House of EDA

Data Processing Addendum

Article 28 GDPR terms for the client data we handle on your behalf.

Version 1.1 · 12 August 2026

Why this exists. When our assistant answers a message from one of your clients, it handles that person's data. Under the GDPR you are the controller of your clients' data and we are your processor — and Article 28 requires a written contract between us. This is that contract. It forms part of our Terms of Service and applies automatically to every subscription.

1. Parties and roles

Controller: you, the subscribing salon.
Processor: Abbott & Raihi B.V., trading as House of EDA, Nicolaas Witsenkade 31G, 1017 ZT Amsterdam, Netherlands, KVK 34279745.

You decide why and how your clients' personal data is processed. We process it only to provide the Service, and only on your documented instructions — of which your subscription and configuration form part.

2. Scope of the processing

ItemDetail
Subject matterProviding an AI assistant that receives and answers messages from your clients, and the shared inbox your team uses.
DurationFor as long as your subscription is active, plus the deletion period in clause 10.
Nature and purposeReceiving, storing, analysing and replying to client messages; generating booking links; recognising returning clients; notifying your team; producing performance statistics for you.
Categories of data subjectYour clients and prospective clients who message you on a connected channel.
Types of personal dataName or profile name; phone number or social handle; the content of messages, including any photos or voice notes sent; appointment and service details; language; and conversation history.
Special category dataNot requested and not required. A client may nonetheless volunteer health-related information in a message (for example about skin or nail conditions, allergies or pregnancy). You must configure the assistant not to solicit it, and must have your own lawful basis under Article 9 if you keep it.
Children's dataNot intended. If you serve minors you are responsible for the lawful basis and any parental consent.

3. Our obligations

We will:

4. Your obligations

5. Security measures

Taking into account the state of the art, the cost of implementation and the risks involved, we maintain appropriate technical and organisational measures, including:

We keep these measures under review and may update them, provided the level of protection is not reduced.

6. No AI model training

Your clients' data is not used to train AI models — ours or anyone else's.

We commit that:

Conversations may be read by people — your own team through the shared inbox, and our staff where necessary for support, fault-finding, or checking the assistant is answering safely and accurately. Access is limited to those who need it, and everyone is bound by confidentiality under clause 3.

7. Sub-processors

You give us general authorisation to engage the sub-processors listed below. They are integral to the Service — it cannot be delivered without them.

Sub-processorPurposeLocation
Anthropic PBCAI model generating assistant repliesUnited States
OpenAIVoice-note transcription (higher plans)United States
Twilio Inc.WhatsApp message deliveryUnited States / Ireland
Meta Platforms Ireland Ltd.WhatsApp Business and Instagram messagingIreland / United States
Railway Corp.Application hosting and data storageUnited States
Netlify Inc.Website and widget hostingUnited States

Each is bound by a written contract imposing data-protection obligations no less protective than these. We remain fully liable to you for their performance.

If we intend to add or replace a sub-processor we will give you at least 30 days' notice. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection you may terminate the affected part of the Service without penalty.

8. International transfers

Providing the Service involves transferring personal data outside the European Economic Area, principally to the United States. Where it does, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), on the EU–US Data Privacy Framework where the recipient is certified, and on supplementary measures including encryption in transit and data minimisation. Copies of the relevant safeguards are available on request.

9. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notification will describe what happened, the categories and approximate number of people and records affected so far as known, the likely consequences, and the measures taken or proposed. We will assist you with your own notification duties to the supervisory authority and to affected individuals.

10. Deletion and return

When your subscription ends you may request, within 30 days, an export of the personal data we process for you in a commonly used machine-readable format. After that period, or once an export has been provided, we will delete the data from our live systems within 90 days, and from backups on the ordinary backup rotation — unless EU or member-state law requires us to keep it, in which case we will tell you what and why.

11. Audits

On reasonable written request, and no more than once a year unless a breach or a supervisory authority requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this Addendum. Where that is genuinely insufficient, we will allow an audit conducted during business hours, on at least 30 days' notice, in a way that does not disrupt the Service or compromise the confidentiality of other customers' data, by you or by an independent auditor who is not our competitor and who is bound by confidentiality. You bear the cost unless the audit reveals a material breach on our part.

12. Assistance with data-subject requests

If one of your clients contacts us directly to exercise their rights, we will not respond substantively ourselves — we will refer them to you and tell you promptly, because you are the controller. Taking into account the nature of the processing, we will provide reasonable technical assistance so you can meet your obligations within the statutory time limits, including locating, exporting, correcting or deleting a given individual's conversation data.

13. Precedence and term

This Addendum forms part of the Terms of Service and applies for as long as we process personal data on your behalf. If it conflicts with the Terms of Service on a data-protection matter, this Addendum prevails. It is governed by the law of the Netherlands, with the courts of Amsterdam competent.

Need this signed as a standalone document for your own records or your auditor? Write to info@houseofeda.ai and we will provide a countersigned copy.