Data Processing Agreement
These processor terms form part of the LineupUK Terms whenever a barber uses LineupUK to handle client booking data.
Last updated 31 August 2026
This Data Processing Agreement (“DPA”) is between the barber or barbering business holding the LineupUK account (“Controller”) and the LineupUK operator identified in the Company Information(“Processor”). It applies from the first processing of client personal data and continues while LineupUK processes that data.
1. Scope and order of terms
This DPA supplements the Terms of Service. It governs personal data processed by LineupUK on the Controller’s behalf. If it conflicts with the Terms on that processing, this DPA controls. UK GDPR, the Data Protection Act 2018 and applicable PECR requirements are referred to together as “Data Protection Law”.
2. Processing details
| Subject matter | Hosting and operating the Controller’s public booking page, availability, appointments, client records, cancellations, waitlist and booking communications as features are enabled. |
|---|---|
| Duration | For the account term and the limited deletion/export period after termination, subject to protected backup cycles and legal obligations. |
| Nature | Collection, storage, organisation, retrieval, consultation, transmission to authorised notification providers, correction, export, restriction and deletion. |
| Purpose | To let clients request and manage appointments with the Controller and let the Controller manage its diary and communications. |
| People | The Controller’s clients, prospective clients, waitlist members and relevant account contacts. |
| Data | Name, phone number, email address, service, appointment time, booking status, cancellation information, waitlist status, notification status and communications needed to administer the booking. |
| Special-category data | Not intended or required. The Controller must not instruct clients to submit health or other special-category data through free-text fields unless separately agreed and lawfully supported. |
3. Controller responsibilities
- Comply with Data Protection Law and issue lawful, documented instructions.
- Have a lawful basis and give clients an appropriate privacy notice.
- Keep access credentials secure and restrict account access appropriately.
- Keep data accurate, avoid unnecessary information and set lawful retention requirements.
- Respond to client rights requests, with LineupUK’s assistance where required.
4. Documented instructions
LineupUK processes personal data only on documented Controller instructions, including those expressed through configured LineupUK features, support requests and these terms. If UK law requires other processing, LineupUK informs the Controller before processing unless the law prohibits notice. LineupUK promptly tells the Controller if an instruction appears to breach Data Protection Law and may pause that instruction while it is clarified.
5. Confidentiality
Anyone authorised by LineupUK to process Controller data is bound by an appropriate duty of confidentiality and receives access only where needed for their role.
6. Security
Taking account of the nature of processing, costs, available technology and risk, LineupUK maintains appropriate technical and organisational measures. Current measures include encrypted transport, managed authentication, database row-level security, owner-scoped storage, server-side secrets, access controls, backups supplied by infrastructure providers and testing of material isolation constraints. See the Security page.
7. Subprocessors
The Controller gives general written authorisation for the providers on the Subprocessor List. LineupUK binds each subprocessor to data-protection obligations appropriate to its service and remains responsible for its obligations under this DPA.
LineupUK will provide reasonable advance notice of a new subprocessor that handles Controller data. The Controller may object on reasonable data-protection grounds before the change takes effect. The parties will try to resolve the concern; if no reasonable alternative exists, either party may end the affected service without penalty for future periods.
8. International transfers
LineupUK does not make a restricted transfer without a lawful mechanism. Where required this may be an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses or another mechanism permitted by Data Protection Law. LineupUK makes relevant transfer information available to the Controller on reasonable request.
9. Individual rights
Taking account of the processing, LineupUK provides reasonable technical and organisational assistance so the Controller can respond to requests for access, correction, erasure, restriction, objection, portability and other applicable rights. If LineupUK receives a request relating to Controller data, it forwards the request and does not respond for the Controller unless authorised or legally required.
10. Incidents, assessments and regulators
LineupUK notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data and provides available information needed for the Controller’s assessment and notifications. LineupUK reasonably assists with security obligations, data-protection impact assessments and prior regulator consultation, taking account of the processing and information available to it.
11. Return and deletion
At the end of the service and on the Controller’s choice, LineupUK deletes or returns Controller data unless UK law requires retention. Operational copies are removed through the account-closure process; protected backup copies remain beyond ordinary use and age out through supplier backup cycles. Legally retained information is isolated and used only for that requirement.
12. Evidence and audits
LineupUK makes information reasonably necessary to demonstrate compliance with this DPA available to the Controller and permits proportionate audits or inspections. The Controller must give reasonable notice, protect confidentiality, avoid disrupting other customers and use available independent reports first. Unless an audit identifies material breach, the Controller bears its audit costs.
13. Contact and legal review
Data-processing questions go to bookings@lineupuk.com. The registered operator details will be inserted before this DPA is used for paid processing. This document is scheduled for UK legal review before paid launch.