Policy
Data Processing Agreement
Version 1.0, July 2026
Version 1.0, July 2026. This document is in force and is undergoing routine legal review; any revisions will be published here as version 1.1.
Between the salon named in the Order (the "Controller") and FOX & WOLF CB, trading as Sondu, CIF E44679041, of Calle Niagara 63, Local 33, Flamenca Beach Centro Comercial, Orihuela Costa, 03189, Alicante, Spain (the "Processor").
This Agreement forms part of the Sondu Terms of Service and applies whenever the Processor processes personal data on behalf of the Controller in the course of providing the Sondu booking platform (the "Service"). It is written to satisfy Article 28 of Regulation (EU) 2016/679 (the "GDPR") and applicable Spanish data protection law, including the LOPDGDD.
1. Roles and scope
1.1 The Controller determines the purposes and means of processing the personal data of its clients and staff. The Processor processes that data only to provide the Service.
1.2 The Processor acts only on the Controller's documented instructions, which are given through the Controller's use of the Service, unless required to act otherwise by law, in which case the Processor will inform the Controller before processing unless the law prevents it.
2. What is processed
2.1 Categories of data subjects: the Controller's clients, prospective clients, and staff.
2.2 Categories of personal data: names, email addresses, phone numbers, preferred language, appointment history, service preferences, notes made by the salon, colour formulas, loyalty records, and booking communications.
2.3 Special category data: patch test dates and related allergy or reaction notes are data concerning health under Article 9 GDPR. The Processor applies the safeguards in clause 6 to this data. The Controller is responsible for holding a lawful basis for recording it, which will ordinarily be the explicit consent of the client under Article 9(2)(a), obtained by the Controller before a record is made.
2.4 Duration: for as long as the Controller subscribes to the Service, plus the wind down period in clause 9.
2.5 Nature and purpose: hosting and storing salon records, taking bookings, sending appointment communications by email, SMS and WhatsApp, payment administration, and producing reports for the Controller.
3. Confidentiality
The Processor ensures that every person it authorises to process the data, including its own partners and any staff, is bound by a duty of confidentiality.
4. Security
4.1 The Processor applies appropriate technical and organisational measures, including: data hosted in the European Union (Ireland); encryption of data in transit and at rest; row level security so that each salon's data is isolated from every other salon's; access to production systems restricted to named individuals; secrets held in a managed vault rather than in code; and separate credentials for administrative access.
4.2 The Processor will not materially reduce the overall security of the Service during the term.
5. Sub processors
5.1 The Controller gives general written authorisation for the sub processors listed below. The Processor will give at least 30 days notice of any intended addition or replacement, during which the Controller may object on reasonable data protection grounds. If the objection cannot be resolved, the Controller may terminate the affected part of the Service.
5.2 Current sub processors:
Sub processor
Purpose
Location of processing
Supabase
Database, authentication, file storage
European Union (Ireland)
Netlify
Hosting of the booking and admin pages
United States and global CDN
Resend
Transactional email delivery
United States
Twilio
SMS delivery
United States
Sent Technologies (sent.dm)
WhatsApp message delivery
United States
Stripe
Subscription billing and payments
European Union and United States
5.3 Where a sub processor processes personal data outside the European Economic Area, the Processor relies on an adequacy decision including the EU US Data Privacy Framework where the sub processor is certified, or on the European Commission's Standard Contractual Clauses.
5.4 The Processor imposes data protection obligations on each sub processor no less protective than those in this Agreement and remains liable for their performance.
6. Special safeguards for health data
6.1 Patch test and allergy records are stored in the same EU hosted, access controlled environment as all salon data and are never used by the Processor for any purpose other than displaying them to the Controller and driving the Controller's own patch test reminders.
6.2 The Processor does not sell, share, or use any Controller data, health data or otherwise, for advertising, profiling, or training of any kind.
7. Assistance to the Controller
7.1 Taking into account the nature of the processing, the Processor will assist the Controller with data subject requests. In practice the Controller can view, correct, and delete a client's record directly in the Service, and the Processor will assist with anything the Service cannot do within 10 working days of a written request to desk@sondu.eu.
7.2 The Processor will assist the Controller with its obligations under Articles 32 to 36 GDPR, including security, breach notification, and data protection impact assessments, so far as they concern the Service.
8. Personal data breaches
8.1 The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller to meet its own 72 hour obligation to the supervisory authority.
8.2 The Processor will document the breach, its effects, and the remedial action taken.
9. Return and deletion
9.1 On termination of the Service, the Controller may export its data from within the Service, or request an export, for 30 days.
9.2 After that window the Processor will delete the Controller's personal data within 60 days, except where law requires retention, in which case the data is isolated and protected until deletion is possible. Backups holding the data expire on their normal cycle.
9.3 Responsibility for retaining patch test records for insurance purposes after leaving the Service rests with the Controller, and the export includes them.
10. Audit
The Processor will make available the information reasonably necessary to demonstrate compliance with this Agreement, and will allow audits by the Controller or its mandated auditor, limited to once in any 12 month period, on 30 days written notice, during business hours, at the Controller's cost, and without access to other controllers' data.
11. Liability and order of precedence
Liability under this Agreement is subject to the limitations in the Sondu Terms of Service. If this Agreement conflicts with the Terms, this Agreement prevails on data protection matters.
12. Governing law
This Agreement is governed by Spanish law and the courts of the province of Alicante have jurisdiction.
Signed for the Controller: name, salon, date
Signed for the Processor: Ryan William Justin, partner, FOX & WOLF CB, trading as Sondu, date
Questions about any of it.
Write to desk@sondu.eu and a person answers, Monday to Friday, 10:00 to 17:00 CET, in English or Spanish.