Data Processing Agreement (Art. 28 GDPR)
Version: 16.08.2026 · 2026-08-16
This agreement applies where the Salon uses Salonza to process personal data of its customers and staff. The Salon is generally the controller for its booking/customer data; Salonza acts as processor to the extent it processes that data on the Salon's documented instructions.
1. Subject, duration and purpose
Processing covers hosting and operating the Salonza booking, calendar, team, notification, support, security, backup and export functions for the duration of the Salonza account and any justified retention period.
2. Data and data subjects
- Salon customers: name, email, phone, appointment/service data, customer notes and communication required for booking.
- Salon staff/team: name, work schedule, services, work email/account and notification data where configured.
- Technical/security data: session, authentication and abuse-prevention information necessary to operate the service.
3. Instructions
Salonza processes processor-scope data only for providing the contracted service and documented instructions, unless Union or Member State law requires otherwise. The Salon remains responsible for the lawfulness of the data it enters and its instructions.
4. Confidentiality and security
Persons authorised to process data are bound to confidentiality. Salonza applies risk-appropriate technical and organisational safeguards including access control, password hashing, scoped tenant access, encrypted HTTPS transport, backups, abuse protection and security logging where appropriate.
5. Sub-processors
Hosting, email delivery, push infrastructure and payment providers may act as sub-processors where they are used to provide processor-scope services. Salonza will use providers under appropriate data-protection terms and will document material sub-processor changes.
6. Assistance
Taking into account the nature of processing, Salonza will reasonably assist the Salon with data-subject requests, security obligations and personal-data breach handling where the relevant information is within Salonza's control.
7. Breaches
Salonza will notify the Salon without undue delay after becoming aware of a personal-data breach affecting processor-scope Salon data and will provide available information needed for the Salon's assessment and notification duties.
8. Return, export and deletion
During an active account the Salon may use available export functions. At the end of service, processor-scope data will be deleted or returned/exported at the Salon's choice where technically and legally applicable, except data that must be retained by law or temporarily remains in protected backups until normal rotation.
9. Audit information
Salonza will make information reasonably necessary to demonstrate compliance with Article 28 obligations available to the Salon and cooperate with proportionate audits, taking security and confidentiality of other customers into account.
10. Own-controller processing
This AVV does not cover data Salonza processes for its own legitimate business purposes as controller, such as Salonza account administration, billing records, security of the platform or separately consented Salonza marketing. Those purposes are described in the Privacy Policy.
Processor / operator:
Ludusan Denis-Lucian
Senefeldergasse 11/3a, 1100 Wien, Österreich
contact@salonza.at