Data Processing Agreement
Last updated: 21 September 2026
This Data Processing Agreement (“DPA”) forms part of the KERSIVO Terms of Service (the “Terms”) between Bartosz Jasinski, trading as KERSIVO, based in Bournemouth, England, United Kingdom (“KERSIVO”, “we”, “us” or “our”), and the Client.
This DPA applies only where KERSIVO processes Customer Personal Data on behalf of the Client in the course of providing the Services. For that processing, the Client is the Controller and Bartosz Jasinski, trading as KERSIVO, is the Processor.
KERSIVO separately acts as an independent Controller for its own account, billing, security, support, legal, tax, marketing and operational data, as explained in the Privacy Policy. That independent-controller processing is outside the scope of this DPA. KERSIVO is not the Processor for every category of personal data processed in connection with the platform.
1. Definitions
In this DPA:
- Applicable Data Protection Law means, to the extent applicable, the UK GDPR, the Data Protection Act 2018, and other applicable UK data-protection law.
- Client means the barbershop or business customer that uses the Services under the Terms.
- Controller and Processor have the meanings given in Applicable Data Protection Law.
- Customer Personal Data means personal data relating to the Client’s customers, clients, staff or other individuals that the Client submits to, collects through, or manages using the Services, and that KERSIVO processes on the Client’s behalf as Processor.
- Data Subject means an identified or identifiable natural person to whom Customer Personal Data relates.
- Processing / Process have the meanings given in Applicable Data Protection Law.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- Sub-processor means a third party engaged by KERSIVO to Process Customer Personal Data on KERSIVO’s behalf in connection with the Services.
- Services means the KERSIVO software and related services described in the Terms (including barbershop website, booking, CRM/admin, retail pickup and related operational features).
2. Roles and scope
The Client is Controller for Customer Personal Data it submits to, collects through, or manages using KERSIVO. KERSIVO acts as Processor only for the Processing required to provide the Services on the Client’s behalf.
KERSIVO remains an independent Controller where it determines its own purposes, including account administration, authentication and security, SaaS billing, legal acceptance records, direct support and customer communications with the Client, accounting, tax and legal compliance, abuse and fraud prevention, KERSIVO marketing analytics, and KERSIVO operational audit records. Those activities are described further in the Privacy Policy and are outside this DPA.
3. Documented instructions
KERSIVO will Process Customer Personal Data only: (a) to provide the Services; (b) according to this DPA, the Terms, the Client’s product configuration and other documented instructions; or (c) where required by applicable law.
Written instructions may include configuration made through the product, authenticated actions in the admin, support requests, and written email instructions consistent with the Services. KERSIVO does not provide legal advice.
If applicable law requires Processing outside the Client’s instructions, KERSIVO will inform the Client beforehand unless prohibited by law. KERSIVO will also inform the Client if, in KERSIVO’s opinion, an instruction appears to infringe Applicable Data Protection Law.
The Client instructs and authorises KERSIVO to transfer Customer Personal Data to the approved Sub-processors listed in Schedule 2, including where this involves a restricted transfer outside the United Kingdom, solely where necessary to provide the Services and subject to section 7 of this DPA.
4. Confidentiality
Any person authorised by KERSIVO to Process Customer Personal Data must be subject to an appropriate contractual or statutory duty of confidentiality.
5. Security
Taking account of the nature of Processing, the state of the art, the costs of implementation, and the likelihood and severity of risk to Data Subjects, KERSIVO will maintain appropriate technical and organisational measures to protect Customer Personal Data. Current measures are described in Schedule 3. No online service can guarantee absolute or perfect security.
6. Sub-processors
The Client grants KERSIVO general written authorisation to engage: (a) the Sub-processors listed in Schedule 2; and (b) replacement or additional Sub-processors, subject to the notification procedure below.
