KRI

Data Processing Agreement

Effective date: 15 July 2026

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the agreement between KRI and the salon or business that uses the KRI service (the "Customer"). KRI is operated by Iurii Rogulia, a sole trader (toiminimi) registered in Finland, Business ID (Y-tunnus) 2984587-5, VAT FI29845875, Vanhanpellonkatu 5, 53850 Lappeenranta, Finland ("KRI", "we").

For the personal data of the Customer's booking customers processed through the KRI software, the Customer acts as the data controller and KRI acts as the data processor. This DPA governs that processor relationship and implements the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR").

KRI separately processes the salon owner's own account, billing and product-usage data as an independent controller. That processing is not covered by this DPA and is described in our Privacy Policy.

2. Subject matter and duration

The subject matter of the processing is the provision of the KRI booking and salon-website software to the Customer, and the processing of the Customer's booking-customer personal data that this requires.

This DPA applies for as long as KRI processes personal data on the Customer's behalf, which is the term of the Customer's subscription to the service. It terminates automatically when the subscription ends, subject to the deletion and return obligations in Section 12.

3. Nature and purpose of processing

KRI processes personal data solely for the purpose of operating the booking and salon-website software for the Customer. This includes taking and storing bookings, displaying the salon's public booking page, sending transactional messages related to bookings, and providing the Customer with access to and management of its own booking data.

The types of personal data processed and the categories of data subjects are set out in Annex I. KRI does not process the booking customers' data for its own purposes.

4. Processing on documented instructions

KRI processes personal data only on the documented instructions of the Customer, including with regard to international transfers, unless required to do so by Union or Member State law to which KRI is subject. Where such a legal requirement applies, KRI will inform the Customer before processing, unless the law prohibits it on important grounds of public interest.

The Customer's use of the software features, together with this DPA and the Terms, constitute the Customer's complete and documented instructions. If KRI believes an instruction infringes the GDPR or other data-protection law, it will inform the Customer without undue delay.

5. Confidentiality

KRI ensures that any person authorised to process the personal data (including Iurii Rogulia and any contractors) is bound by an appropriate obligation of confidentiality, whether a statutory duty or a contractual commitment, and processes the data only as instructed by the Customer.

Access to booking-customer personal data is limited to persons who need it to provide, maintain or support the service.

6. Security of processing (Art. 32)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of the data subjects, KRI implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The measures currently in place for the self-hosted KRI infrastructure are described in Annex II. KRI may update these measures over time provided the level of security is not reduced.

7. Sub-processing (Art. 28(2) and (4))

The Customer gives KRI general authorisation to engage sub-processors to support the provision of the service. The sub-processors engaged at the effective date of this DPA are listed in Annex III.

KRI imposes on each sub-processor, by contract, data-protection obligations that are substantially the same as those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. KRI remains fully liable to the Customer for the performance of each sub-processor's obligations.

Where KRI intends to add or replace a sub-processor, it will notify the Customer in advance (for example by email or by updating Annex III and notifying registered Customers). The Customer may object to the change on reasonable data-protection grounds within 30 days of the notice. If the parties cannot resolve the objection, the Customer may terminate the affected part of the service.

8. Assistance with data-subject requests (Art. 28(3)(e))

The salon's booking customers are the Customer's data subjects, and the Customer is responsible for responding to their requests. Taking into account the nature of the processing, KRI assists the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data-subject rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability and objection).

The software gives the Customer direct access to view, correct, export and delete its booking-customer data. Where a request cannot be handled through the software, KRI will support the Customer on request. KRI will not respond directly to a data subject unless instructed by the Customer or required by law, and will forward any request received directly from a data subject to the Customer without undue delay.

9. Assistance with security, breaches and DPIAs (Art. 32–36)

KRI assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to KRI.

This includes assistance with the security of processing, with the notification of a personal-data breach to the supervisory authority and to affected data subjects, and with data-protection impact assessments and prior consultation.

KRI notifies the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's booking-customer data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. The Customer, as controller, is responsible for any notification to the supervisory authority and to data subjects.

10. Audits and information (Art. 28(3)(h))

KRI makes available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

Audits are limited to what is necessary to verify compliance, must be conducted during normal business hours with reasonable prior written notice, and must not disrupt KRI's operations or compromise the confidentiality or security of other customers' data. KRI may satisfy an audit request by providing existing documentation and answering the Customer's reasonable questions in writing.

