DPA.
How Mane handles your clients’ data when you process them through the platform.
1. Parties & Roles
This Data Processing Addendum ("DPA") supplements the Mane Terms of Service between Christian G Flair LLC, a Florida limited liability company ("Mane," "Processor"), and the operator using Mane to manage their client list ("Operator," "Controller"). For end-client personal data Operator imports into or generates through Mane, Operator is the data controller and Mane is the processor.
2. Scope of Processing
Mane processes end-client personal data only on Operator's documented instructions, which include using the platform for: client management, appointment booking, deposit handling, SMS/email reminders, loyalty points, photos, notes, and analytics. Mane will not process the data for any other purpose without Operator's prior written consent.
3. Categories of Data
Mane processes: full name, phone number, email, physical address (when provided), profile photo (when uploaded), booking history, appointment notes, no-show history, payment metadata (card last 4, transaction IDs — not PANs), referral codes, and any free-text notes Operator adds. We do NOT request, store, or process biometric data, government IDs, health records, or children's data.
4. Subprocessors
Mane uses the following subprocessors, each bound by data protection terms: Stripe (payments), Meta (WhatsApp message delivery), Resend (email), Apple (push notification delivery to iOS devices), Vercel (hosting), Retell (AI phone answering), Anthropic (AI agent inference), OpenAI (AI fallback), PostHog (product analytics), Sentry (error monitoring), and a managed PostgreSQL provider. Operator authorizes Mane to engage these subprocessors. Mane will give Operator 14 days written notice (via email to the address on file) before adding or replacing a subprocessor; Operator may object in writing, in which case Operator may terminate the affected feature.
5. Security
Mane maintains: TLS 1.2+ in transit; encryption at rest for the database; signed JWT authentication tokens; bcrypt password hashing; multi-factor authentication available to Operator; role-based access controls; access logging for sensitive operations. Stripe processes all PAN data under PCI-DSS Level 1. Mane personnel access end-client data only on a need-to-know basis for support, fraud, or maintenance and only with operator consent or under documented legal request.
6. Data Subject Requests
Where Operator receives a request from an end-client to access, correct, port, or delete their data, Mane will assist Operator in responding. Most requests can be fulfilled by Operator directly through the dashboard (export, edit, delete). For requests Mane must fulfill directly (e.g., legal hold release), contact hello@joinmane.com — we respond within 30 days.
7. Breach Notification
If Mane becomes aware of a personal data breach affecting Operator's end-client data, Mane will notify Operator by email within 72 hours of confirmation. Notice will include the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address it. Operator remains responsible for any further notification required under applicable law (e.g., GDPR Art. 34, state breach laws).
8. International Transfers
Mane operates servers in the United States. Where end-client data originates from the EEA, UK, or Switzerland, the transfer to the United States relies on the EU-U.S. Data Privacy Framework where applicable, and on the Standard Contractual Clauses (Module 2: Controller-to-Processor) as a fallback. Operator and Mane both incorporate the SCCs by reference into this DPA.
9. Audit Rights
Operator may, at its expense and on 30 days written notice, audit Mane's compliance with this DPA once per 12-month period. Audits are conducted during business hours, do not unreasonably interfere with Mane's operations, and may be limited to written questionnaires or to information Mane already provides via standard certifications (SOC, ISO) when available.
10. Return or Deletion
On termination of the Mane subscription, Operator may export end-client data via the dashboard for 30 days. After 30 days, Mane deletes (or anonymizes) end-client data within 90 days unless retention is required for tax, legal, or dispute purposes — see Privacy §7 for retention specifics.
11. Liability & Indemnity
Liability arising under this DPA is governed by the limitation-of-liability and indemnification clauses of the Mane Terms of Service. Mane is not liable for processing Operator instructs that violates applicable law; Operator indemnifies Mane against third-party claims arising from such instructions.
12. Governing Law
This DPA is governed by the laws of the State of Florida, except where Operator's end-clients are EEA / UK residents and EU / UK data protection law applies to the processing — in which case, EU / UK data protection law governs that specific processing, without altering the governing law for the rest of the agreement.
13. Contact
Christian G Flair LLC · Royal Palm Beach, FL · hello@joinmane.com