Skip to main content

Data Processing Agreement (DPA)

Compliance in force since 18 June 2026 updated 18 June 2026

1. Purpose and roles

The salon (controller) entrusts Bellisy (processor) with processing end-client data within the services. Bellisy acts only on the salon’s documented instructions.

2. Processor obligations

  • Process data only on the controller’s documented instructions.
  • Ensure confidentiality (staff commitment).
  • Implement the security measures in Annex II.
  • Assist the controller with data subject rights and impact assessments.
  • Notify any breach without undue delay.
  • Delete or return data at the end of the contract.
  • Allow audits and provide necessary information.

3. Data breaches

Bellisy notifies the salon of any confirmed breach as soon as possible and at the latest 72 hours after becoming aware of it, providing the information needed for the salon to meet its obligations.

4. Annex I — Description of processing

ItemDetail
SubjectAppointment and client-relationship management
DurationTerm of the subscription contract
NatureCollection, storage, consultation, deletion
PurposeBooking, reminders, AI assistance
PersonsSalon end clients
DataIdentity, contacts, bookings, preferences, (optional) health/photos

5. Annex II — Security measures

  • Encryption in transit (TLS) and at rest (AES-256).
  • Role-based access control and MFA.
  • Daily encrypted backups (30 days), restoration tests.
  • Logging, monitoring and incident management.
  • Hosting within the EU (OVH).

6. Annex III — Sub-processors

Sub-processorRoleLocation
OVHHostingEU
StripePaymentsEU/USA (SCC)
PayPalPaymentsEU/USA (SCC)
Meta (WhatsApp/Instagram)MessagingEU/USA (SCC)
AI providerAI responsesEU/USA (SCC)
E-mail serviceNotificationsEU

7. End of contract and return of data

At the end of the contract, the salon can export its data. Bellisy deletes or returns it within 30 days, save any legal retention obligation. DPO contact: dpo@bellisy.fr.

Related documents GDPR Compliance

GDPR

Full compliance with Regulation (EU) 2016/679 and CNIL guidance.

EU AI Act

Clients always know they are talking to an AI. The salon stays in control.

Data in the EU

Hosting in France, TLS and AES-256 encryption, backups inside the EU.

Export in one click

Your data belongs to you: export and deletion straight from the cabinet.