KERSIVO will enter into a written agreement with each Sub-processor that imposes data-protection obligations providing an equivalent level of protection for Customer Personal Data to the obligations applicable to KERSIVO under Article 28 and this DPA. KERSIVO remains responsible to the Client for the performance of the Sub-processor’s applicable data-protection obligations and will only permit Processing needed for the relevant service. KERSIVO does not promise a bespoke vendor stack for every Client.
For planned new or replacement Sub-processors, where reasonably practicable KERSIVO will notify active Clients at least 14 days before the change, by email and/or service notice. Emergency, security or legal changes may occur sooner where necessary. During the notice period the Client may object on reasonable data-protection grounds. The parties will attempt to resolve the objection in good faith. If no reasonable solution exists, KERSIVO may discontinue the affected feature, or either party may terminate the affected service in accordance with the Terms.
7. International transfers
Customer Personal Data may be processed outside the United Kingdom where a Sub-processor does so. KERSIVO does not claim that all data remains in the UK.
Where a restricted transfer requires safeguards, KERSIVO will rely on an appropriate lawful mechanism, which may include UK adequacy regulations where applicable, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard recognised under UK data-protection law. Provider-specific transfer mechanisms are governed by the current agreements between KERSIVO and those providers.
Where KERSIVO relies on an Article 46 safeguard for a restricted transfer, KERSIVO will complete any data protection test, also referred to by the ICO as a transfer risk assessment, required by Applicable Data Protection Law and implement any additional safeguards reasonably identified as necessary.
8. Data subject rights
The Client remains responsible for responding to requests from its Data Subjects. Taking account of the nature of Processing, KERSIVO will provide reasonable assistance using available technical and organisational measures for access, correction, erasure, restriction, portability and objection where applicable. Not every right has a self-service interface; assistance is also available via hello@kersivo.co.uk.
If KERSIVO receives a request relating to Customer Personal Data, it will normally direct the requester to the relevant Client unless law requires otherwise.
9. Security, breach and DPIA assistance
Taking account of the nature of Processing and information available to KERSIVO, KERSIVO will provide reasonable assistance with the Client’s obligations relating to Article 32 security, personal data breach assessment, regulator notification, data-subject notification where required, data protection impact assessments, and prior consultation with the ICO where required.
After becoming aware of a Personal Data Breach affecting a Client’s Customer Personal Data, KERSIVO will notify that Client without undue delay. Available information may be provided progressively where not all facts are known at first notification. KERSIVO does not promise a fixed one-, twelve- or twenty-four-hour notification SLA.
10. Return and deletion
While the Services are active, the Client may use the available self-service export tools. The standard CSV export currently contains client contact details and booking history and is not a full database export.
At the end of the Services, at the Client’s choice, KERSIVO will delete or return the Customer Personal Data processed on the Client’s behalf and will delete existing copies, unless Applicable Data Protection Law requires continued storage. Where the Client chooses return, KERSIVO will provide the Customer Personal Data in a reasonably practicable format and may provide reasonable assistance for data not included in the standard self-service CSV.
Unless the Client gives a different lawful instruction before the end of the retention period, KERSIVO applies its standard 30-day post-termination export and retention window, after which Customer Personal Data in the live tenant production environment is deleted through the standard purge process, including tenant EmailOutbound and SmsOutbound records and the associated private Blob cleanup lifecycle.
This obligation does not require deletion of separate records that KERSIVO lawfully retains in its independent-controller capacity, such as billing, tax, legal acceptance or security records. Residual copies may remain temporarily in provider-managed backups where immediate deletion is not technically practicable. Those copies remain protected and beyond normal active use until they are deleted or expire through the applicable backup lifecycle.
11. Audit and compliance information
KERSIVO will make available to the Client all information reasonably necessary to demonstrate compliance with the obligations applicable to KERSIVO under Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Client or an independent auditor mandated by the Client.
Where reasonable, documentation and written evidence will be used first. Audits must be carried out on reasonable advance notice and during normal business hours, must not provide access to another customer’s data, and must not compromise the security, confidentiality or intellectual property of KERSIVO or another person.
