BeautyReply

BeautyReply beta

Data Processing Agreement (Template)

Effective 28 August 2026

Draft template — not legal advice. This document is provided for internal review and must be verified by qualified legal counsel before a public SaaS launch. BeautyReply does not represent that these terms are complete or compliant.

This Data Processing Agreement (“DPA”) template describes how BeautyReply and a business customer may allocate GDPR roles when BeautyReply processes personal data on behalf of the customer through the platform.

Important: The controller/processor roles can differ depending on the processing activity (for example account administration vs. widget visitor messages). A qualified lawyer must confirm the correct roles, annexes, and signatures before use.

1. Parties

Customer / Controller (draft): [Salon legal name], [registered address], contact: [privacy contact email]

Processor (draft): BeautyReply, contact: hello@beautyreply.com

2. Subject matter & duration

BeautyReply provides a hosted AI receptionist platform that allows the Customer to configure an embedded website widget, knowledge base, lead inbox, and related business tools.

This DPA applies for the duration of the Customer's subscription or beta access, and until personal data is deleted or returned in accordance with Section 11.

3. Nature and purpose of processing

  • Hosting and displaying the Customer's approved business information to website visitors
  • Processing widget conversations, messages, and lead capture forms on the Customer's behalf
  • Generating AI-assisted replies from approved Customer content
  • Delivering notifications configured by the Customer
  • Providing analytics and operational logs to the Customer

4. Categories of personal data

  • Widget visitor messages and conversation metadata
  • Names, email addresses, and phone numbers submitted via lead forms
  • Technical data such as IP addresses in server logs and CAPTCHA metadata
  • Customer team account data (handled under separate controller/processor analysis)

5. Categories of data subjects

  • Website visitors and prospective clients of the Customer
  • Customer staff users with dashboard access

6. Customer instructions

BeautyReply processes personal data only on documented instructions from the Customer, including through configuration of the widget, knowledge base, retention settings (when enabled), and use of dashboard features — unless required by Union or Member State law.

7. Confidentiality

BeautyReply ensures that persons authorised to process personal data are subject to confidentiality obligations appropriate to the nature of the service.

8. Security measures

BeautyReply implements appropriate technical and organisational measures, including tenant isolation via row-level database security, authenticated dashboard access, server-side secret handling, and CAPTCHA on sensitive public endpoints where configured. A detailed security annex should be prepared for counsel review.

9. Subprocessors

The Customer authorises BeautyReply to engage subprocessors listed at /subprocessors. BeautyReply should notify the Customer of intended changes and allow objection in accordance with final commercial terms.

10. Data subject requests

BeautyReply shall assist the Customer, taking into account the nature of processing, in responding to data subject requests where feasible through dashboard export, conversation deletion, and account closure workflows.

11. Personal data breaches

BeautyReply shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, providing information required under Article 33 GDPR to the extent available.

12. Deletion or return of data

Upon termination, BeautyReply shall delete or return Customer personal data within a period to be defined in final commercial terms, except where retention is required by law. Beta infrastructure supports workspace deletion via authenticated closure workflow; automatic retention jobs are not enabled by default.

13. Audits

BeautyReply shall make available information necessary to demonstrate compliance and allow audits mandated by supervisory authorities or agreed in writing, subject to reasonable confidentiality and security constraints.

14. International transfers

Where subprocessors process data outside the EEA, BeautyReply shall implement appropriate safeguards (for example Standard Contractual Clauses) as required by applicable law. Verify current provider terms for the subprocessors listed at /subprocessors.

15. Role clarification (for legal verification)

For many widget interactions, the salon may act as controller of visitor personal data while BeautyReply acts as processor. For BeautyReply's own account administration, marketing to business users, and platform security, BeautyReply may act as an independent controller. Final classification must be confirmed by counsel.