ChairTenderHome

Last updated: July 2026

Data Processing Agreement

This summarises how Fluxt Ltd processes personal data on behalf of a shop that uses ChairTender. It forms part of, and is being finalised with, our formal service agreement.

Roles

For a shop's client data, the shop is the controller and Fluxt Ltd is the processor. We process that data only on the shop's documented instructions, which are given by the shop's use of the service.

Scope of processing

Subprocessors

We use vetted subprocessors to deliver the service, each processing data only as needed:

We will give notice of any change to our subprocessors so the shop can object.

Security

We apply appropriate technical and organisational measures, including access controls, encryption in transit, tenant isolation, and least-privilege access. We store only payment provider references, never raw card or bank details.

Data-subject requests

We help the shop meet requests from its clients (access, correction, export, deletion). The service provides a per-shop data export and a client-deletion function; deletion redacts a client's personal data while preserving the appointment and payment records the shop needs as business records.

Retention, return, and deletion

Conversation logs are pruned on a schedule (shop-configurable, twelve months by default). Appointment records are retained as the shop's business records. On the end of the agreement, the shop may export its data, and we will delete or return it as agreed.

International transfers

Where a subprocessor processes data outside the UK, we rely on an appropriate transfer mechanism (for example, the UK International Data Transfer Agreement or an adequacy decision).

Breach notification

We will notify the shop without undue delay after becoming aware of a personal data breach affecting its client data, with the information the shop needs to meet its own obligations.

Contact

Questions: hello@chairtender.com.