Parties
| Processor | Spine HQ, trading as Meet Marley, KvK 82037906, VAT NL003631560B86, Klaverhof 146, 2403 XJ Alphen aan den Rijn, Netherlands |
| Controller | The salon that has entered into the Meet Marley Terms of Service ("you") |
This agreement forms part of the Terms of Service and applies automatically from the moment you create a Meet Marley account. It is required by art. 28(3) GDPR.
1. Roles
For the booking and client-management service, you are the controller and Meet Marley is the processor. You decide which clients to record, what to write about them, and why. We process that data to provide the service and on your instructions.
For several clearly-defined things, Meet Marley is a controller in its own right, because we determine the purpose and nobody instructs us to do them:
| Processing | Why we are the controller | Our basis |
|---|---|---|
| The public salon directory and cross-tenant search | We aggregate listed salons into our own product to help consumers find them. That is our commercial purpose, not yours | Legitimate interest; and you opt in per salon — it is off by default |
| Publishing reviews in the directory | We decide reviews display as "Jane D.", how they are moderated, and how long they stay up | Legitimate interest, with the reviewer told at submission |
| Platform-wide statistics | Counts across every salon, for our own reporting | Legitimate interest, aggregate only |
| Security and audit logging | We decide what is logged and for how long; you cannot switch it off | Legitimate interest in a secure service |
| Product analytics | Improving our software. Attributed to a salon, never a person | Legitimate interest |
| Retention periods | The windows in §5 are set by us and you cannot change them | Legal obligation and legitimate interest |
This split is deliberate and stated rather than glossed over, because the difference decides who answers a data subject and who is accountable to the supervisory authority. Where we act as controller, we carry the obligation and we do not act on your instruction.
Meet Marley is a separate controller for your own account data — the names and email addresses of you and your staff, your billing records, and our security logs. That processing is described in our Privacy Statement, not here. The distinction matters: our security audit log is our own record as a controller, kept for the periods in §5, and it is not something you instruct us to erase.
Why an erasure request does not shorten it. Art. 17(3) GDPR keeps the right to erasure from applying where processing is necessary for compliance with a legal obligation, and where it is necessary for the establishment, exercise or defence of legal claims. That is what an audit log is for: showing later, and to somebody else, who did what. We rely on that provision rather than simply declining, because a right set aside without a stated ground is just a refusal.
2. Subject matter, duration, nature and purpose
The subject matter, duration, nature and purpose of the processing, and the categories of data subject and personal data, are set out in Annex I.
Special categories (art. 9). The Notes field described in Annex I is free text and we do not restrict what goes into it. In a salon context it will predictably be used for allergies, skin and scalp conditions, pregnancy and medication — which are health data under art. 9 GDPR.
If you enter such data you remain the controller of it, and you need your own art. 9 basis — in practice, explicit consent from the client. Meet Marley does not ask for or require it, and does not treat the field as a special-category field, which means the safeguards appropriate to health data are yours to apply.
The field is fully covered by the rights process in §4: its contents can be produced on request and erased on request, like everything else in a client record.
3. Instructions
We process your clients' data only on your documented instructions. Your use of the service is the instruction. We will tell you if we believe an instruction breaches the GDPR.
We do not sell your clients' data, do not use it to advertise, and do not use it to train machine learning models.
Meet Marley operates a public salon directory. Your salon appears there only if you switch listing on — it is off by default. Reviews shown publicly display an abbreviated client name ("Jane D.") and never an email address or telephone number.
4. Assisting you with data subject rights
Art. 28(3)(e) requires us to help you answer requests from your clients. Here is what is true today, stated plainly rather than as a promise we cannot keep.
Every request will be fulfilled. Access, correction and erasure are all carried out in full — the only difference today is who performs the steps.
Self-service, by you, in the app: your own account details and those of your staff.
Carried out by us, on your instruction: requests concerning an individual client record — access, correction, export and erasure, including the Notes field and anything recorded in it. Email [email protected] and we will complete it within 5 working days, at no charge. There is no limit on what can be removed: a client record can be erased completely, and we do so on request.
A self-service screen for this is in development. Until it ships, the route above is the mechanism, and it delivers the same outcome on the same legal timescale.
What erasure means in practice. The record is removed from the live database immediately. Backups retain a copy until they expire on their fixed schedule — see §5 — during which it is never queried or restored selectively, and any restore has the erasure re-applied. This is how erasure works in practice in any system that keeps disaster-recovery backups.
For account holders (you and your staff), we provide access to and correction of profile data in the application. Account deletion is currently handled by us on request.
