Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) governs how IDS Business Live AG ("Stylingcorner") processes personal data on behalf of a beauty business (the "Company") when the Company uses the Stylingcorner PRO software or the free Marketplace plan with its management features.
This version has been approved by the operator and is in force since 23 September 2026. It can be accepted in Stylingcorner PRO.
1. Acceptance and evidence
Where: in Stylingcorner PRO under Settings → Privacy & Data. Only people with the Owner or Manager role in the Company can accept; employees see the status but cannot accept.
What can be accepted: only the currently effective version of this DPA — that is, a version that has been approved internally and whose effective date has been reached, in the chosen language (German or English). Older, not yet effective or unapproved versions cannot be accepted.
What is recorded: the Company, the accepting person, the time, the version, the language, a SHA-256 fingerprint of the exact text of that version in that language, and the IP address and browser user agent of the request. The acceptance is also recorded in the audit log.
Retention of versions: the exact text of every acceptable version is archived under its version number and remains available after a new version is published, so every acceptance can be matched to the wording accepted at the time. Acceptances are only ever appended, never overwritten.
New versions: when a new version takes effect, PRO shows that the earlier acceptance no longer covers the current version; the new version has to be accepted explicitly. Merely using PRO does not count as acceptance.
2. Parties and roles
The processor is IDS Business Live AG (CHE-140.202.303, Badenerstrasse 808, 8048 Zürich). The controller is the respective Company.
This DPA does not cover processing for which Stylingcorner itself is responsible, in particular: Marketplace customer accounts, search and the Marketplace booking flow including booking notifications to customers, the review system and its moderation, employees' login and security accounts, the checking of claim and verification documents, the PRO subscription and its billing, and security and audit logs. Stylingcorner's privacy notice applies to those.
3. Subject matter and duration
The subject matter is the processing of the personal data the Company records in the software or that arises there for the Company (see sections 4–6).
Processing lasts as long as the Company uses the software and ends when the contract ends, subject to section 13 (return and deletion).
4. Nature and purpose of the processing
Stylingcorner processes the data solely to provide the Company with the following software features: customer management (customer records, contact details, birthday, the Company's own customers' consents, notes); calendar and appointment management, including bookings received via the Marketplace insofar as they are kept in the Company's system; team and employee management (profiles, working hours, absences, roles and permissions, invitation emails to employees); point of sale and sales (sales, line items, payments, refunds, tips) and reports based on them; vouchers and gift cards (including the receiving customer and message); notifications to the Company and its employees within PRO; display of the Company's reviews and management of its replies to them.
Stylingcorner does not process this data for its own purposes — such as resale or its own marketing.
5. Data subjects
The Company's customers (including those who booked via the Marketplace, insofar as their data is kept in the Company's system), recipients of vouchers, and the Company's employees.
6. Categories of data
Customer data: master and contact data, birthday, consents, appointment history, sales and payments, vouchers, and free-text notes and appointment remarks.
Employee data: name, profile details, photo, working hours, absence and time blocks including sickness-related absences (with an optional note), role and permissions.
Free-text fields may incidentally contain sensitive personal data (e.g. health information) if the Company enters it. The Company is responsible for recording only what is necessary. Stylingcorner does not analyse the content for its own purposes.
7. Instructions
Stylingcorner processes the data only on the Company's documented instructions. Instructions are this DPA, the Company's configuration and use of the software, and written individual instructions sent to legal@stylingcorner.ch.
If Stylingcorner considers an instruction unlawful, it informs the Company without undue delay and may suspend its execution until clarified.
8. Confidentiality
People at Stylingcorner with access to the data are bound to confidentiality and only receive access insofar as their task requires. Technically, each Company's access is restricted server-side to its own data.
9. Security measures
Stylingcorner takes appropriate technical and organisational measures. The verified status — including measures not yet implemented — is documented on the "Security" page of the Privacy Centre and forms an annex to this DPA in the version published at acceptance.
10. Subprocessors
General authorisation: the Company authorises the engagement of the providers listed on the "Subprocessors" page. Stylingcorner contractually binds each subprocessor to a level of protection equivalent to this DPA and remains responsible to the Company for its compliance.
Advance notice: before engaging a new subprocessor or replacing an existing one, Stylingcorner informs the Company by email to the Company's contact address on file and by updating the "Subprocessors" page and its change history.
Right to object: the Company may object within the notice period on legitimate data-protection grounds. The parties then seek an amicable solution; if none is found, the Company may terminate the contract with effect from the engagement.
Implementation status: automated sending of this advance notice has not been implemented yet; until then, notice is given manually.
11. Transfers abroad
Data is only transferred to countries with adequate data protection or under appropriate safeguards within the meaning of the Swiss Federal Act on Data Protection. Which providers process data outside Switzerland is shown on the "International Data Transfers" page.
12. Assistance to the Company
Data subject requests: if a data subject contacts Stylingcorner about the Company's data, Stylingcorner forwards the request to the Company and does not answer it itself unless instructed. The Company can view, correct and deactivate customer records in PRO itself; permanent deletion or export of individual records is currently carried out manually by Stylingcorner on request.
Data breaches: Stylingcorner informs the Company as quickly as possible after becoming aware of a data security breach affecting the Company's data, and provides the available information the Company needs for its own assessment and any notifications.
Further assistance: Stylingcorner assists the Company within reason with data protection impact assessments and with enquiries from authorities, insofar as the information needed is held by Stylingcorner.
13. Return and deletion at the end of the contract
After the contract ends, Stylingcorner provides the Company with its data (in particular customer, appointment and sales data) in a common, machine-readable format on request to legal@stylingcorner.ch. There is currently no self-service export; the export is done manually.
Stylingcorner then deletes the Company's data or renders it such that it can no longer be attributed to a person, unless a statutory retention duty prevents it. There is currently no automated process for this; deletion is carried out manually on request or under the procedure still to be defined. Copies in backups are only removed when the respective backup expires.
14. Evidence and audits
On request, Stylingcorner provides the Company with the information needed to demonstrate compliance with this DPA and, after prior arrangement, allows audits by the Company or an auditor it appoints who is bound to confidentiality — insofar as this does not compromise the platform's security or other customers' data. There is currently no independent certification or external penetration test.
15. Relationship to the internal approval records
The text shown here comes from the platform's source code. The internal approval of a version is recorded separately in Stylingcorner's administration area; those records do not drive the text on this page. Acceptance is only possible if, for the same version and language, both an effective approval and the archived exact text exist.
16. Applicable law
This DPA is governed by Swiss law, in particular the Swiss Federal Act on Data Protection (FADP).
Whether the EU General Data Protection Regulation (GDPR) additionally applies to the processing depends on an assessment of the specific circumstances (e.g. whether the Company targets services at people in the EU). Where it applies, the parties will supplement this DPA as necessary with the requirements of Art. 28 GDPR.
