CiaoBarber

Data Processing Agreement

Last updated:

This agreement (DPA) governs the processing of your own clients' personal data that CiaoBarber carries out on your behalf. Article 28(3) of Regulation (EU) 2016/679 (GDPR) requires it, and it forms an integral part of the Terms of Service: you accept it by creating an account, with no separate document to sign.

The parties are: you, the controller, identified by your CiaoBarber account details; and Youssef Bitar, sole trader (auto-entrepreneur) under Moroccan law, of Résidence Al Kawtar, Sidi Moumen, 20630 Casablanca, Morocco, registered in the Moroccan national register of auto-entrepreneurs under number 002112908000094, the processor.

Where this agreement and the Terms of Service conflict, this agreement prevails on data protection matters.

1. Subject matter, duration and nature of the processing

We process your clients' personal data solely in order to provide you with the CiaoBarber platform, on your instructions and for the duration of your subscription, including any trial period and any time spent on the free plan.

ElementDescription
Nature and purposeRecording and managing appointments and client records, sending the reminders and messages you instruct, recording sales at the till, issuing documents, and producing statistics for your business.
Types of personal dataName, phone number, email address, date of birth where recorded, service and barber preferences, free-text notes written by you, appointment and absence history, no-show risk score, consents and contact preferences, transactions and amounts.
Categories of data subjectsYour shop's clients, and the colleagues and staff members you add to the platform.
DurationFor the term of the service contract and until the data is deleted under section 9.

The platform is not intended for special categories of data under Article 9 GDPR. If you enter health data into the free-text notes you do so on your own responsibility and outside the agreed purposes.

2. Documented instructions

We process personal data only on your documented instructions. Your documented instructions consist of: the Terms of Service, this agreement, the settings and features you enable in the platform, and any request you send us in writing to privacy@ciaobarber.com.

If an instruction from you appears to infringe the GDPR or other applicable data protection law, we tell you before acting on it.

If a law we are subject to required further processing, we would inform you before proceeding, unless that law prohibits it on important grounds of public interest.

We do not use your clients' data for our own purposes, do not sell it to third parties, and do not use it to train artificial intelligence models.

3. Confidentiality

Anyone authorised to access the data on our behalf is under a contractual or statutory duty of confidentiality, is instructed on how to process it, and can reach only the data their task requires.

Staff access to production data happens only where support or fault diagnosis requires it, and is limited to what that work needs.

4. Security measures

We apply the technical and organisational measures required by Article 32 GDPR, set out below. We may update them over time, provided the level of protection is not reduced.

  • Traffic between the browser and the platform encrypted with HTTPS/TLS.
  • Encryption at rest on the managed database, and application-level encryption of third-party integration tokens.
  • Passwords stored only as non-reversible hashes.
  • Session authentication with expiry and revocation, and mandatory email address verification.
  • Logical separation of data per account: every query is bound to the account identifier, and no account can read another's data.
  • Role-based permissions within an account: a barber sees their own appointments and clients, not billing or staff management.
  • Automated database backups with limited retention and point-in-time restore.
  • Logging of security-relevant application events and error monitoring.
  • Regular updates of software dependencies and runtime environments.

5. Sub-processors

You give general authorisation for the sub-processors listed below, with whom we have agreements imposing data protection obligations equivalent to those in this agreement. We remain fully liable to you for their performance.

Sub-processorServiceProcessing country
Neon Inc.Managed PostgreSQL databaseUnited States
Vercel Inc.Application hosting and executionGlobal network, headquartered in the United States
PayPalPayment processing and QR collectionEuropean Union and United States
ResendTransactional email and campaign deliveryUnited States
TwilioSMS delivery, where the feature is enabledUnited States
UploadThingStorage of uploaded imagesUnited States
Google Ireland Ltd.Google Calendar synchronisation, where enabledEuropean Union and United States

If we intend to add or replace a sub-processor we give you at least 30 days' notice by email or through the platform. Within that period you may object on reasonable data protection grounds. If the objection cannot be resolved, you may terminate without penalty and be refunded the unused part of your subscription.

6. International transfers

The processor is established in Morocco, a country not covered by a European Commission adequacy decision as at the date of this agreement. Transfers of your clients' data to Morocco and to sub-processors outside the European Economic Area rely on the Standard Contractual Clauses adopted by implementing decision (EU) 2021/914, module 2 (controller to processor), which the parties incorporate and accept in full by entering into this agreement.

For the purposes of those clauses: you are the exporter and the processor is the importer; Annex I consists of the tables in sections 1 and 5 of this agreement; Annex II consists of the measures listed in section 4; the competent supervisory authority is that of the Member State where you are established. Clause 9 option 2 applies (general authorisation of sub-processors, with 30 days' notice) and, for clause 17, Italian law applies.

We have assessed the law of the destination country and are not aware of any provision preventing us from complying with these clauses. Were we to become aware of one, we would tell you without delay and could suspend the transfer.

Transfers of personal data out of Morocco are separately governed by Articles 43 and 44 of Moroccan law 09-08 and supervised by the CNDP.

7. Data subject rights

The platform gives you the tools to answer your clients' requests yourself: you can view, correct, export and delete an individual client's data from their record, and export the whole archive from your profile settings.

If one of your clients contacts us directly, we do not answer on the merits: we tell them to contact you and pass the request on to you without undue delay.

Where a request cannot be met with the platform's own functions, we assist you by appropriate technical and organisational measures, insofar as this is possible.

8. Assistance, breaches and impact assessments

We assist you, taking into account the nature of the processing and the information available to us, in meeting the obligations in Articles 32 to 36 GDPR.

In the event of a personal data breach affecting data processed on your behalf, we notify you without undue delay and in any case within 48 hours of becoming aware of it, with the information you need in order to notify the supervisory authority within the 72 hours set by Article 33 GDPR. Notifying the authority and, where required, informing the data subjects remain your responsibility as controller.

On request we provide the information we hold that is relevant to a data protection impact assessment and to any prior consultation with the authority.

9. Return and deletion

You can export the data processed on your behalf at any time, in a structured, machine-readable format, from your profile settings.

On termination of the service, and in any event when you close the account from the platform, your clients' data is deleted immediately and irreversibly from the production systems. Copies held in encrypted backups are overwritten within 30 days by the normal rotation. Export what you need before closing the account: afterwards we cannot recover anything.

The exception is data we are required to keep by law, in particular the accounting records relating to your subscription, which remain subject to the retention rules set out in the Privacy Policy.

10. Audits and information

On your written request we make available all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

To keep costs reasonable on both sides, we agree that requests are made with at least 30 days' notice, take place in working hours and without prejudice to the security of other customers, and are limited to one audit a year, unless a breach has been established or the supervisory authority requires otherwise.

11. Final provisions

  • This agreement lasts as long as the service contract and ends with it, save for obligations intended to survive.
  • Changes to this agreement follow the procedure set for the Terms of Service, with at least 30 days' notice for material changes.
  • This agreement is governed by Italian law, consistently with the Terms of Service.
  • For any communication about this agreement: privacy@ciaobarber.com.