Anexo de Tratamiento de Datos / Data Processing Addendum
Este anexo forma parte del contrato con el negocio suscriptor y se publica y rige en inglés. Si reservaste una cita, consulta el Aviso al cliente en español.
Audience: the business that subscribes to Plaza (the "Tenant"). This Addendum is Exhibit A to the Platform Terms of Service (Platform Terms of Service) and forms part of that agreement.
Self-executing. No separate signature is required. By accepting the Terms, the Tenant accepts this Addendum, and it becomes effective for both parties on that date.
1. Scope, purpose, and precedence
1.1 This Addendum governs Techne's processing of Customer Data — personal information about the Tenant's End Customers and Staff Users — on the Tenant's behalf.
1.2 It does not govern Tenant Account Data, for which Techne is the controller. That is described in Privacy Policy §1 and §2.1.
1.3 Precedence. On any question of data-protection roles, obligations, or the handling of Customer Data, this Addendum controls over the body of the Terms (Platform Terms of Service §1.4).
1.4 Applicable Data Protection Law means every privacy or data-protection law applicable to the parties' processing under this Addendum, including the California Consumer Privacy Act as amended by the CPRA and its regulations at 11 CCR §7000 et seq., the New Jersey Data Privacy Act (N.J.S.A. §56:8-166.4 et seq.), and the comprehensive privacy statutes of other U.S. states as they take effect.
1.5 Terms used. "Controller" includes "business." "Processor" includes "service provider" and "contractor." "Personal information" includes "personal data." "Consumer" includes "data subject." "Sell" and "share" have the meanings given by the CCPA/CPRA. Other capitalized terms have the meanings in Platform Terms of Service §2.
2. Roles and instructions
2.1 Roles. For Customer Data, the Tenant is the controller / business and Techne is the processor / service provider. The Tenant determines the purposes and means of processing; Techne processes only on the Tenant's documented instructions.
2.2 What counts as the Tenant's instructions. The Tenant's documented instructions consist of: (a) the Terms and this Addendum; (b) the Tenant's configuration and use of the Service, including which features it enables, what it puts in custom forms, whom it messages, and what it exports; and (c) any further written instruction the parties agree to. Annex 1 sets out the details of processing required by Applicable Data Protection Law.
2.3 Instructions must be lawful. The Tenant represents that its instructions comply with Applicable Data Protection Law and that it has given all notices and has all lawful bases and consents required for Techne and its subprocessors to process Customer Data as the Service operates — including the consents necessary for Stripe to process payment information and for messages to be sent.
2.4 Techne's notice back. If Techne concludes that an instruction violates Applicable Data Protection Law, or that it can no longer meet its obligations under this Addendum, Techne will promptly notify the Tenant and may suspend the affected processing until the instruction is corrected.
2.5 The Tenant's own duties are its own. Techne is not responsible for whether the Tenant has a privacy notice, whether that notice is accurate, whether the Tenant answered a consumer's request, or whether the Tenant's own collection practices are lawful. Techne provides software, records, and assistance; it does not supervise the Tenant's compliance.
2.6 One narrow controller carve-out, stated deliberately. Techne processes certain information its own infrastructure generates — server and error logs, IP addresses, request metadata, rate-limiting records, and abuse and fraud signals — as a controller, for the sole purposes of operating, securing, and defending the Service. This is a narrow, security-and-availability carve-out; it does not extend to any Customer Data content, is never used for advertising, profiling, or model training, and is never sold or shared. It is stated here rather than left to inference so that the parties' roles are decided, not accidental.
3. Subprocessors
3.1 General authorization. The Tenant authorizes Techne to engage subprocessors. The current list is in Annex 2 and is published at crm.technestudios.net/subprocessors.
3.2 Flow-down. Techne will impose on each subprocessor, by written contract, data-protection obligations no less protective than those in this Addendum, appropriate to the subprocessor's role. Techne remains fully responsible to the Tenant for each subprocessor's performance of those obligations.
3.3 Advance notice, with a real mechanism. Before a new subprocessor begins processing Customer Data, Techne will (a) update the dated subprocessors page and (b) send an email to the Tenant's account address, at least thirty (30) days in advance. Where a change must be made urgently to preserve security or continuity of the Service, Techne will make it and notify as soon as reasonably practicable, with the reason.
3.4 Objection. Within thirty (30) days of a notice under 3.3, the Tenant may object in writing to privacy@technestudios.net on reasonable data-protection grounds. The parties will discuss in good faith. If Techne cannot make the affected functionality available without the new subprocessor, the Tenant may terminate the affected feature or, if the feature is material to its use of the Service, the Terms, effective on notice, and receive a pro-rata refund of prepaid Subscription Fees for the unused remainder of the then-current period. That is the Tenant's sole remedy for an objection.
