Pivot Parlor

Data Processing Agreement

Version 1.0 · Effective July 2026

Pivot Parlor
BytesFX Ltd · Moselle Avenue, London, UK, N22 6ET
[email protected]

This Agreement has been prepared in line with UK GDPR Article 28 and reviewed against current UK data protection guidance, including the Data (Use and Access) Act 2025. It is maintained under ongoing legal review; we publish updated versions on this page as our processing or the law changes.

Purpose

Pivot Parlor is a multi-tenant booking platform. For the personal data of a shop’s booking customers, the shop is the controller and BytesFX Ltd (trading as Pivot Parlor) is the processor, processing that data on the shop’s behalf. UK GDPR Article 28(1) and (3) requires that relationship to be governed by a binding written contract containing specific mandatory terms. This Agreement is that contract.

Parties

  • The Processor: BytesFX Ltd, a company registered in England and Wales, whose registered office is at Moselle Avenue, London, N22 6ET, United Kingdom, trading as “Pivot Parlor” (“Processor”, “we”, “us”).
  • The Controller: the shop, salon, or business that has onboarded onto the Pivot Parlor platform and accepted these terms (“Shop”, “Controller”, “you”).

Together the “Parties”. This Agreement takes effect on the date the Controller accepts it (the “Effective Date”) and forms part of, and is governed by, the Pivot Parlor Terms of Service (the “Principal Agreement”).

1. Definitions

Terms used but not defined here have the meaning given in the UK GDPR (as defined in section 3(10) of, and see section 205(4) of, the Data Protection Act 2018) and the Data Protection Act 2018 (“DPA 2018”), in each case as amended from time to time, including by the Data (Use and Access) Act 2025 (together “Data Protection Law”).

  • Controller Personal Data” means the Personal Data that the Processor Processes on behalf of the Controller under the Principal Agreement, as described in Annex 1.
  • Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach”, “Sub-processor”, and “Supervisory Authority” have the meanings given in Data Protection Law.
  • The Supervisory Authority is the Information Commissioner’s Office (“ICO”) and any successor body, including the Information Commission established under the Data (Use and Access) Act 2025.

2. Roles and scope of processing

2.1 The Parties acknowledge that, for the Controller Personal Data, the Controller is the controller and the Processor is the processor.

2.2 The Processor shall Process Controller Personal Data only as necessary to provide the platform under the Principal Agreement, only for the subject-matter, duration, nature and purposes set out in Annex 1, and only in respect of the types of Personal Data and categories of Data Subjects set out in Annex 1.

2.3 Nothing in this Agreement relieves the Controller of its own obligations under Data Protection Law, including providing a privacy notice to Data Subjects and establishing a lawful basis for the Processing it instructs.

3. Processor obligations (UK GDPR Article 28(3))

The Processor shall:

(a) Documented instructions. Process Controller Personal Data only on the Controller’s documented instructions (including the instructions embodied in the Principal Agreement and the Controller’s configuration and use of the platform), including as regards international transfers, unless required to do otherwise by law; in which case the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits it. If the Processor believes an instruction infringes Data Protection Law, it shall inform the Controller without undue delay.

(b) Confidentiality. Ensure that persons authorised to Process the Controller Personal Data are subject to an appropriate duty of confidentiality.

(c) Security. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of UK GDPR Article 32, as described in Annex 3.

(d) Sub-processors. Not engage another processor (Sub-processor) without the Controller’s prior specific or general written authorisation. The Controller provides general authorisation for the Sub-processors listed in Annex 2. The Processor shall inform the Controller of any intended addition or replacement of a Sub-processor at least 30 days in advance (or, where an upstream provider gives the Processor shorter notice, as soon as reasonably practicable), giving the Controller the opportunity to object on reasonable data-protection grounds; where the Processor engages a Sub-processor it shall impose on it, by contract, data-protection obligations equivalent to those in this Agreement, and remains fully liable to the Controller for the Sub-processor’s performance.

(e) Data-subject rights and complaints. Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection) and to handle and acknowledge data-protection complaints within the timescales under Data Protection Law (including the complaints-handling duty introduced by the Data (Use and Access) Act 2025: acknowledge within 30 days and respond without undue delay). Where a Data Subject contacts the Processor directly regarding Controller Personal Data, the Processor shall promptly forward the request to the Controller and not respond substantively itself except on the Controller’s instruction.

(f) Assistance with compliance. Assist the Controller in ensuring compliance with its obligations under UK GDPR Articles 32 to 36, taking into account the nature of Processing and the information available to the Processor, including security, Personal Data Breach notification, communication to Data Subjects, data protection impact assessments, and prior consultation with the Supervisory Authority.

(g) Breach notification. Notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Controller Personal Data, and provide the Controller with sufficient information to meet any obligation to report the breach to the Supervisory Authority and/or affected Data Subjects.

(h) Deletion or return. At the Controller’s choice, delete or return all Controller Personal Data at the end of the provision of the platform services, and delete existing copies unless UK law requires storage. This is subject to a 30-day grace period for retrieval, and to the retention of records the Processor is required by law to keep (for example, transaction records for accounting). Backup copies may be put beyond use and deleted on the next scheduled deletion cycle where immediate deletion is not practicable.

(i) Demonstrate compliance and audits. Make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. To protect the confidentiality and security of a multi-tenant environment, audits shall be on reasonable prior notice, no more than once per rolling 12 months (save following a Personal Data Breach or a Supervisory Authority requirement), and may be satisfied by the Processor providing an up-to-date independent audit report or security certification where available.

