Legal
Data Processing Agreement
Last updated: 2 September 2026
This Data Processing Agreement (“DPA”) forms part of the QBarber Terms of Service between QBarber (“Processor”) and the barbershop or shop owner that uses the QBarber platform (“Controller”). It applies where QBarber processes Personal Data on the Controller’s behalf in connection with the service.
This DPA is intended to meet Article 28 of the UK GDPR and the Data Protection Act 2018. It should be read with our Privacy Statement, Terms of Service, and Cookie Policy.
1. Parties and incorporation
By creating a QBarber shop account, subscribing, or otherwise using the platform to process customer or operational data, the Controller agrees to this DPA. If the Controller does not agree, it must not use the service to process Personal Data.
In the event of conflict between this DPA and the Terms of Service on a data-protection matter, this DPA prevails. Nothing in this DPA reduces either party’s obligations under UK data-protection law.
2. Definitions
In this DPA, the following terms have the meanings below. Terms defined in UK GDPR have the same meaning unless the context requires otherwise.
- Controller means the barbershop, shop owner, or other organisation that determines the purposes and means of processing Personal Data of its customers and staff when using QBarber.
- Processor means QBarber, which processes Personal Data on behalf of the Controller in order to provide the service.
- Data Subject means an identified or identifiable living individual to whom Personal Data relates (including customers in a queue, barbers, and shop staff, as applicable).
- Personal Data means any information relating to a Data Subject, as defined in UK GDPR.
- Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- Sub-processor means a third party engaged by QBarber to process Personal Data on the Controller’s behalf.
- UK GDPR means the UK General Data Protection Regulation as tailored by the Data Protection Act 2018.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- Service means the QBarber queue-management platform, including website, shop-owner portal, admin tools, kiosk, tablet, customer mobile, public display, and related billing features.
This DPA does not apply where QBarber acts as an independent Controller (for example, in respect of shop-owner account credentials, platform billing records QBarber must keep for its own legal obligations, or website visitor data processed for QBarber’s own purposes). Those activities are described in the Privacy Statement.
3. Scope of processing
QBarber shall process Personal Data only:
- to provide, maintain, secure, and support the Service;
- in accordance with the Controller’s documented instructions, which include use of the Service’s features, configuration, and any reasonable written instructions that are consistent with the Service; and
- as required by UK law, in which case QBarber shall inform the Controller of that legal requirement before processing unless the law prohibits such notice.
QBarber shall not process Personal Data for its own purposes unrelated to the Service, and does not sell Personal Data.
If QBarber believes an instruction infringes UK GDPR or the Data Protection Act 2018, it shall promptly inform the Controller.
QBarber may use automated shop-status signals (such as billing status, compliance flags, or device pairing health) to determine whether certain features should be restricted or suspended, solely for the purpose of providing and securing the Service.
4. Nature and purpose of processing
The nature of the processing is the hosting, storage, transmission, display, and organisation of operational shop data through software, including real-time queue updates.
The purpose of the processing is to enable the Controller to:
- manage customer queues and estimated wait times;
- configure shop settings, branding, and opening hours;
- record barber availability and status;
- operate kiosk, tablet, display, and customer-mobile check-in;
- view operational analytics relating to the Controller’s own shop;
- operation of impersonation tools that allow authorised users (such as administrators or shop owners) to temporarily act through another role within their own shop environment for legitimate operational purposes, including support, troubleshooting, training, and account recovery;
- operation of optional loyalty or reward features enabled by the Controller;
- generation of queue analytics, wait-time estimates, and operational insights for the Controller’s shop; and
- automated or AI-assisted processing used to improve queue predictions, reliability, or operational accuracy, without automated decision-making that produces legal or significant effects on Data Subjects.
Processing is ongoing for the duration of the Controller’s use of the Service and any permitted retention period after termination.
5. Categories of data subjects
Personal Data processed under this DPA may relate to:
- customers and other individuals who join a shop queue;
- barbers and other staff of the Controller; and
- individuals whose details the Controller enters into the Service (for example names on tickets or contact details if provided).
6. Types of personal data processed
The types of Personal Data may include, depending on how the Controller uses the Service:
- names, friendly labels, and optional contact details;
- queue records (position, status, timestamps, preferred barber, ticket identifiers);
- device or client identifiers and push-notification tokens;
- barber names, photos, status, and related shop configuration;
- shop address and operational settings insofar as they identify individuals;
- logs and analytics derived from the above, generated in providing the Service;
- device identifiers, pairing tokens, and hardware linkage data used to connect kiosks, tablets, and displays to the Controller’s shop;
- loyalty configuration and reward-related data, where enabled by the Controller; and
- impersonation session logs and administrative-action logs generated for security and audit purposes.
