SpaGenix Data Processing Terms
The processing instructions, safeguards and responsibilities that apply to tenant-controlled personal data.
- Effective
- 4 October 2026
- Applies to
- Tenant owners and privacy or compliance representatives
1. Scope and roles
These terms form part of the Tenant Subscription Agreement whenever Provider processes personal data supplied or controlled by Tenant. Tenant determines the purposes and essential means and acts as the Data Fiduciary or otherwise responsible business; Provider acts as Data Processor on documented instructions. Provider acts independently for its own account, security, billing, legal and service-administration data.
2. Processing description
Processing lasts for the subscription and documented retention period and consists of hosting, organising, retrieving, transmitting, backing up, securing, supporting and deleting tenant data. Data subjects may include customers, prospects, staff and suppliers. Data may include identity and contact details, bookings, work schedules, attendance, preferences, communication permissions, invoices, payment references and service activity.
Tenant must not supply medical or clinical data, allergies, biometric data, full card credentials, Aadhaar numbers, third-party passwords or children’s data unless Provider first agrees in writing to appropriate controls and terms.
3. Instructions and compliance
Provider processes tenant data only under the agreement, Tenant’s configured feature use, support requests and other documented lawful instructions, unless Indian law requires otherwise. Provider will notify Tenant if an instruction appears unlawful where permitted. Tenant is responsible for notices, lawful grounds, minimisation, accuracy, retention decisions, Data Principal requests and lawful communications.
4. Confidentiality and security
Provider limits access to personnel and contractors who need it and are bound by confidentiality. Provider maintains reasonable safeguards appropriate to the service, including authentication, role-based access, encryption in transit, protected secrets, logs and monitoring, patching, backups, recovery and incident handling. Tenant is responsible for endpoint security, account configuration, authorised exports and downloaded data.
5. Subprocessors
Tenant generally authorises subprocessors needed for infrastructure, hosting, communications, monitoring, security and support. Provider remains responsible for materially equivalent obligations and will make a current subprocessor description available. Provider will give reasonable notice of a material new subprocessor where practicable. A reasonable data-protection objection will be discussed in good faith; if no practical alternative exists, the affected feature or agreement may be terminated.
6. Assistance and incidents
Taking account of the processing and available information, Provider will reasonably assist Tenant with security assessments, Data Principal requests, complaints and legally required assessments. Provider will notify Tenant without undue delay after confirming a personal-data breach affecting tenant data and provide available information needed for notifications. Tenant remains responsible for notices to affected persons and authorities unless law assigns that duty to Provider.
7. Return, deletion and retention
Tenant may use available exports during the subscription. After termination and the 30-day retrieval period, Provider will delete or de-identify tenant data within its documented cycle unless law, legal hold, security or dispute preservation requires retention. Backups may persist until overwritten and remain protected from ordinary use. Minimal audit, billing and legal records may be retained for applicable statutory and limitation periods.
8. Location, evidence and audits
The service is offered for Indian operations. Material processing outside India will be disclosed and handled subject to Indian restrictions. Tenant must not use SpaGenix for another jurisdiction without written approval and appropriate additional terms.
Provider will make reasonable compliance information available. No more than annually, unless following a substantiated incident or regulator request, Tenant may request a scoped independent audit. It must protect other customers, minimise disruption and be at Tenant’s cost unless it identifies a material Provider breach.
9. Conflict, liability and survival
These terms prevail over the Tenant Subscription Agreement on personal-data processing. Liability follows that agreement subject to mandatory law. These terms survive while Provider retains tenant personal data.