Data Processing Agreement
This agreement applies whenever we process personal data of your clients or staff on your behalf, and forms part of our Terms of Service — taking precedence over them for data protection matters. It is written to meet UK GDPR Article 28 without a signature ceremony: using the platform as a shop is acceptance. If your lawyer wants a countersigned copy, email hello@fadelio.com and we'll provide one.
1Roles and scope
You are the controller; Fadelio is your processor.
You are the controller; Fadelio is your processor. (For your own account and billing data, and for our own product analytics, we are a controller — see our Privacy Policy. Stripe is an independent controller of payment data under its own terms; we never see or store card numbers.)
2What we process for you
What we process: client and staff names, phone numbers, email addresses, booking history and preferences, payment status (never card numbers), attendance history and attendance-risk indicators, marketing preferences and consent records — for the duration of your subscription, for the purpose of running your shop's bookings, payments, reminders, marketing and reporting. You instruct us to compute attendance-risk indicators from your booking data to support your deposit and no-show policies. Data subjects: your clients and your staff.
3Our commitments as your processor
We will:
- process this data only on your documented instructions (the Terms and your product settings are those instructions — we'll tell you if we believe an instruction breaks data protection law);
- ensure everyone processing it is bound by confidentiality;
- protect it with appropriate technical and organisational measures — encryption in transit, access controls, tenant isolation, least-privilege access (the Security Overview describes the current measures);
- help you respond to your clients' data rights requests (access, correction, deletion, objection);
- help you with your security, breach-notification and impact-assessment duties;
- tell you without undue delay, and in any case within 72 hours of becoming aware, if a personal data breach affects your data;
- and at the end of the agreement delete or return the data at your choice (the 30-day export window in section 16 of the Terms), then delete remaining copies unless the law requires retention.
4Sub-processors
The list is live, public and versioned — and changes are notified 30 days before they take effect.
You give general written authorisation for the sub-processors we use to run the platform. The current list lives at fadelio.com/legal/subprocessors — every service, what it does, what data can reach it, and where it runs. We flow down equivalent data protection obligations to each, we remain responsible to you for their performance, and we'll notify you at least 30 days before adding or replacing one so you can object; if we can't resolve a reasonable objection, you may cancel under section 4 of the Terms.
5International transfers
Where a sub-processor processes data outside the UK, we rely on UK adequacy regulations or the ICO-approved International Data Transfer Agreement/Addendum with appropriate safeguards. The sub-processor list states the basis for each service.
6Audit and liability
We'll provide the information reasonably needed to demonstrate compliance with this agreement; where that genuinely isn't enough, you (or your auditor) may audit on reasonable notice, during business hours, at your cost, at most once a year. Each party is liable under UK GDPR Article 82 for damage caused by its own breach of its role's obligations; liability under this agreement is otherwise subject to section 14 of the Terms.