DATA PROCESSING AGREEMENT
Last updated: July 2026
1. Parties & Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the artist or studio ("you", the "Controller") and [STENCIL LEGAL ENTITY — TBC] (company number [COMPANY NUMBER — TBC], registered at [REGISTERED ADDRESS — TBC]) ("STENCIL", "we", "us", the "Processor").
It governs our processing of personal data on your behalf and reflects Article 28 of the UK GDPR and the EU GDPR. Where you determine the purposes and means of processing client personal data (for example, your clients' booking details, messages, and reference photos), you are the Controller and we are your Processor. For our own account, billing, and platform-operation data we act as an independent Controller, as described in our Privacy Policy.
2. Subject Matter, Duration & Nature of Processing
We process personal data only to provide the STENCIL platform: hosting bookings, quotes, deposits, messaging, reminders, and related features. Processing continues for the term of your account and ends as described in Section 7. The categories of data subjects are your clients and prospective clients; the categories of personal data are contact details, booking and appointment details, messages, and any reference images you or your clients upload.
3. Our Obligations as Processor
- Process personal data only on your documented instructions, including as set out in the Terms and this DPA, unless required by law.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (encryption in transit and at rest, access controls, and least-privilege access).
- Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
- Make available information necessary to demonstrate compliance and allow for reasonable audits on prior written notice.
4. Special Category Data (Reference Photos)
Reference images and body-placement photos uploaded for a tattoo booking may reveal information capable of being special category data. You are responsible for obtaining any explicit consent required from your clients before uploading such images. We process these images solely to provide the booking and communication features you use, and apply the same security measures described above.
5. Sub-processors
You authorise us to engage the sub-processors listed below to help deliver the service. We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended addition or replacement, giving you the opportunity to object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Paddle.com Market Ltd | Merchant of Record — subscription checkout, billing, tax, invoicing, and refunds | UK / EU |
| Stripe Payments Europe, Ltd. | Payment processing for client deposit and balance payments (Stripe Connect payouts to artists) | EU / US |
| Supabase (via Lovable Cloud) | Database, authentication, file storage, and server functions | EU / UK region |
| Cloudflare, Inc. | Application hosting, edge compute, and CDN | Global (edge) |
| Resend | Transactional and notification email delivery | EU / US |
| Plausible Analytics | Cookieless, privacy-friendly, aggregate usage analytics | EU (Germany) |
6. Personal Data Breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting personal data we process on your behalf. Our notice will describe the nature of the breach, its likely consequences, and the measures taken or proposed to address it, so you can meet your own regulatory obligations.
7. Return & Deletion on Termination
On termination of your account, or on your written request, we will delete or return the personal data we process on your behalf and delete existing copies, unless retention is required by law. Backups are purged on our standard rotation. See our Privacy Policy for retention details.
8. International Transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards, including the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), or transfers to jurisdictions covered by an adequacy decision.
9. Contact
Data protection questions or requests under this DPA can be sent to support@stencils.life.