BeautyReply beta
Data Processing Agreement (Template)
Effective 28 August 2026
This Data Processing Agreement (“DPA”) template describes how BeautyReply and a business customer may allocate GDPR roles when BeautyReply processes personal data on behalf of the customer through the platform.
Important: The controller/processor roles can differ depending on the processing activity (for example account administration vs. widget visitor messages). A qualified lawyer must confirm the correct roles, annexes, and signatures before use.
1. Parties
Customer / Controller (draft): [Salon legal name], [registered address], contact: [privacy contact email]
Processor (draft): BeautyReply, contact: hello@beautyreply.com
2. Subject matter & duration
BeautyReply provides a hosted AI receptionist platform that allows the Customer to configure an embedded website widget, knowledge base, lead inbox, and related business tools.
This DPA applies for the duration of the Customer's subscription or beta access, and until personal data is deleted or returned in accordance with Section 11.
3. Nature and purpose of processing
- Hosting and displaying the Customer's approved business information to website visitors
- Processing widget conversations, messages, and lead capture forms on the Customer's behalf
- Generating AI-assisted replies from approved Customer content
- Delivering notifications configured by the Customer
- Providing analytics and operational logs to the Customer
4. Categories of personal data
- Widget visitor messages and conversation metadata
- Names, email addresses, and phone numbers submitted via lead forms
- Technical data such as IP addresses in server logs and CAPTCHA metadata
- Customer team account data (handled under separate controller/processor analysis)
5. Categories of data subjects
- Website visitors and prospective clients of the Customer
- Customer staff users with dashboard access
6. Customer instructions
BeautyReply processes personal data only on documented instructions from the Customer, including through configuration of the widget, knowledge base, retention settings (when enabled), and use of dashboard features — unless required by Union or Member State law.
7. Confidentiality
BeautyReply ensures that persons authorised to process personal data are subject to confidentiality obligations appropriate to the nature of the service.
8. Security measures
BeautyReply implements appropriate technical and organisational measures, including tenant isolation via row-level database security, authenticated dashboard access, server-side secret handling, and CAPTCHA on sensitive public endpoints where configured. A detailed security annex should be prepared for counsel review.
9. Subprocessors
The Customer authorises BeautyReply to engage subprocessors listed at /subprocessors. BeautyReply should notify the Customer of intended changes and allow objection in accordance with final commercial terms.
10. Data subject requests
BeautyReply shall assist the Customer, taking into account the nature of processing, in responding to data subject requests where feasible through dashboard export, conversation deletion, and account closure workflows.
11. Personal data breaches
BeautyReply shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, providing information required under Article 33 GDPR to the extent available.
12. Deletion or return of data
Upon termination, BeautyReply shall delete or return Customer personal data within a period to be defined in final commercial terms, except where retention is required by law. Beta infrastructure supports workspace deletion via authenticated closure workflow; automatic retention jobs are not enabled by default.
13. Audits
BeautyReply shall make available information necessary to demonstrate compliance and allow audits mandated by supervisory authorities or agreed in writing, subject to reasonable confidentiality and security constraints.
14. International transfers
Where subprocessors process data outside the EEA, BeautyReply shall implement appropriate safeguards (for example Standard Contractual Clauses) as required by applicable law. Verify current provider terms for the subprocessors listed at /subprocessors.
15. Role clarification (for legal verification)
For many widget interactions, the salon may act as controller of visitor personal data while BeautyReply acts as processor. For BeautyReply's own account administration, marketing to business users, and platform security, BeautyReply may act as an independent controller. Final classification must be confirmed by counsel.
