For tailoring houses · version 2026-09-02

Data processing agreement

The processing terms between a tailoring house (controller) and AtelierSuite (processor), and the list of sub-processors.

1. Roles

The house is the controller of its clients' personal data. AtelierSuite is the processor and acts only on the house's documented instructions, which are: to provide the service described in the terms of service.

This agreement forms part of the terms of service and applies for as long as we process data for the house.

2. Subject matter of the processing

Categories of data subject: the house's clients, and the house's own staff.

Categories of data: identity and contact details, addresses, body measurements and fitting notes, garment specifications, appointments, correspondence, photographs of work, invoices and payment records.

Nature and purpose: storing, organising, displaying, drafting from, emailing and exporting that data so the house can run its trade.

3. Our obligations

Process only on instruction, and tell the house if an instruction appears unlawful.

Keep the data confidential and bind everyone with access to confidentiality.

Apply appropriate technical and organisational measures: encryption in transit and at rest, per-house isolation enforced at the database, named-account access, and access and change logging.

Help the house answer a data subject's request, and give it the tools to export, correct and erase a client's record itself.

Tell the house without undue delay, and in any event within 24 hours, of any personal data breach affecting its data, with what we know and what we are doing.

Delete or return the data at the end of the agreement, subject to a 30-day recovery window and any legal retention.

Allow the house to audit this, on reasonable notice, by giving information and evidence of our measures.

4. The house's obligations

Have a lawful basis for the data it puts in, and give its clients a privacy notice covering it.

Keep access limited to staff who need it, and remove leavers promptly.

Review every assistant draft before confirming it.

5. Sub-processors

The house authorises the sub-processors listed on this page. We will give notice inside the software before adding a new one, and the house may object.

Every sub-processor is bound to terms no less protective than these, and international transfers rely on the UK international data transfer addendum or standard contractual clauses.

6. Breach and assistance

We will help the house meet its 72-hour notification duty to the ICO, including by providing the facts we hold within the first 24 hours of becoming aware.

Version history

Every version of this document, newest first, with the day it came into force. Lines here are never edited once published, so what was in force on any date can be shown.

  1. Version 2026-09-02 · in force from 2 September 2026 · current

    Sub-processor list brought in line with the software.

    • Added the model gateway, bank-settlement and open-banking processors.
    • Tied the quarterly review of new features to this list.
  2. Version 2026-08-01 · in force from 1 August 2026

    First published processing terms.

    • Roles, instructions, security, sub-processors, audit and return or deletion on exit.