Data Processing Addendum
Article 28 GDPR terms for the client data we handle on your behalf.
Version 1.1 · 12 August 2026Why this exists. When our assistant answers a message from one of your clients, it handles that person's data. Under the GDPR you are the controller of your clients' data and we are your processor — and Article 28 requires a written contract between us. This is that contract. It forms part of our Terms of Service and applies automatically to every subscription.
1. Parties and roles
Controller: you, the subscribing salon.
Processor: Abbott & Raihi B.V., trading as House of EDA, Nicolaas Witsenkade 31G, 1017 ZT Amsterdam, Netherlands, KVK 34279745.
You decide why and how your clients' personal data is processed. We process it only to provide the Service, and only on your documented instructions — of which your subscription and configuration form part.
2. Scope of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing an AI assistant that receives and answers messages from your clients, and the shared inbox your team uses. |
| Duration | For as long as your subscription is active, plus the deletion period in clause 10. |
| Nature and purpose | Receiving, storing, analysing and replying to client messages; generating booking links; recognising returning clients; notifying your team; producing performance statistics for you. |
| Categories of data subject | Your clients and prospective clients who message you on a connected channel. |
| Types of personal data | Name or profile name; phone number or social handle; the content of messages, including any photos or voice notes sent; appointment and service details; language; and conversation history. |
| Special category data | Not requested and not required. A client may nonetheless volunteer health-related information in a message (for example about skin or nail conditions, allergies or pregnancy). You must configure the assistant not to solicit it, and must have your own lawful basis under Article 9 if you keep it. |
| Children's data | Not intended. If you serve minors you are responsible for the lawful basis and any parental consent. |
3. Our obligations
We will:
- process personal data only on your documented instructions, including on international transfers, unless required otherwise by EU or member-state law — in which case we will tell you first, unless the law forbids it;
- tell you if, in our opinion, an instruction breaches the GDPR;
- ensure everyone authorised to process the data is bound by confidentiality;
- implement the security measures set out in clause 5;
- respect the conditions in clause 7 for engaging another processor;
- assist you, so far as we reasonably can, with responding to data-subject requests;
- assist you with security, breach notification, impact assessments and prior consultation, taking into account what we know and what the processing involves;
- delete or return the data at the end of the contract, as set out in clause 10;
- make available the information needed to show we have met these obligations, and allow audits as set out in clause 11.
4. Your obligations
- Ensure you have a lawful basis for the data you route through the Service, and give your clients the information the GDPR requires — including that an automated assistant handles their messages.
- Maintain your own privacy notice and keep it accurate.
- Configure the assistant lawfully, and not to solicit special category data.
- Give instructions that are lawful.
5. Security measures
Taking into account the state of the art, the cost of implementation and the risks involved, we maintain appropriate technical and organisational measures, including:
- Encryption in transit (TLS) for all traffic between clients, our systems and our providers;
- Access control — administrative access restricted to authorised personnel, protected by credentials held as server-side secrets and never committed to code;
- Segregation — each salon's conversation data is kept separate, and demonstration environments are isolated from live customer data;
- No card data — payment details are handled entirely by our payment provider on its own hosted pages and never reach our systems;
- Hosting with established providers offering physical and network security, with persistent data on managed volumes;
- Retention limits — conversation history is pruned on a defined schedule rather than kept indefinitely;
- Logging and monitoring of system activity, and review of assistant behaviour for quality and safety.
We keep these measures under review and may update them, provided the level of protection is not reduced.
6. No AI model training
Your clients' data is not used to train AI models — ours or anyone else's.
We commit that:
- we do not use personal data processed on your behalf to train, fine-tune or improve any AI model;
- the AI providers we use are contractually prohibited from doing so. Anthropic's commercial terms, which govern our use of their models, state that Anthropic "may not train models on Customer Content from Services";
- data sent to an AI provider is used to generate a reply to that message and for nothing else;
- we will not change this without giving you notice under clause 7 and the opportunity to terminate.
Conversations may be read by people — your own team through the shared inbox, and our staff where necessary for support, fault-finding, or checking the assistant is answering safely and accurately. Access is limited to those who need it, and everyone is bound by confidentiality under clause 3.
7. Sub-processors
You give us general authorisation to engage the sub-processors listed below. They are integral to the Service — it cannot be delivered without them.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic PBC | AI model generating assistant replies | United States |
| OpenAI | Voice-note transcription (higher plans) | United States |
| Twilio Inc. | WhatsApp message delivery | United States / Ireland |
| Meta Platforms Ireland Ltd. | WhatsApp Business and Instagram messaging | Ireland / United States |
| Railway Corp. | Application hosting and data storage | United States |
| Netlify Inc. | Website and widget hosting | United States |
Each is bound by a written contract imposing data-protection obligations no less protective than these. We remain fully liable to you for their performance.
If we intend to add or replace a sub-processor we will give you at least 30 days' notice. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection you may terminate the affected part of the Service without penalty.
8. International transfers
Providing the Service involves transferring personal data outside the European Economic Area, principally to the United States. Where it does, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), on the EU–US Data Privacy Framework where the recipient is certified, and on supplementary measures including encryption in transit and data minimisation. Copies of the relevant safeguards are available on request.
9. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notification will describe what happened, the categories and approximate number of people and records affected so far as known, the likely consequences, and the measures taken or proposed. We will assist you with your own notification duties to the supervisory authority and to affected individuals.
10. Deletion and return
When your subscription ends you may request, within 30 days, an export of the personal data we process for you in a commonly used machine-readable format. After that period, or once an export has been provided, we will delete the data from our live systems within 90 days, and from backups on the ordinary backup rotation — unless EU or member-state law requires us to keep it, in which case we will tell you what and why.
11. Audits
On reasonable written request, and no more than once a year unless a breach or a supervisory authority requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this Addendum. Where that is genuinely insufficient, we will allow an audit conducted during business hours, on at least 30 days' notice, in a way that does not disrupt the Service or compromise the confidentiality of other customers' data, by you or by an independent auditor who is not our competitor and who is bound by confidentiality. You bear the cost unless the audit reveals a material breach on our part.
12. Assistance with data-subject requests
If one of your clients contacts us directly to exercise their rights, we will not respond substantively ourselves — we will refer them to you and tell you promptly, because you are the controller. Taking into account the nature of the processing, we will provide reasonable technical assistance so you can meet your obligations within the statutory time limits, including locating, exporting, correcting or deleting a given individual's conversation data.
13. Precedence and term
This Addendum forms part of the Terms of Service and applies for as long as we process personal data on your behalf. If it conflicts with the Terms of Service on a data-protection matter, this Addendum prevails. It is governed by the law of the Netherlands, with the courts of Amsterdam competent.
Need this signed as a standalone document for your own records or your auditor? Write to info@houseofeda.ai and we will provide a countersigned copy.