Data Processing Agreement
Effective October 10, 2026. Last updated September 8, 2026.
This agreement forms part of the salonMonster Terms of Service and applies automatically to every customer. You do not need to sign anything or ask us for it.
Do you need to read this?
Probably not. This is the formal version of the privacy promises already in section 8 of our terms, written the way privacy legislation requires. It exists so that if your accountant, your lawyer, or a client asks you to prove your software provider handles personal information properly, you have a document to point at.
It matters most if you are in Quebec (Law 25 requires a written agreement with your service providers), the UK or EU (GDPR Article 28), or a US state with a privacy statute.
Nothing here takes anything away from you. If you want a countersigned copy on paper, email [email protected] and we will send one, at no charge.
1Who this is between, and the words it uses
In plain language
You are responsible for your clients' personal information. We hold it for you and do what you tell us with it. That is the whole relationship, and every rule below follows from it.
This Data Processing Agreement (“DPA”) is between salonMonster Software Ltd. (“salonMonster”, “we”, “us”) and the business that holds a salonMonster account (“you”, the “Customer”). It forms part of the Terms of Service and takes effect when you accept them.
Customer Personal Data means personal information about your clients, your staff, and anyone else, that we process on your behalf through the Service.
You are the controller of Customer Personal Data — the “organization” under PIPEDA and BC PIPA, the “enterprise” under Quebec's Law 25, the “controller” under the UK and EU GDPR, and the “business” under US state privacy laws. You decide what personal information you collect and why.
We are the processor — your “service provider” or “third party” under those same laws. We process Customer Personal Data only to provide the Service to you.
Where this DPA and the Terms of Service differ on the handling of Customer Personal Data, this DPA governs.
2What we process, and why
In plain language
We only do what you have asked us to do by using the features you use. We do not sell your clients' information, we do not use it to advertise to them, and we do not use it to build anything for ourselves beyond anonymous statistics that cannot identify anyone.
Subject matter and duration. We process Customer Personal Data to provide the Service, for as long as you have an account and for the retention periods in section 8 of the Terms of Service.
Nature and purpose. Hosting, storing, organising, retrieving, displaying, transmitting, backing up, and deleting Customer Personal Data, and sending messages at your direction, in order to operate online booking, scheduling, client records, point of sale, inventory, reporting, gift cards, and messaging.
Categories of individual.
- Your clients, including people who book online without an account
- Your staff and other users you create
- Your own business contacts, where you record them
Categories of personal information.
- Identity and contact details: name, email address, phone number, postal address
- Appointment history, service preferences, stylist assignment, and booking notes
- Purchase and payment records, tips, gift card balances, and account balances
- Free-text notes you enter, which may include health-related information such as allergies, sensitivities, and patch-test results
- Photographs you upload
- Message history: reminders, confirmations, and campaigns sent, and unsubscribe status
- Staff records: contact details, schedules, permissions, commissions, and pay-relevant figures
Our instructions. We process Customer Personal Data only on your documented instructions. Your use of the Service's features, and your settings, are your instructions. We will not process it for any other purpose, and specifically we will not sell it, share it for cross-context behavioural advertising, use it for our own marketing, or combine it with data from other customers, except to produce aggregated and de-identified statistics that cannot reasonably be used to identify you, your business, or any individual.
If we are required by law to process Customer Personal Data beyond your instructions, we will tell you before doing so unless the law prohibits us from telling you. If we believe an instruction from you breaches privacy law, we will tell you.
Sensitive information. You decide whether to record health-related notes. If you do, you are responsible for the additional consent and safeguards that may require. The Service is not a health record system — see section 13 of the Terms of Service.
3Who else touches it
In plain language
We use other companies to actually deliver your texts, send your emails, process your cards, and store your files. They are listed in full in Annex B, with what each one sees and where it is.
Before we add a new one, we will tell you at least 30 days in advance, and you can object — which in practice means you can cancel without penalty if you are not comfortable with it.
You give us general authorisation to engage subprocessors. The current list is in Annex B.
