This Data Processing Addendum ("DPA") is incorporated into the MyChairHQ Terms of Service and applies when MyChairHQ processes Customer Data or other personal information on behalf of a Professional.
This DPA is between MyChairHQ LLC d/b/a MyChairHQ and the Professional that uses the Platform. It applies to personal information processed by MyChairHQ as processor, service provider, contractor, or equivalent role on behalf of Professional.
This DPA does not apply where MyChairHQ acts as an independent controller/business for its own account, billing, support, security, marketing, legal, or Platform-administration purposes.
Applicable Data Protection Laws means privacy, data protection, breach notification, consumer privacy, electronic communications, and related laws that apply to the processing of personal information under this DPA.
Controller or Business means the party that determines the purposes and means of processing personal information.
Processor, Service Provider, or Contractor means the party that processes personal information on behalf of a Controller or Business.
Personal Information includes personal data, personal information, Customer Data, and similar terms under Applicable Data Protection Laws.
Subprocessor means a third party engaged by MyChairHQ to process Personal Information on behalf of Professional.
For Customer Data collected through Professional booking pages and processed to provide Platform services to Professional, Professional is the Controller/Business and MyChairHQ is the Processor/Service Provider/Contractor.
Professional is responsible for determining the lawful basis, notices, consents, purposes, retention requirements, and instructions for Customer Data. MyChairHQ will process Customer Data only as described in this DPA, the Terms, the Privacy Policy, Professional's Platform configuration, documented instructions, or as required by law.
The subject matter of processing is the provision of the MyChairHQ Platform. The duration is the term of Professional's account plus any retention period described in the Privacy Policy, Terms, this DPA, backups, legal holds, or applicable law.
The nature and purpose of processing includes booking, scheduling, staff assignment, reminders, communications, payment metadata, customer management, calendar sync, AI features where enabled, support, troubleshooting, security, fraud prevention, provider compliance, analytics, and Platform improvement.
Personal Information may include Customer names, emails, phone numbers, appointment details, services selected, prices, deposits, notes, communication preferences, message metadata, payment metadata, booking history, device and IP information, staff assignment, Professional account data, staff data, and other information submitted through the Platform.
Data subjects may include Customers, Professionals, Professional owners, Professional staff, Authorized Users, visitors, support contacts, and other people whose information is submitted to or processed through the Platform.
Professional instructs MyChairHQ to process Personal Information to provide, secure, support, maintain, and improve the Platform; perform obligations under the Terms; operate integrations and providers; send communications selected by Professional; process payment metadata; comply with law; and protect against fraud, abuse, and security incidents.
Professional is responsible for ensuring its instructions are lawful. MyChairHQ may suspend processing or notify Professional if MyChairHQ believes an instruction violates law, provider rules, or Platform policies.
Where MyChairHQ processes Personal Information as a service provider or contractor under California or similar state privacy laws, MyChairHQ will not:
MyChairHQ will comply with applicable obligations and provide the same level of privacy protection required by applicable service-provider or contractor rules.
MyChairHQ will ensure that personnel authorized to process Personal Information are subject to confidentiality obligations or professional duties of confidentiality and are limited to access reasonably needed for their roles.
MyChairHQ will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, destruction, loss, alteration, disclosure, or misuse. Security measures may include encryption in transit, access controls, authentication, logging, monitoring, provider controls, incident response, backups, and least-privilege practices, as further described in the Security Statement.
Professional is responsible for secure account configuration, password practices, staff permissions, exported data, devices, local systems, and data used outside the Platform.
Professional authorizes MyChairHQ to use Subprocessors listed in the Subprocessor List and additional Subprocessors as needed to provide the Platform. MyChairHQ will require Subprocessors to protect Personal Information under written terms that are no less protective in material respects than this DPA for the relevant processing.
MyChairHQ may update the Subprocessor List. If required by law or contract, MyChairHQ will provide notice of material Subprocessor changes. Professional may object to a new Subprocessor by providing a reasonable written objection based on data-protection grounds. MyChairHQ may resolve the objection, provide a workaround, or allow Professional to terminate affected services.
Taking into account the nature of processing and information available to MyChairHQ, MyChairHQ will reasonably assist Professional with responding to Customer requests to access, correct, delete, port, restrict, object, opt out, or otherwise exercise privacy rights. Professional is responsible for determining whether and how to respond to requests where Professional is the Controller/Business.
If MyChairHQ receives a request directly from a Customer concerning Professional-controlled Customer Data, MyChairHQ may direct the Customer to Professional, respond as permitted, or assist Professional.
Upon termination or at Professional's request, MyChairHQ will delete, de-identify, or make available for export Personal Information in accordance with the Terms, Privacy Policy, Platform functionality, and applicable law. MyChairHQ may retain Personal Information where required or permitted for legal compliance, tax, accounting, disputes, security, fraud prevention, backups, provider records, or legitimate business purposes.
Deletion from backups may be delayed until backups expire or are overwritten. MyChairHQ will not use retained data for new marketing purposes after deletion except as permitted by law.
MyChairHQ will notify Professional without unreasonable delay after confirming a Security Incident affecting Personal Information processed on behalf of Professional. The notice may include information reasonably available to MyChairHQ, such as the nature of the incident, affected data categories, mitigation steps, and information needed for Professional's legal obligations.
Professional is responsible for determining whether notice to Customers, regulators, or others is required for Professional-controlled Customer Data, except where MyChairHQ has a direct legal obligation. MyChairHQ's notification is not an admission of fault or liability.
Upon reasonable written request and where required by Applicable Data Protection Laws, MyChairHQ will provide information reasonably necessary to demonstrate compliance with this DPA. MyChairHQ may satisfy audit obligations by providing security documentation, summaries, certifications, questionnaires, or other appropriate materials. Any direct audit must be limited, reasonable, scheduled in advance, subject to confidentiality, and not compromise security, other customers, providers, or operations.
Where Applicable Data Protection Laws require transfer mechanisms for international transfers, the parties will use appropriate safeguards, which may include standard contractual clauses, data-transfer addenda, adequacy decisions, or other lawful mechanisms. If standard contractual clauses are needed, they are incorporated by reference to the extent required.
Professional must not submit Sensitive Data, regulated health data, protected health information, biometric data, government IDs, children's data, financial account credentials, or other high-risk data to the Platform unless permitted by the Terms and lawful for Professional. Professional is solely responsible for required notices, consents, lawful bases, and safeguards for any such data.
If this DPA conflicts with the Terms or Privacy Policy regarding processor/service-provider obligations for Customer Data, this DPA controls to the extent of the conflict. The Terms control for all non-data-processing issues.
| Item | Description |
|---|---|
| Subject matter | SaaS booking, scheduling, communication, payment-metadata, customer-management, staff-management, calendar, AI, and business-management platform |
| Duration | Account term plus retention described in Privacy Policy and this DPA |
| Nature | Collection, storage, hosting, transmission, deletion, retrieval, access, support, security, analysis, communication, synchronization, and provider processing |
| Purposes | Provide, secure, support, maintain, and improve the Platform; fulfill Professional instructions; comply with law; prevent fraud and abuse |
| Data subjects | Customers, Professionals, staff, Authorized Users, visitors, support contacts |
| Data categories | Identifiers, contact data, booking data, appointment data, staff data, payment metadata, communications metadata, notes, device/IP data, usage data, logs |
| Sensitive data | Not intended or permitted except as expressly allowed by the Terms and law |
Privacy notices under this DPA may be sent to privacy@mychairhq.com and legal notices to MyChairHQ LLC.