StudioFlow Data Processing Addendum
Version 1.2
This addendum applies where OHTOOWON LIMITED, an Irish company trading as StudioFlow ("the processor", "we"), processes personal data on behalf of the customer studio ("the controller", "you") in providing StudioFlow. It forms part of the Customer Agreement. "Personal data", "processing", "personal data breach" and similar terms have their GDPR meanings (Regulation (EU) 2016/679).
1. Roles and scope
For the personal data your studio puts into StudioFlow about its members, leads and staff, you are the controller and we are the processor. We are a controller in our own right, handling the data per our privacy notice, for three narrower things: your own account and billing data (the operator who signs up, invoices, usage); the sign-in account a member or a staff user creates directly with us in order to reach StudioFlow; and the crash and technical diagnostics our app and website send us so we can keep the service running. Those three do not cut down the first sentence: the membership records themselves, your members' bookings, attendance, payments and communications, stay under your control.
As controller, you are responsible for the lawfulness of what you ask us to process: having a lawful basis (and an Article 9 condition for any health-related intake data, normally the member's explicit consent), giving your members and staff the privacy information they are entitled to, keeping the data you enter accurate, and issuing only lawful instructions.
2. What we process for you
Subject matter: running your studio in StudioFlow. Duration: while your account exists, plus any onboarding or data-migration work we do for you before it is live, plus the export and deletion windows in section 8. Nature and purpose: storing and processing bookings, memberships, attendance, communications, consent state and payment records so the product works. Data subjects: your members, leads and staff. Categories of data: contact details, booking and attendance history, membership and payment records (card details are held by Stripe, not by us), communication and consent records, and, where you enable it, health-related intake data.
Health-related information (for example injuries or medical conditions collected through intake forms) is special-category data under Article 9 GDPR. Where you configure intake to collect it, you warrant that you have a valid Article 9 condition, normally the member's explicit consent captured as a separate, unbundled step, and you should not make membership conditional on that consent where you can avoid it. We protect it with the Annex A measures and keep it out of emails, SMS and notifications. The product is not otherwise intended for special-category data.
3. Your instructions
We process the personal data described in section 2 (member, lead and staff data) only on your documented instructions. Your documented instructions are: this addendum, the Customer Agreement, your configuration of the product, and your use of its features. Anything beyond that must be agreed in writing. Instructions include transfers outside the EEA, which happen only as section 6 describes. Where you use the AI drafting feature, our AI sub-processor processes the relevant member data solely to draft the suggested message; it is contractually barred from training models on your data, and nothing sends without a person at your studio approving it.
One exception: if EU or Irish law requires us to process regardless, we will tell you about that legal requirement before processing, unless that law prohibits telling you on important public interest grounds. And if we believe an instruction from you infringes the GDPR or other EU or EU member state data protection law, we will tell you immediately and may pause the affected processing until it is resolved.
4. Our commitments as processor
We will ensure that everyone with access to your data (employees and contractors alike) is bound by confidentiality, and protect it with the technical and organisational measures in Annex A, as Article 32 requires, which we keep under review and test regularly.
We will help you respond to members and staff exercising any of their data protection rights (access, rectification, erasure, restriction, portability, objection), first through the product's export, correction and erasure tooling, and beyond the tooling where reasonably needed. If a member contacts us directly, we will not answer on your behalf: we will pass the request to you without undue delay. We will also assist you, so far as reasonable and using information available to us, with your own security, breach notification and DPIA obligations, including prior consultation with the Data Protection Commission where a DPIA leaves a high residual risk. We aim to respond to assistance requests within 5 business days. Assistance through the product and reasonable ad-hoc help is included in your subscription; if a request is manifestly excessive or requires substantial engineering work beyond the product, we may charge a reasonable fee agreed with you in advance.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, with enough detail for you to meet your own 72-hour obligation to the Data Protection Commission, and we will keep you updated as our investigation progresses, providing information in phases if we do not have it all at once.
We maintain records of processing under Article 30(2) and can give you a map of what StudioFlow holds for your studio to support your own records.
5. Sub-processors
You authorise the sub-processors in Annex B; the current list is published at studioflow.ie/legal/dpa. We will give at least 30 days' notice before adding or replacing one (by email to the account owner), except where a replacement is urgently needed for security or service continuity, in which case we will notify you as soon as we reasonably can and you keep the same right to object. If you reasonably object on data protection grounds and we cannot resolve it, you may cancel with a pro-rata refund of any prepaid period.
