Data Processing Agreement
Last updated: August 2026 · Forms part of the Terms of Service
This agreement applies whenever you use Sullio to handle personal data about your clients. It takes effect when you open an account and lasts as long as we hold that data. Where it conflicts with anything else in our terms, this agreement wins on the subject of data protection.
1. Roles
You are the data controllerfor your clients' personal data: you decide what to collect and why. Sullio Technologies Ltd is your data processor for that data, handling it only to run the booking service for you. We are a controller in our own right only for your own account details and how you use the platform, which our privacy policy covers.
2. What we process, and for whom
- Subject matter and purpose: providing the Sullio booking platform — taking appointments, sending confirmations and reminders, handling deposits, and any marketing you choose to send.
- Duration: for as long as your account is open, plus the retention periods set out in our privacy policy.
- Types of personal data: names, email addresses, phone numbers, appointment history, any notes you record, marketing preferences, and payment references. We never hold card numbers.
- Categories of data subject: your clients, and the staff you add to your account.
3. Our obligations
- We act only on your instructions.Using the platform is how you give them. We will not process your clients' data for our own purposes, sell it, or market to your clients on our own behalf. If the law ever requires us to process it otherwise, we will tell you first unless we are legally prohibited from doing so.
- Confidentiality. Everyone with access to the data is bound by a duty of confidence, and access is limited to those who need it to run or support the service.
- Security. We keep appropriate technical and organisational measures under Article 32 — encryption in transit and at rest, hashed passwords, access limited by role, rate limiting on public endpoints, and separation of environments so live data is never used for testing.
- Helping you meet requests. If one of your clients asks for a copy of their data, asks for it corrected, or asks for it deleted, we will help you answer within the statutory time limits. Much of it you can do yourself from your dashboard.
- Breaches. If we discover a personal data breach affecting your data, we will tell you without undue delay and give you what you need to meet your own 72-hour reporting duty.
- Records and audits. We will give you the information you reasonably need to show your own compliance, and will co-operate with an audit at reasonable notice and frequency.
4. Sub-processors
You give us general authorisation to use sub-processors to run the service. Each one is bound by data protection obligations no weaker than these, and we remain fully liable to you for their performance. The current list is published in our privacy policy. We will give you reasonable notice before adding or replacing one, and you may object — if we can't resolve your objection, you may end your subscription and take your data with you.
5. International transfers
Where a sub-processor handles data outside the UK, that transfer is covered by an adequacy decision or by the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses.
6. Return and deletion
You can export everything we hold for you at any time, including after your subscription ends — see your data. When you ask us to delete your account, we delete the personal data we hold for you and instruct our sub-processors to do the same, except where we are legally required to keep it — financial records, which HMRC requires us to keep for seven years.
7. Contact
Data protection questions, requests and objections go to johnmmailey@gmail.com. If you need this agreement signed as a standalone document, ask and we will send you one.