Data Processing Addendum

Last updated 1 July 2026

The Article 28 terms for personal data Rivo processes on a salon’s behalf, including our sub-processors.

This is a working draft provided for transparency while Rivo Software Ltd completes incorporation. Items in [brackets] are to be finalised, and the document should be reviewed by a qualified solicitor before it is relied upon.

1. Introduction and roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the salon (“Controller”) and Rivo Software Ltd, operator of Rivo Salon Software (“Processor”, “Rivo”). It applies where Rivo processes personal data on the Controller’s behalf in providing the Service, and reflects Article 28 of the UK GDPR.

The Controller determines the purposes and means of processing its clients’ personal data. Rivo processes that data only as a processor, on the Controller’s documented instructions, which include the Terms, this DPA, and the Controller’s use of the Service’s settings and features.

2. Subject-matter and details of processing

ItemDetail
Subject-matterProvision of the Rivo salon-management Service
DurationFor the term of the Controller’s account, plus retention periods in the Privacy Policy
Nature and purposeHosting, storage, and processing to deliver booking, payments, messaging, records and reporting
Types of personal dataNames, contact details, appointment and sales history, notes, forms and consents, message content, and staff details
Categories of data subjectThe Controller’s clients, staff, and contacts
Special category dataMay include health-related notes (e.g. allergies, patch tests) where the Controller chooses to record them

3. Rivo’s obligations

Rivo will:

  • Process personal data only on the Controller’s documented instructions, including for transfers, unless required by law (and if so, will tell the Controller unless legally prohibited).
  • Ensure people authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (see below).
  • Respect the conditions for engaging sub-processors set out in this DPA.
  • Assist the Controller, taking account of the nature of processing, to respond to data-subject rights requests.
  • Assist the Controller with security, breach notification, and data protection impact assessments where applicable.
  • At the Controller’s choice, delete or return personal data at the end of the services, save where storage is required by law.
  • Make available information necessary to demonstrate compliance, and allow for and contribute to audits as described below.

4. Security measures

Rivo maintains measures appropriate to the risk, including: encryption of data in transit and encryption of sensitive stored secrets; logical tenant isolation separating each Controller’s data; role-based access controls and least-privilege access; PIN protection for shared devices; audit logging of significant actions; regular backups; and monitoring designed to detect and respond to incidents.

5. Sub-processors

The Controller authorises Rivo to engage the sub-processors listed below to process personal data in connection with the Service. Rivo imposes data protection terms on each sub-processor no less protective than this DPA.

Sub-processorPurposeLocation
StripeCard payments, deposits, saved cards, payoutsUK / EU / USA
TelnyxSMS and voice messagingUK / EU / USA
HostingerApplication and database hostingUK / EU

Email is self-hosted by Rivo on its own infrastructure and is not provided by a third-party sub-processor. Rivo will give the Controller reasonable notice of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds.

6. International transfers

Where a sub-processor processes personal data outside the UK, Rivo relies on an appropriate transfer mechanism, such as UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), together with any supplementary measures required.

7. Personal data breaches

Rivo will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its own notification obligations to the ICO and data subjects where applicable.

8. Data-subject requests

If Rivo receives a request from a data subject relating to data it processes for a Controller, Rivo will, where lawful, direct the request to the Controller and assist the Controller in responding. The Service also provides self-service export and deletion tools the Controller can use directly.

9. Audit

Rivo will make available information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, no more than once a year (unless required by a supervisory authority or following a breach), and subject to confidentiality and to not compromising other customers’ security.

10. Return and deletion

On termination, and at the Controller’s choice, Rivo will return or delete the personal data it processes for the Controller, and delete existing copies, in line with the retention periods in the Privacy Policy, except where storage is required by law. Backups are deleted on their normal rotation cycle.

11. General

If there is a conflict between this DPA and the Terms on data protection, this DPA prevails. This DPA is governed by the law of Scotland. Liability under this DPA is subject to the limitations in the Terms.