Data Processing Addendum
Last updated: 9 August 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Orbis Digital Ltd ("Orbis Salon", "we", "us") and the salon, clinic or venue ("Customer", "Venue") using the Orbis Salon platform. It applies where Orbis Salon processes personal data on behalf of the Venue in the course of providing the platform.
1. Roles of the parties
- For personal data the Venue collects and manages about its own customers and staff inside the platform, the Venue is the controller and Orbis is the processor.
- For some operational data — such as billing, account administration, support, security and legal compliance — Orbis may act as an independent controller.
- For Orbis Salon business customers and website visitors, Orbis Digital Ltd is usually the controller (see our Privacy Policy).
2. Processing instructions
Orbis processes personal data only on the documented instructions of the Venue, as set out in the agreement, this DPA and the Venue's use of the platform, unless required to do otherwise by law.
3. Categories of data subjects
- Salon/clinic customers (end customers)
- Venue staff and practitioners
- Venue users and administrators
4. Categories of personal data
- Contact data (name, email, phone, address)
- Booking and appointment data
- Consultation, follow-up and consent form responses
- Clinical-style/aesthetic records where enabled (see special category data below)
- Documents, uploads and before-and-after photos
- Payment references (e.g. transaction history, last4/brand where returned) — raw card data is not stored by Orbis
- Communications (SMS/email content and logs)
- Website analytics and referral data
5. Special category data
Where the Venue enables aesthetics/clinical-style features, processing may include special category health data — for example medical history, medications, allergies, contraindication notes, treatment notes, consultation answers and treatment photos. The Venue is responsible for ensuring it has a lawful basis and an appropriate Article 9 condition where required, and for deciding what it collects from its customers. Orbis processes such data on behalf of the Venue under this DPA. Access is role-based where implemented.
6. Subprocessors
Orbis uses third-party subprocessors to help provide the platform. The Venue authorises the use of subprocessors of the following types. Specific providers may change; the table below uses placeholders that will be kept current.
| Provider | Purpose | Location | Data processed |
|---|---|---|---|
| Hosting provider | Application & database hosting | UK/EEA | All platform data |
| Email provider | Transactional & marketing email | UK/EEA | Contact data, message content |
| SMS provider | SMS delivery | UK/EEA | Phone numbers, message content |
| Payment provider | Card processing | UK/EEA | Payment references (no raw card data held by Orbis) |
| AI provider (where enabled) | AI-assisted content/form drafting | Varies | Content submitted for processing |
| Analytics provider | Website analytics | Varies | Usage/referral data |
| Domain/hosting registrar | Domain registration & DNS | Varies | Domain admin contact data |
| Storage/backup provider | File storage & backups | UK/EEA | Documents, images, backups |
7. Security measures
Orbis maintains appropriate technical and organisational measures designed to protect personal data, including access controls, role-based permissions where implemented, encryption in transit, secure hosting and logging. No system can be guaranteed to be completely secure.
8. Breach notification
Orbis will notify the Venue without undue delay after becoming aware of a personal data breach affecting the Venue's data, and will provide reasonable information to help the Venue meet its own notification obligations.
9. Assistance and data subject requests
Taking into account the nature of processing, Orbis will provide reasonable assistance to help the Venue respond to data subject requests and to meet its obligations regarding security, breach notification and data protection impact assessments.
10. International transfers
Where personal data is transferred outside the UK/EEA, appropriate safeguards (such as UK-approved transfer mechanisms) will be relied upon where required.
11. Confidentiality
Orbis ensures that personnel authorised to process personal data are subject to appropriate confidentiality obligations.
12. Return or deletion of data
On termination, and subject to the Data Retention and Export Policy, Orbis will delete or return personal data as agreed, except where retention is required by law. Backups may retain data for a limited period before being overwritten.
13. Audit and support
Orbis will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits as reasonably agreed, subject to confidentiality and security.
14. Contact
Questions about this DPA? Email .
For a plain-English overview of platform security measures, see our Security & Data Protection page.