WeLove Services

Data Processing Agreement (DPA)

Version: 2026-05-26

This Agreement complies with Article 28 of the GDPR. It defines the processing of personal data that WeLove Services (processor) carries out on behalf of your business (controller).

1. Roles

You are the controller of your clients' and team's data. WeLove Services is the processor, handling that data solely according to your instructions and in order to provide the service.

2. Subject matter and duration

The processing lasts for as long as you use the platform. It includes hosting and processing the data needed for bookings, communications and payments.

3. Types of data and data subjects

Identification and contact data (name, email, phone), your clients' booking history and preferences, and your team's data. Data subjects: your clients and staff.

4. Processor obligations

We process the data only as instructed; we ensure confidentiality; we apply appropriate technical and organisational measures; and we help you respond to data subject requests and to your security obligations.

5. Sub-processors

We rely on providers such as Stripe (payments), email/WhatsApp services and hosting within the EU. They are bound by equivalent data protection obligations.

6. International transfers

Data is hosted within the European Union. Any transfer outside the EEA is made with the safeguards required by the GDPR (e.g. standard contractual clauses).

7. Security and breaches

We maintain appropriate security measures (encryption in transit, access control, backups). In the event of a data breach, we notify you without undue delay so that you can meet your legal obligations.

8. Deletion

At the end of the service, or at your request, we delete or return the personal data, except where there is a legal obligation to retain it (e.g. tax records), in which case it is anonymised.

Terms of Service Data Processing Agreement (DPA) Platform Privacy Policy