4. International transfers

4.1 Some Controller Personal Data is Processed outside the United Kingdom. In particular, several of the Processor’s Sub-processors Process personal data in the United States, and the platform’s hosting infrastructure replicates certain data across global locations (see Annex 2). The platform does not guarantee UK-only or EEA-only data residency for all components.

4.2 Where Controller Personal Data is transferred outside the United Kingdom, the Processor and its Sub-processors rely on a lawful transfer mechanism under Data Protection Law, applying the data protection test under the UK GDPR (as amended by the Data (Use and Access) Act 2025). These mechanisms are principally the UK International Data Transfer Addendum to the EU Standard Contractual Clauses and, where applicable, the UK Extension to the EU-U.S. Data Privacy Framework. The Processor does not rely on a UK adequacy decision for transfers to the United States. The mechanism relied on for each Sub-processor is set out in Annex 2.

5. Liability

5.1 Liability arising under or in connection with this Agreement is subject to, and governed by, the limitation of liability set out in Section 8 (Limitation of Liability) of the Principal Agreement (the Pivot Parlor Terms of Service), which the Parties agree applies to this Agreement.

5.2 Nothing in this Agreement or the Principal Agreement limits either Party’s liability to a Data Subject under Article 82 of the UK GDPR, which allocates liability for damage caused by Processing by operation of law regardless of contract, or any other liability that cannot be excluded or limited under Data Protection Law.

6. Term and termination

This Agreement takes effect on the Effective Date and continues while the Processor Processes Controller Personal Data under the Principal Agreement. Clauses that by their nature should survive (including Sections 3(h), 3(i), 4 and 5) survive termination.

Annex 1: Details of the Processing

Subject-matterProvision of the Pivot Parlor online booking and shop-management platform to the Controller.
DurationFor the term of the Principal Agreement, plus any retention or return period in Section 3(h).
Nature and purposeHosting, storing, and processing booking and customer-relationship data to enable appointment booking, reminders, walk-in and waitlist queues, reviews, payment facilitation, and shop administration on the Controller’s behalf.
Types of Personal DataCustomer name; email address; telephone number; appointment date and time, service and staff selected; booking notes; booking and transaction identifiers and amounts; and any personal data a customer volunteers via the booking form, walk-in or waitlist form, review, or chat. No special-category data is intentionally collected.
Categories of Data SubjectsThe Controller’s booking customers and prospective customers.
Controller’s obligations and rightsThe Controller determines the purposes and means of the Processing, provides the privacy notice and lawful basis to Data Subjects, issues instructions to the Processor, and has the rights of authorisation, objection, audit, and deletion or return set out in this Agreement.
FrequencyContinuous, for the duration of the service.

Annex 2: Authorised Sub-processors

The Controller provides general written authorisation for the following Sub-processors (Section 3(d)). Data locations and transfer mechanisms reflect each provider’s current published terms.

Cloudflare, Inc.

Service:
Application hosting, data storage (D1, KV, R2), edge compute, and bot or security protection (Turnstile). Acts as the Processor’s Sub-processor.
Location:
Global. UK or EEA data residency is not guaranteed for all components: Workers KV replicates data across global locations, and D1 or R2 EU residency applies only where the EU jurisdiction was selected at creation.
Transfer mechanism:
EU Standard Contractual Clauses as amended by the UK International Data Transfer Addendum, per the Cloudflare Customer DPA (v6.4, 3 April 2026). Data Privacy Framework certification is relied on only as a supplementary US-transfer basis.

Stripe (Stripe Payments Europe, Ltd; Stripe Payments UK, Ltd; Stripe, LLC)

Service:
Payment processing and fraud prevention. Stripe acts as the Processor’s processor for payment facilitation carried out on the platform’s instructions, and as an independent controller in its own right for fraud prevention, anti-money-laundering and know-your-customer checks, and legal and regulatory compliance. Stripe Payments UK, Ltd is the FCA-authorised acquirer; Stripe, LLC is the US data importer.
Location:
United Kingdom, European Economic Area, and United States.
Transfer mechanism:
EU Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by Stripe, LLC’s UK Extension to the EU-U.S. Data Privacy Framework. Cardholder data is governed by Stripe’s own Data Processing Agreement (stripe.com/legal/dpa).

Plus Five Five, Inc. (trading as Resend)

Service:
Transactional email delivery (booking confirmations and reminders). Acts as the Processor’s Sub-processor.
Location:
United States. Email metadata and logs are stored in the United States regardless of the sending region selected.
Transfer mechanism:
UK Extension to the EU-U.S. Data Privacy Framework, with EU Standard Contractual Clauses and the UK Addendum as the fallback mechanism, per the Resend Data Processing Agreement.

Annex 3: Technical and organisational security measures (Article 32)

Current measures include, without limitation:

  • Encryption of data in transit (HTTPS/TLS) across all platform endpoints.
  • Passwords stored only as salted PBKDF2 hashes; no plaintext credential storage.
  • Session tokens are signed (JWT), HttpOnly, Secure, and time-limited (7-day expiry) with server-side revocation.
  • Role-based access control (developer, admin, staff, customer) with shop-scoped data isolation enforced at the query layer.
  • Payment card data is not stored on platform systems (handled by Stripe).
  • Time-based data retention and anonymisation of aged records.
  • Point-in-time recovery and backups of the primary datastore.
  • Logging and monitoring of platform activity.

Contact

For any questions about this Agreement or to exercise a right under it, contact us at [email protected] or write to Pivot Parlor, Moselle Avenue, London, UK, N22 6ET.