Data Processing Addendum

Last updated: May 18, 2026

This Data Processing Addendum ("DPA") is incorporated into the MyChairHQ Terms of Service and applies when MyChairHQ processes Customer Data or other personal information on behalf of a Professional.

1. Parties and Scope

This DPA is between MyChairHQ LLC d/b/a MyChairHQ and the Professional that uses the Platform. It applies to personal information processed by MyChairHQ as processor, service provider, contractor, or equivalent role on behalf of Professional.

This DPA does not apply where MyChairHQ acts as an independent controller/business for its own account, billing, support, security, marketing, legal, or Platform-administration purposes.

2. Definitions

Applicable Data Protection Laws means privacy, data protection, breach notification, consumer privacy, electronic communications, and related laws that apply to the processing of personal information under this DPA.

Controller or Business means the party that determines the purposes and means of processing personal information.

Processor, Service Provider, or Contractor means the party that processes personal information on behalf of a Controller or Business.

Personal Information includes personal data, personal information, Customer Data, and similar terms under Applicable Data Protection Laws.

Subprocessor means a third party engaged by MyChairHQ to process Personal Information on behalf of Professional.

3. Roles

For Customer Data collected through Professional booking pages and processed to provide Platform services to Professional, Professional is the Controller/Business and MyChairHQ is the Processor/Service Provider/Contractor.

Professional is responsible for determining the lawful basis, notices, consents, purposes, retention requirements, and instructions for Customer Data. MyChairHQ will process Customer Data only as described in this DPA, the Terms, the Privacy Policy, Professional's Platform configuration, documented instructions, or as required by law.

4. Subject Matter, Duration, Nature, and Purpose

The subject matter of processing is the provision of the MyChairHQ Platform. The duration is the term of Professional's account plus any retention period described in the Privacy Policy, Terms, this DPA, backups, legal holds, or applicable law.

The nature and purpose of processing includes booking, scheduling, staff assignment, reminders, communications, payment metadata, customer management, calendar sync, AI features where enabled, support, troubleshooting, security, fraud prevention, provider compliance, analytics, and Platform improvement.

5. Categories of Personal Information

Personal Information may include Customer names, emails, phone numbers, appointment details, services selected, prices, deposits, notes, communication preferences, message metadata, payment metadata, booking history, device and IP information, staff assignment, Professional account data, staff data, and other information submitted through the Platform.

6. Categories of Data Subjects

Data subjects may include Customers, Professionals, Professional owners, Professional staff, Authorized Users, visitors, support contacts, and other people whose information is submitted to or processed through the Platform.

7. Professional Instructions

Professional instructs MyChairHQ to process Personal Information to provide, secure, support, maintain, and improve the Platform; perform obligations under the Terms; operate integrations and providers; send communications selected by Professional; process payment metadata; comply with law; and protect against fraud, abuse, and security incidents.

Professional is responsible for ensuring its instructions are lawful. MyChairHQ may suspend processing or notify Professional if MyChairHQ believes an instruction violates law, provider rules, or Platform policies.

8. Service Provider and Contractor Restrictions

Where MyChairHQ processes Personal Information as a service provider or contractor under California or similar state privacy laws, MyChairHQ will not:

  1. sell or share Personal Information processed under this DPA;
  2. retain, use, or disclose Personal Information outside the business purposes described in this DPA, except as permitted by law;
  3. retain, use, or disclose Personal Information for a commercial purpose other than the business purposes described in this DPA, except as permitted by law;
  4. combine Personal Information received from Professional with personal information from other sources except as permitted by law, such as for security, fraud prevention, debugging, service improvement, or other permitted business purposes; or
  5. process Personal Information in a way that would cause MyChairHQ to cease qualifying as a service provider or contractor, where such status applies.

MyChairHQ will comply with applicable obligations and provide the same level of privacy protection required by applicable service-provider or contractor rules.

9. Confidentiality

MyChairHQ will ensure that personnel authorized to process Personal Information are subject to confidentiality obligations or professional duties of confidentiality and are limited to access reasonably needed for their roles.

10. Security Measures

MyChairHQ will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, destruction, loss, alteration, disclosure, or misuse. Security measures may include encryption in transit, access controls, authentication, logging, monitoring, provider controls, incident response, backups, and least-privilege practices, as further described in the Security Statement.

Professional is responsible for secure account configuration, password practices, staff permissions, exported data, devices, local systems, and data used outside the Platform.

11. Subprocessors

Professional authorizes MyChairHQ to use Subprocessors listed in the Subprocessor List and additional Subprocessors as needed to provide the Platform. MyChairHQ will require Subprocessors to protect Personal Information under written terms that are no less protective in material respects than this DPA for the relevant processing.

