1. Our role
For each interaction with the Velixa platform, the controller / processor split is as follows:
- Customer accounts and the velixa.co.uk marketing site — Velixa App Ltd is the controller.
- Merchant accounts (subscription, billing, dashboard logins, native mobile app access) — Velixa App Ltd is the controller.
- Customer data collected via a Merchant booking page, hosted website, widget or loyalty / membership / gift-card flow — the Merchant is the controller and Velixa is the processor under this Data Processing Addendum (DPA).
2. Data Processing Addendum (DPA) for Merchants
This section forms part of the Velixa Terms of service and applies whenever Velixa processes personal data on behalf of a Merchant (the "Controller"). It is governed by the laws of England & Wales.
2.1 Subject matter and duration
Velixa processes personal data only for the duration of the Merchant’s subscription, plus the 30-day export window described in the Terms of service, plus any retention period required by law.
2.2 Nature and purpose
Operation of the booking platform: scheduling, customer payments (bookings, memberships, gift cards), loyalty programme management, customer accounts, transactional and (consent-based) marketing email and SMS, visitor analytics, business intelligence reporting, automated AI-assisted moderation of public content, support, and platform security.
2.3 Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Customers of the Merchant | Name, email, phone, hashed password, bookings (including staff member selected and price paid), payment status and history, loyalty-point balance and transaction history, active membership details, gift-card balances, marketing preference for that Merchant, push-notification tokens (where granted), IP and session data, public reviews and photos. |
| Merchant’s staff | Name, email, phone, role, working hours, time-off, profile photo (if supplied), schedule, per-service pricing (including staff-specific rates), and payroll identifier (where configured for payroll reporting). |
| Visitors to the Merchant’s booking page, hosted site or widget | IP, user-agent, marketing-referral attribution cookie, HMAC-signed visitor-tracking events. |
2.4 Velixa’s obligations as processor
- Process personal data only on documented instructions from the Merchant (the Terms of service and product configuration constitute those instructions).
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see § 4).
- Engage sub-processors only with the Merchant’s general written authorisation given by accepting these terms, give reasonable advance notice of any new sub-processor by updating the list below, and remain responsible for sub-processor acts and omissions.
- Assist the Merchant — taking into account the nature of processing and information available to Velixa — in responding to data subject access, rectification, erasure and portability requests, breach notifications, DPIAs and ICO consultations.
- On termination, make customer and booking data available for export during the 30-day window described in the Terms of service, after which data is deleted or anonymised save where retention is required by law.
- Make available, on reasonable written request, information sufficient to demonstrate compliance with these processor obligations.
2.5 Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Stripe Payments UK Ltd | Card payment processing, subscription billing, membership recurring charges, gift-card payments | UK / EU |
| OpenAI, Inc. | AI-assisted automated moderation of public reviews and photos | USA, with UK GDPR safeguards |
| Email delivery provider | Transactional and consent-based marketing email | UK / EU |
| SMS delivery provider | Transactional SMS notifications (reminders, confirmations) and consent-based marketing SMS | UK / EU |
| Hosting provider | Application hosting and database storage | UK / EU |
We will notify Merchants of any new sub-processor by updating this list and, where required, giving advance notice. Merchants who object to a new sub-processor on data-protection grounds should contact [email protected].
2.6 International transfers
Where personal data leaves the UK (for example, to OpenAI in the USA for content moderation), Velixa relies on appropriate safeguards permitted by UK GDPR — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision. For content moderation, only the submitted text or image is sent; Velixa minimises the personal data included. Details of transfer safeguards for a specific sub-processor are available on written request to [email protected].
3. Data subject rights
Customers can exercise their rights of access, rectification, erasure, restriction, portability and objection by emailing [email protected] or using the Account deletion page. Where the Merchant is the controller (for example, an erasure request from a Merchant’s customer relating to their booking data), Velixa will route the request to the relevant Merchant and assist as required by UK GDPR Article 28(3)(e). We aim to acknowledge all requests within 7 days and complete them within one calendar month.
4. Security measures
- TLS encryption in transit; encryption at rest for backups.
- Bcrypt password hashing; CSRF tokens on every state-changing request; HTTP-only, SameSite session cookies.
- Multi-tenant isolation enforced by a tenant-scope middleware on every database query and every request.
- Role-based access control (owner, manager, staff) within Merchant accounts, restricting data access to what each role needs.
- Restricted, logged production access; rate limiting and lockout on authentication endpoints.
- Visitor-tracking events use HMAC-signed tokens to prevent forgery and attribution fraud.
- Regular backups with tested restore procedures.
- Dependency vulnerability monitoring and security scanning.
5. Data breach notification
Velixa will notify affected Merchants without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting their customer data, in line with UK GDPR Article 33(2). Notifications will describe — where the information is available — the nature of the breach, the categories and approximate number of records affected, likely consequences, and the measures taken or proposed to address it and mitigate its effects.
6. Retention schedule
| Data | Retention |
|---|---|
| Booking, membership and payment records | 6 years (UK tax law) |
| Loyalty-point transaction history | Life of loyalty relationship, then deleted or anonymised |
| Marketing-consent logs | 3 years after consent ends |
| Visitor-tracking and analytics events | 13 months, then aggregated |
| Customer accounts | Until the customer requests deletion |
| Merchant subscription records | Life of subscription + 6 years |
| Application, audit and security logs | 13 months |
7. Contact
Data protection enquiries: [email protected]. Postal: Velixa App Ltd, Office 1168, 60 Tottenham Court Road, Fitzrovia, London, W1T 2EW. Supervisory authority: UK Information Commissioner’s Office (ico.org.uk).
Last updated: August 2026