The sub-processors we engage are the ones listed in Annex B. Before any of them touches your data, we put it under a written contract imposing the data protection obligations Article 28(4) requires, covering security, confidentiality and international transfers, so your data gets materially the same protection it has under this addendum. If one of them fails to meet those obligations, we remain fully liable to you (subject to section 10) for its performance as if the failure were our own. Providers you connect yourself are not sub-processors of ours and are dealt with in section 7; the Article 28(4) commitment and the liability in this section are about the sub-processors in Annex B.
6. International transfers
Your studio's primary database is hosted in the EEA (AWS Ireland). Some sub-processors process data outside the EEA (notably in the United States). Where they do, the transfer rests on an appropriate safeguard under Chapter V GDPR: an adequacy decision (including the EU-US Data Privacy Framework where the provider holds an active certification) or the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, supported by transfer risk assessments where required. Annex B states the mechanism per provider and we keep it current, including the one leg where no such safeguard is on offer from the provider, which Annex B identifies and explains rather than glosses over. If a safeguard we rely on is invalidated, or a provider loses its certification, we will move the affected transfers onto another valid safeguard without undue delay and at no extra cost to you.
Separately from our sub-processors, you can connect your own third-party integrations, described in section 7. Connecting one instructs us to disclose the data set out for it in Annex C to the provider you chose, under your own agreement with that provider. Those are your transfers, not ours: you are responsible for the lawful basis for the disclosure and for any Chapter V safeguard in your agreement with the provider. We set out what each integration sends, in Annex C, so you can meet those responsibilities.
7. Integrations you connect
StudioFlow can connect to other tools you already use: today, Mailchimp, Xero, Google Calendar, Outlook (Microsoft 365), SMS through your own Twilio account, and signed event webhooks to a URL you control. Each is optional and off until you turn it on.
An integration you connect is not a sub-processor of ours. You choose it, you hold the account, and you agree its terms directly with the provider. Connecting it is your instruction to us to send that provider the data set out for it in Annex C, and that sending is the whole of what we do: we send what Annex C describes, on your instruction, and nothing more. We do not connect anything for you, and we send nothing until you connect it.
Because it is your integration, the responsibilities that come with it are yours: the lawful basis for sending the data, the privacy information your members and leads are owed, and, where the provider is outside the EEA, any Chapter V transfer safeguard, which lives in your agreement with the provider rather than in this addendum. Annex C tells you exactly what each integration sends, so you can meet them.
You can disconnect an integration at any time in your settings, and disconnecting stops any further sending straight away. Data we already sent before you disconnected is held by the provider under your agreement with them; retrieving or deleting it there is between you and that provider, and all we can do is stop sending more.
8. Deletion and return
At the end of the agreement, you choose: export your studio's data during the 30-day window (the product's export tooling returns it to you in a machine-readable format), or ask us in writing to delete sooner. After the window closes we delete your studio's data from live systems within 30 days, and it leaves encrypted backups within a further 30 days as backups rotate. Backups are restored only for disaster recovery; if a restore happens after your deletion, we re-apply the deletion. We may keep the minimum that EU or Irish law requires us to keep (for example billing records for tax), and we will confirm deletion in writing on request.
9. Audit
On written request, no more than once a year (except after a personal data breach affecting your data, or where your supervisory authority requires it), we will make available all information necessary to demonstrate compliance with Article 28, including summaries of third-party certifications and the Annex material. Where that does not reasonably demonstrate compliance, we will allow and contribute to an audit, including an inspection, by you or an independent auditor you mandate (not a competitor of ours), at your cost, on reasonable notice, under confidentiality, and without access to other studios' data.
10. Liability and order of precedence
Liability under this addendum is subject to the caps in the Customer Agreement (including the increased cap for data protection breaches). If this addendum conflicts with the Customer Agreement on data protection matters, this addendum wins.
Annex A: technical and organisational measures (summary)
Tenant isolation enforced at the database level with row-level security on every studio-scoped table (each studio's records are invisible to every other studio, and members can read only their own rows). Primary database hosted in the EEA (AWS Ireland). Encryption in transit (TLS) and at rest. Role-based access in the product (owner, manager, receptionist gating). Authentication by a dedicated provider with modern session handling. Least-privilege service credentials, with periodic review of who holds access. Production database changes are versioned migrations with review. Error monitoring configured to exclude member personal data from traces and logs by design. The product never places health-related intake data in emails, SMS or notification payloads. Backups with periodic restore testing, and regular testing and review of these measures' effectiveness. A documented incident response process. Consent recorded per member and enforced programmatically on every marketing send: one-click unsubscribe on email, and, for SMS sent through a studio's own connected Twilio account, opt-out (STOP) handled by that Twilio account, with StudioFlow recording and honouring the opt-outs routed back to it.