Customer-initiated audits are normally limited to one per twelve-month period, unless required by a regulator or law, following a material Personal Data Breach, or where there is a reasonable evidence-based compliance concern.
The Client bears its own audit costs. KERSIVO may charge reasonable costs for extraordinary assistance beyond the information and cooperation KERSIVO is required to provide under Applicable Data Protection Law, to the extent permitted by law.
12. Client responsibilities
The Client is responsible for:
- having a lawful basis for Customer Personal Data;
- providing required privacy information to its customers and staff;
- issuing lawful instructions;
- keeping account and access permissions appropriate;
- ensuring submitted data is relevant and appropriate; and
- complying with its Controller obligations under Applicable Data Protection Law.
Special category data. KERSIVO does not design the normal Services to require special category personal data. The Client must not intentionally submit special category personal data unless KERSIVO has expressly agreed to such Processing in writing and the Client has a lawful basis. Free-text notes and uploads could technically contain sensitive information; KERSIVO is not marketed as a health or special-category data system.
13. Liability, Terms and hierarchy
This DPA forms part of the Terms. Liability under this DPA is subject to the Terms to the extent permitted by applicable law. Nothing in this DPA creates a separate liability cap that conflicts with the Terms.
Where a mandatory international-transfer mechanism directly applies between the parties to this DPA and conflicts with this DPA, that mechanism prevails only to the extent of the conflict. For all other data-protection matters, this DPA prevails over the Terms to the extent of any conflict.
Nothing in this DPA limits rights or obligations that cannot lawfully be limited.
14. Governing law
This DPA is governed by the law of England and Wales. Disputes are subject to the same jurisdiction framework as the Terms (exclusive jurisdiction of the courts of England and Wales).
Schedule 1 — Details of Processing
Subject matter
Provision of KERSIVO barbershop website, booking, CRM/admin, retail pickup, communications and related operational services.
Duration
For the active service duration, plus the applicable post-termination export/deletion period, and limited residual provider backup lifecycle.
Nature / operations
Collection, recording, organisation, storage, retrieval, display to authorised Client users, booking creation, rescheduling and cancellation, client CRM, notes, image and file storage, retail order processing, transactional email, optional SMS reminders, deposit and payment-status recording, migration/import, export, deletion, and security/operational Processing necessary to provide the service.
Purpose
Provide and operate the Client’s KERSIVO service according to the Client’s instructions.
Data subjects
Booking clients; retail customers; barbers; managers and team members; invited staff; individuals represented in legitimate migration or imported business records; and persons legitimately referenced in client records or notes.
Personal data
Name; email; phone; booking and appointment data; service, barber, date, time and status; cancellation/reschedule information; booking management tokens; deposit/payment status and Stripe identifiers (but not full card numbers); CRM tags and notes; client-note images; retail customer email and order contents; staff/barber names, contact and profile data; team invitations and roles; availability/working information where linked to staff; transactional email/SMS delivery data; and uploaded migration/setup material where it contains personal data.
Special category data
Not required or intentionally requested by the standard Services. The Client must not intentionally submit it unless expressly agreed in writing.
Frequency
Continuous or as initiated by the Client or Data Subjects during the service term.
