Data Processing Agreement
When you use our software, it answers your prospects' enquiries and books trial sessions for your studio. In doing so we process personal data of those people on your behalf: you are the controller under the GDPR, we are your processor (Art. 28 GDPR). This agreement governs that. It forms part of the terms of use and you accept it together with the terms when you create your account, before the assistant answers for you for the first time.
1. Subject matter, duration, nature and purpose
Subject matter is the operation of the Leon & Vera software for your studio: answering enquiries on Instagram, Facebook Messenger and web chat; offering and booking trial sessions into your studio system or calendar; drafting replies to comments and reviews; and showing you the figures for all of it in your account.
Duration: as long as your account exists. Nature of processing: collecting, storing, reading, passing on to your studio system, deleting. Purpose: solely to answer your prospects and book trial sessions for you. The software ends at the booked trial; we do not process member data.
2. Data subjects and categories of data
Data subjects: people who enquire at your studio or book a trial session (prospects).
Categories of data: name, phone number or e-mail address, the content of the conversation, the requested slot, the channel the enquiry came through, the time, and the consents given. We do not process health data: the software never answers health questions and hands them to you with the transcript.
3. Your instructions
We process only on your documented instructions. Your instructions are the terms of use, this agreement and the settings you make in your account - which channels are connected, for instance, and which opening hours and prices the assistant states. Further instructions you give in writing to hello@leonandvera.com. If we consider an instruction unlawful, we tell you without delay and may suspend it until you confirm or change it.
4. Confidentiality
Everyone who handles your data at our end is bound to confidentiality, and only those who need access to prospect data to run the service have it.
5. Security
We take the technical and organisational measures under Art. 32 GDPR set out in Annex 2, keep them current and adapt them as risks change.
6. Sub-processors
We use the providers named in Annex 1; by accepting this agreement you authorise them. If we intend to add or replace one, we inform you at least 30 days in advance by e-mail to your account address. If you object on reasonable grounds, either side may terminate this agreement with effect from the change. Every provider is bound by a contract imposing the same obligations on it as this agreement imposes on us; we are liable to you for their work as for our own.
7. Assistance with data subjects' rights
If a prospect approaches us with an access, erasure or other request, we forward it to you without delay and support you with the data we hold. On your instruction we provide, correct or delete a prospect's conversations and bookings within three working days; you can see and export them in your account.
8. Assistance with security, notifications and impact assessments
We support you in your obligations under Art. 32 to 36 GDPR with the information available to us. If we detect a personal data breach we notify you without delay, and at the latest within 48 hours of becoming aware, with everything we know, so that you can meet your own 72-hour deadline.
9. Deletion and return
When your account ends we delete the prospect data within 30 days unless you export it first or instruct us to hand it over. Statutory retention duties are unaffected; whatever we keep for that reason is blocked from other use.
10. Evidence and audits
We make available all information you need to demonstrate compliance with this agreement. You may request an audit; we agree a date with reasonable notice and usually conduct it in writing or remotely. Audits take no longer than necessary and do not disturb the service for other studios.
11. Place of processing
We store and process the data on servers in the European Union (Frankfurt am Main). Where a provider is seated outside the EU, the transfer rests on the basis named in Annex 1.
12. Liability, law, changes
Liability, governing law and jurisdiction follow the terms of use. If we change this agreement, section 13 of the terms applies accordingly. Where this agreement and the terms conflict on a question of data protection, this agreement prevails. For studios in the United States, the United States addendum supplements this agreement.
Annex 1: Sub-processors
As of 20 September 2026. When a provider is added or replaced, section 6 applies.
- Supabase Inc.
- Database and sign-in. Hosted in Frankfurt am Main (EU). Seated in the USA; transfer under standard contractual clauses.
- Vercel Inc.
- Hosting of the software and its server functions. Executed in Frankfurt am Main (EU). Seated in the USA; EU-US Data Privacy Framework and standard contractual clauses.
- Resend Inc.
- Sending of system e-mails (sign-in links, notifications). Seated in the USA; EU-US Data Privacy Framework and standard contractual clauses.
- Anthropic PBC
- The language models behind the software: drafting of replies to messages, comments and reviews, and the reading of your website and your reviews. Anthropic PBC, San Francisco, USA; EU-US Data Privacy Framework and standard contractual clauses. No training on your data; nothing is kept once the answer is given.
Not on this list because they process no prospect data for us: your own studio system and your calendar (they are your contractors, not our sub-processors - we only book into them), the channels themselves (Meta and Google, your own accounts), and the provider that makes pictures and films from your own photographs.
Annex 2: Technical and organisational measures
- Location: storage and processing in Frankfurt am Main (EU).
- Encryption: in transit (TLS) and at rest.
- Separation: each studio's data is separated at database level; no account can read another's. The connection to your channels runs on a key that acts on your studio alone.
- Access: keys with full access never leave the server; the browser receives only what the signed-in account may see. Access by us only to run the service, and logged.
- Data minimisation: There is no phone channel. The software does not answer health questions.
- Traceability: every reply sent is recorded with time, channel and wording and never altered afterwards.
- Recovery: daily database backups at the hosting provider.
- Incidents: notification to you within 48 hours of becoming aware (section 8).