Draft: company details still to be completed.
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Pawdiary Terms of Service between [Company name Ltd] ("Processor", "we") and the business using Pawdiary ("Controller", "you"). It meets the requirements of Article 28 UK GDPR.
What we process
- Subject matter and duration: providing Pawdiary to you, for as long as you have an account and until the data is deleted as described below.
- Nature and purpose: storing, organising, displaying and sending data so you can run your grooming business (bookings, records, messages, payments, terms signing, route planning).
- Types of personal data: pet owners' names, contact details, addresses and locations, emergency and vet contacts, booking and payment history, messages sent, signatures and signing details, and photos; your staff's names and emails.
- Categories of data subjects: your clients (pet owners), their emergency contacts, and your staff.
- We don't expect special category data. Please don't record it unless you need to and have a lawful basis.
Our commitments
- We only process your data on your documented instructions (these terms and your use of the app), unless the law requires otherwise, in which case we will tell you if we're allowed to.
- Everyone who can access your data is bound by confidentiality.
- We keep appropriate technical and organisational security, including encryption in transit and at rest, access rules that keep each business's data separate, two-step sign-in, and logging of staff access.
- We help you respond to requests from individuals exercising their rights, mainly through the export, edit and delete tools in the app.
- We help you with security, breach notification and data protection impact assessments where relevant to our service.
- We tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data.
- When you delete your business, or at the end of the agreement, we delete your data within 30 days (backups within a further 30 days), unless the law requires us to keep it. You can export it first.
- We make available the information you need to show compliance with this DPA, and allow for reasonable audits, normally by providing written answers and certifications from us and our providers.
Sub-processors
- You authorise the sub-processors listed below. We have contracts with each that give the same level of protection as this DPA.
- We will give at least 30 days' notice of any new sub-processor by email or in the app. You can object on reasonable data protection grounds; if we can't resolve it, you can end the agreement.
International transfers
- Where data goes outside the UK, we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
Your responsibilities
- You have a lawful basis for the data you put in Pawdiary, you tell your clients how you use their data, and your instructions to us comply with the law.
Last updated 28 September 2026.
Sub-processors
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage and server functions | UK (London region) |
| DigitalOcean (via Laravel Forge) | Hosting the web app | [confirm server region] |
| Stripe | Pawdiary subscriptions, and card payments for businesses that connect Stripe | EU / US (UK adequacy and SCCs) |
| Resend | Account emails, and booking reminders, sign-in links and campaigns for businesses that use them | EU / US (SCCs) |
| Twilio | Text messages, only for businesses that turn texts on | US / EU (SCCs) |
| Cloudflare | Bot protection on sign-in (Turnstile) | Global (SCCs) |
| Calendar sync and Google sign-in, only if a business turns them on | Global (SCCs) | |
| postcodes.io (Ideal Postcodes) | Turning postcodes into map locations (postcode only) | UK |
| OpenStreetMap Foundation | Map tiles on the route page | UK / EU |
[Company name Ltd] · hello@pawdiary.co.uk