Version v1.0, effective 2026-08-31. The official language of the Terms is English; any translation is provided for convenience only.
KOMASHI — MODULE D(2) · ANNEXES 1–2 (DPA)
Parent agreement. These Annexes form part of the Komashi Data Processing Agreement (Module D(2)), which is incorporated into the Provider Agreement (Module A). Capitalized terms not defined here have the meanings given in the DPA, Module 0, or the GDPR.
Annexes version: v1.0 Annexes effective date: 2026-08-31
Scope. This document contains Annex 1 (Description of Processing) and Annex 2 (Technical and Organizational Measures). Annex 3 (Authorized Sub-processors) is maintained in a separate document, module-d2-annex-3-subprocessors.md, so the sub-processor list can move on its own cadence.
Maintenance / amendment.
- Annex 1 (Description of Processing) changes only with the scope of processing; update alongside the DPA.
- Annex 2 (Technical and Organizational Measures) may be updated by Komashi under DPA §3.3, provided the level of protection is not materially reduced. Each change carries a new version number and effective date, and superseded versions are retained and available on request under Section 4.5 of Module 0.
SCC linkage. Where the EU Standard Contractual Clauses apply under DPA §5.2a (fallback if GDPR-covered Controller Data is ever processed, stored, or accessed outside the EU/EEA), SCC Annex I ← Annex 1 and SCC Annex II ← Annex 2 (below); SCC Annex III ← Annex 3 in module-d2-annex-3-subprocessors.md.
Annex 1 — Description of Processing
Populates SCC Annex I where DPA Section 5.2a applies.
Subject matter. Provision of the Komashi Platform — Provider presence, service catalogue, bookings and orders, subscriptions, invoicing, customer management, QR-code issuance and validation, and transactional messaging — to the Controller.
Duration. The term of the Provider Agreement, plus the deletion periods in Privacy Policy Section 9.2 and the statutory retention in Section 9.2a (DPA Section 3.8).
Nature and purpose. Hosting, storage, transmission, display, backup, and technical processing of Controller Data as needed to operate the Platform on the Controller's instructions.
Frequency of processing. Continuous, for the duration of the Provider Agreement.
Categories of data subjects.
| Category | Description |
|---|---|
| End Users | The Controller's customers who book, subscribe to, or purchase the Controller's services through the Platform |
| Prospective End Users | Visitors who begin but do not complete a booking or registration on the Controller's presence |
| The Controller's staff | Individuals of the Controller appearing in customer-facing records (e.g., the person delivering a booked service, the sender of a message to an End User) |
Categories of personal data.
| Category | Data |
|---|---|
| Identity | First and last name; the name shown on an invoice |
| Contact | Email address; telephone number; postal or billing address |
| Account | Account identifier; language and locale; time zone; account status; authentication events (login timestamps, IP address, user agent); password in salted-hash form; where a third-party identity provider is used to sign in, the identifier returned by that provider |
| Booking and order | Service or product booked; date, time and duration; quantity; location where the Controller records one; booking status and history; cancellation and no-show records; notes the End User or the Controller adds to a booking |
| Subscription | Subscription plan; start date; renewal and expiry dates; subscription status and history |
| Invoice and billing | Invoice number, date and currency; line items and descriptions; net, tax and gross amounts; tax identifiers the End User supplies; payment status and payment date |
| Payment metadata | Payment-status information received from the Provider's payment or invoicing provider — transaction reference, amount, currency, timestamp, success or failure, refund status, and payment-method type (e.g. "card", "transfer"). No card number, no expiry date, no CVC, no bank credentials, no payment token usable to initiate a payment, and no cardholder authentication data (DPA Section 1.3; Provider Terms Section 4.1a) |
| QR code and access | QR-code identifier; issuance and validation events with timestamp; the entitlement the code represents |
| Communications | Messages between the Controller and the End User sent through the Platform; transactional email sent to the End User and its delivery metadata; support correspondence relating to the Controller's End Users |
| Usage and technical | Page and screen events within the Controller's presence; device and browser information; IP address; timestamps; application and security log entries |
Special categories of personal data (Art. 9 GDPR). None. The Platform is not configured to collect special-category data, and the Controller must not use free-text fields (booking notes, service descriptions, messages) to enter it. Processing special-category data requires separate written agreement and additional safeguards under DPA Section 2.1(d).
Practical warning for Controllers in health, wellness, and similar sectors: a service name, a booking note, or an End User's message can turn into health data without anyone deciding that it should. The Controller is responsible for what it and its End Users type into free-text fields. Where a Controller's business necessarily involves such data, it must raise this with Komashi under Section 2.1(d) before processing begins.
