Data processing terms
Last updated: 28 September 2026
When you run your business on Soopaspace, you store your clients' personal data with us: their names, contact details, bookings, payments and the notes you keep. For that data, you are the controller and we, Black Isle Group Limited (company number SC809719, trading as Soopaspace), are your processor. These terms are the agreement UK GDPR (Article 28) requires between us. They form part of our Terms & Conditions, so you accept them when you accept the Terms.
1. What we process, and why
- Purpose: to provide Soopaspace to you: your booking page, bookings, payments, reminders and other emails, client records, finance figures and the assistant.
- Whose data: your clients and prospective clients, the people who book with or enquire to you, and anyone else whose details you add.
- What data: names, email addresses, phone numbers, addresses where given, booking and attendance history, payment records (card details are held by Stripe, never by us), answers to your booking questions, messages, reviews and your notes.
- Sensitive data: if your work involves health or other special category data (a therapist's notes, for example), you are responsible for having a lawful basis and condition for it. We process it under these terms in the same way.
- How long: for as long as you use Soopaspace, then as set out in section 7.
2. Your instructions
We only process your clients' data on your documented instructions. Your instructions are these terms, the Terms & Conditions, and what you tell Soopaspace to do when you use it (taking a booking, sending an email, running a report, asking the assistant). If the law ever requires us to process it otherwise, we'll tell you first unless the law forbids that. If we think an instruction breaks data protection law, we'll tell you.
Anonymised data. You also instruct us to turn data into aggregated, anonymised statistics, combined across many businesses so that no person or business can be identified, as described in section 7 of the Terms. Once data is anonymised it is no longer personal data. Whether your business contributes to shared benchmarks follows the choice you make during setup (see Benchmarking & your data). We never sell or share data that identifies you or your clients.
3. Confidentiality and security
Anyone at Soopaspace who can access your clients' data is bound to keep it confidential, and access is limited to what is needed to run and support the service. We protect the data with appropriate technical and organisational measures, including:
- encryption in transit (HTTPS) everywhere, and encryption at rest by our database provider;
- access controls in the database itself that keep each business's records separate from every other business's;
- sign-in required for everything except the pages you choose to publish;
- regular backups, and regular checks of the software we depend on for known vulnerabilities.
4. Our suppliers (sub-processors)
You give us general permission to use the suppliers listed in section 4 of our Privacy Policy (hosting, database, email delivery and AI, for example). We hold each of them to data protection obligations no weaker than these terms, and we remain responsible to you for what they do. Before we add or replace a supplier that will handle your clients' data, we'll update that list and email you at least 14 days ahead. If you object and we can't reasonably accommodate it, you can close your account.
Some suppliers operate outside the UK. Where they do, the transfer is protected by UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum, as described in section 5 of the Privacy Policy.
5. Helping you meet your obligations
- Your clients' rights. Most requests you can handle yourself in Soopaspace: you can view, correct, export and delete a client's record. If a client contacts us directly, we'll pass the request to you rather than answer it ourselves, and help you respond where you need us to.
- Breaches. If we become aware of a personal data breach affecting your clients' data, we'll tell you without undue delay, and where possible within 48 hours, with what we know, so you can meet your own 72-hour duty to report to the ICO where it applies.
- Assessments. We'll give you reasonable help with data protection impact assessments and any consultation with the ICO that relate to our service.
6. Showing we comply
On request, we'll give you the information reasonably needed to show we meet these terms. If that isn't enough, you (or an independent auditor bound by confidentiality) may audit our compliance once a year, on at least 30 days' notice, at your cost, in a way that doesn't expose other businesses' data.
7. When you leave
You can export your client list at any time from Clients. When you close your account, you can ask us to delete your clients' data, or to send you a copy first, by emailing hello@soopaspace.com; we'll do it within 30 days. If you don't ask, we keep your account for 90 days after closure in case you come back, then delete it. Copies in backups are removed as the backups expire. We keep only what the law requires us to (our own financial records, for example).
8. Everything else
Our liability under these terms is subject to section 8 of the Terms & Conditions, which also apply to anything these terms don't cover. If the two ever conflict about your clients' personal data, these terms win. Questions: hello@soopaspace.com.