We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
Changes. We will give you at least 30 days' notice before a new subprocessor starts processing Customer Personal Data, by updating Annex B and notifying you by email or in the Service. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative; if we cannot, you may cancel the affected part of the Service without penalty and we will refund prepaid fees for the period you will not receive.
Where a change is urgent — replacing a provider that has failed or become a security risk — we may make it immediately and tell you as soon as we can.
4Where your data goes
In plain language
Your salonMonster database lives in Canada, in Montreal. Some of the companies in Annex B are American, so some information passes through the United States. That means US authorities can, in some circumstances, lawfully demand access to it. We are telling you plainly because your privacy policy needs to tell your clients the same thing.
We store the salonMonster database, file storage, and backups in Amazon Web Services' Canada (Central) region. Certain subprocessors process Customer Personal Data outside Canada, principally in the United States, as set out in Annex B. Personal information processed in another country is subject to that country's laws, including lawful access by its courts and authorities.
You are responsible for disclosing the fact of cross-border processing to your clients where the law that applies to you requires it. We will give you the information you need to do so.
For transfers of UK or EEA personal data, we enter into the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, as applicable, and those clauses are incorporated into this DPA by reference for such transfers. Where Quebec's Law 25 requires a privacy impact assessment before a transfer outside Quebec, we will provide the information you reasonably need to complete it.
5How we protect it
In plain language
Encryption in transit, access on a need-to-know basis, logged support access, regular backups. The specifics are in Annex A.
We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature and sensitivity of the data. Those measures are described in Annex A.
We ensure that our personnel who access Customer Personal Data are bound by confidentiality obligations and access it only as described in section 9 of the Terms of Service. Support access to a customer account is logged.
We may update our security measures over time, provided they do not materially reduce the level of protection.
6If something goes wrong
In plain language
If your data is breached, we tell you promptly — we do not sit on it while we decide whether it legally counts as serious. Deciding whether to report it to a regulator or to your clients is your call, and we will give you what you need to make it.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a confirmed breach of security safeguards affecting Customer Personal Data. We do not apply a harm threshold before notifying you.
Our notification will include, as far as we know it at the time:
- the nature of the breach, and the categories and approximate number of individuals and records affected;
- the likely consequences;
- the measures we have taken or propose to take, including to mitigate harm; and
- a contact point for further information.
We will update you as we learn more, and we will assist you in meeting your own notification obligations to individuals and to a privacy regulator. Whether a breach is reportable under the law that applies to you is your assessment to make.
Where Quebec's Law 25 applies to you, we will also notify your designated privacy officer without delay of any breach or attempted breach affecting Customer Personal Data, on the contact details you give us.
We maintain a record of breaches affecting Customer Personal Data and will make it available to you on request.
7Helping you meet your obligations
In plain language
When a client asks you what information you hold about them, or asks you to correct or delete it, we will help you answer — at no charge, for reasonable requests.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in:
- responding to requests from individuals to access, correct, delete, port, or withdraw consent in respect of their personal information, including by providing export tools and, where those are not sufficient, by extracting the data for you;
- carrying out privacy impact assessments and prior consultations with a regulator, by providing the information about our processing that you reasonably need; and
- demonstrating your compliance with your security and accountability obligations.
If an individual contacts us directly about Customer Personal Data, we will not respond substantively. We will tell them to contact you and, where we can identify you, let you know.
We do not charge for reasonable assistance under this section.
8Checking that we do what we say
In plain language
Ask us how we handle your data and we will answer honestly and in writing. If your regulator or your own compliance obligations require a proper audit, we will cooperate with a reasonable one.
We will make available to you, on request, the information reasonably necessary to demonstrate our compliance with this DPA, including a description of our security measures and our subprocessor arrangements.
Where the law that applies to you requires an audit right, you or an independent auditor you appoint may audit our compliance with this DPA, no more than once in any 12-month period unless a regulator requires otherwise or a breach has occurred, on at least 30 days' written notice, during business hours, and subject to reasonable confidentiality obligations and to not disrupting the Service or the data of other customers. You bear the cost of an audit unless it reveals a material breach of this DPA by us.
