← Terms & Conditions

Data processing terms

Last updated: 28 September 2026

When you run your business on Soopaspace, you store your clients' personal data with us: their names, contact details, bookings, payments and the notes you keep. For that data, you are the controller and we, Black Isle Group Limited (company number SC809719, trading as Soopaspace), are your processor. These terms are the agreement UK GDPR (Article 28) requires between us. They form part of our Terms & Conditions, so you accept them when you accept the Terms.

1. What we process, and why

2. Your instructions

We only process your clients' data on your documented instructions. Your instructions are these terms, the Terms & Conditions, and what you tell Soopaspace to do when you use it (taking a booking, sending an email, running a report, asking the assistant). If the law ever requires us to process it otherwise, we'll tell you first unless the law forbids that. If we think an instruction breaks data protection law, we'll tell you.

Anonymised data. You also instruct us to turn data into aggregated, anonymised statistics, combined across many businesses so that no person or business can be identified, as described in section 7 of the Terms. Once data is anonymised it is no longer personal data. Whether your business contributes to shared benchmarks follows the choice you make during setup (see Benchmarking & your data). We never sell or share data that identifies you or your clients.

3. Confidentiality and security

Anyone at Soopaspace who can access your clients' data is bound to keep it confidential, and access is limited to what is needed to run and support the service. We protect the data with appropriate technical and organisational measures, including:

4. Our suppliers (sub-processors)

You give us general permission to use the suppliers listed in section 4 of our Privacy Policy (hosting, database, email delivery and AI, for example). We hold each of them to data protection obligations no weaker than these terms, and we remain responsible to you for what they do. Before we add or replace a supplier that will handle your clients' data, we'll update that list and email you at least 14 days ahead. If you object and we can't reasonably accommodate it, you can close your account.

Some suppliers operate outside the UK. Where they do, the transfer is protected by UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or Standard Contractual Clauses with the UK Addendum, as described in section 5 of the Privacy Policy.

5. Helping you meet your obligations

6. Showing we comply

On request, we'll give you the information reasonably needed to show we meet these terms. If that isn't enough, you (or an independent auditor bound by confidentiality) may audit our compliance once a year, on at least 30 days' notice, at your cost, in a way that doesn't expose other businesses' data.

7. When you leave

You can export your client list at any time from Clients. When you close your account, you can ask us to delete your clients' data, or to send you a copy first, by emailing hello@soopaspace.com; we'll do it within 30 days. If you don't ask, we keep your account for 90 days after closure in case you come back, then delete it. Copies in backups are removed as the backups expire. We keep only what the law requires us to (our own financial records, for example).

8. Everything else

Our liability under these terms is subject to section 8 of the Terms & Conditions, which also apply to anything these terms don't cover. If the two ever conflict about your clients' personal data, these terms win. Questions: hello@soopaspace.com.