Data Processing Terms
How Lowmark processes the personal data of a business's customers on that business's behalf.
Last updated:In short
- Your customers' data is yours. We process it only to provide Lowmark to you.
- We keep it secure, confidential and separate from other businesses.
- We tell you promptly about incidents, help you answer customer requests, and delete the data when you leave.
1. Scope and roles
These Data Processing Terms form part of the Terms of Service. They apply to personal data about your customers, and about your team members, that Lowmark processes on your behalf ("customer personal data"): bookings, reservations, queue entries, customer records, notes, form answers and related records.
You decide the purposes and means of processing customer personal data and are responsible for it. Lowmark processes it on your behalf as your service provider.
2. Processing only on your instructions
We process customer personal data only to provide, secure and support Lowmark as described in the Terms, the Privacy Policy and your settings, and as you instruct through the workspace or in writing, unless the law requires otherwise; in that case we will tell you first unless the law forbids it. We do not sell customer personal data, use it for advertising, or combine it across businesses.
3. Your obligations
- Have a lawful basis, including consent where required, for all customer personal data you collect or upload.
- Tell your customers, in Arabic and English where required, who you are, what you collect, why, and how to contact you about their data.
- Collect only what you need; keep health and other sensitive data to the minimum required, and do not ask for identity card numbers or payment card numbers.
- Give team members only the access their job needs, and remove access when it is no longer needed.
- Answer your customers' requests about their data. Tools such as export, edit and archive are available in the workspace.
4. Confidentiality
Everyone at Lowmark who can access customer personal data is bound by confidentiality, and accesses it only when needed to provide support you asked for, to keep the service secure and working, or to comply with the law.
5. Security measures
- Encryption in transit (HTTPS) for all traffic.
- Separation of each business's data, with server-side permission checks on every request based on each team member's job.
- Argon2 password hashing, HttpOnly session cookies, session revocation on sign-out everywhere, and limits on sign-in attempts.
- A firewall that blocks abusive traffic, web server logs stripped of query strings, cookies and authorisation headers and kept for 7 days, and records of sensitive administrative actions.
- Daily backups kept for 30 days, used only to restore the service.
- Access to production systems limited to the people who operate Lowmark.
We review and improve these measures over time and will not reduce the overall level of protection.
6. Service providers
You authorise Lowmark to use the following providers to process customer personal data: Hostinger (hosting of the application, database, images and backups in France; sending of Lowmark emails). We will tell account owners at least 14 days before adding or replacing a provider that processes customer personal data. If you object on reasonable data protection grounds and we cannot address the objection, you may end your plan and receive a pro-rata refund of the unused prepaid period.
Each provider is bound by obligations that protect the data at least as well as these terms, and we remain responsible for its performance.
7. Transfers outside Kuwait
Customer personal data is stored on servers in France, in the European Union. By using Lowmark you instruct us to transfer and store it there. We will tell you before moving storage to another country.
8. Security incidents
If we confirm a breach of security that leads to accidental or unlawful destruction, loss, alteration, disclosure of, or access to, customer personal data, we will notify you without undue delay, and where possible within 24 hours of confirming it, with what we know about the nature of the incident, the data and people affected, its likely consequences, and the steps we are taking. We will give you further information as it becomes available and help you meet any obligation you have to notify authorities or customers.
9. Help with requests and assessments
If a customer contacts us about data you control, we will forward the request to you and will not respond directly except to confirm we have forwarded it, unless the law requires otherwise. We will provide reasonable help, taking into account the tools already in the workspace, with customer requests and with any data protection assessment or consultation with a regulator relating to Lowmark.
10. Return and deletion
You can export customer records and bookings at any time. When you ask us to delete your business, we schedule it for deletion after a 30-day period in which it can still be recovered, and then delete customer personal data from the live system. Copies in backups are deleted when those backups expire, within 30 days, unless the law requires us to keep them.
11. Information and audits
On written request, we will provide the information reasonably needed to show that we meet these terms, such as descriptions of our security measures and providers. Any further audit must be agreed in advance, conducted at your cost, with reasonable notice, during business hours, without access to other businesses' data, and not more than once a year unless required by a regulator or after an incident.
12. Liability
The limitations of liability in the Terms of Service apply to these Data Processing Terms.