← Back to home

Data Processing Agreement

Last updated 13 June 2026

01Scope

This summary applies when AESTHETECH processes personal data on behalf of a client, for example, data handled while building, testing, or operating software for that client. It is summarised here; the binding DPA is signed with each client.

02Roles

The client is the controller and decides why and how data is processed. AESTHETECH is the processor and acts only on the client's documented instructions.

03Processing and sub-processors

We process the data necessary to design, build, and run the client's software. We engage sub-processors for hosting and infrastructure under equivalent obligations, and maintain an up-to-date list available on request.

04Security measures

Encryption in transit and at rest, role-based access control, secrets management, audit logging, and least-privilege access. Personnel are bound by confidentiality.

05Transfers, requests and deletion

International transfers rely on Standard Contractual Clauses. We assist the controller with data-subject requests and breach notification, and return or delete data on termination.