9Getting it back, and getting it deleted
In plain language
The same promise as the terms: you can export it any time, you get 90 days of read-and-export access after you cancel, and we permanently delete it whenever you ask.
You may export Customer Personal Data at any time as described in section 7 of the Terms of Service, at no charge, and we will provide assisted export in a commonly used machine-readable format where the self-serve tools are not sufficient.
On termination, retention and deletion follow section 7 of the Terms of Service: read-only access for 90 days, archival thereafter, and permanent deletion on your request, within 30 days from production systems and within a further 90 days from backups as those backups age out. We retain only what we are legally required to retain, for no longer than the law requires. We will confirm deletion in writing on request.
10Liability, and the rest
In plain language
Our liability under this agreement works the way it does in the terms — and a breach of the privacy promises here falls under the higher cap in section 18, not the ordinary one.
Each party's liability under this DPA is subject to section 18 of the Terms of Service. A breach by us of this DPA is a breach of our confidentiality and privacy obligations for the purposes of the higher cap in that section.
This DPA is governed by the law and dispute resolution provisions in section 22 of the Terms of Service, except where a mandatory provision of applicable privacy law requires otherwise.
If any provision of this DPA is unenforceable, the remainder continues in force. If privacy law changes in a way that requires changes to this DPA, we will make them and give you notice under section 21 of the Terms of Service.
AAnnex A — Security measures
We maintain, at minimum:
- Encryption. TLS for all data in transit between you, the Service, and our subprocessors. Encryption at rest for the database, file storage, and backups.
- Access control. Individual accounts for our personnel, role-based access, need-to-know provisioning, and prompt revocation on role change or departure. Customer-side access is controlled by you through the staff permissions in the Service.
- Support access logging. Access by our staff to a customer account for support purposes is recorded.
- Segregation. Customer data is logically segregated by account, and access is scoped to a single account per authenticated session.
- Backups. Regular automated backups, stored encrypted, with periodic restore testing.
- Monitoring. Application error and performance monitoring, and alerting on anomalous conditions.
- Payment data. Card numbers, CVV codes, and PINs are captured and stored by PCI-compliant payment processors, not by salonMonster.
- Personnel. Confidentiality obligations for all personnel with access to Customer Personal Data.
- Change management. Code review and staged deployment for changes to the Service.
BAnnex B — Subprocessors
Current as at September 8, 2026. We give at least 30 days' notice before adding a subprocessor, as described in section 3. To be notified of changes, email [email protected] and ask to be added to the subprocessor notification list.
| Subprocessor | What it does | What it sees | Where |
|---|---|---|---|
| Amazon Web Services | Application hosting, database, file storage, and email delivery | All Customer Personal Data | Canada (ca-central-1) |
| Stripe | Card payment processing, terminals, and payouts | Transaction data, payer name, cardholder details, salon bank details | United States, Ireland |
| Square | Card payment processing, where the customer connects a Square account | Transaction data, payer name, cardholder details | United States |
| Maxio (Chargify) | salonMonster subscription billing | Salon account and billing contact details | United States |
| Twilio and Telnyx | SMS delivery for reminders, confirmations, and text campaigns | Recipient mobile number, message content | United States |
| SendGrid, Postmark, and Amazon SES | Email delivery for reminders, confirmations, and email campaigns | Recipient email address, name, message content | United States, Canada |
| Cloudinary | Image hosting for client photos, staff photos, and gift card designs | Uploaded images and associated identifiers | United States |
| Google Firebase | Push notifications to the salonMonster mobile apps | Device tokens, notification content | United States |
| Sentry | Error and performance monitoring | Technical diagnostic data, which may incidentally include identifiers | United States |
| PostHog | Product analytics on how the Service is used | Usage events, staff user identifiers | Self-hosted by salonMonster |
We also use infrastructure and software suppliers that do not process Customer Personal Data in the ordinary course, such as source control and internal communication tools. They are not listed here.
CContact
Questions about this agreement, or a request for a countersigned copy:
salonMonster Software Ltd.
British Columbia, Canada
Email: [email protected]
Phone: 1-800-901-1001