Data Processing Agreement

Last updated: 15 July 2026

This Data Processing Agreement ("DPA") is between you ("Controller"), a beauty and wellness professional using the Ricorda professional app, and UNKNWN LABS LTD ("Ricorda", "Processor"), a company registered in England and Wales under company number 17301306, with its registered office at 10 Clifton Terrace, London, N4 3JP, United Kingdom, the operator of the Ricorda platform. This DPA forms part of the Professional Terms of Use and takes effect when you create a Ricorda professional account.

1. Definitions

In this DPA:

2. Scope and Purposes of Processing

Ricorda processes the following categories of personal data on behalf of the Controller solely for the purpose of providing the Ricorda record-keeping and scheduling service:

Data CategoryExamplesClassification
Client identity data Name, date of birth, email address, phone number, Ricorda passport ID Personal data
Session records Session type, date, status, session photos, and any optional free-text notes the Controller chooses to add Personal data
Health and aftercare information Allergies, conditions, medication, medical history, aftercare details and related session notes Special-category personal data where it concerns health
Agreement records Forms and agreements signed by the client, including the signature method and the date signed Personal data
Account audit logs Timestamps and records of account and record activity Personal data

Data concerning health is special-category personal data. Before directing Ricorda to process it, the Controller must identify and document both an Article 6 lawful basis and an applicable Article 9 condition, together with any additional requirements under the Data Protection Act 2018. The Controller must limit structured and free-text records to information necessary for the stated purpose. Ricorda processes that information only on the Controller's documented instructions and for no other purpose.

3. Duration of Processing

Processing continues while the Controller's account remains open. Subscription cancellation or expiry may restrict Studio features but does not itself constitute an instruction to delete the account. The Controller can export data from account settings before deletion. On a confirmed account-deletion instruction:

4. Controller Obligations

The Controller shall:

5. Processor Obligations

Ricorda (the Processor) shall:

6. Sub-processors

By accepting these terms, the Controller authorises Ricorda to use the following sub-processors. Ricorda will impose data protection obligations on each sub-processor equivalent to those in this DPA.

Sub-processorRoleData processedLocation
Google Cloud / Firebase Cloud infrastructure, database (Firestore), file storage, authentication, push notifications and crash reporting All client data and session records EU (europe-west1 / eur3 region)
Stripe Payment processing and subscription management Professional billing details only — no client records are shared with Stripe EU / UK (Stripe UK Ltd)
Resend Transactional email delivery Email address and name only, for notification and account management emails EU

Ricorda will notify Controllers of any intended addition or replacement of sub-processors by updating this DPA and providing notice by email. If a Controller objects to a new sub-processor, they may terminate their subscription within 30 days of the notice.

7. Security Measures

Ricorda implements the following technical and organisational security measures:

While Ricorda implements appropriate technical and organisational measures designed to protect personal data, no method of transmission or storage is completely secure, and Ricorda cannot guarantee absolute security. Ricorda's obligation is to maintain a level of security appropriate to the risk, as required by UK GDPR Article 32, and not to guarantee that a breach will never occur.

8. International Data Transfers

Client data is stored primarily within the EU (Google Cloud europe-west1 / eur3 region). Where sub-processors transfer data outside the UK or EEA, such transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority or a UK adequacy decision.

9. Data Subject Rights

Ricorda will assist the Controller in responding to data subject requests within a reasonable timeframe, allowing the Controller to meet its statutory deadlines (one calendar month under UK GDPR).

Clients may also exercise certain rights directly via the Ricorda ID app:

Where a client submits a request directly to Ricorda relating to data controlled by a professional, Ricorda will forward the request to the relevant Controller within 5 working days.

10. Data Breach Notification

In the event of a personal data breach, Ricorda will:

11. Audit Rights

The Controller may audit Ricorda's compliance with this DPA on reasonable written notice (at least 14 days), no more than once per year, and at the Controller's own expense. Audits must be conducted during normal business hours and in a manner that minimises disruption to Ricorda's operations.

12. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Professional Terms of Use, which apply to this DPA as if set out in full here. In particular, the Processor's total aggregate liability to the Controller under this DPA shall not exceed the cap set out in those terms (the greater of the subscription fees paid in the twelve (12) months preceding the claim, or £100).

The Processor is liable only for damage caused by processing where it has not complied with obligations under the UK GDPR specifically directed to processors, or where it has acted outside or contrary to the Controller's lawful documented instructions. The Controller remains responsible for ensuring a lawful basis for processing, for the lawfulness of its instructions, and for the content and nature of the data it directs the Processor to process.

Nothing in this DPA limits or excludes either party's liability to a data subject under Article 82 of the UK GDPR, or any other liability that cannot lawfully be limited or excluded.

13. Indemnity

The Controller shall indemnify and hold the Processor harmless against all claims, losses, liabilities, fines, penalties, and costs (including reasonable legal fees) — including any compensation paid to a data subject under Article 82 of the UK GDPR and any administrative fine imposed by a supervisory authority — to the extent arising from:

The Processor shall indemnify the Controller against claims, losses, and liabilities to the extent directly arising from the Processor's own breach of its processor obligations under this DPA, subject to the limitation of liability above.

14. Governing Law

This DPA is governed by the laws of England and Wales. Disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

15. Contact

Data protection enquiries and subject access requests: