Legal

DATA PROCESSING AGREEMENT

Last updated: July 2026

1. Parties & Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the artist or studio ("you", the "Controller") and [STENCIL LEGAL ENTITY — TBC] (company number [COMPANY NUMBER — TBC], registered at [REGISTERED ADDRESS — TBC]) ("STENCIL", "we", "us", the "Processor").

It governs our processing of personal data on your behalf and reflects Article 28 of the UK GDPR and the EU GDPR. Where you determine the purposes and means of processing client personal data (for example, your clients' booking details, messages, and reference photos), you are the Controller and we are your Processor. For our own account, billing, and platform-operation data we act as an independent Controller, as described in our Privacy Policy.

2. Subject Matter, Duration & Nature of Processing

We process personal data only to provide the STENCIL platform: hosting bookings, quotes, deposits, messaging, reminders, and related features. Processing continues for the term of your account and ends as described in Section 7. The categories of data subjects are your clients and prospective clients; the categories of personal data are contact details, booking and appointment details, messages, and any reference images you or your clients upload.

3. Our Obligations as Processor

  • Process personal data only on your documented instructions, including as set out in the Terms and this DPA, unless required by law.
  • Ensure personnel authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (encryption in transit and at rest, access controls, and least-privilege access).
  • Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits on prior written notice.

4. Special Category Data (Reference Photos)

Reference images and body-placement photos uploaded for a tattoo booking may reveal information capable of being special category data. You are responsible for obtaining any explicit consent required from your clients before uploading such images. We process these images solely to provide the booking and communication features you use, and apply the same security measures described above.

5. Sub-processors

You authorise us to engage the sub-processors listed below to help deliver the service. We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended addition or replacement, giving you the opportunity to object on reasonable data-protection grounds.

Sub-processorPurposeLocation
Paddle.com Market LtdMerchant of Record — subscription checkout, billing, tax, invoicing, and refundsUK / EU
Stripe Payments Europe, Ltd.Payment processing for client deposit and balance payments (Stripe Connect payouts to artists)EU / US
Supabase (via Lovable Cloud)Database, authentication, file storage, and server functionsEU / UK region
Cloudflare, Inc.Application hosting, edge compute, and CDNGlobal (edge)
ResendTransactional and notification email deliveryEU / US
Plausible AnalyticsCookieless, privacy-friendly, aggregate usage analyticsEU (Germany)

6. Personal Data Breaches

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting personal data we process on your behalf. Our notice will describe the nature of the breach, its likely consequences, and the measures taken or proposed to address it, so you can meet your own regulatory obligations.

7. Return & Deletion on Termination

On termination of your account, or on your written request, we will delete or return the personal data we process on your behalf and delete existing copies, unless retention is required by law. Backups are purged on our standard rotation. See our Privacy Policy for retention details.

8. International Transfers

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards, including the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), or transfers to jurisdictions covered by an adequacy decision.

9. Contact

Data protection questions or requests under this DPA can be sent to support@stencils.life.