Data Processing Agreement
Last updated: August 1, 2026
Terms under which the Salon entrusts the processing of personal information to DOKUMENT.PL sp. z o.o. as its service provider, in accordance with PIPEDA and Quebec's Law 25: subject and duration, information categories, safeguards, sub-processors, support for individuals' rights, transfers outside Canada, breach handling, and deletion or return of information.
Table of Contents
Parties, subject and nature of the agreement
This Data Processing Agreement (the "DPA") is an integral part of the Salon Subscription Terms and is concluded between:
the Salon - a business (an organization under PIPEDA and, in Quebec, a person carrying on an enterprise) using the Meeti Me platform under the Agreement, and
the Service Provider:
- Name: DOKUMENT.PL sp. z o.o.
- Address: Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland
- Identifiers: NIP 5242982251, KRS 0001055336
The Service Provider is a company established in the European Union that provides the Service into Canada.
Privacy contact: meetime.company@gmail.com. Privacy officer, if designated: meetime.company@gmail.com. Contractual matters: meetime.company@gmail.com.
This DPA sets out how the Service Provider handles personal information on the Salon's behalf, in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where the Salon operates in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25. Where processing is subject to the GDPR because the Service Provider is an EU entity, it applies GDPR-level safeguards as an additional, not a lower, standard.
This DPA is in force from the Salon's acceptance of the Terms and for the whole term of the Agreement, and as to return, deletion and confidentiality of information also after it ends. Where they conflict on entrusted information, this DPA prevails over the Terms.
Document version: 2026-08-01. Effective: 2026-08-01.
Roles and allocation of responsibility
The Salon determines the purposes of processing the personal information of its clients and of its staff and collaborators entered into the platform or created through the use of its features: the client records, notes, visit history at this Salon, service arrangements, staff schedule and the content of communications the Salon sends to its clients. The Salon is responsible for a valid basis to collect and use that information, for the notices and consents required of it, for keeping the information proportionate to the purpose, and for the lawfulness of its instructions.
DOKUMENT.PL sp. z o.o. acts as the Salon's service provider (mandatary) for that information and handles it only on the Salon's behalf and instruction, to the extent needed to provide the Service. It does not use the information for its own purposes.
DOKUMENT.PL sp. z o.o. acts for its own purposes in respect of: the Salon's registration and billing data, Salon-user account data for authentication and security, technical and security logs, product-analytics data, and marketplace-client data for account management, booking intermediation and transactional notifications. This DPA does not apply to that scope; the Meeti Me Privacy Policy governs it.
Scope, nature and purpose of processing
Subject. Processing of personal information entrusted by the Salon in connection with the SaaS Service.
Nature. Automated operations in the information system: collection, recording, storage, adaptation, retrieval, use, communication, restriction, deletion or destruction.
Purpose - solely to provide the Service to the Salon:
- keeping the appointment calendar and staff schedule,
- keeping the client records (CRM) with notes and visit history,
- receiving, confirming, changing and cancelling bookings on the Salon's behalf,
- sending notifications on the Salon's behalf by e-mail, SMS, push and Telegram,
- keeping the Salon's settlements and internal reports,
- providing export and data-copy features,
- technical support on the Salon's request,
- maintaining, protecting, backing up and restoring the environment.
Duration - for the term of the Agreement plus the export and deletion period (see the deletion section).
Categories of individuals and information
Individuals: the Salon's clients (including those booking via the marketplace and those entered by the Salon); the Salon's staff and collaborators; contact persons named by the Salon; parents or guardians booking on behalf of a minor.
Information categories:
| Category | Approximate scope | | --- | --- | | Identification | Name, surname or display name | | Contact | E-mail, phone number, Telegram id if linked | | Booking | Date and time, service, staff member, status, change history | | Client record | Salon notes, preferences, visit history, spend and frequency | | Staff | Name, role, service scope, working hours, absences, work e-mail | | Communication | Content of booking-related messages, delivery status | | Technical | Session and device identifiers, IP, access logs |
Sensitive information. The platform is not intended for health information or other sensitive personal information. The Salon undertakes not to enter such information (including in note fields) without a valid basis and prior agreement of additional measures. Doing so against this undertaking is at the Salon's sole responsibility.
