Legal
Data Processing Agreement
Last updated September 9, 2026
Please note: this Data Processing Agreement is a template we provide for convenience and is pending review by legal counsel. It is not legal advice. If you need a signed or negotiated agreement for your studio, contact us at hello@studioside.app.
This Data Processing Agreement (“DPA”) describes how StudioSide LLC (“StudioSide,” “we,” “us”) handles the personal data you put into StudioSide to run your business. It forms part of, and is governed by, our Terms of Service and Privacy Policy.
Who is who
For the personal data about your own clients and team that you put into StudioSide, you (the studio) are the controller — you decide what to collect and why. StudioSide is the processor — we handle that data only to provide the service to you. We do not use it for our own purposes.
Subject matter and duration
The subject matter is StudioSide’s processing of personal data on your behalf so you can run your studio — bookings, sessions, clients, invoices, and payments. We process this data for as long as your account is active and until the data is deleted or returned as described below.
Nature and purpose of processing
We process your studio data to provide and operate StudioSide: storing and displaying your schedule, managing clients and gear, creating and sending invoices, recording payments, syncing calendars you connect, keeping your studio’s data isolated from every other studio, securing the service, and supporting you. We process it only to deliver these features — not for advertising, and not to train AI models.
Types of personal data
The personal data we process on your behalf typically includes:
- Contact details of your clients and contacts: names, email addresses, and phone numbers.
- Company or business details you record for a client.
- Session and booking data: who is booked, which room, the times, the gear, and the team assigned.
- Invoice and payment data: line items, amounts, status, and payment records.
- Notes and other free-text information you choose to add about a client or session.
Categories of data subjects
The people whose personal data we process on your behalf are your studio’s clients (the customers and contacts you book and bill) and your team members (the staff you add, schedule, and assign to sessions).
Our obligations as processor
- We process your studio data only on your documented instructions, including the instructions built into how you use the product. If the law requires us to process it otherwise, we will tell you first unless the law forbids that.
- Everyone on our side who can access the data is bound by a duty of confidentiality.
- We keep appropriate technical and organizational security measures in place: each studio’s data is isolated at the database level, data is encrypted in transit, passwords are stored hashed, and sensitive tokens (such as Google Calendar access) are encrypted at rest.
- We help you meet your own obligations as controller, including the assistance described below.
Subprocessors
We use a small set of trusted companies (“subprocessors”) to provide StudioSide. Each receives only what it needs and is bound by its own data-protection terms:
- Supabase — database, sign-in, and file storage.
- Vercel — application hosting, scheduled jobs, and page-view counts.
- Stripe — subscription billing and client card payments.
- Resend — transactional email.
- Google Calendar — one-way calendar sync, only if you connect a Google account.
- Google Gemini — drafting help-centre answers from support tickets, only if you write to support and we turn your ticket into a published answer.
- Sentry — error monitoring.
- PostHog — product analytics and session replay.
- Mapbox — address and city lookup.
- OpenStreetMap — address lookup, as a fallback when mapbox has no answer.
- Google Analytics — marketing-site visitor counts.
What each one receives is set out on our security page.
If we add or change a subprocessor, we will update this list and give you reasonable notice so you can object. You authorize these subprocessors by using StudioSide.
Helping with data-subject requests
If one of your clients or team members asks to access, correct, export, or delete their personal data, you can handle most of this yourself from inside the app, and you can export to CSV at any time. Where you need more, we will give you reasonable help to respond to those requests, taking into account how the service works.
Personal-data breaches
If we become aware of a breach affecting the personal data we process for you, we will notify you without undue delay and share the information you reasonably need to meet your own notification duties.
Returning or deleting data
You can export your data to CSV at any time. When your account ends, we make your data available for export and then delete it within 30 days — except for anything we are legally required to keep (for example, basic billing records) and routine backups that age out on their own.
Audits and information
We will make available the information you reasonably need to confirm we are meeting the obligations in this DPA, and we will cooperate with reasonable audit requests. To respect every studio’s confidentiality, audits are arranged in advance, at a reasonable scope and frequency, and may rely on the security documentation we provide.
Where data is processed
StudioSide is operated from the United States, and the personal data we process for you is handled there, including by our subprocessors. If you or your data subjects are outside the U.S., you instruct us to process the data in the U.S. to provide the service.
Changes to this DPA
If we update this DPA, we will change the date at the top and, where appropriate, let you know in the app or by email.
Contact
Questions about how we process data? Email hello@studioside.app.