indris.

Data Processing Agreement

How Indris handles the personal data of your clients, which you remain responsible for.

Version 2026-09-02

1. Which of us is responsible for what

Your salon is the data controller for your clients' personal data. You decide whose records you hold, what you record about them, and why.

Indris is the data processor. We hold and handle that data on your behalf, on your instructions, and for no purpose of our own.

This agreement is required by Article 28 of the UK GDPR and forms part of our Terms of Service. It applies for as long as we hold personal data on your behalf.

2. What we process, and about whom

The subject matter of the processing is the operation of salon booking software. Its purpose is to let you manage appointments and client records, and to let your clients book with you.

The categories of data subject are your clients, and your own staff who hold logins.

The personal data we process on your behalf is:

  • Client names, email addresses, telephone numbers and postal addresses
  • Emergency contact names and telephone numbers
  • Allergies and medical notes recorded by you or provided by the client
  • Appointment history — services booked, times, and the therapist seen
  • Staff names, email addresses and password hashes
  • Photographs your therapists choose to upload of themselves

3. Special category data

Allergies and medical notes are data concerning health, and therefore special category data under Article 9 of the UK GDPR. They receive the same protection as everything else we hold, but you should be aware they carry additional obligations for you as controller.

In particular, you need a lawful basis under Article 6 and a separate condition under Article 9 to hold them at all, and you must tell your clients what you record and why. Indris provides the field; deciding whether to use it, and on what basis, is yours.

We do not transmit health information outside the application. It is not included in any email we send, and it is not shared with any sub-processor beyond the hosting provider that stores the database.

4. We act only on your instructions

We process personal data only on your documented instructions, which for normal operation means your use of the software's features. We will not process it for our own purposes, and we will not sell it or use it to advertise to your clients.

If we are ever required by law to process it otherwise, we will tell you before doing so unless the law prevents us.

Everyone with access to your data is bound by a duty of confidentiality.

5. Security measures

We maintain the following technical and organisational measures:

  • Encryption in transit — all traffic is served over HTTPS
  • Passwords stored only as bcrypt hashes, never in a recoverable form
  • Strict separation between salons: every record is scoped to one salon, and that boundary is enforced on the server for every request rather than in the interface
  • Access to the production database limited to named administrators
  • Password reset tokens that are single-use, time-limited and stored hashed
  • Role-based access control: staff logins are owner, administrator or therapist, and what each can change is enforced on our servers for every request. A therapist cannot alter your service list, remove client records or reach your billing.
  • A known and disclosed limitation: those roles restrict what staff can CHANGE, not what they can SEE. Any staff login you create can read every client record in your salon, including allergies and medical notes. This is deliberate — a therapist needs to know what a client is allergic to before treating them — but it means deciding who to give a login to remains your most important control, and we would rather say so than imply otherwise.

6. Sub-processors

We use the following sub-processors, each under a written contract imposing equivalent obligations:

  • Railway — application hosting and database storage, in an EU region. Has access to all data stored in the application.
  • Resend — transactional email delivery. Receives only names, email addresses and appointment details. Never receives allergies or medical notes.
  • Cloudflare — storage and delivery of therapist photographs, and the domain through which the service is reached. Receives images uploaded by your staff and nothing else. It holds no client data.

7. Changes to sub-processors

We will give you reasonable notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may end your use of Indris and ask us to return and delete your data.

8. International transfers

Data is stored in the European Union. Where a sub-processor is established outside the UK or EU, transfers are made under an approved transfer mechanism such as the UK International Data Transfer Addendum or Standard Contractual Clauses.

9. Helping you meet your obligations

If a client exercises their rights — access, correction, erasure, portability, objection — we will help you respond, taking into account the nature of the processing and the information available to us.

We will also assist you, so far as we reasonably can, with data protection impact assessments and with consultation of the Information Commissioner where those are required of you.

10. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours, with the information you need to meet your own reporting obligations.

Reporting a breach to the Information Commissioner, and to affected individuals where required, is your responsibility as controller. We will support you in doing so.

11. Deletion and return

At any time, and on request when you stop using Indris, we will provide an export of your data and then delete it, unless we are legally required to keep it.

Deleting a client record in the application removes it, including any allergies and medical notes it held. Note that we do not currently apply an automatic retention period: records you keep are kept until you delete them, so setting and applying a retention policy is yours to decide.

12. Demonstrating compliance

We will make available the information you reasonably need to verify that we are meeting these obligations, and will contribute to audits carried out by you or an auditor you appoint, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.

See also Terms of Service. Both are accepted together when a salon signs up.

Questions about either document? Email hello@indris.co.uk.