Data processing agreement
Last updated 7 August 2026.
Article 28 of the GDPR requires a written contract between a controller and its processor. This is it. It forms part of the terms of service and you accept it when you create an account. There is nothing to sign and nothing to negotiate.
1. Roles
You are the controller of your customers’ personal data. FreshTrim is the processor. We process it only to provide the service, and only on your documented instructions, which in practice means the settings you choose and the actions you take in the product.
If we ever believe an instruction from you would breach data protection law, we will tell you.
2. What we process
- Subject matter and duration: providing online booking for your shop, for as long as you have an account.
- Nature and purpose: storing and displaying appointments, sending confirmations and reminders, taking payments where you enable them, and producing your reports.
- Types of personal data: customer name, phone number, email address, appointment history, any note you record against a customer, no-show count, and payment records. We do not ask for and you should not record special category data.
- Categories of data subject: your customers, and the staff you give access to.
3. Confidentiality
Anyone with access to your data is bound by a duty of confidentiality. Access is limited to what is needed to run and support the service.
4. Security
We maintain appropriate technical and organisational measures under Article 32, including: encryption in transit and at rest; multi-factor authentication on administrative access; row-level database isolation between shops, so one shop’s records cannot be read by another; audit logging of changes; and tested backups.
Tenant isolation is the measure that matters most in a product of this shape, and it is enforced in the database, not in application code, so a bug in a screen cannot expose another shop’s customers.
5. Subprocessors
You give general authorisation for us to engage the subprocessors listed at /subprocessors. We will give you 30 days’ notice by email before adding or replacing one, and you may object; if we cannot resolve the objection you may terminate without penalty.
Each subprocessor is bound by terms no less protective than these, and we remain fully liable to you for their performance.
6. International transfers
Your customers’ data is stored in Ireland. Where a subprocessor may process data outside the EEA, that transfer is covered by Standard Contractual Clauses. The subprocessor page states the position for each.
7. Helping you answer your customers
Data subject rights are your obligation as controller, and the software is what makes them possible. We provide, in the product: a full export of a single customer’s record for access and portability requests; deletion of a customer and their associated records; and correction of their details.
If a customer contacts us directly we will not respond on your behalf. We will refer them to you and tell you it happened.
8. Breach notification
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting data we process for you, with what we know at the time, and we will keep you updated as we learn more.
Article 33(2) says only “without undue delay”. The 48 hours is our commitment, not the statutory floor, because you are the one on a 72-hour clock to the Data Protection Commission and a vague promise is no use to you.
9. Deletion and return
At any time during the contract you can export your data yourself, in a machine-readable format, without asking us.
On termination we will delete your data within 30 days of your request. Backups roll on a 30-day cycle and deleted data ages out with them; it is never restored to live systems.
10. Audit
We will make available the information you reasonably need to demonstrate compliance with Article 28, and will contribute to audits carried out by you or an auditor you appoint, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.
11. Contact
Privacy questions and any of the above: fresh@dv.ie, or Darragh Verschoyle, 2 Elmbrook, Eighter, Virginia, Co. Cavan.