Legal
Data Processing Terms
Version 2.0 · Last updated: 17 August 2026 · Effective: 17 August 2026
These Data Processing Terms constitute the data processing agreement required by Article 28 of the GDPR and its equivalents in other applicable laws. They form part of the Terms of Service and apply for so long as Flit is used to hold personal data concerning clients. No separate signature is required: acceptance of the Terms of Service constitutes acceptance of these. The processing is described in Annex I and the technical and organisational measures in Annex II.
Contents
- Definitions
- Roles, and what these terms cover
- Our instructions
- Confidentiality
- Security
- Sub-processors
- Helping you answer your clients
- Helping you with impact assessments
- Personal data breach
- International transfers
- Deletion and return
- Information and audits
- Liability, and which document wins
- Duration
- Annex I: description of the processing
- Annex II: technical and organisational measures
- Annex III: sub-processors
1. Definitions
1.1 Data Protection Law means every law about personal data that applies to either of us, including the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, Swiss data protection law, the CCPA as amended, the Washington My Health My Data Act, other United States state privacy laws, PIPEDA and Quebec Law 25.
1.2 Client Personal Data means personal data about your clients that we process on your behalf through Flit: contact details, intake and health answers, consent records, photographs, lash maps, notes, appointments, treatments and payment records.
1.3 Controller, processor, data subject, processing and personal data breach have the meanings given in the GDPR, and their nearest equivalents under any other applicable law. "You" means the account holder; "we", "us" and "RCS" mean RCS (FZE); "Flit" means the Service defined in the Terms of Service.
1.4 SCCs means the standard contractual clauses approved by the European Commission on 4 June 2021, and UK Addendum means the International Data Transfer Addendum issued by the UK Information Commissioner.
2. Roles, and what these terms cover
2.1 For Client Personal Data, you are the controller and we are your processor. You decide what to collect, why, how long to keep it, and on what lawful basis.
2.2 For your own account data (your name, email, business details, subscription and support history), we are the controller, and our Privacy Policy governs it. These terms do not apply to it.
2.3 You confirm that you have a lawful basis for each category of Client Personal Data you enter, that you have given your clients the information your law requires, and that where you collect health information or run the try-on on someone, you have obtained the explicit consent that law requires. We are entitled to rely on that confirmation.
2.4 Neither of us will do anything with Client Personal Data that puts the other in breach of Data Protection Law.
3. Our instructions
3.1 We process Client Personal Data only on your documented instructions. Using the features of Flit is how you give those instructions, together with the Terms of Service, these terms, and anything you ask us in writing that we agree to.
3.2 We will not process Client Personal Data for our own purposes. In particular, it is not used to train artificial-intelligence models, is not sold, is not shared for advertising, and is not used to build profiles.
3.3 If the law compels us to process it beyond your instructions, we will tell you before we do, unless that same law forbids us from telling you.
3.4 If we believe an instruction of yours would breach Data Protection Law, we will tell you promptly and may suspend that instruction until it is resolved.
4. Confidentiality
Everyone we allow to access Client Personal Data is bound by a duty of confidentiality that survives their engagement, is trained on handling it, and is given access only to what their role requires.
5. Security
5.1 We implement and maintain the technical and organisational measures set out in Annex II, appropriate to the risk, taking into account the nature of the data and in particular the presence of health information.
5.2 We may update those measures as technology and threats change, provided the level of protection is never reduced.
6. Sub-processors
6.1 You give us general written authorisation to engage sub-processors. They are listed in Annex III by the role each performs, with the data it can access and where it operates. You may obtain the name of the company behind any role by writing to support@flitapp.ai, and we will provide it promptly and free of charge.
6.2 Each sub-processor is bound by written terms that impose data protection obligations no less protective than these, and we remain fully liable to you for what a sub-processor does.
6.3 Before adding or replacing a sub-processor we will notify account holders by email at least 30 days in advance, and update this annex. If you object on reasonable data protection grounds within that period, tell us; we will work with you to find a solution, and if we cannot, you may terminate your subscription and receive a pro-rated refund of the unused period.
