Skip to content

Data Processing Addendum

Effective:

Last updated:

Version 1.0

Leer en español

In plain words

  • Your shop decides why its customers' information is collected. We process it for you, only to run your line.
  • We keep it confidential, protect it, use the providers listed on our Subprocessors page, and tell you about changes to that list.
  • If something goes wrong with the data, we tell you without undue delay and help you.
  • When your shop ends, customer information is erased on a fixed schedule.
  • This addendum is part of the Terms of Service; you accept it with them.

Parties and scope

This Data Processing Addendum ("addendum") is between the shop that accepted the Terms of Service ("shop", "you") and Kallos Labs LLC ("we"). It applies to the personal information of the shop's customers that we process to provide Walk-In Waitlist ("customer data"). If this addendum and the terms conflict about customer data, this addendum controls.

Roles

  • You are the business (controller) for customer data: you decide to run your line with Walk-In Waitlist, which customers join it and how you use their information at your shop.
  • We are your service provider (processor): we process customer data only on your behalf to provide the service.
  • For a few things we act on our own account, as the Privacy Policy explains: the list of numbers that replied STOP, the records that prove consent to texts, security and abuse prevention, and aggregated counts without names or numbers. We keep these to comply with the law and protect the service, not to sell or market anything.

The processing

ItemDescription
Subject matterRunning a walk-in line: joining, the live queue, the status page and visit texts
DurationWhile the shop uses the service, plus the retention periods below
Kinds of peopleThe shop's walk-in customers, and the people they add to their visit
Kinds of dataFirst names, optional mobile numbers, consent to texts, visit details (service, team member, times, outcome), text messages and replies, keyed codes of phone numbers and IP addresses
Sensitive dataNone is requested. Do not enter health, financial or other sensitive information in names.

Our commitments

We will:

  1. Follow your instructions. Process customer data only to provide the service as described in the terms and as you configure it in the app. If we think an instruction breaks the law, we will tell you.
  2. Not sell or share it. Not sell customer data, not share it for cross-context behavioral advertising, not use it for our own marketing, and not combine it with other data except as needed to provide the service (for example honoring a STOP across shops).
  3. Keep it confidential. Everyone who can reach customer data at Kallos Labs LLC is bound to confidentiality. Our platform administrators cannot see customer names, phone numbers or texts.
  4. Protect it. Keep the security measures below and review them as the service grows.
  5. Use approved subprocessors. Use only the providers on the Subprocessors page, under written contracts with protections at least as strong as this addendum, and stay responsible for them.
  6. Help with requests. Help you answer customers who ask to see, correct or delete their information. Customers can also delete their own visit information on the status page.
  7. Tell you about incidents. Notify you without undue delay, and within 72 hours when we can, after we confirm a breach of customer data, with what we know, and keep you updated. We help you meet your own notice duties, including under Puerto Rico Act 111 of 2005 and other state breach laws.
  8. Delete it on schedule. Erase customer data as described below.
  9. Show we comply. Answer reasonable written questions about our compliance once a year, or after an incident, and give you the information you need to show your own compliance.

Security measures

  • Hosting with providers that encrypt data in transit and at rest, in the United States.
  • Row-level access rules in the database: each team member reaches only the shops they belong to; members who are not owners see partly hidden phone numbers.
  • Phone numbers and IP addresses used for limits and opt-outs kept only as keyed codes; raw IP addresses never stored.
  • Customers have no accounts and no passwords; their status links are random and stored only as codes, and stop working about 12 hours after the visit.
  • One-time email codes for staff sign-in, an optional PIN lock on shared devices, and an audit trail of admin changes.
  • Least-privilege access for our own staff, and secret keys kept out of the code.

Subprocessors

You authorize the subprocessors listed on the Subprocessors page. We will post any new subprocessor there and email shop owners at least 30 days before it starts processing customer data, unless an emergency (such as a provider failure) requires a faster change, in which case we tell you as soon as we can. If you object for a reasonable data protection reason, tell us within that period; if we cannot address it, you may cancel the subscription and we will refund any prepaid amount for the time after the change.

Retention and deletion

  • Customer names, mobile numbers, status links and IP codes are erased 30 days after the visit (or the period the shop chooses, from 1 to 365 days), and right away when a customer chooses "Delete my info".
  • Text bodies and the numbers they went to are erased after 30 days; replies after 90 days.
  • If the shop is suspended, its customer data is erased after 90 days; if the owner deletes the last account of a shop with no team, right away.
  • We keep keyed phone codes so STOP keeps working, consent records for about 4 years as evidence of consent to texts, and visit counts and times without names for the shop's statistics.

Audits

On written request, and no more than once a year unless there was an incident or a regulator asks, we will answer a reasonable security questionnaire and provide summaries of our providers' independent security reports where they make them available. On-site audits need a separate written agreement.

International processing

We and our subprocessors process customer data in the United States. If you serve customers outside the United States, you are responsible for any notice their laws require.

Liability

Each party's liability under this addendum is subject to the limits in the Terms of Service.

Contact

Kallos Labs LLC, our support email (coming soon).

Change log

  • Version 1.0, October 1, 2026: First version.

Questions about this page? Write to our support email (coming soon).

All legal pages