Data Processing Addendum

Last updated 21 July 2026 · Version v1.0

Processor: Clements & Catterall LTD (company number 16966378), trading as Thyme Studio

Registered office: 128 City Road, London EC1V 2NX

Controller: The business named on the Thyme Studio account

Applies to: Personal data about your own clients that we process on your behalf. Forms part of the Terms of Service and takes priority over them.

1. What this addendum does

1.1This Data Processing Addendum ("Addendum") governs our processing of personal data about your own clients when you use Thyme Studio. It forms part of the Terms of Service between you and Clements & Catterall LTD, trading as Thyme Studio.

1.2It applies automatically. You do not need to sign or request it, and you do not need to send us a copy of your own.

1.3If anything in this Addendum conflicts with the Terms of Service, this Addendum takes priority.

1.4This Addendum does not cover personal data for which we are ourselves the controller — for example, the contact details of your staff who hold Thyme Studio logins, or your billing records. Our Privacy Policy explains that processing.

2. Definitions

Client Personal Datapersonal data about your own clients that we process on your behalf through the Service, as described in Annex I.

Data Protection Lawthe UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other law about the processing of personal data that applies to either of us.

Sub-processorany third party we engage to process Client Personal Data on our behalf.

"Controller", "processor", "personal data", "data subject", "processing" and "personal data breach" have the meanings given to them in the UK GDPR. "We", "us" and "our" mean Thyme Studio; "you" and "your" mean the business holding the account.

3. Our roles

3.1You are the controller of Client Personal Data. We are your processor. You decide what client information to record, why, and for how long. We process it only to provide the Service to you.

3.2Annex I sets out the subject matter, duration, nature and purpose of the processing, the types of personal data involved, and the categories of data subject, as Article 28(3) of the UK GDPR requires.

3.3We are the controller of the data described in clause 1.4. Nothing in this Addendum makes us a controller of Client Personal Data, and nothing makes you a processor of ours.

4. What we will do

4.1We will process Client Personal Data only on your documented instructions, including in relation to transfers outside the UK, unless the law requires us to do otherwise. If the law requires us to process without your instruction, we will tell you before we do, unless the law prohibits us from telling you.

4.2Your instructions are: the Terms of Service, this Addendum, the settings and choices you make within the Service, and any other written instruction you give us that we agree to.

4.3We will tell you if we think an instruction breaches Data Protection Law. We may suspend the relevant processing until the instruction is withdrawn or amended.

4.4We will make sure that everyone we authorise to process Client Personal Data is subject to a duty of confidentiality, whether by contract or by statute, and that they are trained appropriately.

4.5We will implement and maintain the technical and organisational measures set out in Annex II, which are appropriate to the risk, as Article 32 of the UK GDPR requires.

4.6We will not sell Client Personal Data, and we will not use it for our own marketing or to train AI models.

5. What you must do

5.1You must comply with Data Protection Law in your use of the Service.

5.2You are responsible for the accuracy, quality and legality of Client Personal Data, and for having the right to give it to us.

5.3You must have a lawful basis for the Client Personal Data you record, and you must give your clients the privacy information the law requires them to receive, including telling them that you use a third-party platform to manage their records.

5.4The Service allows you to record medical notes and signed consent-form responses about your clients. This is special category personal data. You warrant that you have a valid condition under Article 9 of the UK GDPR — normally the client's explicit consent — before recording it.

5.5You warrant that you have valid consent under the Privacy and Electronic Communications Regulations 2003 for every recipient of a marketing message you send through the Service, and that the consent record you hold in the Service reflects consent that was properly obtained.

5.6You must not enter client names or other personal details into the Sprout AI chat feature. The Service displays a permanent reminder of this, but the obligation is yours.

6. Sub-processors

6.1You give us general authorisation to engage sub-processors. The sub-processors we use today are listed in Annex III and published, kept current, at our sub-processors page.

6.2Before we add or replace a sub-processor, we will tell you at least 14 days in advance by email and by updating our sub-processors page.

6.3If you object to a new sub-processor on reasonable data protection grounds, tell us within that 14-day period. If we cannot offer you a reasonable alternative, you may terminate your subscription without penalty and we will refund fees you have paid for the unused part of your current billing period.

