Data Processing Agreement (DPA)
Version: 2026-05-26
This Agreement complies with Article 28 of the GDPR. It defines the processing of personal data that WeLove Services (processor) carries out on behalf of your business (controller).
1. Roles
You are the controller of your clients' and team's data. WeLove Services is the processor, handling that data solely according to your instructions and in order to provide the service.
2. Subject matter and duration
The processing lasts for as long as you use the platform. It includes hosting and processing the data needed for bookings, communications and payments.
3. Types of data and data subjects
Identification and contact data (name, email, phone), your clients' booking history and preferences, and your team's data. Data subjects: your clients and staff.
4. Processor obligations
We process the data only as instructed; we ensure confidentiality; we apply appropriate technical and organisational measures; and we help you respond to data subject requests and to your security obligations.
5. Sub-processors
We rely on providers such as Stripe (payments), email/WhatsApp services and hosting within the EU. They are bound by equivalent data protection obligations.
6. International transfers
Data is hosted within the European Union. Any transfer outside the EEA is made with the safeguards required by the GDPR (e.g. standard contractual clauses).
7. Security and breaches
We maintain appropriate security measures (encryption in transit, access control, backups). In the event of a data breach, we notify you without undue delay so that you can meet your legal obligations.
8. Deletion
At the end of the service, or at your request, we delete or return the personal data, except where there is a legal obligation to retain it (e.g. tax records), in which case it is anonymised.