7. Helping you answer your clients
7.1 The following can be carried out by you directly in the app: viewing and correcting any record, exporting a client's data, deleting a photograph, deleting a client, and deleting the account itself.
7.2 If a client contacts us directly, we will not answer on your behalf: we will tell them to contact you, and tell you promptly that they tried.
7.3 Where a request cannot be satisfied through the app, we will provide reasonable assistance, at no charge for a request of ordinary scope.
8. Helping you with impact assessments
Taking into account what we know as a processor, we will give you reasonable help with a data protection impact assessment or a prior consultation with a supervisory authority that concerns your use of Flit. Annex I and Annex II are written to give you most of what such an assessment needs.
9. Personal data breach
9.1 If we become aware of a personal data breach affecting Client Personal Data, we will notify you without undue delay, and in any event within 48 hours of becoming aware.
9.2 The notification will describe what we know: the nature of the breach, the categories and approximate volume of data and people affected, the likely consequences, and the measures taken or proposed. Where we cannot give it all at once, we will give it in stages, without further undue delay.
9.3 We will assist you in meeting your own obligation to notify a supervisory authority or the data subjects concerned. That notification is the controller's obligation.
9.4 We will not publicly attribute a breach to you without your agreement, unless the law requires it.
10. International transfers
10.1 Client Personal Data is hosted in the European Union.
10.2 Where Client Personal Data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, that transfer is governed by the SCCs, which are incorporated into these terms by reference and which the parties are deemed to have signed:
- Module Two (controller to processor) applies to transfers from you to us, with you as data exporter and RCS (FZE) as data importer.
- Module Three (processor to processor) applies to transfers from us to a sub-processor.
- Clause 7 (docking) applies. Under clause 9, option 2 (general written authorisation) applies, with the 30-day notice period in clause 6.3 above. Under clause 11, the optional redress body is not used. Under clause 17, the governing law is that of Ireland; under clause 18(b), the forum is the courts of Ireland. Annex I and Annex II of the SCCs are populated by Annex I and Annex II below.
- For the United Kingdom, the UK Addendum applies to the SCCs, with the tables completed by reference to the same annexes; for Switzerland, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Federal Data Protection and Information Commissioner.
10.3 We will tell you if we become subject to a law that prevents us meeting those clauses, and you may suspend the transfer or terminate.
11. Deletion and return
11.1 You can delete a client, a photograph or your whole account from the app at any time, and you can export your data before you do.
11.2 On termination, we delete Client Personal Data as set out in clause 21 of the Terms of Service: immediately from live systems on deletion of the account, and from any backup copy we hold within 30 days. Where a subscription simply lapses, the data is kept for 90 days so you can return or export, then deleted after a warning.
11.3 We may keep a copy only where the law requires it, and only for as long as it requires, and it stays protected by these terms while we hold it.
12. Information and audits
12.1 On written request, and no more than once a year unless a regulator or a breach requires otherwise, we will give you the information reasonably necessary to demonstrate that we meet these terms.
12.2 Where that is not enough for a regulator, we will cooperate with an audit carried out by you or an independent auditor you appoint, on reasonable notice, during working hours, without disrupting the Service or exposing another customer's data, and subject to confidentiality. Each of us bears its own costs for one such audit a year.
13. Liability, and which document wins
13.1 The limitations and exclusions of liability in the Terms of Service apply to these terms, and to the SCCs to the extent the law permits.
13.2 If these terms conflict with the Terms of Service or the Privacy Policy on anything concerning the processing of Client Personal Data, these terms prevail. If the SCCs conflict with these terms, the SCCs prevail.
14. Duration
These terms apply for as long as we process Client Personal Data for you, and the obligations that by their nature should continue afterwards do so.
Annex I: description of the processing
A. The parties
Data exporter (controller): the account holder, being the lash professional or business identified by the account, whose contact details are those held in the account. Data importer (processor): RCS (FZE), licence No. 9943, Block B, Office B50-030, SRTI Park, Sharjah, United Arab Emirates, contact support@flitapp.ai.