Schedule 2 — Approved Sub-processors
| Provider | Service | Data | Condition | Transfer note |
|---|---|---|---|---|
| Vercel | Application hosting/runtime and Vercel Blob storage | Customer Personal Data necessary to host/run the application and files | Always used for hosted production service | Current Vercel DPA / applicable UK transfer safeguards |
| Neon (Databricks) | Managed PostgreSQL database infrastructure | Customer Personal Data stored in the application database | Always used for hosted production service | Current Neon/Databricks contractual safeguards applicable to the KERSIVO account |
| Resend / Plus Five Five, Inc. | Transactional email delivery | Recipient email, name where included, booking/order transactional content, manage links and delivery metadata | Used where transactional email is sent | Current Resend DPA, including applicable UK transfer safeguards |
| Twilio | SMS delivery | Phone number, reminder message content, delivery metadata | Only where SMS functionality is enabled | Current Twilio DPA / applicable UK transfer safeguards |
| Sentry | Server/application error monitoring where configured | Minimised/scrubbed operational telemetry; direct customer PII is not intentionally sent | Only where SENTRY_DSN / monitoring is configured | Current Sentry DPA / applicable UK transfer safeguards |
| Slack | Operational alert delivery / incident notification | Minimised operational telemetry. Direct customer email addresses and phone numbers are intentionally sanitised before transmission, but alerts may contain tenant-linked or record-linked operational identifiers and technical error context. | Only where OPS_SLACK_WEBHOOK_URL is configured and Slack operational alerting is enabled | Current Slack data-processing terms and applicable lawful UK transfer safeguards |
| OpenAI | Admin AI assistant / language-model processing | Free-text prompts and conversation context submitted by authorised Client users. This may include Customer Personal Data if a Client user enters it. Responses and technical request metadata may also be processed. | Only where the KERSIVO admin AI assistant is enabled and OPENAI_API_KEY is configured | Current OpenAI Data Processing Addendum and applicable UK transfer safeguards |
The following are not listed as Sub-processors for Customer Personal Data under this DPA: Google Analytics / Google Ads (tenant analytics disabled; KERSIVO own marketing-controller processing); Stripe platform billing (KERSIVO controller billing); and Google OAuth (KERSIVO account/auth context).
OpenAI note. Catalogue and recommendation AI processing remains designed around product/catalogue semantics and is not intended to send Customer Personal Data. Separately, the admin free-text AI assistant is a conditional Customer Personal Data path listed above where that feature is enabled. KERSIVO does not claim that OpenAI always receives tenant data for every Client.
Stripe Connect note. Live booking deposits and retail card payments are processed through the Client’s connected Stripe account. The Client has its own Stripe relationship. Stripe may act as controller and/or processor depending on the payment activity under Stripe’s terms. KERSIVO stores limited identifiers and statuses and does not store full card numbers. Stripe Connect is not listed above as a normal KERSIVO Sub-processor for Customer Personal Data.
Schedule 3 — Technical and organisational measures
A. Access control
- Authenticated admin access
- Role-based permissions
- Tenant/shop scoping
- Session controls
- Authorised access only
B. Data protection in transit / storage
- HTTPS/TLS for web traffic
- Managed database and storage provider safeguards
- Private Blob storage for client-note and onboarding private assets
- No full payment card storage by KERSIVO
C. Application security
- Environment-managed secrets
- Webhook signature validation
- Selected-route rate limiting / abuse controls
- Input validation
- Upload type/size allowlists
- Private authenticated streaming for new client-note images
D. Tenant isolation
- Shop-scoped database and API access controls
- RBAC checks
- Authenticated private media access
E. Availability / recovery
- Provider-managed database backup / point-in-time recovery capabilities
- Documented recovery procedures
This DPA does not create a public SLA, RPO or RTO unless separately offered in a written commercial agreement.
F. Data minimisation / logging
- Customer PII removed or sanitised from Slack operational alerts
- Sentry configured with default PII off and additional event scrubbing
- No KERSIVO Google Analytics / Ads tags on live tenant customer surfaces
G. Lifecycle
- Tenant outbox deletion during shop purge
- Production tenant data purge after applicable retention
- Private Blob cleanup lifecycle
- Controller records kept separately where legally required
H. Incident management
- Documented incident-response process
- Operational alerting and error monitoring when configured
- Breach escalation under this DPA
KERSIVO does not claim ISO or SOC 2 certification for KERSIVO, independent penetration tests for KERSIVO, 24/7 staffed monitoring, or antivirus scanning of uploads, unless separately implemented and stated in writing.