Data Processing Agreement

Last updated: 4 October 2026

Version: 1.0

This Data Processing Agreement (the "Agreement") is concluded between:

  • the Salon that uses Calandra (the "Salon" or "controller"); and
  • Everloop BV, with registered office at Hofstraat 22H, 3530 Houthalen-Helchteren, Belgium, enterprise number KBO/BCE 1043.283.597, VAT BE1043283597, which operates Calandra ("Everloop" or "processor").

This Agreement implements Article 28(3) of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). It forms an integral part of the General Terms and Conditions (the "Terms") and is agreed by the Salon by accepting the Terms. No separate signature is required. Terms defined in the Terms (such as Platform, Salon, End Customer and Customer Data) have the same meaning here. Terms defined in the GDPR (such as personal data, processing and personal data breach) have the meaning given in the GDPR.

1. Subject matter and duration

Everloop processes personal data on behalf of the Salon insofar as this is necessary to provide the Platform to the Salon under the Terms. This Agreement applies for as long as Everloop processes personal data on behalf of the Salon, and in any case for the duration of the Salon's subscription. Obligations that by their nature continue after termination, such as confidentiality and deletion, remain in force.

This Agreement does not apply to personal data that Everloop processes as controller for its own purposes, as described in article 14.2 of the Terms and in the Privacy Policy.

2. Nature and purpose of the processing

The processing consists of storing, hosting, organising, displaying, transmitting, backing up and deleting personal data, so that the Salon can use the Platform for:

  • managing its clients and client records;
  • online booking, appointment planning and reminders;
  • recording treatments and treatment reports;
  • communicating with clients, including through chat;
  • payments and deposits, where offered;
  • and the other functionality of the Platform used by the Salon.

3. Categories of personal data

Depending on how the Salon uses the Platform, the following categories of personal data may be processed:

  • client contact and identification data, such as name, email address, telephone number, date of birth and address;
  • booking data, such as appointments, chosen treatments, staff member, history, cancellations, no-shows and notes;
  • treatment reports, including products used, observations and aftercare;
  • data concerning health that a Salon may record, such as allergies, skin conditions, sensitivities, contraindications and markings on a body map (special categories of personal data under Article 9 GDPR);
  • photos, such as before-and-after photos of a treatment;
  • chat messages between the Salon and its clients;
  • payment and deposit status data;
  • data of the Salon's own staff members who use the Platform, such as name, role, login data and schedules;
  • technical data such as log data relating to the above.

The Salon decides which data it records. It is responsible for having a legal basis for this, in particular for data concerning health, as set out in article 14.1 of the Terms.

4. Categories of data subjects

  • the Salon's clients and prospective clients (End Customers);
  • where applicable, legal representatives of clients, such as parents of minors;
  • the Salon's staff members, students and other users;
  • other persons whose data the Salon enters into the Platform.

5. Processing only on documented instructions

Everloop processes the personal data only on documented instructions from the Salon, including with regard to transfers to a third country. The Terms, this Agreement and the Salon's use and configuration of the Platform constitute the Salon's complete instructions. Further instructions must be given in writing and must be consistent with the functionality of the Platform.

Everloop may process personal data otherwise only where required by Union or Member State law to which it is subject. In that case Everloop informs the Salon of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

Everloop informs the Salon immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.

6. Confidentiality

Everloop ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they have access only to the extent necessary for their tasks.

7. Security of processing

Everloop takes appropriate technical and organisational measures as required by Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, including data concerning health. These measures include:

  • hosting of the database and file storage in the European Union;
  • encryption of data in transit (TLS) and encryption at rest by the hosting provider;
  • access control at database level (row-level security), so that a Salon can access only its own data;
  • role-based permissions within a Salon, so that staff members see only what their role requires;
  • authentication of users and restriction of internal access on a need-to-know basis;
  • regular back-ups and the ability to restore data;
  • logging and monitoring, and regular review of security practices.

Everloop may adapt these measures over time, provided that the overall level of security is not reduced. The Salon is responsible for the security of its own accounts, devices and passwords, and for granting appropriate roles to its staff members.

