Skip to main content

Data Processing Agreement

Last updated: August 1, 2026

Terms under which the Salon (controller) entrusts the processing of personal data to DOKUMENT.PL sp. z o.o. (processor) in accordance with the Law of Ukraine "On the Protection of Personal Data": subject and duration, data categories, security measures, sub-processors, support for data-subject rights, cross-border transfer to the EU, and deletion or return of data.

This translation is provided for convenience. The UK version is the binding one.

Parties, subject and nature of the agreement

This Data Processing Agreement (the "DPA") is an integral part of the Salon Subscription Terms and is concluded between:

the Controller - the Salon, a business using the Meeti Me platform under the Agreement, and

the Processor:

  • Name: DOKUMENT.PL sp. z o.o.
  • Address: Aleja Stanow Zjednoczonych 51 lok. 222, 04-028 Warszawa, Poland
  • Identifiers: NIP 5242982251, KRS 0001055336, REGON 526237551

The Processor is a company registered in the Republic of Poland, providing electronic services into Ukraine as a non-resident.

Data-protection contact: meetime.company@gmail.com. Responsible person, if appointed: meetime.company@gmail.com. Contractual matters: meetime.company@gmail.com.

This DPA is concluded to satisfy Article 24 of the Law of Ukraine "On the Protection of Personal Data" and defines the subject, duration, nature and purpose of processing, the type of personal data, the categories of data subjects and the obligations and rights of the Controller. As the Processor is an EU entity, it applies to the entrusted processing safeguards at the level of Article 28 of Regulation (EU) 2016/679 (GDPR) - a standard of protection no lower than Ukrainian law requires.

This DPA is in force from the Salon's acceptance of the Terms and for the whole term of the Agreement, and as to return, deletion and confidentiality of data also after it ends. Where they conflict on entrusted data, this DPA prevails over the Terms.

Document version: 2026-08-01. Effective: 2026-08-01.

Roles and allocation of responsibility

The Salon is the controller of the personal data of its clients and of its staff and collaborators entered into the platform or created through the use of its features: the client records, notes, visit history at this Salon, service arrangements, staff schedule and the content of communications the Salon sends to its clients.

As controller the Salon alone determines the purposes and means of processing this data and is responsible for a valid legal basis, for informing data subjects, for keeping the data collected proportionate to the purpose, and for the lawfulness of the instructions it gives the Processor.

DOKUMENT.PL sp. z o.o. is the processor of that data and processes it only on behalf of and under the documented instruction of the Salon, to the extent needed to provide the Service.

DOKUMENT.PL sp. z o.o. is a separate controller for: the Salon's registration and billing data, Salon-user account data for authentication and security, technical and security logs, product-analytics data, and marketplace-client data for account management, booking intermediation and transactional notifications. This DPA does not apply to that scope; the Meeti Me Privacy Policy governs it.

The Salon becomes a separate controller of a client's data passed to it by the platform to fulfil a booking, from the moment it receives it.

Scope, nature and purpose of processing

Subject. Processing of personal data entrusted by the Salon in connection with the SaaS Service.

Nature. Automated operations in the information system: collection, recording, storage, adaptation, retrieval, consultation, use, transmission, restriction, erasure or destruction.

Purpose - solely to provide the Service to the Salon:

  1. keeping the appointment calendar and staff schedule,
  2. keeping the client records (CRM) with notes and visit history,
  3. receiving, confirming, changing and cancelling bookings on the Salon's behalf,
  4. sending notifications on the Salon's behalf by e-mail, SMS, push and Telegram,
  5. keeping the Salon's settlements and internal reports,
  6. providing export and data-copy features,
  7. technical support on the Salon's request,
  8. maintaining, protecting, backing up and restoring the environment.

Duration - for the term of the Agreement plus the export and deletion period (see the deletion section).

Categories of data subjects and data

Data subjects: the Salon's clients (including those booking via the marketplace and those entered by the Salon); the Salon's staff and collaborators; contact persons named by the Salon; legal guardians booking on behalf of a minor.