3.5 Tenant-connected integrations are not subprocessors. When a Tenant connects an optional integration (for example QuickBooks Online or Google Calendar), that provider receives data at the Tenant's direction and under the Tenant's own agreement with it. It is not Techne's subprocessor and Techne is not responsible for it (Platform Terms of Service §11.2).
4. Techne's commitments as processor / service provider
Techne makes the following commitments, which are intended to satisfy the mandatory service-provider contract terms of 11 CCR §7051 and the processor-contract requirements of the NJDPA and comparable state law. Techne:
- Will not sell or share Customer Data, as "sell" and "share" are defined by the CCPA/CPRA, and will not disclose it for monetary or other valuable consideration.
- Will process Customer Data only for the specific business purposes set out in Annex 1, which are stated specifically and not in generic terms.
- Will not retain, use, or disclose Customer Data for any purpose other than those specific business purposes, including any commercial purpose of its own.
- Will not retain, use, or disclose Customer Data outside the direct business relationship between Techne and the Tenant.
- Will not combine Customer Data with personal information received from, or on behalf of, any other person, or collected from its own interactions with a consumer, except as permitted by Applicable Data Protection Law to detect security incidents or resist malicious or illegal activity.
- Will provide the same level of privacy protection required of the Tenant by Applicable Data Protection Law, and will implement and maintain reasonable security as described in Section 6 and Annex 3.
- Will notify the Tenant promptly, and in any event without undue delay, if it determines it can no longer meet these obligations.
- Grants the Tenant the right, on reasonable prior written notice and no more than once in any twelve-month period (unless a security incident or a regulator requires otherwise), to take reasonable and appropriate steps to verify Techne's compliance, as described in Section 9.
- Grants the Tenant the right, on notice of unauthorized use, to take reasonable and appropriate steps to stop and remediate it, and Techne will cooperate in doing so and will confirm deletion where deletion is the remedy.
- Will cooperate with, and reasonably assist, the Tenant in responding to consumer rights requests, as described in Section 5, and will impose each of these obligations on its subprocessors by contract.
Additionally, Techne will: ensure personnel with access to Customer Data are bound by confidentiality; keep access limited to what is necessary to provide and support the Service; and not use Customer Data to train or improve any artificial-intelligence model, its own or any third party's.
5. Assisting with consumer rights requests
5.1 The Tenant answers. The Tenant is responsible for responding to requests from its End Customers and Staff Users to know, access, correct, delete, port, opt out, or appeal.
5.2 Self-service first. The Service gives the Tenant the tools to answer most requests itself: client-record access and correction; per-report CSV export; consent-preference management; message-history review; and an account-deletion function (Section 7). There is no single whole-account export; a full export is produced manually on request under Section 7.5.
5.3 Where a request reaches Techne. If a consumer sends a rights request directly to Techne about Customer Data, Techne will not act on it as a controller. Techne will forward it to the Tenant without undue delay, tell the consumer it has done so, and provide the Tenant reasonable assistance to respond within the statutory period.
5.4 Regulators and legal process. If Techne receives a binding legal demand for Customer Data, Techne will, unless legally prohibited, notify the Tenant before disclosing, disclose only what is legally required, and seek to redirect the requester to the Tenant.
5.5 Cost. Assistance under this Section is provided at no charge for requests in normal volume. If the Tenant's requests become materially burdensome, the parties will agree on reasonable cost recovery before Techne is obliged to continue.
6. Security
6.1 Techne will implement and maintain the technical and organizational measures described in Annex 3, appropriate to the nature of the data and to the size and resources of the operation.
6.2 No certification claim. Techne holds no security certification and makes no representation of SOC 2, PCI-DSS, HIPAA, ISO 27001 or comparable compliance. Annex 3 describes what the system actually does. Techne does not represent that the Service cannot be breached.
6.3 Changes. Techne may change its security measures, provided the overall level of protection is not materially reduced.
7. Retention, deletion, and return
7.1 During the term. Techne retains Customer Data for as long as the Tenant maintains it in the Service.
7.2 Deletion by the Tenant. The Tenant may run the Service's account-deletion function. On execution:
(a) Day 0 — hard erasure. Personal information of the Tenant's End Customers and Staff Users — names, contact details, notes, message contents, and stored third-party integration tokens — is erased across the Tenant's business.
(b) Seven years — de-identified financial records. Sales, refunds, payouts, gift-card and loyalty ledgers, and deposit charges are retained in de-identified form to satisfy tax, accounting, and financial-record obligations. A daily scheduled job hard-purges them when the seven-year period expires.
(c) Consent records are retained. Records of messaging consent — the exact language shown, the method, and the timestamp — are deliberately excluded from erasure and survive. They are retained as the evidence that messages sent were consented to, which protects both parties against a complaint made after the underlying records are gone. They are protected by an append-only control that the deletion process must explicitly bypass.
