Data Processing Addendum
1. Scope and roles
This Addendum is part of the Terms of Service and applies to Customer Data that PrettyCRM processes on the Customer’s behalf. The Customer is the controller (or “business”) and NetGuards LLC (DBA PrettyCRM) is the processor (or “service provider” / “contractor” under US state privacy laws). Effective 2026-10-08.
2. Processing details
- Subject matter and purpose: providing the PrettyCRM service (client book, looks, schedules, documents, import and export, studio billing).
- Data subjects: the Customer’s clients and team members.
- Data: identification and contact details, language preferences, beauty profile, looks, schedules and any fields the Customer adds.
- Sensitive data: the service does not request it; the Customer decides whether to add it through its own fields and is responsible for the lawful basis.
- Duration: the subscription term plus the retention period in the Terms.
3. Instructions
PrettyCRM processes Customer Data only on the Customer’s documented instructions (these Terms and use of the service). PrettyCRM does not sell or share Customer Data; does not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the service; and does not combine it with data from other sources except as the law permits. PrettyCRM will tell the Customer if it believes an instruction violates the law or if it can no longer meet its obligations.
4. Confidentiality
People authorized to process Customer Data are bound by confidentiality and access it only when needed to provide support or operate the service.
5. Security
PrettyCRM maintains technical and organizational measures including: field-level encryption with a per-studio key protected in an HSM (Google Cloud KMS, us-west2); per-studio isolation enforced by the database (row-level security); TLS; mandatory two-step verification; Argon2id password hashing; short-lived links; access logging; encrypted backups; least privilege and access reviews.
6. Subprocessors
The Customer authorizes the subprocessors below. PrettyCRM will give at least 30 days’ notice before adding or replacing one; the Customer may object on reasonable grounds and, if the objection cannot be resolved, cancel.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud (Google LLC) | Application hosting, database, encryption keys (Cloud KMS / HSM), backups, phone-number verification (Identity Platform) | United States (us-west2, Los Angeles) |
| Stripe, Inc. | Subscription payments, invoices, tax calculation | United States |
| Resend (Plus Five Five, Inc.) | Transactional email (verification codes, invitations, feedback delivery) | United States |
| Cloudflare, Inc. | Bot protection on sign-up and sign-in (Turnstile) | Global network |
| Vercel Inc. | Hosting of the marketing website and documentation (no Customer Data) | Global network |
7. Assistance
Taking into account the nature of the processing, PrettyCRM will help the Customer respond to data subject requests (the Customer can view, correct, export and delete data in the app), and with impact assessments and regulator consultations where reasonable.
8. Security incidents
PrettyCRM will notify the Customer without undue delay, and in any case within 72 hours of confirming an incident affecting Customer Data, with the information available to help the Customer meet its obligations.
9. Return and deletion
The Customer can export its data at any time. At the end of the service, PrettyCRM will delete Customer Data in line with the Terms by destroying the studio’s encryption key; backups expire within 35 days.
10. Audits
PrettyCRM will make available the information reasonably necessary to demonstrate compliance, including summaries of its controls and of its cloud providers’ certifications. On-site audits require 30 days’ notice, no more than once a year, and a confidentiality agreement.
11. Transfers
Customer Data is hosted in the United States. For data subject to the EEA, UK or Swiss GDPR, the parties apply the Standard Contractual Clauses (Module 2, controller to processor) and the UK Addendum, which are incorporated by reference.