Data Processing Terms
Last updated: August 3, 2026
← Home Terms of Service Privacy Policy Refund Policy SMS Consent Policy Data Processing

1. Roles

A business using the Platform is the data controller for the personal information of their own clients, vendors, and guests — they decide what's collected and why. VisualsBySaad acts as a data processor: we process that information on the business's behalf, to provide the Platform's functionality, not for our own independent purposes.

2. Where Data Is Processed

The Platform is built on infrastructure provided by named third parties, each acting as a sub-processor. Personal information may pass through:

ProviderPurpose
SupabaseDatabase hosting, authentication, file storage
StripePayment processing for subscriptions and client invoices
TwilioSMS and WhatsApp message delivery
AnthropicAI-assisted features, where a business chooses to enable them for their own client communications
HostingerWeb hosting for the Platform's pages, and outbound SMTP delivery for transactional emails (booking confirmations, contracts, invoices, notifications) sent through the Platform

These providers have their own data handling practices and security certifications, which we have not independently audited beyond reviewing their published terms — a business with specific data residency or compliance requirements should review each provider's own documentation directly.

3. Cross-Border Data

Some of these providers may process or store data outside Canada, including in the United States. Under PIPEDA, this is permitted, but a business must be transparent with their own clients about it if asked — this document is intended to make that transparency straightforward rather than something a business has to dig for.

4. Sub-Processor Changes

If a core sub-processor changes (for example, switching SMS providers), this document will be updated to reflect it.

5. Security Measures

Data is protected through account-level authentication and row-level database security, meaning one business's data is not accessible to another business, and a vendor or venue can only see data for events they're actually involved in. Payment card details are handled entirely by Stripe and never stored directly by the Platform.

6. Data Deletion

On request, and subject to reasonable legal and accounting retention requirements, a business's data can be deleted from the Platform. Deletion requests should be directed to us through the Platform's contact channels.

7. Assistance With Compliance

If a business is asked by their own client how that client's data is handled, this document and the Privacy Policy provide a specific, concrete answer.

8. No Independent Use

We do not use personal information processed on a business's behalf for our own marketing, do not sell it, and do not share it with any party not listed above except as required by law.