1. Parties and order of precedence
If there is a conflict about data protection, this DPA prevails over the Business Terms for that conflict, except that the Business Terms liability cap and exclusions still apply to the extent UK data protection law allows.
2. Roles
For Client Personal Data (defined in the Annex), the business is controller and COZQ Limited is processor. For Cobbtree account, billing, security and platform-administration data, COZQ Limited is an independent controller and this DPA does not apply to that processing.
3. Subject matter and duration
The Processor provides the Cobbtree software, including appointments, client records, payments metadata display, Sites, messaging tools and related features the Controller enables. Processing lasts for the subscription and any permitted retention afterwards.
4. Instructions
The Processor shall process Client Personal Data only on documented instructions from the Controller, including in the Business Terms, product configuration, and this DPA, unless UK law requires otherwise. The Controller instructs the Processor to process the categories in the Annex in order to provide Cobbtree. If an instruction infringes UK GDPR, the Processor shall tell the Controller.
5. Confidentiality
Persons authorised to process Client Personal Data are under a confidentiality duty.
6. Security
Taking into account the state of the art, costs, and the nature of salon and clinic records (which may include health information), the Processor shall implement appropriate technical and organisational measures. These include encryption in transit, access controls, secure credential management, monitoring and incident-response procedures. The Processor does not warrant a named external certification.
7. Subprocessors
The Controller generally authorises the Processor to use the subprocessors listed in the Privacy Notice / this Annex. The Processor shall impose data-protection terms equivalent in substance to this DPA. The Processor remains responsible to the Controller for a subprocessor's performance of those obligations.
The Processor shall give notice of a material subprocessor change by updating the Privacy Notice or Legal Centre and, where reasonably practicable, by email to the business owner. The Controller may object on reasonable data-protection grounds within 14 days. If the parties cannot resolve an objection, the Controller may stop using the affected feature or terminate the subscription at period end.
8. International transfers
Where the Processor transfers Client Personal Data outside the UK, it shall ensure a lawful transfer mechanism (adequacy or a UK-approved transfer tool) as described in the Privacy Notice.
9. Assistance
Taking into account the nature of processing, the Processor shall assist the Controller with data-subject rights requests, security obligations, data-protection impact assessments, and prior consultation with the ICO, by providing reasonable product tools and information. The Controller handles requests that relate to its client files unless the request is clearly directed at Cobbtree as controller.
10. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Client Personal Data, with information reasonably available at the time to help the Controller meet Article 33 and 34 duties.
11. Deletion and return
After the end of processing, the Processor shall delete or return Client Personal Data at the Controller's choice, unless UK law requires storage (including tax and dispute records). The Controller should export reports it needs before access ends. Backup copies expire on the backup cycle and are not erased instantaneously.
12. Information and audits
The Processor shall make available information reasonably necessary to demonstrate Article 28 compliance. Audits shall be limited to once in any 12-month period unless a competent authority or a confirmed breach reasonably requires more, on reasonable notice, during business hours, and subject to confidentiality. The Processor may satisfy an audit request with up-to-date security summaries rather than on-site inspection where that is proportionate.
13. Liability
Article 82 UK GDPR allocation applies. Contractual caps in the Business Terms apply only to the extent they do not limit liability that cannot legally be limited.
Annex: processing description
Subject matter: hosting and processing data the Controller enters into Cobbtree.
Duration: the subscription and permitted retention.
Nature and purpose: collection, storage, retrieval, display, organisation, transmission, deletion and related operations needed to provide appointments, CRM, payments display, Sites, messaging, reports, imports and exports.
Categories of data subjects: the Controller's clients, staff, suppliers and other people the Controller records.
Categories of personal data: identity, contact, appointment, payment metadata, photos, reviews, and any other fields the Controller configures.
Special-category data: may include health-related consultation, allergy, medication, pregnancy, skin, disability or patch-test information if the Controller chooses to store it. The Controller must not instruct processing of special-category data without an Article 9 condition.
Subprocessors:
- Stripe group companies (including the Stripe entity named in Stripe's UK terms) - Card payments, Connect onboarding, Billing, Terminal and related payment metadata (EEA, United Kingdom and United States, as described by Stripe)
- Cloudflare, Inc. - DNS, TLS termination, traffic protection and related edge services for public sites (Global edge network. Cloudflare's customer content region depends on Cloudflare's configuration)
- Infrastructure hosting providers - Secure hosting and operation of the Cobbtree service (Locations used by contracted providers under applicable data-transfer safeguards)
- Cloud storage providers - Secure storage of images, files and other uploaded media (Locations used by contracted providers under applicable data-transfer safeguards)
- Email delivery providers - Transactional and account email delivery and inbound support routing (Locations used by contracted providers under applicable data-transfer safeguards)
- Expo (Expo Application Services) - Push notification delivery for the Cobbtree mobile apps (United States and other locations used by Expo)
- The SMS Works Ltd - SMS delivery when Cobbtree SMS is enabled for a business (United Kingdom, with any routing used by that provider to reach the destination handset)
- OpenStreetMap Nominatim (geocoding) - Turning addresses and map queries into coordinates for marketplace search (Nominatim operators as published by OpenStreetMap)
- tawk.to - Optional live support chat widget on Cobbtree websites (United States and other locations used by tawk.to)
- Google (Google Fonts / Material Symbols) - Loading icon fonts used in the Cobbtree web interface (Google's global infrastructure)
- Google - Optional Google Calendar or Google Business Profile connection chosen by a business (Google's global infrastructure)
- Microsoft - Optional Microsoft calendar connection chosen by a business (Microsoft's global infrastructure)
- Meta Platforms Ireland Limited / Facebook - Optional Facebook Page booking links chosen by a business (Meta's global infrastructure)
- Apple - App Store distribution, Apple Push via Expo, and Apple Wallet passes where used (Apple's global infrastructure)