Data Processing Agreement
How we protect salon customer data.
This Data Processing Agreement (DPA) forms part of the HoundCheck Terms of Service. It applies when a grooming business uses HoundCheck to process personal data about its customers, staff or other contacts.
The grooming business is the controller. John Batey, trading as HoundCheck, is the processor. Each party will meet the obligations that apply to it under UK data protection law, including the UK GDPR and Data Protection Act 2018.
Details of the processing
Subject and purpose: providing HoundCheck's booking, customer and dog records, consent, communication, reporting, storage, security, support and backup functions.
Duration: for as long as the salon has an account, plus the limited deletion, recovery and backup periods described in our Privacy policy or required by law.
People covered: salon owners and staff, pet owners and prospective customers, emergency contacts, and other people whose details the salon lawfully records.
Data covered: names, contact details, account and security information, appointment and payment records, communications, consent records and signatures, photographs, grooming notes, dog and vet-related records, and technical or audit information.
Processing carried out: collecting, recording, organising, storing, retrieving, displaying, transmitting, backing up, exporting and deleting data solely to provide and protect the service.
HoundCheck's commitments
- Process personal data only on the salon's documented instructions, including instructions created by normal use of HoundCheck, unless the law requires otherwise.
- Ensure people authorised to access personal data are bound by confidentiality.
- Use appropriate security measures, including encrypted connections and backups, access controls, tenant separation, security logging and restricted administrative access.
- Help the salon respond to data-subject requests, security incidents, impact assessments and regulator enquiries where reasonably required.
- Notify the salon without undue delay after becoming aware of a personal-data breach affecting its data, and provide available information needed for its response.
- At the end of the service, delete or return salon personal data as requested, subject to legal duties and normal protected-backup deletion cycles.
- Provide information reasonably needed to show compliance and support proportionate audits, subject to confidentiality, security and reasonable notice.
The salon's responsibilities
The salon must have a lawful reason for collecting and using the data it enters, give people any required privacy information, keep records accurate, protect account access, and follow the rules for email and SMS marketing. The salon must not instruct HoundCheck to process data unlawfully or enter unnecessary highly sensitive information about people into free-text dog notes.
Approved subprocessor categories
The salon authorises HoundCheck to use providers in the following categories. HoundCheck remains responsible for their data-protection duties relating to the service and requires suitable written protections. The current named supplier register is available to salon customers on request.
- Cloud hostingApplication hosting and delivery
- Database hostingManaged database services
- File and backup storagePrivate files and encrypted backups
- Email deliveryTransactional email delivery
- SMS deliveryText-message delivery
- Error monitoringApplication error detection and investigation
- Uptime monitoringAvailability monitoring and public service status
- AuthenticationOptional third-party account authentication
We may change this list as the service develops. We will give reasonable notice of a material new subprocessor where practical. A salon may object on genuine data-protection grounds; if the issue cannot reasonably be resolved, it may stop using the affected service and close its account.
International transfers
Some providers may process limited data outside the UK. Where UK law requires a transfer safeguard, HoundCheck will use an approved mechanism such as adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to standard contractual clauses, as appropriate.
Questions and requests
Email us for security information, help with a data request, or notice of an objection to a subprocessor.
Email us about data processingEffective and last reviewed: 9 August 2026. This interim DPA should be reviewed alongside the Terms of Service and Privacy policy.