Data relating to criminal convictions or offences (Art. 10 GDPR). None.
Children's data. The Platform is not directed at children. Where the Controller's own services are directed at or used by children, the Controller is responsible for the legal basis and for any parental consent required.
Transfers. None outside the EU/EEA for GDPR-covered Controller Data (DPA Section 5.2). Sub-processors and the parties that are expressly not sub-processors are set out in Annex 3.
Annex 2 — Technical and Organizational Measures (Art. 32 GDPR)
Populates SCC Annex II where DPA Section 5.2a applies. This Annex describes the measures actually in force. Komashi may update it under DPA Section 3.3 provided the level of protection is not materially reduced; on each change, bump the version and archive the superseded text.
Infrastructure baseline. Komashi operates its own infrastructure and does not rent hosting, compute, or database services from a cloud provider (Annex 3, Section A). The measures below are therefore Komashi's own, not inherited from a hosting provider's control framework; only the physical-security layer rests with the data-centre facility.
| Area | Measures |
|---|---|
| Encryption | TLS 1.2+ for all data in transit, including between internal services; encryption at rest (AES-256 or equivalent) for databases and backups; encryption keys held separately from the data and rotated on compromise or personnel change |
| Access control & least privilege | Role-based access; access to Controller Data limited to personnel who need it for a defined task; access granted on request, reviewed quarterly, and revoked on role change or exit; all access to EU/EEA Controller Data is from within the EU/EEA only (DPA Section 5.2) |
| Administrative authentication | Multi-factor or passwordless authentication for all administrative and production access; no shared administrative credentials; administrative sessions time-limited |
| Logging & monitoring | Centralized, tamper-resistant logging of access and security events; alerting on anomalous activity; log retention per Privacy Policy Section 9.2(b) — application and security logs 12 months, infrastructure and file-level logs 14 days |
| Network security | Network segregation between production, staging and development; firewalls and security groups with default-deny; production isolated from development; no database exposed to the public internet; administrative interfaces not publicly reachable |
| Vulnerability & patch management | Dependency and infrastructure patching on a defined cycle, with out-of-cycle patching for critical vulnerabilities; automated dependency scanning in CI; periodic vulnerability scanning of internet-facing services. No external penetration testing — see the paragraph below this table |
| Backup & disaster recovery | Encrypted backups held within the EU/EEA on the rotation in Privacy Policy Section 9.2(c) (daily 2 weeks, weekly 2 months, monthly 6 months); documented restore procedure; restore tested at least annually; RPO 24 hours; RTO 72 hours |
| Secure development | Code review before merge; separation of duties between development and production access; secrets held in a secrets manager and never in source control; change control with an audit trail; dependency scanning in CI |
| Personnel | Written confidentiality obligations for all staff and contractors with access (DPA Section 3.2); security-awareness briefing on onboarding and refreshed annually; access revoked on the last working day |
| Incident response | Documented incident-response process with named responsibilities; breach notification to Controllers within the window in DPA Section 3.7; post-incident review with corrective actions recorded |
| Physical security | The equipment is held at Komashi's own premises in the EU/EEA, in a lockable server room separate from general office space, fitted with fire detection. No third-party facility operator has physical access (Annex 3, Section A), and there is correspondingly no external facility certification: Komashi is solely responsible for these controls. Physical entry is not separately logged — access is restricted by the lock and by the small number of people holding a key, and there is no recorded entry trail. Komashi states this expressly rather than leaving it to be inferred |
| Sub-processor assurance | Written contracts imposing materially equivalent obligations (DPA Section 4.3); sub-processors, and the parties that are expressly not sub-processors, listed in Annex 3 |
| Segregation of Controllers | Each Controller's data is logically separated and access-controlled; a Provider cannot reach another Provider's data through the application |
Testing the effectiveness of these measures (Art. 32(1)(d)). Komashi does not commission external penetration testing, and does not hold a SOC 2 report or ISO/IEC 27001 certification (DPA Section 3.9(a)). Effectiveness is tested through the measures already stated in the table above: automated dependency scanning in CI, periodic vulnerability scanning of internet-facing services, patching on a defined cycle with out-of-cycle patching for critical vulnerabilities, and an annual restore test of backups. This paragraph states the position rather than leaving it to be inferred: a Controller's auditor asking what independent assurance exists should find the answer here, and the answer is that there is none beyond Komashi's own testing.
Annex 3 — Authorized Sub-processors
Annex 3 is maintained in a separate document, module-d2-annex-3-subprocessors.md (also published at https://komashi.com/legal/subprocessors), with its own version and effective date, under the general authorization in DPA §4.1 and the notice/objection process in DPA §4.2. It populates SCC Annex III under DPA §5.2a.