Data categories:

| Category | Approximate scope | | --- | --- | | Identification | Name, surname or display name | | Contact | E-mail, phone number, Telegram id if linked | | Booking | Date and time, service, staff member, status, change history | | Client record | Salon notes, preferences, visit history, spend and frequency | | Staff | Name, role, service scope, working hours, absences, work e-mail | | Communication | Content of booking-related messages, delivery status | | Technical | Session and device identifiers, IP, access logs |

Special categories. The platform is not intended for health data or other sensitive data. The Salon undertakes not to enter such data (including in note fields) without a separate legal basis and prior agreement of additional measures. Doing so against this undertaking is at the Salon's sole responsibility.

Children's data. The platform is for persons aged 16 or over; a booking for a minor is made by a legal guardian.

The controller's documented instructions

The Processor processes the data only on the Controller's documented instruction. Such instructions are: this DPA together with the Terms; the Salon's Account configuration; the actions of Salon users in the interface or via the API; requests from persons authorised by the Salon to meetime.company@gmail.com or meetime.company@gmail.com.

The Processor does not use the entrusted data for its own purposes, in particular does not train models on it, build marketing profiles, or pass it to third parties beyond the scope of this DPA.

If, in the Processor's view, an instruction infringes data-protection law, it informs the Controller without delay and may suspend the instruction until confirmed. Atypical instructions beyond the Service may require separate agreement and reasonable remuneration, of which the Processor gives prior notice.

Confidentiality of personnel

The Processor ensures that persons authorised to process the entrusted data are expressly authorised on a least-privilege basis, are bound to confidentiality, have been trained in data protection and security, and access only the data needed for their task. The confidentiality obligation survives the end of their engagement. The Processor keeps a register of authorised persons and reviews authorisations periodically.

Security measures

The Processor implements technical and organisational measures appropriate to the risk:

Encryption. TLS 1.2+ with enforced HTTPS and HSTS in transit; AES-256 at rest (database, S3 file storage, backups); passwords stored only as a salted cryptographic hash.

Access control. Role-based model (owner/manager/staff) on a least-privilege basis; strict data isolation between Salons; multi-factor authentication for administrative access; short-lived tokens; staff access to production data only on a justified, logged and time-limited basis.

Backups. Automated daily encrypted backups in at least two availability zones within the EEA; 30-day retention; periodic restore tests; RTO 8 h, RPO 24 h.

Logging and monitoring. Recording of security and data-access events; 12-month tamper-resistant log retention; anomaly monitoring, rate limiting, DoS protection.

Development. Environment separation (no real data outside production); code review, automated tests, dependency scanning; secrets kept in a vault; periodic security testing.

Organisational. Data-protection and security policies; an incident-management procedure; vetting of sub-processors; data protection by design and by default.

The Processor may change the measures provided the security level is not lowered. A current description is provided on request to meetime.company@gmail.com.

Sub-processors

The Controller gives general authorisation to engage sub-processors on the terms of this section. The Processor concludes with each an agreement imposing data-protection obligations no less strict than this DPA and remains fully liable for their performance.

Current list:

| Sub-processor | Role | Place of processing | | --- | --- | --- | | Amazon Web Services EMEA SARL | App and DB hosting, S3 storage, backups | EU regions | | Amazon SES | E-mail delivery on the Salon's behalf | EU regions | | SMS provider | SMS delivery on the Salon's behalf | EEA | | PostHog | Dashboard product analytics (after consent), pseudonymised | EU | | Telegram | Telegram notification delivery (after self-linking) | Outside the EEA, with safeguards |

Stripe serves only the Salon's subscription payments to DOKUMENT.PL sp. z o.o. and is a separate controller in that scope, not a sub-processor; it has no access to the Salon's client data.

Changes and objection. The Processor gives at least 30 days' notice of adding or replacing a sub-processor. The Controller may raise a reasoned objection within 30 days to meetime.company@gmail.com; the parties seek a solution in good faith, and if none is reached and the engagement is necessary for the Service, the Controller may terminate the Agreement with a proportionate refund and a preserved export right.

