Data Processing Agreement (DPA)

Last updated: 27.08.2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between IiroMan OÜ (“Taimli”, “Processor”) and the salon or business using Taimli (“Salon”, “Controller”).

This DPA ensures compliance with the EU General Data Protection Regulation (GDPR) for all personal data processed by Taimli on behalf of the Salon.


1. Definitions

“Controller”
The Salon that determines the purposes and means of processing personal data of its clients.

“Processor”
Taimli (IiroMan OÜ), which processes personal data on behalf of the Salon.

“Personal Data”
Any information relating to an identifiable individual.

“Services”
The Taimli booking platform and related features provided to the Salon.

“Sub-processors”
Third-party providers engaged by Taimli to support the service.


2. Subject Matter and Duration

Taimli processes personal data solely for the purpose of providing the booking, scheduling, communication, and related features of the platform.

This DPA remains valid as long as the Salon uses Taimli.

For clarity, this DPA covers personal data that Taimli processes on behalf of the Salon as Processor. It does not govern processing Taimli carries out as an independent Controller for its own account administration, billing, security, abuse prevention, optional Stripe Connect connection metadata, privacy-friendly analytics on Taimli-controlled pages, PostHog EU product analytics in the authenticated salon admin interface, Ferndesk in-app changelog announcements in the authenticated salon admin interface, or Fernand support and other inbound email.


3. Nature and Purpose of Processing

Taimli processes personal data for:

  • Managing customer bookings
  • Sending email and SMS confirmations and reminders
  • Storing customer waitlist preferences and sending waitlist notification emails when matching appointment times become available
  • Displaying salon schedules
  • Storing booking history (until deleted by the salon)
  • Optional communications from salon to clients
  • Storing internal salon notes and optional treatment-progress photos, if the Salon chooses to use those features
  • Securely hosting customer data for salon operations

If enabled by the Salon or an authorized worker, Taimli may also sync bookings to Google Calendar for the relevant worker as an optional integration feature.

If the Salon chooses to set up its connected Stripe account, Taimli may transmit limited salon and connection data to Stripe to create and maintain the connection. Stripe hosts the onboarding flow and independently determines how it processes identity, business, banking, tax, and compliance information under its own legal obligations. Setting up the account does not currently transmit salon-client booking or payment data to Stripe.

Taimli does not process salon customer data for its own purposes.


4. Types of Personal Data and Data Subjects

4.1 Data Subjects

  • Salon clients
  • Salon staff (optional)

4.2 Types of Data

  • Name
  • Email address
  • Phone number
  • Appointment details
  • Waitlist preferences, such as requested services, preferred dates and time ranges, worker preference, and notification history
  • Optional notes
  • Optional treatment-progress photos attached to internal salon notes, if enabled and used by the salon

Optional treatment-progress photos may include health information or other special-category personal data. The Salon is responsible for determining whether to collect such photos and for documenting the applicable GDPR Article 6 lawful basis and, where required, the GDPR Article 9 condition for processing special-category data.

Where the optional Google Calendar integration is enabled, the data transferred for synced events may also include:

  • booking date and time
  • service names
  • salon location
  • a Taimli manage link containing the booking identifier

Where optional Stripe Connect account setup is enabled, the data transferred by Taimli may include:

  • the salon's email address
  • the internal salon identifier
  • connected account and onboarding-status metadata

Identity documents, full bank account details, tax information, and other Stripe verification data are entered directly into Stripe-hosted onboarding and are not stored by Taimli.

Taimli does not collect IP addresses or device fingerprints.


5. Obligations of the Processor (Taimli)

Taimli agrees to:

  1. Process personal data only on documented instructions from the Salon.
  2. Not use client data for advertising, analytics, training models, or any unrelated purpose.
  3. Maintain appropriate technical and organisational security measures.
  4. Ensure that staff with access to data are under confidentiality obligations.
  5. Assist the Salon in fulfilling GDPR data subject requests.
  6. Notify the Salon without undue delay of any personal data breach.
  7. Provide and maintain self-service exports for salon data available in the product.
  8. Not remove export functionality to make leaving the service harder, charge for standard self-service exports of the Salon's own data, require support tickets for basic exports, offer intentionally crippled exports, or use intimidating legal language to restrict reasonable access to the Salon's own data.
  9. On reasonable request, help the Salon understand exported files and provide migration-related assistance, including helping a future provider understand the export when needed.
  10. Delete all salon data upon account deletion, subject to provider backup cycles.
  11. Make available all information necessary to demonstrate GDPR compliance.

6. Obligations of the Controller (Salon)

The Salon agrees to:

  1. Collect client data lawfully and inform clients that Taimli processes their data.
  2. Use Taimli only for legitimate business purposes.
  3. Handle all GDPR requests from clients, with support from Taimli.
  4. Determine its own lawful basis for processing (typically performance of contract for ordinary booking data).
  5. Determine and document an applicable GDPR Article 9 condition before using Taimli to store treatment-progress photos or other special-category personal data.
  6. Ensure contact information provided to clients is accurate.