(d) Irreversible, and it forecloses return. Techne cannot restore a deleted account, and deletion extinguishes the return obligation in Section 7.5. Export first (Platform Terms of Service §15.4).
7.3 The Tenant's acknowledgement. The Tenant acknowledges that 7.2(b) and 7.2(c) are exceptions to deletion, that they are described in Privacy Policy §7 which the Tenant's own privacy notice should reflect, and that the Tenant is responsible for telling its own customers about them where its notice obligations require.
7.4 Credential purging. Independently of account deletion, a scheduled job purges dead bearer-credential records — recognition tokens, portal sessions, portal sign-in rate records, calendar-feed tokens, and other portal tokens — thirty (30) days after each record becomes dead.
7.5 Return on termination. For thirty (30) days after termination of the Terms, Techne will, on the Tenant's written request to soporte@technestudios.net, produce an export of Customer Data in a machine-readable format (Platform Terms of Service §15.4). Techne produces this manually and does not commit to a turnaround time. This obligation does not survive the Tenant's use of the account-deletion function in Section 7.2: erasure under 7.2(a) is immediate and irreversible, and once run there is no Customer Data left to return. The Tenant should request and receive any export before running deletion. After the window, Techne will delete or de-identify Customer Data in the ordinary course, subject to backup-rotation cycles and to retention required by law.
7.6 Backups. Data in backup media is deleted on the ordinary backup-rotation cycle rather than instantaneously. Until it is, it remains protected by this Addendum.
8. Security incidents
8.1 Notice. On becoming aware of a security incident affecting Customer Data, Techne will notify the affected Tenant without undue delay and as required by Applicable Data Protection Law, describing what is known, the categories and approximate number of records affected if known, the likely consequences, and the measures taken or proposed.
8.2 No fixed clock, and why. Techne deliberately does not commit to a fixed number of hours. New Jersey law requires notice without unreasonable delay. Plaza is operated by one person who would, in an incident, be simultaneously performing containment, forensics, counsel engagement, insurer notice, and drafting. A contractual seventy-two-hour promise would create an independent breach-of-contract claim that the statute does not create. The Tenant should not rely on this Addendum for a notification deadline; it should rely on the statute.
8.3 Assistance. Techne will provide the Tenant reasonable assistance and information needed for the Tenant to meet its own notification obligations to consumers and regulators. The Tenant, as controller, is responsible for deciding whether to notify and for making the notification.
8.4 No admission. A notice under this Section is not an admission of fault or liability.
9. Verification and audit
9.1 On at least thirty (30) days' prior written notice, and no more than once in any twelve-month period (unless a security incident affecting the Tenant has occurred or a regulator requires otherwise), the Tenant may verify Techne's compliance with this Addendum.
9.2 How. Verification is by written questionnaire and by Techne's written responses, supporting documentation, and a remote conference. On-site inspection, penetration testing, and vulnerability scanning of the Service are not permitted, because Plaza is multi-tenant and those activities would affect other tenants' data and availability (Platform Terms of Service §10.3).
9.3 Conditions. Verification must be at the Tenant's expense, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or compromise another tenant's data.
10. Sensitive and prohibited data
10.1 Sensitive data. The Tenant may configure custom intake and consent forms and may thereby collect information that Applicable Data Protection Law treats as sensitive — including health-adjacent information, precise geolocation, immigration status, or biometric data. Techne does not control, review, or restrict what a Tenant asks. The Tenant is solely responsible for obtaining any opt-in consent required (including under the NJDPA), for performing any required data-protection assessment, and for the heightened handling obligations that follow.
10.2 Prohibited data. The Tenant must not submit to the Service: payment card numbers outside Stripe's payment form; Social Security or other government identification numbers; financial account credentials; information subject to HIPAA where the Tenant is a covered entity or business associate (Techne is not a business associate and will not sign a BAA); information subject to the Gramm-Leach-Bliley Act; or information of a child under 13 without the consent required by law.
10.3 Effect. If the Tenant submits prohibited data, it does so in breach of this Addendum, it is responsible for the consequences, and Techne's indemnity under Platform Terms of Service §12 applies.
11. Location of processing
Processing occurs in the United States and in other countries where Techne's subprocessors operate. The Service is not currently offered in the European Economic Area or the United Kingdom, and no EU/UK transfer mechanism is relied upon. If Techne begins offering the Service in those regions, it will implement an appropriate transfer mechanism and amend this Addendum first.
12. Liability, term, and construction
12.1 Liability. Each party's liability under this Addendum is subject to the exclusions and the cap in Platform Terms of Service §13, and this Addendum does not create a separate or additional cap. Nothing here limits a party's liability where Applicable Data Protection Law prohibits limitation.
