Data Processing Agreement
Salon Guild CRM, part of the Opti Flo ecosystem
Last updated: 28 July 2026
This document is not legal advice and should be reviewed by a solicitor before publication, to confirm it properly satisfies UK GDPR Article 28 requirements before being relied upon as a binding processor agreement.
1. Purpose of this agreement
This Data Processing Agreement (DPA) applies where you (the salon, "the Operator") are the data controller for your clients' personal data, and Opti Flo Apps Ltd ("we", "us") processes that data on your behalf as part of providing Salon Guild CRM. It forms part of, and is incorporated into, our Terms of Service. Where there's a conflict between this DPA and the Terms of Service on data protection matters, this DPA takes precedence.
This DPA applies automatically to every Operator using Salon Guild CRM; you don't need to sign a separate copy for it to apply, though a signed version is available on request to support@optiflo.app for Operators who need one for their own records or compliance purposes.
2. Roles
The Operator is the data controller for personal data relating to their own clients. Opti Flo Apps Ltd is the data processor, processing that data only on the Operator's documented instructions, as set out in this agreement and as configured by the Operator through the platform.
3. Subject matter and duration
Processing continues for the duration of the Operator's subscription to Salon Guild CRM, and for any post-termination period described in our Privacy Policy during which data is retained before deletion.
4. Nature and purpose of processing
We process client personal data to provide the Salon Guild CRM service as configured by the Operator: operating the booking system and client portal, storing CRM records, sending communications the Operator has configured (subject to the Operator's own consent obligations), processing payments where applicable, and providing AI Workforce features where enabled.
5. Categories of data subjects
The Operator's clients, and, where applicable, the Operator's staff members who use the platform.
6. Types of personal data
Contact details (name, email, phone number), booking and appointment history, communications sent and received through the platform, payment history relating to salon services processed through the platform, and any additional notes or fields the Operator chooses to record.
7. Our obligations as processor
We will:
- Process personal data only on the Operator's documented instructions, including as set by the Operator's own configuration of the platform
- Ensure our staff and contractors with access to personal data are subject to confidentiality obligations
- Implement appropriate technical and organisational security measures, as summarised in our Privacy Policy and available in more detail on request
- Not engage a new sub-processor without giving the Operator the opportunity to object, as described in Section 9
- Assist the Operator, insofar as reasonably possible, in responding to data subject rights requests relating to their clients' data
- Notify the Operator without undue delay after becoming aware of a personal data breach affecting their clients' data
- At the end of the subscription, delete or return personal data per our standard retention practices, unless we're required by law to retain it
- Make available to the Operator the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, subject to reasonable notice and confidentiality protections
8. Operator obligations
The Operator confirms that:
- They have a valid lawful basis for the personal data they process about their clients through Salon Guild CRM
- Where consent is the basis for any processing (such as marketing communications), that consent has been properly obtained, per our SMS and Email Communications Policy
- Their instructions to us, including through their own configuration of the platform, comply with applicable data protection law
- They will not instruct us to process personal data in a way that would breach UK GDPR
9. Sub-processors
The Operator provides general authorisation for us to engage the sub-processors listed on our Sub-processors page, which is incorporated into this DPA by reference and kept up to date. Where we intend to add a new sub-processor, we will update that page and, for material changes, notify Operators in advance, giving a reasonable opportunity to object on reasonable data protection grounds before the new sub-processor begins processing their clients' data. We remain responsible for each sub-processor's compliance with data protection obligations equivalent to those in this DPA.
10. International transfers
Where a sub-processor is located outside the UK, transfers are made under appropriate safeguards as described in our Privacy Policy, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
11. Security measures
We maintain security measures including encryption of data in transit and at rest, access controls scoped by workspace so one Operator cannot access another's data, and regular review of sub-processor security practices. Full details are available on request to support@optiflo.app.
12. Data breach notification
If we become aware of a personal data breach affecting an Operator's client data, we will notify the Operator without undue delay, providing the information reasonably available to us to help the Operator meet their own notification obligations to the ICO and affected individuals where required.
13. Deletion on termination
On termination of the Operator's subscription, we will delete client personal data per the retention practices described in our Privacy Policy, except where we're required to retain it by law, or where the Operator has requested an export of their data before deletion.
14. Liability
Liability under this DPA is subject to the limitations set out in our Terms of Service.
15. Contact us
Opti Flo Apps Ltd
SIU Offices, 4-6 Greatorex Street, London, E1 5NF, United Kingdom
support@optiflo.app