Assistance with data-subject rights

Taking account of the nature of processing, the Processor assists the Controller in responding to data-subject requests for access, rectification, erasure, restriction, portability and objection. Assistance is primarily through dashboard features (search, view, CSV/JSON export, correction, deletion or anonymisation of a client record).

A request that reaches the Processor directly is not answered on the merits but passed to the Controller within 3 business days. Where fulfilment goes beyond dashboard features, the Processor gives technical assistance within a time that lets the Controller meet its statutory deadlines, no later than 10 business days.

Breach notification

On becoming aware of a breach of the entrusted data, the Processor notifies the Controller without undue delay, no later than 24 hours after becoming aware, describing the nature of the breach, the categories and approximate number of subjects and records, the likely consequences and the measures taken. If full information cannot be given at once, it is provided in phases.

The decision to notify the supervisory authority and data subjects rests with the Controller; the Processor gives the necessary technical and informational support and keeps a register of breaches of the entrusted data.

Cross-border transfer

The entrusted data is processed within the European Economic Area (infrastructure, database, storage and backups in EU regions). For the Salon as controller this is a cross-border transfer to a processor in the EU, carried out in accordance with Article 29 of the Law of Ukraine "On the Protection of Personal Data", relying on the adequate level of protection ensured by EU law and by the measures in this DPA.

Transfer outside the EEA is possible only for: the optional Telegram channel (activated by the recipient); possible technical support by teams outside the EEA on a one-off logged-access basis; or on the Controller's separate instruction. Each such transfer is accompanied by appropriate safeguards, in particular standard contractual clauses and encryption.

Deletion or return of data after the engagement ends

At the Controller's choice the Processor deletes the entrusted data or returns it, and deletes existing copies, unless retention is required by law. Schedule:

  1. Days 1-30 after the Agreement ends - export period. Read-only access and self-service CSV/JSON export. On request to meetime.company@gmail.com the period is extended once by another 30 days.
  2. Up to 90 days - deletion from production systems.
  3. Up to 90 days - deletion from backups on the rotation cycle; until then backups stay encrypted.

On request during the export period, deletion is done sooner - within 14 days (subject to the backup rotation cycle). Deletion is confirmed in writing on request. This does not cover data whose retention the law requires (accounting and tax records for the subscription, data needed to defend legal claims).

Audits

The Processor provides the information needed to demonstrate compliance and allows audits:

Documentation. On request to meetime.company@gmail.com, within 20 business days: a description of security measures, the sub-processor list, a completed security questionnaire, and information on incidents affecting the Controller's data.

Audit. If documentation is insufficient - an audit on 30 days' notice, in working hours, no longer than 3 business days, no more than once a year (unless justified by a breach or an authority's instruction), without access to other clients' data, source code or sensitive security details, and without penetration testing absent separate consent. The Controller bears the cost; the first standard yearly audit does not impose the Processor's own costs.

Liability

Each party is liable for damage caused by processing to the extent of Ukrainian law. The Processor is liable only where it failed its own obligations or acted outside the Controller's lawful instructions. The Controller is liable for the legal basis, for informing subjects, for the lawfulness of instructions, and for processing data after receiving it from the platform.

The liability limitations set in the Terms (including the aggregate cap) apply, and do not apply to intent, gross negligence, harm to life or health, or any extent where a limitation is impermissible under mandatory law.

Final provisions

This DPA is amended as the Terms provide for amending a standard document (at least 15 days' notice and a right to terminate); changes required by law or an authority's guidance take effect in the corresponding time. Invalidity of one provision does not affect the rest.

This DPA is governed by law of Ukraine. Disputes are resolved by courts of Ukraine at the consumer place of residence, without prejudice to a data subject's right to complain to the supervisory authority Уповноважений Верховної Ради України з прав людини (ombudsman.gov.ua).

Binding version

This document is drawn up in Ukrainian (uk) and English (en). For the UA region the Ukrainian (uk) version is binding; the translation is provided for convenience and, in case of divergence, the Ukrainian version prevails.