This addendum forms part of the Partner Terms between a shop (the controller) and Posaura (the processor) for personal data Posaura processes on the shop's behalf, under UK GDPR Article 28. It does not cover account, marketplace, security or support data that Posaura controls itself — see our privacy notice for that.
Subject matter and duration
Posaura processes personal data submitted through the shop's booking page, admin account and related Functions for as long as the shop has an active Posaura account, plus any period required to meet a legal, tax or dispute retention obligation.
Nature and purpose of processing
Posaura stores, transmits and makes available customer booking, contact, payment-reference and, where the shop chooses to record it, relevant health/allergy data; and employee rota, holiday and HR-record data; solely to provide the booking, payment, CRM, rota and compliance features the shop has configured.
Categories of data subject
The shop's customers, prospective customers and employees, and any other individual whose data the shop enters into Posaura.
Posaura's obligations as processor
- Process personal data only on the shop's documented instructions, as given through the shop's configuration and use of the service, unless required to do otherwise by UK law.
- Keep personal data confidential and ensure anyone processing it under Posaura's authority is under a confidentiality obligation.
- Implement appropriate technical and organisational security measures, including per-shop data isolation, role-based access control, encryption in transit, and audit logging of sensitive actions.
- Only engage a sub-processor with the shop's general authorisation (see below) and impose the same data-protection obligations on it.
- Assist the shop, taking into account the nature of processing, in responding to data subject rights requests (access, correction, erasure, restriction, portability, objection).
- Assist the shop with its UK GDPR Article 32–36 obligations, including notifying the shop without undue delay after becoming aware of a personal data breach affecting the shop's data.
- At the shop's choice, delete or return personal data at the end of the relationship, except where UK law requires Posaura to keep it.
- Make available the information reasonably necessary to demonstrate compliance with this section and allow for audits, including inspections, conducted by the shop or an auditor it mandates.
Sub-processors
The shop generally authorises Posaura to use the following categories of sub-processor: cloud infrastructure and database hosting, payment processing, and transactional email delivery. Posaura will give reasonable notice of a new sub-processor category so the shop can object on reasonable data-protection grounds.
International transfers
Where a sub-processor is located outside the UK, Posaura relies on an adequacy decision, the UK International Data Transfer Agreement/Addendum, or another lawful transfer mechanism.
Liability
Each party remains responsible for its own compliance with UK GDPR. Nothing in this addendum limits liability where the law does not allow it to be limited. This draft requires qualified UK legal review and registered entity details before launch.