1. Our role
For each interaction with the Velixa platform, the controller / processor split is as follows:
- Customer accounts and the velixa.co.uk marketing site — Velixa App Ltd is the controller.
- Merchant accounts (subscription, billing, dashboard logins) — Velixa App Ltd is the controller.
- Customer data collected via a Merchant booking page, hosted website or widget — the Merchant is the controller and Velixa is the processor under this Data Processing Addendum (DPA).
2. Data Processing Addendum (DPA) for Merchants
This section forms part of the Velixa Terms of service and applies whenever Velixa processes personal data on behalf of a Merchant (the "Controller"). It is governed by the laws of England & Wales.
2.1 Subject matter and duration
Velixa processes personal data only for the duration of the Merchant’s subscription, plus the export window described in the Terms of service, plus any retention period required by law.
2.2 Nature and purpose
Operation of the booking platform: scheduling, payments, customer accounts, transactional and (consent-based) marketing email, analytics, BI, automated moderation of public content, support, and security.
2.3 Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Customers of the Merchant | Name, email, phone, hashed password, bookings, payments, marketing preference for that Merchant, IP and session data, public reviews and photos. |
| Merchant’s staff | Name, email, phone, role, working hours, photo (if supplied), schedule, time-off. |
| Visitors to the Merchant’s booking page or hosted site | IP, user-agent, HMAC-signed visitor-tracking events. |
2.4 Velixa’s obligations as processor
- Process personal data only on documented instructions from the Merchant (the Terms of service and product configuration constitute those instructions).
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see § 4).
- Engage sub-processors only with the Merchant’s general written authorisation given by accepting these terms, give reasonable advance notice of any new sub-processor by updating the list below, and remain responsible for the acts and omissions of sub-processors.
- Assist the Merchant, taking into account the nature of processing and the information available to Velixa, in responding to data subject requests, breach notifications, DPIAs and ICO consultations.
- On termination, return or delete the personal data within the export window described in the Terms of service, save where retention is required by law.
- Make available, on reasonable written request, the information necessary to demonstrate compliance with these processor obligations.
2.5 Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Stripe Payments UK Ltd | Card payment processing & subscription billing | UK / EU |
| OpenAI, Inc. | Automated moderation of reviews and photos | USA, with UK GDPR safeguards |
| SMTP / email delivery provider | Transactional and consent-based marketing email | UK / EU |
| Hosting provider | Application hosting and database | UK / EU |
2.6 International transfers
Where personal data leaves the UK (for example to OpenAI in the USA for moderation), Velixa relies on appropriate safeguards permitted by UK GDPR — in practice this means the transfer mechanism made available by the relevant sub-processor (such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision). Details for any specific transfer are available on request.
3. Data subject rights
Customers can exercise their rights of access, rectification, erasure, restriction, portability and objection by emailing [email protected]. Where the Merchant is the controller (e.g. an erasure request from a Merchant’s customer), Velixa will route the request to the Merchant and assist as required by UK GDPR.
4. Security measures
- TLS in transit; encryption at rest for backups.
- Bcrypt password hashing; CSRF tokens on every state-changing request; HTTP-only, SameSite session cookies.
- Multi-tenant isolation enforced by a tenant-scope middleware on every request.
- Role-based access control (owner, manager, staff) within Merchant accounts.
- Restricted, logged production access; rate limiting on authentication endpoints.
- Visitor-tracking events use HMAC-signed tokens to prevent forgery and conversion fraud.
- Backups taken regularly with tested restore procedures.
- Vulnerability monitoring and dependency scanning.
5. Data breach notification
Velixa will notify affected Merchants without undue delay after becoming aware of a personal data breach affecting their personal data, in line with the timing required of a processor under UK GDPR Article 33(2). Notifications will, where the information is available, describe the nature of the breach, the categories and approximate number of records affected, likely consequences, and the measures taken or proposed in response.
6. Retention schedule
| Data | Retention |
|---|---|
| Booking and payment records | 6 years (UK tax law) |
| Marketing-consent logs | 3 years after consent ends |
| Visitor-tracking events | 13 months, then aggregated |
| Customer accounts | Until the customer deletes them |
| Merchant subscription records | Life of subscription + 6 years |
| Application and security logs | 13 months |
7. Contact
Data protection enquiries: [email protected]. Postal: Velixa App Ltd, Office 1168, 60 Tottenham Court Road, Fitzrovia, London, W1T 2EW. Supervisory authority: UK Information Commissioner’s Office (ico.org.uk).
Last updated: April 2026