Skip to content

Data processing agreement

Last updated 19 August 2026

This agreement covers the personal data of a studio’s customers that TimiTomi processes on the studio’s behalf. It is part of the Terms, between the studio (the controller) and EȘANU EUGENIU ÎNTREPRINDERE INDIVIDUALĂ, registered in the Romanian trade register under number F2026004309006 (EUID ROONRC.F2026004309006), fiscal code 53575824, with its registered office at Strada Weiner Palada, Nr. 14, Bl. 3, Scara 2, Etaj 7, Ap. 66, Sat Roșu, Comuna Chiajna, Județul Ilfov, Romania (the processor), and it applies from the moment the studio has an account. It is written to meet Article 28 of the GDPR.

What this covers

The processing this agreement covers: running the studio’s booking page, schedule, class packs, memberships, payments and messages, for as long as the studio has an account. The people concerned are the studio’s customers and attendees. The data concerned:

  • Names, email addresses, phone numbers and profile pictures.
  • Bookings, class packs, memberships, credits and order history.
  • Stripe customer identifiers. Card numbers go straight to Stripe and never reach us.
  • Records of accepting the studio’s terms: version, date, IP address and browser.
  • Notes the studio writes about a customer.

Your instructions

We process this data only to run the service, following the Terms and the settings you choose in the app. We do not use it for anything of our own.

If the law requires us to process it in another way, we will tell you first, unless that same law forbids telling you. If an instruction from you would break data protection law, we will say so.

Who can see it

Only people who need the data to run or support the service can reach it, and every one of them is bound to keep it confidential.

Security

We protect the data with measures that fit the risk: encrypted connections, access controlled by role, studio accounts isolated from each other, and regular backups.

Subprocessors

You agree that we use the companies listed in the Privacy policy to run the service. Each one receives only the data its part needs, under a written contract with the same duties this agreement puts on us. We stay fully responsible for their work.

If we add or replace one, we will tell you by email at least 30 days before the change. If you object for a data protection reason we cannot resolve, you may close your account before the change applies, and we refund any part of a paid period you have not used.

Helping you

When a customer asks you for their data, or asks you to correct or delete it, the app covers most of it directly. Where it does not, we help you answer within the legal deadline.

We help you with your own security, breach notification and impact assessment duties, as far as they touch our processing.

If data is breached

If we learn of a breach affecting your customers’ data, we tell you without undue delay, with what we know: what happened, which data is affected, and what we are doing about it.

Where the data goes

The data is stored in the European Union. Where a subprocessor processes it in the United States, the transfer is covered by the EU-US Data Privacy Framework when the company is certified under it, and otherwise by the standard contractual clauses approved by the European Commission.

When the account closes

While your account is open, you can export your data at any time. After the account closes we keep your customers’ data for 90 days so you can still export it, then delete it, except what the law requires us to keep.

Audits

On request, we give you the information needed to show that this agreement is kept, and we answer reasonable audit questions. An audit on site happens at most once a year, with 30 days notice, at your cost, and must not put other studios’ data at risk.