 Categories of data subjects:

- Clients of the Controller.

5. Security

5.1 The Processor implements appropriate technical and organisational security measures, including:

  • Encrypted connections (SSL/TLS);
  • Access controls and role-based permissions;
  • Logging and monitoring;
  • Secure data storage;
  • Regular updates and security patches;
  • Backups and recovery procedures;
  • Additional authentication and security measures.

5.2 The Processor independently determines which measures are appropriate, taking into account risks, available technology and costs. The Controller acknowledges that the security measures provided are appropriate for the nature of the services.

5.3 The Controller remains responsible for correctly configuring and managing accounts, access rights, role structures and data access within its own organisation, including chair rental arrangements, multiple locations and branch structures.

5.4 The Processor is not liable for unauthorised access, loss of data or other damage resulting from incorrectly configured permissions, shared accounts or improper user management within the Controller's organisation.

6. Sub-processors

6.1 The Controller grants general authorisation for the engagement of sub-processors.

6.2 The Processor remains responsible for its sub-processors.

6.3 An up-to-date list of sub-processors is available upon request.

6.4 The Processor reserves the right to change or add sub-processors during the provision of its services.

7. Rights of data subjects

7.1 The Controller is responsible for handling requests from data subjects.

7.2 The Processor provides assistance insofar as reasonably and technically possible.

7.3 The Processor is entitled to charge fees for such assistance.

8. Personal data breaches

8.1 The Processor shall report a personal data breach without undue delay.

8.2 Information shall be provided based on what is reasonably available.

8.3 The Controller is responsible for notifying supervisory authorities and affected data subjects.

8.4 The Processor is entitled to temporarily restrict or block affected systems or accounts where necessary to limit security risks or damage.

9. Confidentiality

9.1 The Processor treats personal data as confidential.

9.2 Persons with access to personal data are contractually bound by confidentiality obligations.

10. Transfers outside the EEA

10.1 The Processor processes personal data within the EEA unless appropriate safeguards are in place.

11. Audits

11.1 The Processor complies with audit requests by providing documentation and explanations.

11.2 On-site audits are permitted only where compelling reasons exist and following prior written coordination.

11.3 The costs of audits shall be borne by the Controller.

12. Liability

12.1 The Processor's total liability is limited to the amount paid by the Controller to the Processor during the twelve (12) months preceding the incident.

12.2 The Processor is not liable for:

  • Indirect damages;
  • Consequential damages;
  • Loss of profits.

12.3 The Controller shall indemnify the Processor against third-party claims arising from:

  • Unlawful use of the software;
  • Incorrect data entry;
  • Violations of the GDPR by the Controller.

12.4 Liability arises only where a demonstrable and attributable failure by the Processor has occurred.

13. Retention periods and deletion

13.1 The Processor shall delete personal data within a reasonable period following termination of the Agreement.

13.2 Deletion shall take place in accordance with the Processor's standard procedures.

13.3 Statutory data retention obligations remain applicable.

13.4 The Controller remains responsible for exporting or securely retaining its data in a timely manner before termination of the services.

14. Amendments

14.1 The Processor reserves the right to unilaterally amend or supplement this Data Processing Agreement.

14.2 Amendments shall be communicated to the Controller in a timely manner through the website, software or by email.

15. Governing law

15.1 This Agreement is governed by Dutch law.

15.2 Disputes shall be submitted to the competent court of the District Court of Oost-Brabant, the Netherlands.