Last updated: 15 July 2026
This Data Processing Agreement ("DPA") is between you ("Controller"), a beauty and wellness professional using the Ricorda professional app, and UNKNWN LABS LTD ("Ricorda", "Processor"), a company registered in England and Wales under company number 17301306, with its registered office at 10 Clifton Terrace, London, N4 3JP, United Kingdom, the operator of the Ricorda platform. This DPA forms part of the Professional Terms of Use and takes effect when you create a Ricorda professional account.
In this DPA:
Ricorda processes the following categories of personal data on behalf of the Controller solely for the purpose of providing the Ricorda record-keeping and scheduling service:
| Data Category | Examples | Classification |
|---|---|---|
| Client identity data | Name, date of birth, email address, phone number, Ricorda passport ID | Personal data |
| Session records | Session type, date, status, session photos, and any optional free-text notes the Controller chooses to add | Personal data |
| Health and aftercare information | Allergies, conditions, medication, medical history, aftercare details and related session notes | Special-category personal data where it concerns health |
| Agreement records | Forms and agreements signed by the client, including the signature method and the date signed | Personal data |
| Account audit logs | Timestamps and records of account and record activity | Personal data |
Data concerning health is special-category personal data. Before directing Ricorda to process it, the Controller must identify and document both an Article 6 lawful basis and an applicable Article 9 condition, together with any additional requirements under the Data Protection Act 2018. The Controller must limit structured and free-text records to information necessary for the stated purpose. Ricorda processes that information only on the Controller's documented instructions and for no other purpose.
Processing continues while the Controller's account remains open. Subscription cancellation or expiry may restrict Studio features but does not itself constitute an instruction to delete the account. The Controller can export data from account settings before deletion. On a confirmed account-deletion instruction:
The Controller shall:
Ricorda (the Processor) shall:
By accepting these terms, the Controller authorises Ricorda to use the following sub-processors. Ricorda will impose data protection obligations on each sub-processor equivalent to those in this DPA.
| Sub-processor | Role | Data processed | Location |
|---|---|---|---|
| Google Cloud / Firebase | Cloud infrastructure, database (Firestore), file storage, authentication, push notifications and crash reporting | All client data and session records | EU (europe-west1 / eur3 region) |
| Stripe | Payment processing and subscription management | Professional billing details only — no client records are shared with Stripe | EU / UK (Stripe UK Ltd) |
| Resend | Transactional email delivery | Email address and name only, for notification and account management emails | EU |
Ricorda will notify Controllers of any intended addition or replacement of sub-processors by updating this DPA and providing notice by email. If a Controller objects to a new sub-processor, they may terminate their subscription within 30 days of the notice.
Ricorda implements the following technical and organisational security measures:
While Ricorda implements appropriate technical and organisational measures designed to protect personal data, no method of transmission or storage is completely secure, and Ricorda cannot guarantee absolute security. Ricorda's obligation is to maintain a level of security appropriate to the risk, as required by UK GDPR Article 32, and not to guarantee that a breach will never occur.
Client data is stored primarily within the EU (Google Cloud europe-west1 / eur3 region). Where sub-processors transfer data outside the UK or EEA, such transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority or a UK adequacy decision.
Ricorda will assist the Controller in responding to data subject requests within a reasonable timeframe, allowing the Controller to meet its statutory deadlines (one calendar month under UK GDPR).
Clients may also exercise certain rights directly via the Ricorda ID app:
Where a client submits a request directly to Ricorda relating to data controlled by a professional, Ricorda will forward the request to the relevant Controller within 5 working days.
In the event of a personal data breach, Ricorda will:
The Controller may audit Ricorda's compliance with this DPA on reasonable written notice (at least 14 days), no more than once per year, and at the Controller's own expense. Audits must be conducted during normal business hours and in a manner that minimises disruption to Ricorda's operations.
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Professional Terms of Use, which apply to this DPA as if set out in full here. In particular, the Processor's total aggregate liability to the Controller under this DPA shall not exceed the cap set out in those terms (the greater of the subscription fees paid in the twelve (12) months preceding the claim, or £100).
The Processor is liable only for damage caused by processing where it has not complied with obligations under the UK GDPR specifically directed to processors, or where it has acted outside or contrary to the Controller's lawful documented instructions. The Controller remains responsible for ensuring a lawful basis for processing, for the lawfulness of its instructions, and for the content and nature of the data it directs the Processor to process.
Nothing in this DPA limits or excludes either party's liability to a data subject under Article 82 of the UK GDPR, or any other liability that cannot lawfully be limited or excluded.
The Controller shall indemnify and hold the Processor harmless against all claims, losses, liabilities, fines, penalties, and costs (including reasonable legal fees) — including any compensation paid to a data subject under Article 82 of the UK GDPR and any administrative fine imposed by a supervisory authority — to the extent arising from:
The Processor shall indemnify the Controller against claims, losses, and liabilities to the extent directly arising from the Processor's own breach of its processor obligations under this DPA, subject to the limitation of liability above.
This DPA is governed by the laws of England and Wales. Disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Data protection enquiries and subject access requests: