Data Processing Addendum
processing of personal information by Dakoli LLC for salon business customers
Introduction and scope
Pinsot is a product operated by Dakoli LLC, a California limited liability company. This document explains the rules, rights, procedures, and responsibilities that apply to processing of personal information by dakoli llc for salon business customers
Pinsot provides subscription software and technology for nail salon operations in a global market. Salons are independent businesses that provide nail, beauty, wellness, and related services to their clients. Unless a document expressly says otherwise for a specific transaction, the salon—not Pinsot—is responsible for its services, prices, technicians, schedules, employment relationships, commissions, taxes, refunds, client care, licensing, sanitation, and regulatory compliance.
The English version is the controlling version unless applicable law requires otherwise. The Vietnamese translation is provided for meaningful access and convenience and is intended to preserve the same substance.
Roles and documented instructions
For Customer Personal Data processed to provide Pinsot on behalf of a salon customer, the customer is controller or processor as applicable and Dakoli LLC is processor or subprocessor. The customer determines lawful purposes, categories, data subjects, retention instructions, and authorized users. Dakoli LLC processes only documented instructions in the agreement, order, configured use, and valid written requests, unless law requires otherwise.
The customer warrants that its instructions and disclosure of data comply with law and that it has required notices, rights, consents, contracts, and lawful bases. Dakoli LLC will inform the customer if an instruction appears to violate applicable data-protection law unless prohibited, but the customer remains responsible for its legal determination.
Confidentiality and security
Dakoli LLC will ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain appropriate technical and organizational measures proportionate to risk. Verified measures include authenticated access, server-side authorization, tenant and location boundaries, role controls, session foundations, audit history, redacted diagnostics, development checks, and incident procedures described in the Security Overview.
The customer must configure access, protect credentials and devices, minimize inputs, review exports, and maintain its own continuity and legal records. Security is shared; no measure guarantees protection from every threat. Detailed measures may be provided confidentially where appropriate rather than published in a way that increases risk.
Subprocessors and international transfers
Dakoli LLC may engage subprocessors for verified hosting, infrastructure, communications, support, security, or enabled product functions. The public Subprocessor List identifies verified providers and known purposes and regions. Dakoli LLC will impose data-protection obligations appropriate to the service and remains responsible for subprocessor performance to the extent required by the agreement and law.
Customers may request update notices by emailing privacy@pinsot.com; no automated subscription is promised unless confirmed. Where restricted data is transferred internationally, the parties will use an applicable lawful mechanism. Displaying this page does not execute Standard Contractual Clauses, the UK Addendum, or another transfer instrument. Those instruments require an applicable agreement or execution workflow.
Individual requests and compliance assistance
Taking into account the nature of processing, Dakoli LLC will provide reasonable technical and organizational assistance for the customer's response to access, correction, deletion, portability, restriction, objection, consent withdrawal, and appeal requests. If Dakoli LLC receives a request concerning customer-controlled data, it may refer the requester to the customer and will not respond substantively without authorization unless required by law.
Dakoli LLC will provide reasonable information for data-protection impact assessments, regulator consultations, and demonstrated compliance, considering available information and confidentiality. Requests must be proportionate and not compromise other customers, security, trade secrets, or legal privilege.
Personal data incidents
Dakoli LLC will notify the customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data where notification is required. Notice will include available information about nature, likely consequences, affected categories, containment, and contact, and may be provided in phases as facts become available. Notification is not an admission of fault or liability.
The customer decides whether and how to notify individuals or regulators unless law assigns that duty to Dakoli LLC. Both parties will cooperate, preserve relevant evidence, avoid misleading statements, and take reasonable mitigation steps. The customer must promptly report suspected incidents within its users, devices, integrations, or instructions.
Return, deletion, audits, and liability
At the end of service and on documented instruction, Dakoli LLC will delete or return Customer Personal Data as provided by the agreement and available product capability, unless law requires retention. Limited protected recovery copies may expire under a verified lifecycle. The customer should request available exports before access ends and identify legally required retention.
Dakoli LLC will make available reasonable compliance information and may satisfy audit requests through current documentation, questionnaires, summaries, or an independent report if one is later verified. On-site or intrusive audits require prior agreement, confidentiality, reasonable frequency, noninterference, and customer payment of extraordinary cost. Liability follows the main agreement unless mandatory law requires otherwise.
Processing annex
Subject matter: provision, security, support, and improvement of configured Pinsot salon-management services. Duration: the service term plus documented deletion, legal-retention, and incident-preservation periods. Nature and purpose: hosting, organizing, transmitting, displaying, securing, supporting, and deleting data under customer instructions.
Data subjects may include salon owners, managers, receptionists, technicians, applicants where configured, clients, authorized users, and support contacts. Data categories may include identity, contact, account, role, salon, location, technician, client, appointment, service, preference, transaction, tip, commission-input, communication, consent, support, device, usage, audit, and uploaded content. Sensitive data is not intended unless specifically verified and lawfully instructed. Transfer-mechanism details remain to be completed in an executed annex where applicable.
Request or execute a DPA
This public framework does not by itself create an executed DPA. An authorized salon representative may email privacy@pinsot.com with the legal business name, country, Pinsot account relationship, requested role, and contact person. Do not send client data or identification documents in the initial request.
Dakoli LLC will verify the account and authority, identify the applicable agreement and transfer requirements, provide the current execution path, and retain the executed version according to business-record obligations. Negotiated changes require written approval by authorized representatives.
Changes, language, and contact
This document is version 2026.07.20, effective and last updated July 20, 2026. We may update it to reflect product, legal, safety, or operational changes. Material changes will be communicated through an appropriate public or in-product notice when reasonably required. Continued use after an effective change is governed by applicable law and any notice or consent that law requires.
Questions and requests concerning this document may be sent to privacy@pinsot.com. Contact addresses are centralized and require owner verification before production. Do not email passwords, verification codes, full payment credentials, government identification, health details, or unrelated client records.

