Data Processing Agreement (DPA)
Data Processing Agreement
Last updated: 03-02-2026
Introduction
This Data Processing Agreement ("DPA") is part of the Partner Terms and/or the agreement between:
- Lookster, Chamber of Commerce 94593051, Piet Heinstraat 12, 7511JE Enschede ("Processor" or "Lookster"); and
- the salon/partner using the Lookster Salon Software/Dashboard ("Controller" or "Partner").
Together: "Parties".
1. Purpose and scope
- This DPA applies when Lookster processes personal data on behalf of Partner in the context of providing the Salon Software/Dashboard and related services (such as support, maintenance and security).
- Parties acknowledge that:
- Partner is the controller for personal data of (potential) customers and contact persons that Partner processes in the Dashboard; and
- Lookster acts as a processor insofar as Lookster processes those personal data on behalf of Partner.
- This DPA does not apply to processing where Lookster independently determines the purpose and means (e.g. own business administration, invoicing, security/fraud prevention for its own systems, or Lookster website analytics). Lookster acts as an (independent) controller for these processing operations.
2. Definitions
- GDPR: the General Data Protection Regulation (EU) 2016/679.
- Personal data, Processing, Processor, Controller, Data subject: as defined in the GDPR.
- Subprocessor: a processor engaged by Lookster who carries out parts of the processing on behalf of Partner.
3. Subject of the processing (Appendix 1)
- The details of the processing (categories of personal data, data subjects, purposes, duration) are set out in Appendix 1 to this DPA.
4. Instructions from Partner
- Lookster only processes personal data:
- based on written instructions from Partner; and
- to the extent necessary to provide the Services in accordance with the agreement/Partner Terms.
- Instructions may emerge from the use of Dashboard functionalities and the configurations that Partner sets.
- If Lookster believes that an instruction is contrary to the GDPR or other applicable law, Lookster will inform Partner of this (to the extent permitted by law).
5. Security measures
- Lookster takes appropriate technical and organizational measures to protect personal data against loss, unauthorized access, modification or disclosure, taking into account the state of the art, implementation costs and the nature, scope, context and purposes of the processing.
- "Appropriate measures" include in any case (where applicable):
- access security (accounts, roles/rights);
- transport security (e.g. TLS/HTTPS where possible);
- logging/monitoring for security and stability purposes;
- backups and recovery measures (best effort);
- organizational measures (need-to-know, confidentiality).
- Partner is responsible for secure configuration and use on its side, including:
- managing Seats/employee accounts and using strong passwords;
- preventing account sharing;
- correctly setting roles/rights within the Dashboard;
- processing personal data in accordance with its own privacy policy and legal obligations.
6. Confidentiality
- Lookster guarantees that persons who process personal data under its responsibility (employees, contractors) are bound by appropriate confidentiality.
7. Subprocessors
- Partner hereby gives Lookster general permission to engage sub-processors, to the extent necessary for the provision of the Services.
- Lookster remains responsible for sub-processors' compliance with the obligations under this DPA.
- Current (known) sub-processors within the scope of this DPA:
- Hosting/Infrastructure: Hetzner (data center/hosting).
Explanation: Google Analytics is used by Lookster exclusively for Lookster website analytics and is therefore not covered by this DPA (see Article 1.3).
- Lookster may change or add sub-processors. Lookster will inform Partner of this via an update in the Platform, by email or via a current list (e.g. on a support page), unless this is disproportionate. If Partner reasonably has serious objections to a new sub-processor, Parties will enter into consultation to find a solution. If no solution is possible, Partner may (as a last resort) terminate the agreement with effect from the introduction date of that sub-processor, without penalty, to the extent permitted by law.
8. Data breaches and security incidents
- A “Data Breach” means a personal data breach within the meaning of Article 4(12) GDPR.
- Lookster shall report a Data Breach to Partner without unreasonable delay after Lookster has become aware of the Data Breach, providing, to the extent available:
- nature of the Data Breach;
- (probable) consequences;
- (proposed) measures to limit the Data Breach;
- contact point for follow-up.
