Last updated · August 19, 2026
Data Processing Agreement
How we handle your clients' data on your behalf.
This agreement is required by Article 28 of the GDPR. It applies whenever a salon stores its clients' personal data in KBSalonBook: the salon is the controller of that data, and Kevin & Bruno Solutions, Lda. ("KBSalonBook") is its processor. It forms part of our Terms of Service and is accepted automatically when you subscribe — you do not need to sign anything. If your accountant or your own customers require a countersigned copy, ask us at [email protected] and we will provide one.
1. Parties and scope
This agreement is between you — the salon, barbershop or independent stylist that holds a KBSalonBook subscription, acting as controller — and Kevin & Bruno Solutions, Lda., Rua Eusébio Exposto N17 2DC 4720-078 Braga, Portugal, acting as processor.
It covers only the personal data you put into KBSalonBook about your own clients. It does not cover your own account data (your name, email, subscription), for which KBSalonBook is the controller — that is governed by our Privacy Policy.
Where this agreement and the Terms of Service conflict on a matter of data protection, this agreement wins.
2. What is processed, and why
Subject matter and purpose. We process your clients' personal data solely to provide the KBSalonBook booking service to you: taking bookings, running your calendar, keeping client records and waiting lists, and — where you have bought the add-on — sending reminders and messages.
Duration. For as long as your subscription is active, and then for the short period described in section 10.
Categories of data subject. Your clients, and anyone who requests an appointment through your public booking page.
Types of personal data.
- identity and contact details — name, phone number, email address;
- date of birth, where you choose to record it;
- appointment history, services booked, and waiting-list preferences;
- free-text notes you write about a client;
- a log of messages sent to that client through KBSalonBook.
Special categories. KBSalonBook is not designed to hold special-category data (such as health information) and you should not enter it in the free-text notes. If you do, you remain responsible for the additional obligations the GDPR places on such data.
3. We act only on your instructions
We process your clients' data only on your documented instructions, including on international transfers, unless the law requires otherwise — in which case we will tell you before processing, unless that law forbids us from telling you.
Your use of the software is itself an instruction: when you create a booking, write a note, or send a reminder, you are instructing us to process that data. Our Terms and this agreement are the rest of your instructions.
If we believe an instruction from you infringes data protection law, we will tell you, and we may refuse to carry it out.
We will never use your clients' data for our own purposes, sell it, or use it to advertise to your clients.
4. Confidentiality
Everyone we authorise to access your clients' data is bound by a duty of confidentiality, and only gets access where they need it to run the service for you.
5. Security measures
We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to the people involved. In practice these include:
- encryption in transit — all traffic is served over HTTPS;
- hashed credentials — passwords are stored hashed with bcrypt and cannot be read by us;
- tenant isolation — each salon's data is separated from every other salon's, and every request is checked against the account that made it;
- access control — access to production data is limited to the people who need it to operate the service;
- resilience and backups — so data can be restored after an incident;
- a private database — not exposed to the public internet.
We may change these measures over time, but not in a way that materially lowers the level of protection.
6. Sub-processors
You give us general authorisation to engage sub-processors. Each is bound by written terms that impose data-protection obligations no weaker than those in this agreement, and we remain fully liable to you for what they do.
The sub-processors we currently use:
- Paddle — payments. Only your billing data; your clients' data is never sent to Paddle.
- Meta Platforms Ireland (WhatsApp) — delivery of your WhatsApp messages, only if you have bought the messaging add-on. It receives the recipient's phone number and the message text. With the add-on off, no client phone number leaves KBSalonBook.
- Our CDN and network security provider — sits in front of our servers to speed up delivery and filter malicious traffic; it processes connection data (IP address, request headers) for that purpose only.
- Our hosting and database provider — stores the data that runs the service, in the European Union.
- Our email provider — sends transactional email such as booking confirmations and password resets.
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds within that period, we will try to offer an alternative; if we cannot, you may cancel your subscription for the affected service without penalty, and we will refund any period you have paid for but not used.
7. Helping you answer your clients
Your clients' requests to access, correct, delete, restrict, object or receive a portable copy of their data are yours to answer — you are the controller.
We will help you: the app lets you read, edit, export and delete a client record yourself, and where that is not enough, we will assist you on request, at no extra cost for reasonable volumes.
If a client of yours contacts us directly, we will not answer on your behalf. We will tell them to contact you, and let you know.
8. Personal data breaches
If we become aware of a personal data breach affecting your clients' data, we will notify you without undue delay — in any event within 48 hours of becoming aware of it — with what we know: what happened, who and what is affected, the likely consequences, and what we are doing about it.
Notifying your supervisory authority (within 72 hours) and your clients where required is your responsibility as controller. We will give you the information you need to do it.
We will also help you, on request, with data protection impact assessments and prior consultations under Articles 35 and 36.
9. International transfers
Your clients' data is stored in the European Union.
Some sub-processors may process data outside the EU. Where they do, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses, together with any additional safeguards required. We will not transfer your clients' data outside the EU on any other basis.
10. Return and deletion
You can export your data at any time from Settings → Your data, and erase any individual client from their record. Because your appointments reference the client, erasure anonymises the record: the booking survives without any personal data, so you keep your business history while the person is removed.
When your subscription ends, we keep your data for 30 days so you can come back or take an export, and then delete it. If you ask us to delete it sooner, we will.
We may keep data for longer only where EU or member-state law requires it (for example, invoices for tax purposes), and only for as long as that law requires.
11. Audits
On request, we will give you the information you reasonably need to show that we are meeting our obligations under Article 28.
You may audit us, or appoint an independent auditor to do so, on 30 days' notice, no more than once a year (unless a regulator or a breach requires otherwise), during business hours, without disrupting the service, and subject to confidentiality. You bear the cost, unless the audit finds a material breach on our part.
12. Liability, law and changes
Liability under this agreement is subject to the limits in our Terms of Service, except where the GDPR does not permit that.
This agreement is governed by the law of Portugal, and the courts of Lisbon, Portugal have jurisdiction.
We may update this agreement to keep it accurate or compliant. If a change matters to you, we will give you at least 30 days' notice by email or in the app.
Questions, or a request for a countersigned copy: [email protected].