6.4We will impose data protection obligations on every sub-processor that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.

7. Transfers outside the UK

7.1Our primary database is hosted in the UK or the European Economic Area. Some of our sub-processors are established outside the UK, as identified in Annex III.

7.2Where we transfer Client Personal Data outside the UK, we will do so only if a transfer mechanism recognised under Chapter V of the UK GDPR is in place — normally the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — or if the destination is covered by UK adequacy regulations.

7.3We will make details of the mechanism relied on for any particular sub-processor available to you on request.

8. Security

8.1We will implement appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Annex II describes the measures currently in place.

8.2We may update those measures as the Service develops, but we will not reduce the overall level of protection.

8.3We will take reasonable steps to ensure that anyone acting under our authority who has access to Client Personal Data processes it only on our instructions.

9. Personal data breaches

9.1We will tell you about any personal data breach affecting Client Personal Data without undue delay, and in any event within 72 hours of becoming aware of it.

9.2Our notification will describe, so far as we can, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose to take.

9.3Where we cannot provide all of that information at once, we will provide it in phases without undue further delay.

9.4We will assist you in meeting your own obligations to notify the Information Commissioner and affected data subjects. Deciding whether a breach is notifiable is your decision as controller, not ours.

9.5We will not make any public statement identifying you in connection with a breach without your prior written consent, unless the law requires it.

10. Helping you with your clients' rights

10.1The Service is built so that you can respond to most requests from your clients yourself — you can access, correct, export and delete client records directly.

10.2If a client contacts us directly about their personal data, we will not respond to the substance of their request. We will tell them to contact you, and we will tell you promptly that they got in touch.

10.3Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as is reasonably possible, in fulfilling your obligation to respond to requests to exercise rights under Chapter III of the UK GDPR.

10.4Assistance beyond what the Service already provides is chargeable at our then-current professional rate, where the request is unusually complex or repetitive. We will tell you before we charge.

11. Helping you with your other obligations

11.1We will provide reasonable assistance to help you comply with your obligations under Articles 32 to 36 of the UK GDPR — security, breach notification, data protection impact assessments, and prior consultation with the Information Commissioner — taking into account the nature of the processing and the information available to us.

12. Audits and information

12.1We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR and with this Addendum.

12.2We will do that by responding to a reasonable written request, including a completed security questionnaire, and by providing any relevant third-party certification or report we hold. You may make one such request in any 12-month period, on at least 30 days' notice and at your own cost.

12.3An on-site audit is available only where a confirmed personal data breach has affected your Client Personal Data, or where the Information Commissioner requires it. Any on-site audit must be at a reasonable time, must not unreasonably disrupt our business, and must not give access to any other customer's data.

12.4Anyone conducting an audit must be bound by confidentiality obligations at least as protective as those in the Terms of Service.

13. Returning and deleting data

13.1You can export your data from within the Service at any time. You can export your client records and financial records yourself. For a fuller export, email us at support@thymestudio.co.uk.

13.2When your account is deleted, you have 30 days to change your mind, during which any member of your staff can reactivate the account and the deletion is cancelled entirely.

13.3After 30 days we permanently and irreversibly delete your entire dataset, including all Client Personal Data, and delete the login credentials of every staff member who belonged to your account. All remaining copies, including backups, are purged within a further 90 days.

13.4If your subscription ends and you do not ask us to delete your account, we will keep your data for 90 days so that you can resubscribe, after which it is deleted in accordance with clause 13.3.

13.5We will keep financial records for 6 years where the law requires us to. This is the only exception to clause 13.3.

13.6We will confirm deletion in writing on request.

14. Liability

14.1Our liability under this Addendum is subject to the limitations and exclusions in clause 23 of the Terms of Service. The cap in that clause applies to all liability arising under the Terms of Service and this Addendum taken together, not to each separately.

14.2Nothing in this Addendum limits either party's liability to a data subject, or to the Information Commissioner, under Data Protection Law.

15. General

15.1This Addendum takes effect when you create your account and continues for as long as we process Client Personal Data for you.

15.2Clauses 13 and 14 survive the end of this Addendum.

