Data Processing Agreement

DRAFT — pending legal review.This agreement is drafted against GDPR Article 28 and describes the platform's actual processing, but has not yet been reviewed by a qualified lawyer. The Dutch-language version (Verwerkersovereenkomst) is the version of record; this English text is a convenience translation. Questions? Email info@pbw.life.

0. Context and roles

When a beauty professional ("the Professional") uses pbw.life to take bookings, the Professional decides why and how their end clients' personal data is processed. The Professional is therefore thecontroller. pbw.life processes that data solely on the Professional's instructions and is therefore theprocessor. This agreement governs only that processor relationship between the Professional and pbw.life.

On Mollie: Mollie acts as an independent controller for the payment data it processes. pbw.life is not Mollie's processor and Mollie is not pbw.life's sub-processor for deposits; no processor agreement with Mollie is required and none forms part of this document.

1. Parties

2. Subject matter and duration

pbw.life processes personal data of the Professional's end clients solely to provide the booking, scheduling, deposit, notification and record-keeping functionality of the platform. The agreement applies for as long as the Professional's account is active, plus the statutory retention periods described in section 9 and thePrivacy policy.

3. Nature and purpose of processing

4. Categories of data subjects and personal data

The platform is not intended for special categories of personal data (such as health data). The Professional is instructed not to record special-category data in free-text note fields; if the Professional does so anyway, that is done under their own responsibility as controller.

5. Obligations of the processor

  1. Process personal data only on the Professional's documented instructions. The agreement, the platform settings the Professional configures, and the functionality described in section 3 together constitute those instructions.
  2. Ensure that persons with access to the data are bound by confidentiality.
  3. Take appropriate technical and organisational security measures (Annex A).
  4. Engage sub-processors only in accordance with section 6.
  5. Assist the Professional with data-subject requests (access, rectification, erasure, portability) and with breach notification, DPIAs and prior consultation.
  6. Inform the Professional without undue delay after establishing a personal data breach, with the information the Professional needs for their own notification duties.
  7. On termination, delete or return all personal data at the Professional's choice, except where EU or Dutch law requires retention (section 9).
  8. Make available the information necessary to demonstrate compliance, and enable audits in accordance with section 8.

6. Sub-processors

The Professional grants general authorisation for the sub-processors listed in Annex B. pbw.life imposes obligations on each sub-processor equivalent to those in this agreement. Intended changes (adding or replacing a sub-processor) are announced by email at least 30 days in advance; the Professional may object in writing within that period and may terminate the agreement if the objection cannot reasonably be resolved.

7. International transfers

No transfers outside the European Economic Area take place for the core service: hosting, storage and email run in Microsoft Azure (West Europe region), authentication on Auth0's EU environment, and error monitoring on Sentry's EU environment (Frankfurt). Any future exception requires a valid transfer mechanism (such as standard contractual clauses) and advance notice per section 6.

8. Audits and accountability

On request, pbw.life makes available the information reasonably needed to demonstrate compliance with this agreement (including available certifications and sub-processor reports). The Professional may conduct or commission an audit at most once per twelve months — or additionally after an established breach — with at least 30 days' written notice, during business hours, without disproportionate disruption to the service. Each party bears its own costs.

9. Liability, term and termination

10. Governing law

This agreement is governed by Dutch law. This Data Processing Agreement forms part of the Terms of service and is expressly accepted by the Professional during onboarding.

Annex A — Technical and organisational measures

Annex B — Sub-processors

Sub-processorPurposeLocation
Microsoft AzureHosting, database, storage, transactional email (Azure Communication Services), realtime notificationsEU (West Europe)
Auth0 (Okta)AuthenticationEU
SentryError monitoringEU (Frankfurt)

Mollie B.V. (Amsterdam) processes payment data as an independent controller and is not a sub-processor (see section 0).