Privacy Notice

Last updated: 15 September 2026

This notice explains how the platform operator handles personal data for the service. It does not replace each business customer’s own privacy information for its customers and clients.

Controller and processor roles

The platform operator is the controller for platform account, business-user, billing and contact information, security logs and its own operational records. Each business customer is normally the controller for its own customers’ and clients’ information and related service records.

For business-controlled customer and client data, the platform acts as processor. We process it only to provide and support the service, on the business customer’s instructions, and where necessary to meet legal or security requirements. The business customer remains responsible for its controller obligations.

Information we handle

Depending on how the service is used, this may include business-user names, email addresses, roles and account details; business contact and billing information; customer or client names, contact details, appointment and booking details, form responses, service records, payment-related records, memberships, plans and waiting-list information; and technical and security information such as access, error and service logs.

Why we use platform data

We use platform-controller data to set up and administer accounts, provide support, manage billing and communications, protect the service, prevent misuse, meet legal obligations and improve the reliability of the service. Our lawful bases are usually performance of a contract, compliance with legal obligations and our legitimate interests in operating and securing the service. We will ask for consent where the law requires it.

Providers and transfers

We use Supabase for database, authentication and storage services, and Resend to send transactional emails. A hosting provider will be identified in deployment documentation once selected. These providers may process personal data only as needed to provide their services to us.

Where data is transferred outside the UK, we will use appropriate safeguards required by applicable data protection law, such as recognised adequacy arrangements or contractual protections.

Retention, security and deletion

We keep personal data only for as long as needed for the service, our legitimate operational needs, and applicable legal, accounting, security or retention requirements. The service does not currently use an automated retention or deletion engine; retention and deletion decisions are reviewed through a documented manual process.

We use proportionate technical and organisational measures designed to protect personal data. On account closure or a valid deletion request, we will handle data in line with the relevant business customer’s instructions where it is controller, and with applicable retention, legal and security requirements.

Your rights and contact

You may have rights to request access, correction, deletion, restriction, objection or portability, depending on the circumstances. If you are a customer or client of a business using the service, you should normally contact that business first because it controls your information. We handle subject access, correction and deletion requests through our documented operational process.

You may complain to the Information Commissioner's Office if you are unhappy with how personal data is handled. For privacy questions or a request concerning platform-operator data, contact dubblseven@gmail.com.

TermsPrivacyCookies