5. Retention and deletion
| Data | Retention | Enforced by |
|---|---|---|
| Client records | 24 months after that client's last appointment, then anonymised | Automated retention sweep |
| Appointment records | Kept as financial history; the client's identity and the appointment's free-text notes are removed on the same pass | Automated retention sweep |
| Billing audit records | 84 months (7 years), Dutch bewaarplicht | Automated retention sweep |
| Authentication and security audit records | 24 months | Automated retention sweep |
| Other audit records | 12 months | Automated retention sweep |
| Sign-in sessions | 30 days | Token expiry |
| Backups — point-in-time recovery | ≈7 days, rolling | Railway PITR |
| Backups — daily volume snapshots | ≈7 days, rolling | Railway scheduled backups |
| Backups — weekly volume snapshots | Rolling, on our hosting provider's schedule | Railway scheduled backups |
| Backups — monthly volume snapshots | Rolling, on our hosting provider's schedule — so a copy can persist for months | Railway scheduled backups |
Backups, and what erasure actually means
Anonymisation and deletion act on the live database. They do not reach into backups, and no system's do — a backup that could be selectively edited would not be a reliable backup.
So when a record is anonymised or a client's data is erased on request, it remains in backups until those backups age out. In the meantime it is put beyond use: backups are not queried, not restored selectively, and exist solely for disaster recovery. Our understanding is that this is a widely taken position under the GDPR, and that the European Data Protection Board and the Autoriteit Persoonsgegevens both treat it as compliant provided three things hold, which they do here:
- Backups expire on a fixed schedule rather than being kept indefinitely.
- Nobody queries a backup to retrieve data that was erased from the live system.
- If a restore ever happens, the erasures are re-applied afterwards. For retention that is automatic — the sweep runs daily and cross-tenant, so anything a restore reinstates is re-anonymised on its next run. A manual erasure has no such safety net and is re-applied by hand, from the erasure register. The procedure is in our restore runbook.
Be aware of the monthly snapshots. Point-in-time recovery covers about a week, which is the figure people usually have in mind when they think about backups. But the volume-backup schedule also keeps weekly and monthly snapshots, so the true tail during which a copy still exists is measured in months, not days.
That does not change the legal position — beyond-use is beyond-use whatever the window — but it does change what we can honestly tell someone who asks "when will it actually be gone", so it is stated here rather than rounded down to the reassuring number.
Dormancy is measured per client, from their own most recent appointment — not from your salon's activity. A client who last visited three years ago is anonymised even though you are still trading, because the purpose the data was collected for has ended for them.
We anonymise rather than delete. The appointment row survives with its date, service and amount, so your revenue history and your accounts stay intact. What goes is the person: name, email address, telephone number, notes, and language. The visit count stays, because a number attached to nobody identifies nobody and it keeps your lifetime totals honest. Any review keeps its rating and comment but loses the name it was attributed to.
On termination we delete or return your clients' data within 30 days, except where retention is required by law. Audit records covering your account are retained for the periods above as Meet Marley's own controller-side record of who did what, and an erasure request does not shorten them. The ground is art. 17(3) GDPR: the right to erasure does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims. See §1.
6. Confidentiality
Everyone at Meet Marley with access to your clients' data is bound by confidentiality. Access is limited to those who need it to run and support the service.
7. Security (art. 32)
The technical and organisational measures we apply are set out in Annex II.
8. Sub-processors
You give general authorisation for the sub-processors listed in Annex III. We will give 30 days' notice before adding or replacing one, and you may object; if we cannot resolve your objection you may terminate without penalty for the remainder of the paid period.
9. Personal data breach
We notify you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your clients' data, with the nature of the breach, likely consequences, and measures taken. Notifying the Autoriteit Persoonsgegevens and your clients is your responsibility as controller; we will give you what you need to do it.
The 48 hours is ours, not the law's. Art. 33(2) requires a processor to notify the controller without undue delay and sets no fixed period. Forty-eight hours is a commitment we are choosing to make, and it is tighter than the article requires — it exists so a salon still has a day inside its own 72-hour clock to the AP. It is also a promise we have to be able to keep at 23:00 on a Saturday with one person on call.
10. Audit
On reasonable notice, and at most once a year unless a breach has occurred, we will provide the information needed to demonstrate compliance with this agreement.
11. Governing law
Dutch law. Disputes go to the competent court in the Netherlands.
Annex I — Details of the processing
Subject matter. Provision of appointment booking and salon management software.
Duration. For as long as you hold an account, plus the retention periods in §5.
Nature and purpose. Taking and managing bookings; sending confirmations, reminders and receipts; recording appointment history; collecting and publishing verified reviews; producing reporting and statistics for you.
Categories of data subject. Your clients — consumers who book appointments — and, where you enter them, people who contact you without booking.
