1. Who does what
This addendum applies when your business uses Rosa ONE for its customers' and its team's records. For those records, your business is the controller and Rosa Group Ltd is its processor (under Brazil's LGPD, the controlador and the operador). Rosa Group is the controller of the information it uses for its own accounts, subscriptions, support and security, as our Privacy Policy explains.
It applies for as long as we process those records: while your business uses Rosa ONE and until the records are deleted as section 9 describes. Where this addendum and the Terms of Service differ about personal data, this addendum prevails.
2. What we process and why
Purpose and nature: to provide, secure and support Rosa ONE for your business: storing and organising its records, carrying out what its authorised people ask for in the dashboard and through Rosa, sending the messages it switches on, and the assistant features our Privacy Policy describes.
People: your business's customers and the people who contact it, its team members, and other people named in its records, such as suppliers. Information: names, phone numbers and email addresses; appointments and services; payment records (never full card numbers); messages and their delivery status; notes your team writes; team schedules, roles, costs and revenue shares; assistant conversations and, when voice messages are switched on, their transcripts.
Rosa ONE is not designed for health or other especially sensitive information: please do not record it. We do not sell personal information or use your records for advertising, and we use them only to provide Rosa ONE to you, unless the law requires otherwise. WhatsApp messages, voice messages included, are never used to train or improve AI models. We may produce anonymous statistics about how Rosa ONE is used, such as counts of bookings or assistant requests, only in a form that identifies no person and no business, to run and improve Rosa ONE.
3. Your instructions
We process these records only on your documented instructions: these terms, this addendum, your settings, and what the people you authorise ask Rosa ONE to do. If we believe an instruction breaks data-protection law, we tell you and may decline to follow it. If the law requires us to process the records in another way, we tell you first, unless the law forbids that.
The people we allow to access the records, our own staff included, are bound by confidentiality and access them only as needed to provide, support and secure the service.
4. Security
We protect the records with measures suited to the risk, including HTTPS, encrypted credentials and backups, a separate database and runtime for each business, access controls and role permissions, sign-in protections and tested restores of our backups. We review these measures as Rosa ONE changes.
5. Sub-processors
You authorise us to use the providers listed below, which process workspace records for us in the roles shown. Each is bound by written terms that protect the data at least as well as this addendum does, and we remain responsible to you for them.
We will tell your business's owners about a new provider at least 30 days before it starts processing your records, by email and on this page, unless an urgent change is needed to keep the service secure or running; then we tell you as soon as we can. If you object on reasonable data-protection grounds, we will discuss it with you; if we cannot resolve your objection, you may cancel the affected service and we will refund any unused prepaid period for it.
ElevenLabs
Speech-to-text for staff voice messages to Rosa, when voice messages are switched on
Privacy informationStripe
Subscription payments and billing for your Rosa ONE plan (Rosa Group's own billing: it does not process your workspace records)
Privacy information6. International transfers
Rosa ONE is hosted in the United States (Ashburn, Virginia), with encrypted backups in Finland. Rosa Group is established in the United Kingdom; our authorised support staff and our providers may process data in other countries, as our Privacy Policy and their terms describe.
Data from the UK: where the UK's data-protection law restricts a transfer, we and our providers rely on the UK's adequacy regulations, including the UK–US data bridge where the recipient is certified, or on the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Data from the European Economic Area: on an adequacy decision or the EU standard contractual clauses.
Data from Brazil: where the LGPD applies to a transfer, the standard contractual clauses approved by Brazil's data protection authority (ANPD Resolution CD/ANPD No. 19/2024) form part of this addendum, with your business as the exporter and Rosa Group as the importer, acting as your processor; we require equivalent protection from the providers that receive the data. On request, we give you a copy of the clauses that apply to your records.
7. Requests and assistance
If someone asks us to access, correct, delete or move their data held in your workspace, we pass the request to you promptly and do not answer it ourselves, except to tell them we have done so. The dashboard and its exports let you answer most requests; for the rest, we help you.
We help you, as far as is reasonable, with your security duties, data-protection impact assessments and consultations with regulators, taking into account the processing and the information available to us. If an authority asks us for your records, we tell you unless the law forbids that, ask the authority to come to you, challenge a request that is unlawful, disclose no more than the law requires and keep a record of the request.
8. If something goes wrong
If we become aware of a personal-data breach affecting your workspace records, we tell your business's owners without undue delay, and in any case within 48 hours, by email. We tell you what happened and when, the kinds of data and roughly how many people are affected, the likely consequences, what we have done and will do to contain it, and who you can contact; where we do not know everything yet, we tell you what we know and update you as we learn more.
We help you meet your own duties: in the UK, telling the ICO within 72 hours of becoming aware of a breach that puts people's rights at risk; in Brazil, telling the ANPD and the people affected within 3 working days when the breach may cause them relevant risk or harm; and telling the people affected wherever the law requires. We do not notify your customers or a regulator about a breach of your records on your behalf without your agreement, unless the law requires us to. We keep a record of every incident, including those that need no notice.
9. When the service ends
Before closing an account, you can export your records or ask us for help. After the service ends, we do not delete your records on a timer: they are deleted after an authorised person's review, as our Terms of Service describe, unless the law requires us to keep part of them. Copies in our encrypted backups are used only to recover the service, and the off-site copies expire within 12 months. On request, we confirm in writing when the deletion is done.
10. Showing that we comply
On request, we give you the information you reasonably need to check that we meet this addendum, such as this document, our Privacy Policy and a summary of our security measures. If that is not enough, you, or an auditor bound by confidentiality, may audit our compliance once a year on 30 days' notice, at your cost and without access to other businesses' data; we also cooperate with an audit a regulator requires.
11. United States and other laws
Where a US state privacy law applies, we act as your service provider or processor: we do not sell or share the personal information in your workspace, or keep, use or disclose it for any purpose other than providing Rosa ONE to you, and we tell you if we can no longer meet these duties. Where another data-protection law applies to your records, we follow the parts of this addendum that meet its requirements and work with you on anything more it needs.
This addendum is governed by the same law as the Terms of Service (section 14). Our Terms of Service explain how either of us can raise a concern.
We are here to help.
Tell us what you need through our private form. You do not need to sign in.
Open contact form →Also by email: [email protected]