12.2 Term. This Addendum applies for as long as Techne processes Customer Data, and its Sections 4, 7, 8 and 12 survive termination of the Terms.
12.3 Changes. Techne may update this Addendum to reflect a change in Applicable Data Protection Law or in the Service, on notice under Platform Terms of Service §16.2. An update will not reduce the level of protection.
12.4 Contact. privacy@technestudios.net · Techne Studios LLC, 59 2nd Ave, Unit 374, Raritan, NJ 08869.
Annex 1 — Details of processing
Subject matter. Provision of the Plaza booking, CRM, point-of-sale, payments-enablement and messaging service to the Tenant.
Duration. For the term of the Terms, plus the retention periods in Section 7.
Nature of processing. Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, disclosure to subprocessors, restriction, erasure and destruction — all by automated means within the Service.
Specific business purposes (the only purposes for which Customer Data is processed):
- Operating the Tenant's public booking page and receiving bookings.
- Maintaining the Tenant's calendar, appointments, and staff schedules.
- Maintaining the Tenant's client records, including notes and custom form responses.
- Sending transactional appointment messages and receipts by SMS and email on the Tenant's instruction.
- Sending marketing messages only to recipients whose marketing consent is recorded.
- Recording, storing and evidencing consent (the append-only consent log).
- Enabling checkout, deposits, refunds and payouts on the Tenant's own Stripe Connected Account.
- Operating the gift-card and loyalty ledgers.
- Operating the "Mis citas" customer portal, including magic-link sign-in and consent preferences.
- Producing reports for the Tenant, including sales, deposit, and unclaimed-property aging reports.
- Providing support to the Tenant at its request.
- Backing up, restoring, and securing the data, and detecting and resisting fraud and abuse.
- Complying with Techne's legal obligations.
Categories of data subjects: the Tenant's End Customers; the Tenant's Staff Users.
Categories of personal information: identifiers (name, phone, email); appointment and service history; free-text notes and custom-form responses; consent records; message contents and delivery status; commercial and transaction records; gift-card and loyalty balances; staff role and schedule information; and, only where the Tenant chooses to collect it, sensitive information (Section 10.1).
Frequency: continuous, for the term.
Annex 2 — Subprocessors
Current as of the version date of this Addendum. The live, dated list is at crm.technestudios.net/subprocessors.
| Subprocessor | Function | Data processed | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing; Connect accounts; subscription billing | Payment and transaction data; payer identifiers | United States |
| Supabase, Inc. | Database, authentication, storage | Substantially all Customer Data | United States |
| Twilio Inc. | SMS send/receive over toll-free number | Phone numbers; message contents; opt-out records | United States |
| Google LLC (Google Workspace) | Email service account for transactional mail and receipts | Email addresses; message contents | United States |
| Resend, Inc. | Transactional email delivery | Email addresses; message contents | United States |
| Cloudflare, Inc. | Hosting, CDN, scheduled jobs, network protection | Traffic metadata; IP addresses | United States |
| Anthropic, PBC | AI assistant in-app and on booking pages | Text typed into the assistant | United States |
Tenant-connected, not subprocessors (Section 3.5): Intuit (QuickBooks Online); Google (Google Calendar).
Annex 3 — Technical and organizational measures
Described honestly, at the level the system actually implements.
Access control. Row-level security in the database isolating each tenant's data; capability-gated permissions within each tenant account, with elevated capabilities required for money-moving and value-minting actions; least-privilege administrative access held by the sole member.
Authentication. Password and session authentication for staff and owners through Supabase Auth; magic-link, single-use, expiring sign-in for the customer portal; rate limiting on portal sign-in attempts.
Credential hygiene. Bearer credentials stored as short-lived, revocable tokens; a scheduled job purges dead credential records 30 days after death (Section 7.4).
Encryption. TLS for data in transit; encryption at rest as provided by Supabase and Cloudflare; secrets held outside the source repository.
Payment isolation. Card data collected exclusively by Stripe's Payment Element; full card numbers never reach Techne's systems.
Integrity. Append-only ledgers for consent records and gift-card value; idempotent, claim-first money operations that refuse rather than double-execute; typed refusals instead of silent failure on refund, redemption and permission paths.
Auditability. Consent events record exact language, method and timestamp; refunds and gift-card adjustments record the acting user; server events are logged.
Resilience. Managed database backups through Supabase; infrastructure operated on Cloudflare.
Organizational. One operator, who is the sole person with production access; confidentiality obligations flowed down to subprocessors by contract; changes reviewed against an automated test suite before deployment.
Not claimed: independent audit, certification, formal incident-response retainer, 24/7 monitoring, or penetration testing.
Exhibit A to Platform Terms of Service. Related: Privacy Policy · Acceptable Use Policy (Exhibit B) · Messaging Program Terms (Exhibit C).