Categories of personal data.
| Category | Fields |
|---|---|
| Identity | Name |
| Contact | Email address, telephone number |
| Appointment data | Date, time, service, assigned staff member, status, price, tip, payment method |
| Preferences | Language, visit count |
| Free text | The Notes field on a client record and on an appointment |
| Reviews | Rating, comment, name as captured at submission |
| Technical | IP address and user agent, recorded in the security audit log |
Special categories. Not intentionally processed. See the warning under §2 regarding the Notes field.
Annex II — Technical and organisational measures
Each measure below is implemented in the product today.
Access control and authentication
- Passwords hashed with BCrypt; never stored or recoverable in plain text
- Access tokens valid 15 minutes, with refresh-token rotation and reuse detection
- Automatic account lockout after five consecutive failed sign-in attempts
- Rate limiting on sign-in, public booking and review submission
- Superadmin access is a separate account type with its own credential and its own audit category
Tenant separation
- Every query is filtered by salon at the data-access layer, applied globally rather than per query
- One salon can never reach another's data. There is no route, setting or role that allows it
- The single exception is our own support access, described below. It is not a way for one salon to see another; it is us, named and logged, working inside one salon at a time
Logging and accountability
- Append-only audit log enforced by a database trigger, which rejects
DELETEoutright and rejectsUPDATEof anything but the redaction columns. The guarantee is at the database, not in application code, so it holds even against someone with direct database access - Retention sweeps run automatically per category
Support access to your salon
Sometimes we work inside your salon — most often to set it up with you, occasionally to see a problem you are describing. We would rather tell you exactly how that works than leave you to assume.
- It is us, not you. Nobody signs in as you or as one of your staff. The session carries the name of the person at Marley who opened it, and Studio shows a banner naming them for as long as it lasts
- Two levels, and the smaller one is the default. A setup session reaches only your salon's configuration — services, prices, staff, locations, opening hours, branding. It cannot open your appointments, your clients or your reviews. A support session can, and is used only when the question is about them
- A reason is recorded before it opens. It cannot be started without one
- Two-step sign-in is required, and the session is short-lived and expires on its own
- You can see it. Every action appears in your own Activity screen, labelled Marley support rather than as one of your team. Nothing we do inside your salon is hidden from you, and the audit log it is written to cannot be edited or deleted — see above
- Money and credentials are out of reach. A session cannot change your subscription, set up a direct debit, open your payment details, publish your salon to the public directory, or set a staff PIN
Data integrity and input handling
- Uploads restricted to PNG/JPEG/WebP, with the format determined by inspecting the file's leading bytes rather than trusting the declared content type; SVG is refused because it can carry script
- Upload size capped
Storage and transport
- TLS in transit; HSTS enforced
- Private object storage — every file read goes through a short-lived presigned URL, and no object is publicly readable
- Encryption at rest as provided by Railway and its Postgres service
- Point-in-time recovery backups
Ongoing
- Error monitoring with EU-resident processing
- Dependency vulnerability pinning (documented in the repository's central package configuration)
Browser-side
- A Content-Security-Policy on every application, restricting the origins a page may load from or send data to
Strict-Transport-Security,X-Content-Type-Options: nosniffand a referrer policy on every response- The salon-facing and administrative applications additionally refuse to be framed by other sites
Annex III — Sub-processors
Seven, and this annex is deliberately narrower than the full recipient list. It covers only sub-processors engaged for your clients' data, which is what art. 28(2) requires you to authorise.
The data inventory lists an eighth recipient — the browser push services (Google, Mozilla, Apple) that deliver notifications to salon staff devices. They are not here because they never receive a client's personal data: a push subscription belongs to a member of your staff, is Meet Marley's own controller-side processing described in the Privacy Statement, and carries no booking or client information. The two counts differ for that reason, not by oversight.
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway Corp. | Hosting, database, object storage | EU West (Amsterdam, NL) |
| Cloudflare, Inc. | CDN, TLS, WAF, cookieless site analytics | Global edge network |
| Resend | Transactional email | Ireland (EU) |
| Functional Software, Inc. (Sentry) | Error monitoring | EU (Germany) |
| PostHog, Inc. | Product analytics — Meet Marley Studio only, never client-facing pages | EU (Frankfurt) |
| Stripe Payments Europe, Ltd. | Salon subscription billing | EU / US |
| PDOK / Kadaster | Geocoding salon addresses only — no client data | Netherlands |
All personal data of your clients is stored in the European Union. Cloudflare processes traffic in transit at its global edge; that transfer is covered by Cloudflare's data protection terms and the EU Standard Contractual Clauses.