11. International transfers

The self-hosted PostgreSQL database and Redis cache used to store the Customer's booking-customer data are hosted on KRI's own server located in a data centre within the European Union (EU/EEA).

Certain sub-processors (Resend, Cloudflare and Vultr) are established in the United States and may process personal data outside, or provide infrastructure that could be accessed from outside, the European Economic Area. Where such a transfer occurs, it is carried out under an appropriate transfer mechanism, in particular the European Commission's Standard Contractual Clauses and/or certification under the EU–U.S. Data Privacy Framework, together with any supplementary measures required.

KRI will not transfer booking-customer personal data outside the EEA except through a sub-processor covered by such safeguards or on the Customer's documented instructions.

12. Deletion or return of data

On termination of the Customer's subscription, and at the Customer's choice, KRI deletes or returns all booking-customer personal data processed on the Customer's behalf and deletes existing copies, unless Union or Member State law requires storage of the data.

Unless the Customer requests return or earlier deletion, KRI deletes the Customer's booking-customer data within 30 days of the end of the subscription. Residual copies held in routine encrypted backups are deleted in the ordinary backup-rotation cycle and are not restored or used for any other purpose in the meantime.

13. Liability and order of precedence

The limitations and exclusions of liability set out in the Terms apply to this DPA and to any claim arising from or related to it, to the extent permitted by applicable law. Nothing in this DPA limits any liability that cannot be limited under applicable data-protection law.

This DPA is incorporated into and forms part of the Terms. In the event of a conflict between this DPA and the Terms on a matter concerning the processing of the Customer's booking-customer personal data, this DPA prevails. This DPA is governed by the laws of Finland, and the courts of Finland have jurisdiction, without prejudice to any mandatory rights of data subjects or the competence of the supervisory authority.

Annex I — Details of the processing

Subject matter: provision of the KRI booking and salon-website software.

Duration: the term of the Customer's subscription, subject to the deletion and return obligations above.

Nature and purpose: taking, storing, displaying and managing bookings and the salon's public booking page, and sending transactional messages related to bookings.

Categories of data subjects: the Customer's own booking customers (members of the public who book appointments with the salon).

Types of personal data:

  • Name of the booking customer
  • Phone number
  • Email address (optional)
  • Preferred booking language
  • Appointment notes
  • Booking details: the service booked, the date and time, and the price

No special categories of personal data (Article 9 GDPR) are required by the software. The Customer must not enter special-category data into free-text fields such as appointment notes.

Annex II — Technical and organisational security measures (Art. 32)

KRI applies the following measures to the self-hosted infrastructure on which booking-customer data is processed:

  • Encryption of data in transit using TLS for all connections to the application and its public booking pages.
  • A self-hosted PostgreSQL database and Redis cache that are not exposed to the public internet and are reachable only inside the private server network.
  • Access to the production server and database restricted to authorised administrators using strong authentication, with credentials and secrets stored as environment variables and never in source code.
  • Tenant isolation in the application so that each salon can access only its own booking-customer data, enforced at the application layer.
  • Passwordless (magic-link) sign-in for salon accounts, removing stored passwords as an attack vector.
  • Regular, access-restricted backups of the database, with restoration procedures, to ensure availability and resilience.
  • Logging and monitoring of application and access events to detect and investigate incidents.
  • Sub-processors selected for their security posture and bound by contractual data-protection and confidentiality obligations.
  • Deletion of booking-customer data on termination in accordance with the retention periods set out in this DPA.

Annex III — List of sub-processors

The following sub-processors are engaged at the effective date of this DPA:

  • Resend — delivery of transactional email, such as sign-in and booking-related messages (US-based; transfers safeguarded by SCCs and/or the EU–U.S. Data Privacy Framework).
  • Cloudflare — DNS, content delivery and network security (US-based; transfers safeguarded by SCCs and/or the EU–U.S. Data Privacy Framework).
  • Vultr — provision of the underlying cloud-server infrastructure on which KRI's self-hosted database and application run, located in a data centre within the European Union (EU/EEA) (US-based provider; any transfers safeguarded by Standard Contractual Clauses).