MyChairHQ may update the Subprocessor List. If required by law or contract, MyChairHQ will provide notice of material Subprocessor changes. Professional may object to a new Subprocessor by providing a reasonable written objection based on data-protection grounds. MyChairHQ may resolve the objection, provide a workaround, or allow Professional to terminate affected services.

12. Assistance with Privacy Requests

Taking into account the nature of processing and information available to MyChairHQ, MyChairHQ will reasonably assist Professional with responding to Customer requests to access, correct, delete, port, restrict, object, opt out, or otherwise exercise privacy rights. Professional is responsible for determining whether and how to respond to requests where Professional is the Controller/Business.

If MyChairHQ receives a request directly from a Customer concerning Professional-controlled Customer Data, MyChairHQ may direct the Customer to Professional, respond as permitted, or assist Professional.

13. Deletion and Return

Upon termination or at Professional's request, MyChairHQ will delete, de-identify, or make available for export Personal Information in accordance with the Terms, Privacy Policy, Platform functionality, and applicable law. MyChairHQ may retain Personal Information where required or permitted for legal compliance, tax, accounting, disputes, security, fraud prevention, backups, provider records, or legitimate business purposes.

Deletion from backups may be delayed until backups expire or are overwritten. MyChairHQ will not use retained data for new marketing purposes after deletion except as permitted by law.

14. Security Incidents

MyChairHQ will notify Professional without unreasonable delay after confirming a Security Incident affecting Personal Information processed on behalf of Professional. The notice may include information reasonably available to MyChairHQ, such as the nature of the incident, affected data categories, mitigation steps, and information needed for Professional's legal obligations.

Professional is responsible for determining whether notice to Customers, regulators, or others is required for Professional-controlled Customer Data, except where MyChairHQ has a direct legal obligation. MyChairHQ's notification is not an admission of fault or liability.

15. Audits and Assessments

Upon reasonable written request and where required by Applicable Data Protection Laws, MyChairHQ will provide information reasonably necessary to demonstrate compliance with this DPA. MyChairHQ may satisfy audit obligations by providing security documentation, summaries, certifications, questionnaires, or other appropriate materials. Any direct audit must be limited, reasonable, scheduled in advance, subject to confidentiality, and not compromise security, other customers, providers, or operations.

16. International Transfers

Where Applicable Data Protection Laws require transfer mechanisms for international transfers, the parties will use appropriate safeguards, which may include standard contractual clauses, data-transfer addenda, adequacy decisions, or other lawful mechanisms. If standard contractual clauses are needed, they are incorporated by reference to the extent required.

17. Sensitive Data and Prohibited Data

Professional must not submit Sensitive Data, regulated health data, protected health information, biometric data, government IDs, children's data, financial account credentials, or other high-risk data to the Platform unless permitted by the Terms and lawful for Professional. Professional is solely responsible for required notices, consents, lawful bases, and safeguards for any such data.

18. Order of Precedence

If this DPA conflicts with the Terms or Privacy Policy regarding processor/service-provider obligations for Customer Data, this DPA controls to the extent of the conflict. The Terms control for all non-data-processing issues.

Annex A - Processing Details

ItemDescription
Subject matterSaaS booking, scheduling, communication, payment-metadata, customer-management, staff-management, calendar, AI, and business-management platform
DurationAccount term plus retention described in Privacy Policy and this DPA
NatureCollection, storage, hosting, transmission, deletion, retrieval, access, support, security, analysis, communication, synchronization, and provider processing
PurposesProvide, secure, support, maintain, and improve the Platform; fulfill Professional instructions; comply with law; prevent fraud and abuse
Data subjectsCustomers, Professionals, staff, Authorized Users, visitors, support contacts
Data categoriesIdentifiers, contact data, booking data, appointment data, staff data, payment metadata, communications metadata, notes, device/IP data, usage data, logs
Sensitive dataNot intended or permitted except as expressly allowed by the Terms and law

Annex B - Security Measures

  1. Encryption in transit using HTTPS/TLS.
  2. Authentication and account access controls.
  3. Role-based or need-to-know access for operational systems where supported.
  4. Logging and monitoring for security, abuse, performance, and reliability.
  5. Provider management and written provider commitments.
  6. Backups and recovery measures appropriate to the Platform.
  7. Incident response procedures.
  8. Secure development, updates, and vulnerability remediation practices appropriate to Platform risk.
  9. Administrative restrictions on employee and contractor access.
  10. Professional controls for staff permissions and integrations where available.

Annex C - Contact

Privacy notices under this DPA may be sent to privacy@mychairhq.com and legal notices to MyChairHQ LLC.