Orbis Salon ← Back to Orbis Salon
Terms of Service Privacy Policy Cookie Policy Acceptable Use Data Processing Addendum

Data Processing Addendum

Last updated: 7 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Orbis Digital Ltd (trading as "Orbis Salon") ("Orbis", the "Processor") and the Customer (the "Controller"). It applies whenever Orbis processes personal data on behalf of the Customer in the course of providing the Orbis Salon platform (the "Service"), and is entered into to satisfy the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 (together, "Data Protection Law").

Terms defined in the Terms of Service have the same meaning here. "Personal data", "processing", "data subject", "controller", "processor", "personal data breach" and similar terms have the meanings given in Data Protection Law.

1. Roles and scope

1.1 The Customer is the controller of the personal data of its own clients, staff and other individuals that it submits to the Service ("Customer Personal Data"). Orbis processes Customer Personal Data only as the Customer's processor.

1.2 For clarity, this DPA does not apply to personal data for which Orbis is itself a controller (account, billing and usage data of the Customer and its Users), which is governed by the Orbis Privacy Policy.

1.3 The Customer warrants that it has, and will maintain, a lawful basis for the collection and processing of all Customer Personal Data, that it has provided all required privacy information to data subjects, and that its instructions to Orbis comply with Data Protection Law.

2. Details of the processing

Description
Subject matterProvision of the Orbis Salon platform: salon management, bookings, client records, communications, forms, payments and website publishing.
DurationThe term of the Customer's subscription, plus the post-termination export and deletion period described in clause 9.
Nature and purposeHosting, storage, retrieval, display, transmission, backup and deletion of data as required to operate the features of the Service used by the Customer, on the Customer's documented instructions.
Categories of data subjectsThe Customer's clients and prospective clients; the Customer's staff and other Users; recipients of the Customer's communications.
Categories of personal dataNames, contact details, appointment and purchase history, notes, preferences, photographs, form responses, communications, payment references (full card details are held by the payment provider, not Orbis), portal account details.
Special category dataHealth-related information may be collected where the Customer uses consultation or patch-test forms (for example allergies, skin conditions, medication relevant to treatments). The Customer is responsible for ensuring an Article 9 condition (normally explicit consent) is met before collecting such data.

3. Instructions

3.1 Orbis will process Customer Personal Data only on the Customer's documented instructions โ€” which consist of these Terms, the Customer's configuration and use of the Service, and any other written instructions agreed between the parties โ€” unless required to process otherwise by law, in which case Orbis will inform the Customer of that requirement before processing (unless the law prohibits this).

3.2 Orbis will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

4. Confidentiality

Orbis will ensure that all personnel authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality and process the data only as needed to provide the Service.

5. Security

5.1 Taking into account the state of the art, costs of implementation and the nature, scope, context and purposes of processing, Orbis implements and maintains appropriate technical and organisational measures to protect Customer Personal Data, including:

  • encryption of data in transit (HTTPS/TLS);
  • password hashing and optional two-factor authentication for User accounts;
  • logical tenant isolation so that each venue's data is scoped to that venue;
  • role-based access control and per-module staff permissions configurable by the Customer;
  • hashed storage of API keys and one-time tokens; masked display of credentials;
  • security logging and audit trails of significant actions;
  • anti-abuse controls including rate limiting, lockouts and spam protections on public forms;
  • regular backups and documented update and patching procedures.

5.2 The Customer remains responsible for its own security configuration, including choosing strong passwords, enabling two-factor authentication, assigning appropriate roles, and keeping exported data secure.

6. Sub-processors

6.1 The Customer gives general written authorisation for Orbis to engage sub-processors to support the Service, currently in the following categories: hosting and infrastructure (UK/EU data centres); payment processing; email delivery; and AI drafting services (used only when the Customer invokes AI features). A current list of sub-processors is available on request from [email protected].

6.2 Orbis will impose data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains liable for its sub-processors' performance.

6.3 Orbis will give the Customer at least 14 days' notice of the addition or replacement of a sub-processor (by email or dashboard notice). The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service in accordance with the Terms.

7. International transfers

Customer Personal Data is stored in the United Kingdom and/or the European Economic Area. Orbis will not transfer Customer Personal Data outside the UK unless the transfer is covered by UK adequacy regulations or appropriate safeguards under Articles 44โ€“49 UK GDPR (such as the UK International Data Transfer Agreement or Addendum), and will ensure its sub-processors do the same.

8. Assistance to the Customer

8.1 Taking into account the nature of the processing, Orbis will assist the Customer by appropriate technical and organisational measures (including the Service's built-in export, correction and deletion tools) in fulfilling the Customer's obligation to respond to data subject requests under UK GDPR (access, rectification, erasure, restriction, portability, objection).

8.2 If Orbis receives a request directly from a data subject relating to Customer Personal Data, it will (to the extent legally permitted) promptly forward the request to the Customer and will not respond substantively without the Customer's authorisation, except to direct the data subject to the Customer.

8.3 Orbis will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with the ICO, to the extent required of a processor and taking into account the information available to Orbis.

9. Personal data breach

Orbis will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably required for the Customer to meet its own notification obligations (nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed). Orbis will take reasonable steps to contain and remediate the breach. Orbis's notification is not an admission of fault.

10. Return and deletion

On termination or expiry of the subscription, the Customer may export Customer Personal Data using the Service's export tools during the 30-day period described in the Terms. After that period, Orbis will delete Customer Personal Data within a reasonable time, except to the extent that retention is required by law and except for residual copies in routine backups, which are overwritten in the ordinary course of backup rotation and remain protected by this DPA until deleted.

11. Audit

Orbis will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow for and contribute to audits (including inspections) conducted by the Customer or its mandated auditor, provided that: audits are limited to once in any 12-month period (except following a personal data breach or where required by a regulator); at least 30 days' written notice is given; audits are conducted during business hours without unreasonable disruption; and the auditor is bound by confidentiality. Orbis may first satisfy an audit request by providing recent security documentation or summaries.

12. Liability and general

12.1 Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, to the extent permitted by Data Protection Law.

12.2 If there is a conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA prevails.

12.3 This DPA is governed by the law of England and Wales.

13. Contact

Data protection contact: [email protected].

© 2026 Orbis Digital Ltd · Orbis Salon · [email protected] · Account Deletion