8. Sub-processors

The Salon gives Everloop general authorisation to engage sub-processors. On the date of this Agreement, Everloop engages the following sub-processors:

  • Supabase for database and file storage hosting, with data held in the European Union (AWS eu-west-1, Ireland).
  • Amazon Web Services for the infrastructure underneath the above, with data held in the European Union (eu-west-1, Ireland).
  • Hetzner for hosting the Platform's application servers (the API, sessions and server logs), with data held in the European Union (Hetzner Online GmbH).
  • Vercel for hosting this website, the Platform's web application and the demo, including their server logs, with data held in the European Union (Frankfurt, Germany, fra1).
  • Cloudflare for securely routing traffic to the Platform's servers and the bot check (Turnstile) on the demo request form, with data held on Cloudflare's global network (Cloudflare, Inc., United States; transfers covered by the EU–US Data Privacy Framework and Standard Contractual Clauses).
  • Resend for sending transactional email, such as demo links and other service messages, with data held in the European Union (eu-west-1, Ireland).
  • Google Workspace for sending the Platform's service emails, such as booking confirmations, password resets and staff invitations, with data held by Google Ireland Limited, which may also process it outside the European Union (transfers covered by the EU–US Data Privacy Framework and Standard Contractual Clauses).
  • GatewayAPI for sending the text messages that verify your phone number, with data held in the European Union (Denmark).
  • Mollie for processing online payments and deposits, when offered (for its own payment services Mollie acts as a separate controller, see below), with data held in the European Union (Mollie B.V., the Netherlands).

Everloop informs the Salon of any intended addition or replacement of a sub-processor, by email or through the Platform, at least 30 days in advance, except in urgent cases where security or continuity requires a faster change. The Salon may object to the change on reasonable grounds relating to data protection within that period. If the parties cannot reach a solution, the Salon may terminate its subscription before the change takes effect, without a termination fee.

Everloop imposes the same data protection obligations as those in this Agreement on each sub-processor by contract, in particular sufficient guarantees for appropriate technical and organisational measures. Everloop remains fully liable to the Salon for the performance of its sub-processors' obligations.

Personal data is in principle processed in the European Union. If a sub-processor transfers personal data outside the European Economic Area, Everloop ensures that an appropriate transfer mechanism under Chapter V GDPR applies, such as an adequacy decision or standard contractual clauses.

9. Assistance to the Salon

Taking into account the nature of the processing, Everloop assists the Salon by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). Much of this can be done by the Salon itself through the Platform, for example by viewing, correcting, exporting or deleting a client record.

If Everloop receives a request directly from a data subject that concerns the Salon's processing, it forwards the request to the Salon without undue delay and does not respond to it itself, unless the Salon instructs it to do so.

Everloop also assists the Salon, taking into account the information available to it, in ensuring compliance with Articles 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation of the supervisory authority.

10. Personal data breaches

Everloop notifies the Salon without undue delay after becoming aware of a personal data breach affecting the Salon's personal data, and aims to do so within 48 hours. The notification describes, insofar as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all information is available at once, it is provided in phases.

Everloop takes the reasonable measures needed to limit the consequences of the breach. The Salon, as controller, decides whether the breach must be reported to the supervisory authority and to data subjects.

11. Deletion or return at the end

Before the end of the subscription, the Salon can export its data using the Platform's export functionality, as set out in article 22.3 of the Terms. After the end of the subscription, and after any transition period, Everloop deletes the personal data processed on behalf of the Salon, unless Union or Member State law requires storage of the personal data. Copies in back-ups are deleted when those back-ups are overwritten in the normal back-up cycle, and remain protected in the meantime.

12. Information and audits

Everloop makes available to the Salon all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Salon or another auditor mandated by the Salon.

An audit is requested in writing at least 30 days in advance, takes place during normal business hours, is limited to the processing under this Agreement, and is carried out by an auditor bound by confidentiality, in a way that does not disproportionately disrupt Everloop's operations or compromise the security of other customers. Where possible, Everloop may first answer questions in writing or provide existing documentation or certifications of its sub-processors. The Salon bears its own audit costs. Audits ordered by a supervisory authority are always permitted.

13. Liability

Each party's liability under this Agreement is governed by the liability provisions of the Terms, including article 26, insofar as permitted by law and without prejudice to the rights of data subjects under Article 82 GDPR.

14. Precedence, amendments and governing law

In matters concerning the processing of personal data on behalf of the Salon, this Agreement takes precedence over the Terms, as set out in article 34 of the Terms. Everloop may amend this Agreement in the same way as the Terms, or where required by changes in law or guidance from supervisory authorities.

This Agreement is governed by Belgian law. Disputes are settled in accordance with article 32 of the Terms.

15. Contact

Questions about this Agreement can be sent to Everloop BV, Hofstraat 22H, 3530 Houthalen-Helchteren, Belgium, or by email to info@everloop.be.