Data Processing Agreement (DPA)
This agreement is deemed an integral annex to the Lumiperi subscription agreement and is drafted to meet the requirements of Art. 28 GDPR.
1. Parties and Scope
This Data Processing Agreement ("DPA") governs the processing of personal data entered into the Platform, between the business using the Platform (the "Controller") and Lumiperi (the "Processor"). It takes effect upon acceptance of the subscription agreement and is deemed an annex to it.
2. Subject Matter, Duration and Nature of Processing
The subject matter of processing is the provision of appointment, customer relationship, staff, stock and finance management services. Processing continues for the duration of the subscription. Its nature comprises hosting, displaying, transmitting (SMS/WhatsApp/email notifications), backing up and, upon request, deleting the data.
3. Data Categories and Data Subjects
Data subjects: the business's clients and staff. Data categories: identity and contact details, appointment and service history, notes and photos entered by the business, form responses, payment and balance records.
4. Processing on Documented Instructions
The Processor processes personal data only on the Controller's documented instructions (use of Platform features constitutes an instruction), unless required by law. If the Processor believes an instruction infringes data protection law, it informs the Controller without delay.
5. Confidentiality
The Processor ensures that personnel with access to personal data are bound by confidentiality obligations and limits access on a need-to-know basis.
6. Security Measures
Pursuant to Art. 32 GDPR, the Processor implements at least the following measures:
- Encryption in transit and at rest (HTTPS/TLS, encrypted database).
- Role-based access control and password policies.
- Row-level tenant isolation: each business's data is logically separated from all others.
- Regular backups and logging; retention of access records.
7. Sub-processors
The Controller grants general written authorisation for the Processor to use the sub-processors listed on the Sub-processors page. Changes to the list are published on that page and announced to subscribers by email; the Controller may object on reasonable grounds.
8. Assistance with Data Subject Requests
The Processor assists the Controller in fulfilling access, rectification, erasure, portability and objection requests through Platform features (customer record deletion, JSON export) and the support channel. Requests received directly by the Processor are forwarded to the Controller.
9. Personal Data Breach Notification
Upon becoming aware of a personal data breach, the Processor notifies the Controller without undue delay and at the latest within 72 hours, providing information on the nature of the breach, the records affected and the measures taken.
10. Deletion or Return at End of Contract
When the subscription ends, the Controller may export its data in JSON format (Settings → Data Backup). After a 90-day grace period following the end of the billing period, all personal data is deleted, except where retention is required by law.
11. Audit Rights
The Processor makes available to the Controller the information necessary to demonstrate compliance with this DPA and, once per year upon reasonable prior written notice and under confidentiality, allows audits or the sharing of independent audit reports.
Related documents
This is a draft — review with legal counsel before relying on it.