Data Processing Agreement

The agreement between your salon and NOZAIA about the data of your clients and team, as required by article 28 of the GDPR. You accept it in your dashboard under Settings, Privacy. The list of sub-processors is on a separate page.

1. Parties and roles

1.1 This agreement is between the salon that uses NOZAIA (the "Salon") and Iconiqdesign, trading as NOZAIA, the sole proprietorship of Nicole Steggerda, Planetenlaan 202, 3204 BR Spijkenisse, the Netherlands, Chamber of Commerce number 77966473 ("NOZAIA").

1.2 The Salon decides why and how the data of its clients and team is used and is the controller. NOZAIA processes that data only on behalf of the Salon and is the processor.

1.3 This agreement is part of the NOZAIA Terms for salons. If they conflict on the processing of personal data, this agreement prevails.

2. What NOZAIA processes, and why

2.1 Purpose: providing the NOZAIA platform to the Salon: online booking, calendar, client cards, payments and invoices, messages and reminders, marketing the Salon sends itself, reports, and the AI features the Salon chooses to use.

2.2 Data subjects: the Salon's clients, people who book or join a waiting list, and the Salon's team.

2.3 Personal data: name, contact details, address, date of birth, language, appointments and history, payments and invoices, notes, photos, forms, marketing consent and message logs. Special category data: allergies and patch tests (health data), only with the explicit consent of the client, and not in countries where the law requires a permit or forbids storage outside the country (see the Salon's Privacy settings).

2.4 Duration: as long as the Salon uses NOZAIA, followed by the end-of-contract period in article 10.

3. Instructions

3.1 NOZAIA processes the data only on the documented instructions of the Salon. The Salon gives those instructions by using the platform and its settings, and by this agreement.

3.2 NOZAIA does not use the Salon's client data for its own purposes and does not sell it. NOZAIA may use anonymous, aggregated figures that cannot be traced to a salon or person to improve the platform.

3.3 If NOZAIA believes an instruction breaks the law, it tells the Salon. If the law requires NOZAIA to process data without an instruction, it tells the Salon first unless the law forbids that.

4. Confidentiality

4.1 Anyone working for NOZAIA who can access personal data is bound to confidentiality and only accesses it when that is needed for support, maintenance or security, or when the Salon asks for it.

5. Security

5.1 NOZAIA takes appropriate technical and organisational measures, described in Annex 1. NOZAIA may improve these measures, but never lowers the overall level of protection.

6. Sub-processors

6.1 The Salon gives general permission for the sub-processors on the page /subverwerkers. NOZAIA gives each sub-processor, by contract, obligations that protect the data at least as well as this agreement, and remains responsible for them.

6.2 NOZAIA announces a new sub-processor at least 30 days in advance on that page and by email to the Salon's owner. The Salon may object on reasonable grounds within those 30 days. If no solution is found, the Salon may end its subscription without costs before the change takes effect.

6.3 Payment services the Salon links itself (for example Stripe Connect, Sentoo, PayTabs, Paystack, Mopé or a payment terminal) are used under the Salon's own contract with that provider and are not sub-processors of NOZAIA.

7. Transfers outside the European Union

7.1 NOZAIA stores the data in the European Union (Frankfurt, Germany). A transfer outside the EU and EEA only takes place with a safeguard under Chapter V GDPR: an adequacy decision, the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.

7.2 If the Salon is established outside the EU, the Salon remains responsible for the rules of its own country on transferring data to the EU. The Privacy settings show what NOZAIA knows about those rules; that is guidance, not legal advice.

8. Helping the Salon

8.1 The platform lets the Salon answer requests from its clients itself: view, correct, export and erase a client's data, and withdraw marketing and health data consent. If a client contacts NOZAIA directly, NOZAIA forwards the request to the Salon without delay.

8.2 NOZAIA helps the Salon, to a reasonable extent, with a data protection impact assessment, prior consultation of a regulator, and questions from a regulator.

9. Data breaches

9.1 NOZAIA informs the Salon without undue delay, and in any case within 48 hours after discovery, of a personal data breach affecting the Salon's data. NOZAIA gives the information the Salon needs to notify the regulator and the people involved, and keeps the Salon informed of the measures taken.

9.2 Deciding whether to notify the regulator or clients is up to the Salon, as controller. NOZAIA does not notify on the Salon's behalf unless the Salon asks.

10. End of the agreement

10.1 Before closing its account, the Salon can export its data from the dashboard. After closing, NOZAIA erases the Salon's personal data within 30 days, and removes it from backups within a further 90 days.

10.2 Data that the law requires to be kept, such as invoices for tax purposes (in the Netherlands 7 years), is kept for that period only, protected, and not used for anything else.

11. Audits and information

11.1 NOZAIA gives the Salon, on request, the information needed to show that it complies with this agreement. If that is not enough, the Salon may have an audit carried out by an independent expert bound to confidentiality, at most once a year, announced at least 30 days in advance and at the Salon's cost.

12. Liability, law and changes

12.1 Liability is governed by the NOZAIA Terms for salons.

12.2 This agreement is governed by Dutch law. Disputes go to the competent court in Rotterdam, unless mandatory law of the Salon's country says otherwise.

12.3 If the Salon's own law (for example the UK GDPR, POPIA, LGPD or PIPEDA) sets further requirements for a processor agreement, this agreement is read so that it meets them as far as possible.

12.4 NOZAIA may change this agreement. A new version is shown to the Salon in the dashboard; changes that reduce the Salon's protection need the Salon's consent.

Annex 1. Security measures

  • Encrypted connections (HTTPS/TLS) for all traffic, and encryption of stored data by the hosting provider.
  • Every salon's data is separated at database level (row level security): a salon can never see another salon's data.
  • Access within a salon by role and permission, set by the Salon. NOZAIA staff only access salon data when that is needed.
  • Invoices and payments cannot be changed afterwards; corrections go through credit notes. Important changes are logged.
  • Automatic backups by the hosting provider. Files of erased clients are removed from storage, and old mail and campaign data is cleaned up automatically.
  • Secrets and payment keys are stored server-side only, never in the browser. Card data is handled by the payment provider, never by NOZAIA.
  • Health data (allergies, patch tests) can only be recorded with the client's explicit consent, enforced by the database, and is switched off in countries where it is not allowed.

Questions: info@nozaia.nl

Data Processing Agreement | NOZAIA