← Legal Hub

Data Processing Addendum

Last updated: 9 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Orbis Digital Ltd ("Orbis Salon", "we", "us") and the salon, clinic or venue ("Customer", "Venue") using the Orbis Salon platform. It applies where Orbis Salon processes personal data on behalf of the Venue in the course of providing the platform.

1. Roles of the parties

  • For personal data the Venue collects and manages about its own customers and staff inside the platform, the Venue is the controller and Orbis is the processor.
  • For some operational data — such as billing, account administration, support, security and legal compliance — Orbis may act as an independent controller.
  • For Orbis Salon business customers and website visitors, Orbis Digital Ltd is usually the controller (see our Privacy Policy).

2. Processing instructions

Orbis processes personal data only on the documented instructions of the Venue, as set out in the agreement, this DPA and the Venue's use of the platform, unless required to do otherwise by law.

3. Categories of data subjects

  • Salon/clinic customers (end customers)
  • Venue staff and practitioners
  • Venue users and administrators

4. Categories of personal data

  • Contact data (name, email, phone, address)
  • Booking and appointment data
  • Consultation, follow-up and consent form responses
  • Clinical-style/aesthetic records where enabled (see special category data below)
  • Documents, uploads and before-and-after photos
  • Payment references (e.g. transaction history, last4/brand where returned) — raw card data is not stored by Orbis
  • Communications (SMS/email content and logs)
  • Website analytics and referral data

5. Special category data

Where the Venue enables aesthetics/clinical-style features, processing may include special category health data — for example medical history, medications, allergies, contraindication notes, treatment notes, consultation answers and treatment photos. The Venue is responsible for ensuring it has a lawful basis and an appropriate Article 9 condition where required, and for deciding what it collects from its customers. Orbis processes such data on behalf of the Venue under this DPA. Access is role-based where implemented.

6. Subprocessors

Orbis uses third-party subprocessors to help provide the platform. The Venue authorises the use of subprocessors of the following types. Specific providers may change; the table below uses placeholders that will be kept current.

ProviderPurposeLocationData processed
Hosting providerApplication & database hostingUK/EEAAll platform data
Email providerTransactional & marketing emailUK/EEAContact data, message content
SMS providerSMS deliveryUK/EEAPhone numbers, message content
Payment providerCard processingUK/EEAPayment references (no raw card data held by Orbis)
AI provider (where enabled)AI-assisted content/form draftingVariesContent submitted for processing
Analytics providerWebsite analyticsVariesUsage/referral data
Domain/hosting registrarDomain registration & DNSVariesDomain admin contact data
Storage/backup providerFile storage & backupsUK/EEADocuments, images, backups

7. Security measures

Orbis maintains appropriate technical and organisational measures designed to protect personal data, including access controls, role-based permissions where implemented, encryption in transit, secure hosting and logging. No system can be guaranteed to be completely secure.

8. Breach notification

Orbis will notify the Venue without undue delay after becoming aware of a personal data breach affecting the Venue's data, and will provide reasonable information to help the Venue meet its own notification obligations.

9. Assistance and data subject requests

Taking into account the nature of processing, Orbis will provide reasonable assistance to help the Venue respond to data subject requests and to meet its obligations regarding security, breach notification and data protection impact assessments.

10. International transfers

Where personal data is transferred outside the UK/EEA, appropriate safeguards (such as UK-approved transfer mechanisms) will be relied upon where required.

11. Confidentiality

Orbis ensures that personnel authorised to process personal data are subject to appropriate confidentiality obligations.

12. Return or deletion of data

On termination, and subject to the Data Retention and Export Policy, Orbis will delete or return personal data as agreed, except where retention is required by law. Backups may retain data for a limited period before being overwritten.

13. Audit and support

Orbis will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits as reasonably agreed, subject to confidentiality and security.

14. Contact

Questions about this DPA? Email .

For a plain-English overview of platform security measures, see our Security & Data Protection page.