The Controller shall not instruct QBarber to process special-category data (UK GDPR Articles 9 and 10) through the Service unless the parties have agreed additional measures in writing. The Service is not designed for that purpose.
7. Obligations of the Processor (QBarber)
QBarber shall:
- process Personal Data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by UK law;
- ensure that persons authorised to process Personal Data are under an appropriate duty of confidentiality;
- implement appropriate technical and organisational measures as described in this DPA;
- not engage a Sub-processor except as permitted in this DPA;
- taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, with Data Subject rights requests;
- assist the Controller in meeting its obligations regarding security, Personal Data Breaches, data protection impact assessments, and prior consultation, taking into account the nature of processing and information available to QBarber;
- at the choice of the Controller, delete or return Personal Data after the end of the provision of processing services, and delete existing copies unless UK law requires storage;
- make available to the Controller information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as set out below;
- not sell Personal Data or use it for independent marketing; and
- maintain audit logs for impersonation sessions and administrative actions performed through the Service, and make such logs available to the Controller upon reasonable request.
8. Obligations of the Controller (the shop)
The Controller shall:
- ensure that it has a lawful basis and, where required, valid notices or consents for the Personal Data it causes to be processed through the Service;
- be responsible for the accuracy, quality, and legality of Personal Data it enters or collects, including customer names and contact details;
- not instruct QBarber to process data in a manner that would infringe UK GDPR or other applicable law;
- configure the Service (including staff access) in a manner consistent with the principle of least privilege;
- respond to Data Subject requests that relate to the Controller’s processing, using the Service’s tools where available;
- promptly notify QBarber of any unauthorised use of the Controller’s accounts that may affect Personal Data;
- be responsible for any actions taken through impersonation tools by its authorised staff and ensure impersonation is used only for legitimate operational purposes; and
- keep device pairing codes secure and not share them outside authorised staff.
The Controller remains responsible for its own in-shop practices, including how it collects information from customers at the kiosk or otherwise.
9. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, QBarber shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- encryption of Personal Data in transit using TLS/HTTPS;
- role-based access control (RBAC) for shop, barber, support, and admin functions;
- restricted administrative access to production systems and Personal Data;
- hashed storage of passwords and similar secrets;
- authentication, session controls, and monitoring reasonably designed to detect misuse;
- secure hosting of applications and related infrastructure;
- monitoring and logging of impersonation sessions and administrative actions;
- secure handling of device pairing tokens and hardware identifiers; and
- controls to prevent cross-shop impersonation or unauthorised role elevation.
The Controller is responsible for keeping its own credentials confidential and for access granted to its staff.
10. Sub-processors
The Controller provides a general authorisation for QBarber to engage Sub-processors to deliver the Service, provided that QBarber:
- imposes on each Sub-processor data-protection obligations substantially no less protective than those in this DPA; and
- remains responsible to the Controller for the Sub-processor’s performance of those obligations.
Current categories of Sub-processors include:
- Vercel — application hosting and content delivery for QBarber front-end applications;
- Cloudflare — network, DNS, and security services;
- Stripe — payment processing for subscriptions and related charges (to the extent payment data is processed in connection with the Controller’s account);
- Transactional email provider — sending service, account, and operational emails; and
- Infrastructure and database hosting providers — storage and operation of the Service backend;
- Error and performance monitoring providers — used to detect crashes, reliability issues, or operational anomalies (if introduced); and
- AI-assisted analytics or queue-estimation providers — used only for operational reliability and not for marketing (if introduced).
QBarber shall give the Controller reasonable notice of the addition or replacement of a material Sub-processor (including by updating this DPA or the Privacy Statement, or by email to the account contact). The Controller may object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Controller may terminate the affected Service in accordance with the Terms.
11. International transfers and safeguards
Personal Data may be processed in the United Kingdom and, where Sub-processors operate elsewhere, in other countries.
Where QBarber transfers Personal Data outside the UK, it shall ensure an appropriate safeguard is in place, such as a UK adequacy regulation or the UK International Data Transfer Agreement / Addendum (or another lawful mechanism).
The Controller instructs QBarber to make such transfers as are reasonably necessary to provide the Service through the Sub-processors listed in this DPA.
12. Data breach notification procedures
QBarber shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
The notification shall include, to the extent reasonably available at the time:
- a description of the nature of the breach;
- the categories and approximate number of Data Subjects and records concerned;
- likely consequences; and
- measures taken or proposed to address the breach and mitigate its effects.