Minors' information. The platform is for persons aged 16 or over; a booking for a minor is made by a parent or guardian, whose consent governs where required.
The Salon's documented instructions
The Service Provider processes the information only on the Salon's documented instruction. Such instructions are: this DPA together with the Terms; the Salon's Account configuration; the actions of Salon users in the interface or via the API; requests from persons authorised by the Salon to meetime.company@gmail.com or meetime.company@gmail.com.
The Service Provider does not use the entrusted information for its own purposes, in particular does not train models on it, build marketing profiles, or disclose it to third parties beyond the scope of this DPA. If an instruction appears to infringe applicable privacy law, it informs the Salon without delay and may suspend the instruction until confirmed.
Confidentiality of personnel
The Service Provider ensures that persons authorised to handle the entrusted information are authorised on a least-privilege basis, are bound to confidentiality, have been trained in privacy and security, and access only the information needed for their task. The confidentiality obligation survives the end of their engagement. The Service Provider keeps a register of authorised persons and reviews authorisations periodically.
Safeguards
The Service Provider implements physical, organisational and technological safeguards appropriate to the sensitivity of the information:
Encryption. TLS 1.2+ with enforced HTTPS and HSTS in transit; AES-256 at rest (database, S3 file storage, backups); passwords stored only as a salted cryptographic hash.
Access control. Role-based model (owner/manager/staff) on a least-privilege basis; strict data isolation between Salons; multi-factor authentication for administrative access; short-lived tokens; staff access to production data only on a justified, logged and time-limited basis.
Backups. Automated daily encrypted backups in at least two availability zones; 30-day retention; periodic restore tests; RTO 8 h, RPO 24 h.
Logging and monitoring. Recording of security and data-access events; 12-month tamper-resistant log retention; anomaly monitoring, rate limiting, DoS protection.
Development. Environment separation (no real information outside production); code review, automated tests, dependency scanning; secrets kept in a vault; periodic security testing.
Governance. Privacy and security policies; an incident-management procedure; vetting of sub-processors; privacy by design and by default; a designated person accountable for the protection of personal information.
The Service Provider may change the safeguards provided the protection level is not lowered. A current description is provided on request to meetime.company@gmail.com.
Sub-processors
The Salon authorises the engagement of sub-processors on the terms of this section. The Service Provider concludes with each an agreement imposing protection obligations no less strict than this DPA and remains accountable for their performance.
Current list:
| Sub-processor | Role | Place of processing | | --- | --- | --- | | Amazon Web Services EMEA SARL | App and DB hosting, S3 storage, backups | EU regions | | Amazon SES | E-mail delivery on the Salon's behalf | EU regions | | SMS provider | SMS delivery on the Salon's behalf | EEA | | PostHog | Dashboard product analytics (after consent), pseudonymised | EU | | Telegram | Telegram notification delivery (after self-linking) | Outside the EEA, with safeguards |
Stripe serves only the Salon's subscription payments to DOKUMENT.PL sp. z o.o. and acts for its own purposes in that scope, not as a sub-processor; it has no access to the Salon's client information.
Changes and objection. The Service Provider gives at least 30 days' notice of adding or replacing a sub-processor. The Salon may raise a reasoned objection within 30 days to meetime.company@gmail.com; the parties seek a solution in good faith, and if none is reached and the engagement is necessary for the Service, the Salon may terminate the Agreement with a proportionate refund and a preserved export right.
Assistance with individuals' rights
Taking account of the nature of processing, the Service Provider assists the Salon in responding to requests from individuals to access, correct, delete or de-index their information and to withdraw consent. Assistance is primarily through dashboard features (search, view, CSV/JSON export, correction, deletion or anonymisation of a client record).
A request that reaches the Service Provider directly is not answered on the merits but passed to the Salon within 3 business days. Where fulfilment goes beyond dashboard features, the Service Provider gives technical assistance within a time that lets the Salon meet its statutory deadlines, no later than 10 business days.
