← The Hairdresser’s Diary

Protecting salon client records

Data Processing Terms

Last updated 23 August 2026

These terms form part of the The Hairdresser’s Diary subscription agreement. They apply when an account holder uses the service to store personal information about salon clients. In these terms, the salon account holder is the controller and Joe Walsh, trading as The Hairdresser’s Diary, is the processor.

1. Processing details

Subject and duration
Providing the secure salon diary for the subscription term and the limited period needed to return, delete or expire backup copies after the service ends.
Nature and purpose
Receiving, storing, organising, synchronising, retrieving, displaying, backing up and deleting records so the controller can manage genuine salon client relationships and appointments.
People concerned
The controller's salon clients and prospective clients whose information the controller chooses to record.
Information processed
Names, contact details, birthdays, appointments, services, colour formulas, preferences, conversation notes, loyalty history, photographs and any allergy, sensitivity or treatment details entered by the controller.

2. Documented instructions

We process salon client records only to provide, secure, maintain and support the diary in line with the controller's documented use of the service and lawful written instructions. We will tell the controller if, in our reasonable view, an instruction infringes applicable data-protection law, unless the law prevents us from doing so.

3. Confidentiality and access

Anyone authorised to access salon client records on our behalf must be bound by confidentiality and may access only what is necessary for their role. Platform-owner reporting is designed not to display client names, private notes, formulas, allergy information or photographs.

4. Security measures

We use encrypted connections, authenticated accounts, row-level database controls, private photo storage, time-limited photo links, restricted administrative access, revision checks to reduce accidental overwrites and service-provider backup controls. We review these measures as the service and risks develop.

5. Sub-processors

The controller gives general authorisation for the specialist providers needed to run the service. Current providers include Supabase for database, authentication and private storage, and OpenAI's Sites service and its contracted infrastructure for application hosting. Stripe processes the salon owner's subscription payments under its own terms and privacy notice and does not receive salon client diary records from us.

We will require sub-processors that handle salon client records to protect them under written terms. Material additions or replacements will be communicated through the service, this page or email, allowing the controller to raise a reasonable data-protection objection before the change takes effect where practicable.

6. International processing

Where a provider processes records outside the European Economic Area or the United Kingdom, we will use an applicable adequacy decision or approved contractual safeguards and any additional measures reasonably required for the transfer.

7. Assistance and incidents

Taking account of the nature of the service and information available to us, we will reasonably help the controller respond to client data-rights requests and meet relevant duties concerning security, breach notification, impact assessments and regulator consultation. We will notify the controller without undue delay after becoming aware of a personal-data breach affecting that controller's salon records.

8. Return and deletion

The diary provides backup and deletion controls. When the service ends, the controller may request return or deletion of salon client records unless the law requires limited retention. Active copies will then be deleted and backup copies will expire through the normal backup cycle. Cancellation alone does not immediately delete records.

9. Information and audits

On reasonable request, we will provide information needed to demonstrate these processor commitments. If that information is not sufficient, the controller may request a proportionate audit by an independent, confidential auditor with reasonable notice, provided it does not expose another salon's records or create an avoidable security risk.

10. Controller responsibilities

The controller is responsible for giving lawful instructions, telling salon clients how their information is used, limiting entries to what is relevant, keeping records accurate, protecting account credentials and obtaining any consent required for photographs or sensitive treatment information.

11. Contact and priority

Data-processing questions can be sent to walsh2695@hotmail.com. If these terms conflict with the general subscription terms about our processing of salon client records, these Data Processing Terms take priority for that processing.

Processor

Joe Walsh, trading as The Hairdresser’s Diary

Calle Artola Golf, Artola Alta, Las Chapas, Marbella, 29604, Spain

walsh2695@hotmail.com