QBarber shall provide further information as it becomes available. The Controller is responsible for determining whether to notify the Information Commissioner’s Office and Data Subjects, and for doing so within applicable time limits (including the UK GDPR 72-hour ICO notification rule where it applies). QBarber shall reasonably cooperate with that assessment.
The Controller shall notify QBarber promptly of any Personal Data Breach that occurs in the Controller’s own environment (for example compromised staff logins) and that may affect the Service.
13. Data retention and deletion
QBarber shall retain Personal Data processed under this DPA only for as long as needed to provide the Service and to comply with this DPA and UK law.
Queue and operational records may be retained for a limited period after completion of a ticket for support, security, and operational analytics for the Controller. Account-related data follows the retention described in the Privacy Statement and any legal retention duty (including billing records QBarber keeps as an independent Controller).
Impersonation and administrative-action logs may be retained for a reasonable period for security, audit, fraud-prevention, and operational integrity.
Upon written request during the term, QBarber shall, where technically feasible, assist the Controller to delete or correct specific Personal Data using Service functionality or a reasonable support process.
14. Assistance with data subject rights
Taking into account the nature of the processing, QBarber shall assist the Controller in fulfilling requests from Data Subjects to exercise rights under UK GDPR, including access, rectification, erasure, restriction, objection, and portability, insofar as possible through the Service or reasonable support.
If QBarber receives a request directly from a Data Subject relating to Personal Data for which the Controller is Controller, QBarber shall, unless prohibited by law, promptly redirect the Data Subject to the Controller or notify the Controller, and shall not respond substantively except on the Controller’s documented instructions or as required by law.
Where impersonation logs contain Personal Data, QBarber shall assist the Controller in responding to Data Subject requests relating to those logs.
15. Audit rights
Upon reasonable written notice, QBarber shall make available information reasonably necessary to demonstrate compliance with this DPA.
The Controller may request an audit no more than once in any twelve-month period, unless a Personal Data Breach or a competent authority requires an additional audit. Audits shall:
- be reasonable in scope and duration;
- be conducted in a manner that does not disrupt the Service or other customers;
- be subject to confidentiality undertakings; and
- take place during normal business hours, or remotely where appropriate.
QBarber may satisfy an audit request by providing recent independent reports, certifications, or written responses, where those reasonably demonstrate compliance. The Controller shall bear its own costs and any reasonable costs of an on-site audit that goes beyond standard documentation, unless the audit reveals a material breach of this DPA by QBarber.
16. Liability and indemnity
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing in this DPA excludes liability that cannot be excluded under the law of England and Wales, including for death or personal injury caused by negligence, or for fraud.
The Controller shall indemnify QBarber against claims, losses, and reasonable costs arising from: (a) Personal Data the Controller provides that is inaccurate, unlawful, or collected without a lawful basis; (b) the Controller’s instructions; or (c) the Controller’s failure to comply with UK GDPR in its capacity as Controller.
QBarber shall be liable to the Controller for damages caused by processing where QBarber has not complied with UK GDPR obligations specifically directed to processors, or has acted outside or contrary to the Controller’s lawful instructions, as provided in UK GDPR.
17. Termination and data return or deletion
This DPA continues for as long as QBarber processes Personal Data on behalf of the Controller and survives termination to the extent needed to delete or return data and to handle residual legal duties.
Upon termination of the Service, the Controller may, within thirty (30) days, request return of Personal Data in a reasonable common machine-readable format, where technically feasible. After that period, or immediately if no return is requested, QBarber shall delete Personal Data processed under this DPA, except for copies retained as required by UK law or as QBarber must keep as an independent Controller (such as invoices).
Deletion from live systems shall occur within a reasonable period. Backup copies may persist until they cycle out in accordance with QBarber’s backup schedule, after which they are overwritten or destroyed.
18. General
This DPA is governed by the law of England and Wales. The courts of England and Wales have jurisdiction, consistent with the Terms of Service.
QBarber may update this DPA to reflect changes in law, Sub-processors, or the Service. Material changes will be notified in a manner consistent with the Terms. Continued use of the Service after the effective date constitutes acceptance, except where applicable law requires a different form of agreement.
If any provision of this DPA is held invalid, the remaining provisions continue in force.
19. Contact information
Notices and data-protection enquiries under this DPA should be sent to:
QBarber (Processor)
United Kingdom
Email: hello@qbarber.co.uk
Website: https://staging.qbarber.co.uk
Related documents: Privacy Statement · Terms of Service · Cookie Policy