7. Sub-processors

Taimli uses GDPR-compliant sub-processors essential to delivering the service:

  • Stripe — Taimli subscription payment processing
  • Hetzner & Servinga — VPS hosting (EU)
  • PlanetScale — managed PostgreSQL database (EU region)
  • Cloudflare — DNS, security, and content delivery (SCCs may apply)
  • Cloudflare R2 — media storage (EU region)
  • Cloudflare Turnstile — bot protection on booking pages (no cookies, minimal data processing)
  • Mailgun — transactional email (EU region)
  • Fernand — support and other inbound email (EU)
  • Prelude — SMS delivery for booking confirmations and reminders

Where Taimli-controlled pages are measured using privacy-friendly website analytics, Taimli may also use:

  • Plausible — cookie-free website analytics
  • PostHog EU — product analytics for the authenticated salon admin interface only

Where Taimli shows in-app product update announcements to salon staff, Taimli may also use:

  • Ferndesk — changelog announcements for the authenticated salon admin interface only (United States; Standard Contractual Clauses apply)

Taimli ensures all sub-processors provide appropriate data protection guarantees.

The Salon authorizes Taimli to use these sub-processors.

7.1 Optional Third-Party Integrations Chosen by the Controller

If the Salon or an authorized worker enables the optional Google Calendar integration, Taimli will transfer relevant booking data and connection metadata to Google solely to provide that integration.

This transfer occurs only on the Controller's instruction through enabling and using the integration. For this feature, Google acts as a third-party service selected by the Controller for the Controller's own use.

If the Salon enables optional Stripe Connect account setup, Taimli will transfer the limited salon and connection data described in section 4 to Stripe solely to create and maintain the connected account. Stripe acts as an independent controller for its hosted onboarding, identity verification, compliance, connected-account administration, and related regulatory processing.

The Salon is responsible for ensuring that its representative is authorized to create the connected account and receives an appropriate notice about Stripe's separate terms and privacy policy.


8. International Transfers

Taimli stores and processes data primarily within the EU.

Some providers (e.g., Cloudflare or Ferndesk) may transfer limited data outside the EU.
Such transfers are protected using:

  • Standard Contractual Clauses (SCCs)
  • Additional contractual and technical safeguards

Taimli aims to use EU-based processing whenever possible.


9. Security Measures

Taimli employs industry-standard security practices, including:

  • HTTPS encryption in transit
  • Encryption at rest where supported by providers
  • Access control and authentication
  • Password hashing (Argon2 for upcoming password features; magic link for now)
  • Database backups managed by hosting providers
  • Regular patching and security updates

10. Data Retention and Deletion

Minimal Retention Policy (Controller-Friendly)

  • Client data is retained only while the Salon’s account is active.
  • Upon account deletion, all personal data is deleted immediately from production systems.
  • Backup retention by providers (e.g., PlanetScale) persists for 30–90 days, then is automatically purged.
  • Taimli does not maintain additional internal backups of production data.

The Salon may delete client data at any time through the interface or by request.

Salon business data processed on behalf of the Salon belongs to the Salon.

Before account deletion, the Salon may export its salon data through Taimli's self-service export tools. Taimli will maintain these exports, will not charge for standard self-service exports of the Salon's own data, will not require support tickets for basic exports, will not remove export functionality to make leaving harder, will not offer intentionally crippled exports, and will not use intimidating legal language to restrict reasonable access to the Salon's own data. On reasonable request, Taimli will help the Salon understand exported files and provide migration-related assistance, including helping a future provider understand the export when needed.


11. Breach Notification

In case of a confirmed personal data breach, Taimli will notify the Salon without undue delay and provide all necessary information for compliance with GDPR Articles 33–34.


12. Assistance with Data Subject Requests

Taimli will support the Salon in handling:

  • Access requests
  • Correction
  • Deletion
  • Export and portability
  • Objection or restriction requests

Requests from salon clients must be initiated by the Salon.


13. Verification and Audits

At the Salon’s written request, Taimli will provide all information reasonably necessary to demonstrate compliance with this DPA, including a description of relevant security measures and a list of sub-processors.

The Salon’s verification rights are limited to reviewing such documentation.
No on-site audits, inspections, or access to Taimli’s infrastructure, systems, or hosting environments are permitted.

If additional information is required for the Salon’s GDPR compliance, Taimli will make reasonable efforts to respond to such requests.


14. Termination

Upon termination of the Salon’s Taimli account:

  • All personal data is deleted from active systems
  • Backup data is automatically purged according to provider retention cycles
  • Taimli retains no copies of personal data beyond required legal obligations

15. Governing Law

This DPA is governed by the laws of Estonia.
Disputes shall be resolved exclusively in the courts of Tallinn, Estonia.


16. Entire Agreement

This DPA forms part of the Terms of Service.
In case of conflict between the Terms and this DPA, the DPA prevails for data protection matters.


IiroMan OÜ (Taimli)
Email: [email protected]