Data Processing Addendum (DPA)

Last updated: 2026-05-01

This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Customer", acting as data controller) and Cosmixxology, Inc. ("Processor") when we process personal data on your behalf in connection with the Services. The version posted here is offered as our pre-signed standard form for Salon, Professional, and Enterprise plans.

1. Definitions

Capitalized terms used but not defined here have the meaning given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), the Texas Data Privacy and Security Act ("TDPSA"), and any other applicable US state-level data-protection law (collectively, "Data Protection Laws").

2. Roles

For personal data the Customer uploads to or processes through the Services about its own clients ("Customer Personal Data"), the Customer is the controller and Cosmixxology, Inc. is the processor. Where we process other categories of data described in our Privacy Policy for our own purposes — for example, account, billing, security, product analytics — we act as an independent controller.

3. Subject matter, duration, nature, and purpose

We process Customer Personal Data to provide the Services described in the Customer's order form, for the duration of the order term plus any post-termination period required to return or delete the data. Processing includes collection, storage, organization, structuring, retrieval, transmission, deletion, and other operations that are necessary to provide the Services.

4. Categories of data subjects and personal data

  • Data subjects: the Customer's clients, staff, and end users.
  • Categories: identifiers, contact info, photos of hair/scalp/face, derived measurements, hair-care preferences, allergies, appointment and order history, payment metadata.

5. Customer instructions

We process Customer Personal Data only on the documented instructions of the Customer, which include the order form, the Services configuration, and any further written instructions consistent with the Services. We will tell the Customer if we believe an instruction violates Data Protection Laws.

6. Confidentiality

We ensure that personnel authorized to process Customer Personal Data are bound by confidentiality and have completed appropriate training.

7. Security (Article 32)

We implement appropriate technical and organizational measures, including:

  • Encryption in transit (TLS 1.2+) and at rest (Azure Storage Service Encryption);
  • Role-based access control with least-privilege defaults;
  • Audit logging of administrative actions;
  • Vulnerability scanning, secure SDLC, and code review;
  • Incident response plan with notification to Customer without undue delay (and within 72 hours where the breach is likely to result in a risk to data subjects);
  • Regular backup, disaster recovery testing, and resilience procedures.

8. Sub-processors

The Customer authorizes us to engage the sub-processors listed at /legal/sub-processors. We will notify B2B Customers at least thirty (30) days before we add a new sub-processor that materially affects the processing of Customer Personal Data, and give the Customer a right to object. We remain liable for sub-processors' compliance with this DPA.

9. Location of processing

We process Customer Personal Data in the United States. We do not currently transfer Customer Personal Data outside the United States. If we ever begin processing in another country, we will notify the Customer in advance and execute appropriate transfer terms.

10. Assistance to the Customer

We assist the Customer, taking into account the nature of processing, with: (a) responding to data-subject rights requests; (b) carrying out data-protection impact assessments; (c) consulting with supervisory authorities; (d) ensuring appropriate security and notifying personal-data breaches.

11. Audits

We make available to the Customer the information necessary to demonstrate compliance with applicable Data Protection Laws and allow audits by the Customer or a mutually agreed independent auditor, no more than once per year (more often if required by a regulator), with reasonable notice and during business hours, subject to confidentiality and reasonable cost reimbursement. We may satisfy this obligation by providing recent third-party audit reports (e.g., SOC 2 Type II) where available.

12. Return or deletion

On termination of the Services, the Customer may export Customer Personal Data for 30 days. After that period, we will delete Customer Personal Data within 60 days, except as required by law. Backup copies are deleted on the next backup-rotation cycle (no longer than 90 days).

13. CCPA addendum

For purposes of the CCPA, in respect of Customer Personal Data we are a "service provider" or "contractor". We will not sell or share Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship, and will not combine it with personal information received from another source.

14. Conflict

In case of conflict, the order is: (1) this DPA, (2) the order form, (3) our general Terms of Service.

15. Contact

dpo@cosmixxology.com · legal@cosmixxology.com