- Partner is responsible for any notifications to the Dutch Data Protection Authority and/or data subjects, unless the Parties agree otherwise in writing. Lookster will reasonably support Partner with information that Partner needs for those notifications.
9. Assistance with data subject rights and DPIA
- Lookster will support Partner, as far as reasonably possible and appropriate to the nature of the processing, in:
- requests from data subjects (access, rectification, deletion, restriction, data portability, objection);
- security obligations and reporting obligations;
- DPIAs (data protection impact assessments) and prior consultation with the supervisory authority, to the extent that the processing by Lookster so requires.
- If Lookster receives a request directly from a data subject that relates to data for which Partner is the controller, Lookster will forward this request (to the extent permitted) to Partner and Lookster will not substantively respond to the data subject, unless Partner instructs Lookster to do so or legal obligations provide otherwise.
10. Transfer outside the EEA
- Lookster will not process or have personal data processed outside the European Economic Area (EEA) unless:
- Partner gives permission for this or gives instructions; or
- this is necessary for a sub-processor and appropriate safeguards are applied (e.g. EU Standard Contractual Clauses) in accordance with GDPR.
11. Retention periods, deletion and return
- Lookster processes personal data during the term of the agreement and thereafter only as long as and to the extent that:
- necessary to complete the Services (e.g. limited technical aftercare);
- necessary due to legal obligations; or
- necessary for security/backups, within reasonable timescales.
- After termination of the Services, Partner may export data via the Dashboard (where available) prior to termination. Upon request, Lookster can, where reasonably possible, provide an export at any reasonable costs (as agreed in the partner terms).
- Lookster will delete or anonymize personal data on behalf of Partner within a reasonable period after termination, unless:
- legal retention obligations or security/backup cycle temporarily prevent this; or
- Partner requests longer storage in writing.
12. Audits and information
- Partner has the right to verify compliance with this DPA. Parties agree that audits:
- take place no more than once a year, unless there is a serious incident or valid reason;
- during office hours and with reasonable notice;
- respect the security and confidentiality of other customers/partners.
- Instead of a physical audit, Lookster may also (first) offer reasonable evidence, such as an overview of measures, policies or (if available) audit reports/certifications.
- Costs of audits are borne by Partner, unless an audit demonstrates material non-compliance on the part of Lookster.
13. Liability
- The liability of the Parties under this DPA follows the liability provisions of the Partner Terms/main agreement, unless mandatory law provides otherwise.
14. Ranking and duration
- In the event of any conflict between this DPA and other data protection contractual documents, this DPA shall prevail.
- This DPA applies as long as Lookster processes personal data on behalf of Partner.
Appendix 1 – description of the processing
- Subject: Hosting, storing, making available and supporting the Salon Software/Dashboard and related functions (agenda, appointments, customer management, employee accounts) on behalf of Partner.
- Purposes of the processing
- Schedule and manage appointments
- Manage customer data
- Communication about bookings (e.g. confirmations/reminders, if activated)
- Technical management, support, maintenance and security
- Reports/statistics within the Dashboard (if based on Partner data)
- Categories of people involved
- (Potential) customers of Partner
- Employees/users of Partner (Seats)
- Partner Contacts (Owner/Manager)
- Categories of personal data (example)
- Identification: name (first and last name)
- Contact: email, telephone number
- Booking details: appointment date/time, service selected, employee, comments
- Company and account details: salon name, address, login/account details
Optional (depending on Partner usage): notes/preferences.
- Special personal data (recommended / limitation)
- Partner will not process special categories of personal data within the meaning of Article 9 GDPR (such as medical data) via the Dashboard, nor data about criminal convictions and criminal offenses (Article 10 GDPR), unless this is strictly necessary for the performance of the service by Partner and Partner has a valid basis and appropriate guarantees.
- If Partner nevertheless enters such data, Partner remains fully responsible for:
- the legality (basis), transparency and information obligation towards those involved;
- minimizing the data (data minimization) and limiting access;
- any additional security and retention requirements.
Lookster is not responsible for Partner's choice to process such data.
- Duration of processing
For the duration of the agreement and thereafter in accordance with Article 11 (deletion/retention/backups).