B. Description
| Subject matter | Providing the Flit application to the controller |
| Duration | The term of the subscription, plus the retention periods in clause 11 |
| Nature and purpose | Storing, displaying, organising, synchronising and backing up the data the controller enters; generating a public booking page; sending the transactional emails a booking needs; producing consent and record documents at the controller's request |
| Categories of data subject | The controller's clients, people who request an appointment through the booking page, and emergency contacts named by a client |
| Categories of personal data | Identity and contact details; appointment and treatment history; prices and payment status; photographs; lash maps; free notes; signature images and the consent text signed; device and log data incidental to use |
| Special categories | Health information collected on an intake form: allergies, medication, pregnancy, eye conditions, contact lens use, patch-test results. Processed only to store and display it in the client's file, on the explicit consent the controller obtains, with the restrictions in clause 6 of the Privacy Policy. No biometric identifier is collected: the try-on measurement never leaves the device and is never stored |
| Frequency | Continuous, on the controller's use |
| Transfers to sub-processors | As described in Annex III, for the duration and purposes stated there |
C. Competent supervisory authority
Where the SCCs apply, the competent supervisory authority is that of the EU member state in which the data exporter is established or, where the exporter is not established in the Union, that of the member state in which its representative is established or in which the data subjects are located.
Annex II: technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | TLS for all data in transit, including between the app, our database and every sub-processor. Encryption at rest for the database, file storage and backups. Passwords stored only as salted hashes; third-party access tokens encrypted and held server-side, never in the browser |
| Isolation between customers | Row-level security enforced by the database itself: one account's queries cannot reach another account's rows even if the application layer were bypassed. Covered by automated tests |
| Access control | Access by our staff limited to those who need it to operate or support the Service, on individual credentials. Production secrets are held outside the code base and are never present in anything sent to a browser |
| Application security | Server-side authorisation on every request; no secret held in client code; no third-party script or font loaded by the app; a documented internal security review of the code base |
| Data minimisation by design | The try-on computes a facial measurement in device memory only, never stores or transmits it; the calendar integration requests only free-busy intervals, never event contents; no advertising or analytics identifier is set on a client's device |
| Resilience and recovery | Data is held both in the managed cloud database and, because Flit is offline-first, in full on each device the account signs into, and a complete export is available at any time. Synchronisation is designed so that a returning device cannot silently overwrite or erase data held elsewhere, with automated tests covering that behaviour |
| Logging | Application and security logs retained up to 12 months, reviewed on incident, and kept free of client health information |
| Personnel | Confidentiality obligations for everyone with access; access removed promptly when it is no longer needed |
| Incident response | A defined procedure to contain, assess and notify a breach, with the 48-hour commitment in clause 9 |
| Sub-processor governance | Written data protection terms with each, no less protective than these; a published list; 30 days notice before a change |
| Deletion | Deletion in the app removes data from live systems at once, and from any backup copy within 30 days |
Annex III: sub-processors
The following five providers, and no others. Each is identified by the role it performs; the identity of the company performing a role is provided on request, under clause 6.1.
| Role | What it does for us | What it can access | Where |
|---|---|---|---|
| Hosting and database | Stores the database, the files and the accounts system | All app data, including client records, health answers and photographs, encrypted at rest | European Union |
| Delivery and measurement | Serves the website and the app, and counts page views without cookies | Technical request data (IP address, browser) in transit. No stored client data | Served from the location closest to the visitor |
| Email delivery | Delivers the emails a booking needs | The recipient's name and email, and the content of that message (appointment time, service, deposit instruction). No health data, no photographs | United States |
| Payments | Takes subscription payments, invoicing and taxes, as the seller of the subscription | The subscriber's own name, email, billing country and payment details. No client data of any kind | United Kingdom and European Union |
| Document reading | Reads the pages you upload, and only if you choose to import a paper client book | Only the images you submit for that import, for the time it takes to read them. Not retained, and not used to train models | United States |
Where a role above operates outside the European Economic Area or the United Kingdom, clause 10 governs the transfer. Your app data itself, including every client record and photograph, stays in the European Union.
Google is not in this list. If you connect your Google account, Flit exchanges calendar information with Google at your request: that connection is yours to make and yours to end, and what Flit reads and writes is limited to what clause 8 of the Privacy Policy describes.