Annex B: sub-processors (at last update)
Core infrastructure (used for all studios):
| Provider | Purpose | Transfer mechanism |
|---|---|---|
| Supabase, Inc. | Database and storage (EEA-hosted, AWS Ireland) | SCCs for limited US access (support, control plane) |
| Vercel, Inc. | Application hosting | DPF certified (SCCs as fallback) |
| Clerk, Inc. | Authentication | DPF certified (SCCs as fallback) |
| Sentry (Functional Software, Inc.) | Error monitoring (configured to exclude member personal data) | DPF certified (SCCs as fallback) |
Feature-dependent (engaged only when your studio uses the feature):
| Provider | Purpose | Transfer mechanism |
|---|---|---|
| Plus Five Five, Inc. (Resend) | Email delivery (transactional and consented marketing) | DPF certified (SCCs as fallback) |
| Anthropic, PBC | AI drafting of suggested messages (human-approved before send; no model training on your data) | SCCs |
| 650 Industries, Inc. (Expo) | Push notification delivery to the member mobile app | DPF certified (SCCs as fallback) |
| Google LLC (Firebase Cloud Messaging) | Push notification delivery to Android devices | DPF certified (SCCs as fallback) |
| Apple Inc. (Apple Push Notification service) | Push notification delivery to iOS devices | No DPF certification and no standard contractual clauses offered for this service; see the note below |
Stripe is not our sub-processor. Payments run through your studio's own Stripe account under your own agreement with Stripe, and card data is held by Stripe, never by us. The product passes booking and membership data to your Stripe account on your instruction, and we note that here for transparency.
Twilio is not our sub-processor either. If you send SMS, it runs through your own Twilio account under your own agreement with Twilio, in the same way as the integrations in section 7, and the data that reaches it is listed in Annex C. We do not hold a Twilio account of our own for your sends, so we do not bill you for SMS and we assume no Article 28(4) responsibility for Twilio.
Push notifications reach the member mobile app through Expo, which relays them to Apple's and Google's notification services. Push payloads are content-minimal, and the product does not place health-related information in them. What crosses this path is the device notification token, the short notification text, and a small routing payload identifying the studio, the member record and the class or appointment concerned, which the app uses to open the right screen when the member taps the notification. The member record identifier is derived from the member's name. The token is deleted when the member deletes their account.
The Apple leg is the one place where we cannot point at a Chapter V safeguard, and we would rather say so than imply one. Apple provides its push notification service under the Apple Developer Program terms, which contain no Article 28 processor clauses and no standard contractual clauses for that service, and Apple does not appear on the Data Privacy Framework register (checked 22 July 2026, when the certifications of 650 Industries, Inc. and Google LLC were both confirmed active). Apple's own terms state that push notifications are sent by the developer rather than by Apple. We therefore hold what crosses that leg to the minimum described above, and a member can stop delivery at any time by turning notifications off in their phone's settings. If Apple makes transfer terms available for this service, we will adopt them.
Annex C: integrations you connect (at last update)
These are the third-party tools you can connect yourself, under section 7. They are not our sub-processors: you hold each account and agree its terms with the provider directly. This is what StudioFlow sends to each, on your instruction, once you connect it.
| Integration | What it is | What we send to it, on your instruction |
|---|---|---|
| Mailchimp | Your own Mailchimp account | The email address and name of each member AND lead who has marketing consent recorded in StudioFlow. Nothing else: no phone number, no bookings, attendance or health data. |
| Xero | Your own Xero organisation | For each completed sale: the member's name and email, and the sale's description, amount and date, created as an invoice. |
| Google Calendar | Your own Google account | Your class timetable only: each class title, its start and end time, its room or location label, and the instructor's name. No member is named, and no booking or attendance data is sent. |
| Outlook (Microsoft 365) | Your own Microsoft account | The same class timetable as Google Calendar: class title, times, room or location label, and instructor name. No member data. |
| SMS (Twilio) | Your own Twilio account | When you send an SMS, the member's mobile number and the text of the message, passed to your Twilio account to deliver it. |
| Webhooks | An endpoint URL you control | For each event you subscribe to, a signed message carrying the member's first name, our internal record ids, and the event's details: for a booking, the class name and whether it is booked or waitlisted; for a failed payment, the amount, currency and reason. Never a surname, email address, phone number or note. |
Last updated: 5 August 2026.
This addendum forms part of the Customer Agreement. Questions: info@studioflow.ie.