Confidentiality incidents and breach handling
On becoming aware of a confidentiality incident affecting the entrusted information (including unauthorised access, use, disclosure or loss), the Service Provider notifies the Salon without undue delay, no later than 24 hours after becoming aware, describing the nature of the incident, the categories and approximate number of individuals and records, the likely consequences and the measures taken. If full information cannot be given at once, it is provided in phases.
The Salon, as the organization accountable to individuals, decides on reporting to the Office of the Privacy Commissioner of Canada and, in Quebec, to the Commission d'accès à l'information, and on notifying affected individuals where there is a real risk of serious harm. The Service Provider gives the necessary support and keeps a register of confidentiality incidents affecting the entrusted information.
Transfer and storage outside Canada
The entrusted information is stored and processed by the Service Provider and its sub-processors within the European Union / European Economic Area (infrastructure, database, storage and backups in EU regions). The Salon acknowledges this location. The Service Provider maintains a level of protection comparable to that required under PIPEDA and Law 25, through the safeguards in this DPA and its agreements with sub-processors.
Where the Salon operates in Quebec, the Salon remains responsible for conducting, before communicating personal information outside Quebec, the privacy impact assessment required by Law 25; the Service Provider provides, on request, the information about its safeguards and processing location needed for that assessment.
Transfer outside the EEA occurs only for: the optional Telegram channel (activated by the recipient); possible technical support by teams outside the EEA on a one-off logged-access basis; or on the Salon's separate instruction, in each case with appropriate safeguards including standard contractual clauses and encryption.
Deletion or return of information after the engagement ends
At the Salon's choice the Service Provider deletes the entrusted information or returns it, and deletes existing copies, unless retention is required by law. Schedule:
- Days 1-30 after the Agreement ends - export period. Read-only access and self-service CSV/JSON export. On request to meetime.company@gmail.com the period is extended once by another 30 days.
- Up to 90 days - deletion from production systems.
- Up to 90 days - deletion from backups on the rotation cycle; until then backups stay encrypted.
On request during the export period, deletion is done sooner - within 14 days (subject to the backup rotation cycle). Deletion is confirmed in writing on request. This does not cover information whose retention the law requires (accounting and tax records for the subscription, information needed to defend legal claims).
Audits
The Service Provider provides the information needed to demonstrate compliance and allows verification:
Documentation. On request to meetime.company@gmail.com, within 20 business days: a description of the safeguards, the sub-processor list, a completed security questionnaire, and information on incidents affecting the Salon's information.
Audit. If documentation is insufficient - an audit on 30 days' notice, in working hours, no longer than 3 business days, no more than once a year (unless justified by an incident or an authority's order), without access to other clients' information, source code or sensitive security details, and without penetration testing absent separate consent. The Salon bears the cost; the first standard yearly audit does not impose the Service Provider's own costs.
Liability
Each party is liable for damage caused by processing to the extent of applicable law. The Service Provider is liable only where it failed its own obligations or acted outside the Salon's lawful instructions. The Salon is liable for the basis to collect and use the information, for the notices and consents required of it, for the lawfulness of instructions, and for handling information after receiving it from the platform.
The liability limitations set in the Terms (including the aggregate cap) apply, and do not apply to intent, gross fault, harm to life or health, or any extent where a limitation is impermissible under mandatory law.
Final provisions
This DPA is amended as the Terms provide for amending a standard document (at least 15 days' notice and a right to terminate); changes required by law or an authority's guidance take effect in the corresponding time. Invalidity of one provision does not affect the rest.
This DPA is governed by law of the province or territory of your residence. Disputes are resolved by courts of the province or territory of your residence, without prejudice to an individual's right to complain to the supervisory authority Office of the Privacy Commissioner of Canada; for Quebec residents, the Commission d acces a l information du Quebec (priv.gc.ca).
Binding versions
This document is drawn up in English (en) and French (fr). For the CA region the English and French versions are equally authoritative; in case of divergence each version is read to give effect to the other.