15.3We may update this Addendum. If a change is material, we will give you at least 30 days' notice by email or through the Service. If a change is required by law or by a change to our sub-processors, we may make it on shorter notice.

15.4This Addendum is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising out of it.

Annex I Details of the processing

Required by Article 28(3) of the UK GDPR.

Subject matterProvision of the Thyme Studio salon and studio management platform to the controller.

DurationFor as long as the controller holds an account, plus the retention periods in clause 13.

Nature and purposeHosting, storage, organisation, retrieval, transmission and deletion of client records, for the purposes of appointment booking and management, client record-keeping, payment recording, consent-form collection, and sending transactional and marketing messages at the controller's direction.

Categories of data subjectThe controller's own clients, including prospective clients who make a booking through a public booking page.

Types of personal dataName; contact details (email address, telephone number); appointment and booking history; payment records; marketing consent status; message history, including the content and delivery status of SMS and email sent through the Service; and free-text notes recorded by the controller.

Special category dataMedical notes and signed consent-form responses, where the controller chooses to record them. Health data within the meaning of Article 9(1) of the UK GDPR.

Criminal offence dataNone. The Service is not designed to record criminal offence data and controllers should not enter it.

Frequency of transferContinuous, for the duration of the account.

Annex II Technical and organisational measures

Required by Articles 28(3)(c) and 32 of the UK GDPR. These are the measures in place at the date of this version.

Tenant isolationEvery database table enforces row-level security keyed to the business that owns the record. Isolation is enforced by the database itself, independently of application code, so one customer's data cannot be returned to another customer's session.

Access controlRole-based access within each account, with four staff roles and granular capability permissions. Permission changes take effect on the next request rather than at the next login.

Credential handlingNo privileged database credential is ever exposed to the browser. Browser code holds only a scoped, low-privilege key. Passwords are checked for strength and against common-password lists at the point they are set.

EncryptionData is encrypted in transit using TLS. Data at rest is encrypted by our hosting provider.

Transport and browser securityHTTP Strict Transport Security, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers are enforced on every response.

Abuse preventionBot defence on registration (challenge and disposable-email blocking), rate limiting on AI and messaging functions, and mandatory verification of a genuine business mobile number before any SMS can be sent.

Integrity of inbound callbacksEvery inbound provider callback is signature-verified before it is processed.

AI data minimisationStructured AI features receive only business-level and aggregate data. The set of fields that may be sent is fixed in code by an allow-list, and an automated test fails the build if a client-identifying field is ever added to it.

AI retentionAI chat conversations are automatically and permanently deleted 90 days after they take place.

Error monitoringError tracking is configured to avoid capturing personal data in error reports.

BackupsManaged backups are maintained by our hosting provider, with point-in-time recovery available.

Accessibility and code qualityAutomated accessibility and security checks run in our continuous integration pipeline, including secret-scanning and dependency vulnerability checks.

Annex III Sub-processors

Current at the date of this version. The live list is maintained at our sub-processors page.

SupabaseDatabase, authentication and file storage — the system of record for all Client Personal Data. Project hosted in the UK or European Economic Area.

TwilioSMS delivery, including booking confirmations, marketing campaigns and phone-number verification. Processes client telephone numbers and message content. United States; sends from a UK number. Transfer mechanism: EU Standard Contractual Clauses with the UK Addendum.

ResendEmail delivery, including booking confirmations, marketing campaigns, consent-form links and account emails. Processes client and staff email addresses and message content. United States. Transfer mechanism: Standard Contractual Clauses with the UK Addendum, and the EU-US Data Privacy Framework.

AnthropicPowers the Sprout AI assistant. Receives business-level and aggregate data only for structured suggestions, and free text typed by the controller's staff in chat. Never receives client names, contact details or individual records through the structured path. United States.

StripeBilling and subscription payments. Processes the controller's own billing data, not Client Personal Data. Card details are handled entirely by Stripe's hosted checkout and never reach our servers.

SentryError tracking. Configured to avoid capturing personal data.

PostHogProduct analytics. Listed for completeness, same basis as Stripe and Sentry above — it processes anonymous, aggregate usage data about how the Service is used, not Client Personal Data. No client identifiers, and no individual user profiles are created.