Data Processing Agreement

Last updated: 31.08.2026

This Data Processing Agreement supplements the Terms and governs the processing of personal data carried out by Tattoomii GmbH, Badenerstrasse 541, 8048 Zurich, Switzerland (processor) on behalf of the studio (controller). It is deemed agreed upon acceptance of the Terms. A separately signed version is available on request at hello@taddoo.com.

1. Subject matter and duration

The subject matter is the processing of personal data for the provision of the Service described in the Terms. The agreement starts when the Service is used and ends with the main contract. Obligations that by their nature continue, in particular confidentiality and deletion, survive.

2. Nature, purpose, categories of data and data subjects

The data processed comprises contact and communication data, the content of emails and attachments, appointment and customer data, payment metadata and technical usage data. Data subjects are the studio's customers, its staff and persons who write to the studio. The purpose is exclusively the provision of the Service: receiving and assigning inquiries, extracting structured details, drafting replies for approval by the studio, appointment and customer management, payment and sending operations, and security and error analysis. Where the studio introduces sensitive data, for example health details in free-text fields, we process it within the same framework; the studio ensures that a valid legal basis exists.

3. Instructions

We process personal data solely on documented instructions from the studio. Use of the Service and its settings constitute instructions; any further instruction must be given in text form to hello@taddoo.com. Where we are required to process by Swiss or Union law, we inform the studio in advance unless the law prohibits it. If we consider an instruction unlawful, we say so and may suspend its execution.

4. Confidentiality

All persons at our company with access to personal data are bound in writing to confidentiality before starting work, or are subject to a statutory duty of secrecy. The obligation continues after the activity ends.

5. Technical and organisational measures

We take the measures required by Art. 32 GDPR and the Swiss FADP: encryption in transit and at rest, an additional layer of encryption for access tokens, technical separation of the data of different studios with every access checked at studio level, access to production data only on a least-privilege basis and with multi-factor authentication, logging, rate limiting and abuse detection, regular backups, and a process for detecting and reporting incidents. The measures are reviewed continuously and may be developed further as long as the level of protection is not reduced. A detailed description is made available to studios confidentially on request.

6. Sub-processors

The studio grants general authorisation for the use of sub-processors. The current list is published on a dedicated page. We bind every sub-processor contractually to obligations equivalent to this agreement and remain liable for them as for our own conduct. We announce changes with reasonable notice; the studio may object within 30 days on serious data protection grounds and, if no solution is found, terminate with effect from the date of the change.

7. Assistance with data subject rights

We assist the studio with appropriate technical and organisational means in responding to requests for access, rectification, erasure, restriction, portability and objection. If a data subject contacts us directly, we forward the request to the studio responsible without delay and do not answer it ourselves unless the studio instructs us to.

8. Breach notification and impact assessment

We notify the studio of any personal data breach without undue delay after becoming aware of it, as a rule within 48 hours, with the available information on the nature of the breach, the categories affected, the likely consequences and the measures taken. We support the studio in meeting its notification obligations and, where necessary, with a data protection impact assessment and prior consultation of the supervisory authority.

9. Deletion and return

After the main contract ends the studio may request an export of its data in a structured, commonly used, machine-readable format within 30 days. We then delete or anonymise the personal data, subject to statutory retention obligations. Backups are overwritten in the normal rotation; until then they remain access-protected and are no longer actively processed. On request we confirm deletion in text form.

10. Evidence and audits

We make available to the studio the information needed to demonstrate compliance with this agreement, primarily through up-to-date descriptions of our measures and, where available, reports or certificates. If that is not sufficient we allow an audit with at least 30 days notice, during normal business hours, no more than once a year unless there is specific cause, and without impairing operations or the confidentiality of other studios. Third-party auditors must not be competitors and must be bound to confidentiality.

11. Transfers to third countries

Transfers to countries outside Switzerland and the EEA take place only where an adequacy decision exists or appropriate safeguards are in place, in particular the EU Standard Contractual Clauses together with the adaptations recognised by the Swiss FDPIC and any necessary supplementary measures. The applicable safeguard is stated for each sub-processor in the public list.

12. Responsibility of the studio

The studio remains responsible for the lawfulness of the processing. It ensures a valid legal basis, informs its customers under Art. 13 and 14 GDPR or the Swiss FADP, keeps its own record of processing activities, manages its staff's access rights carefully, and does not introduce data into the Service that we would not be permitted to process.

13. Final provisions

In all other respects the Terms apply, in particular the liability provision, the governing law and the place of jurisdiction. In the event of a conflict between this agreement and the Terms, this agreement prevails for data processing. If a provision is invalid, the remainder stays in force. In case of discrepancy between language versions the English version prevails.