Legal
Privacy Statement
Last updated: 2026-06-26
1. Identity and contact details
CasBizz Holding BV operates Booking Tools for Techs. Public business and contact details are listed on the contact page and in the footer when configured.
Privacy questions can be sent to info@casbizz.nl.
2. Controller and processor roles
The SaaS provider is generally controller for account, contract, billing, platform security, and service communication data.
The customer organization is generally controller for its own booking/customer data. The SaaS provider processes customer and booking data on behalf of that organization as processor.
3. Categories of personal data
- organization account data, including organization name, authorized users, roles, and subscription status;
- staff-user data, including names, email addresses, access roles, and notification preferences;
- customer and booking data processed on behalf of organizations, such as customer contact details, selected services, requested dates, notes, and appointment status;
- payment-related references, including Mollie customer, payment, subscription, and mandate references where billing is enabled;
- technical logs, audit data, security events, browser/session data, and system diagnostics.
4. Purposes and legal bases
Data is processed to provide the booking service, administer accounts and subscriptions, process payments, secure the platform, communicate service messages, comply with legal obligations, and support customers.
Legal bases may include contract performance, legitimate interests, legal obligations, and consent where a specific feature requires it.
5. Subprocessors and providers
Hosting, email delivery, backup/storage, Mollie payment processing, and Twilio SMS services may be used depending on the deployment and enabled features.
- Mollie: Payment processing.
- Twilio: SMS verification and notifications.
6. Retention
Account, billing, security, and operational records are retained only as long as needed for the service, legal obligations, dispute handling, and security monitoring.
Data is retained for 30 days after termination.
7. Security
The platform uses access controls, role separation, encrypted transport, audit-relevant logs, backups, and operational monitoring. No statement on this page should be read as an absolute guarantee of GDPR compliance or uninterrupted security.
8. Data-subject rights and complaints
Data subjects may request access, correction, deletion, restriction, portability, or objection where applicable. Booking/customer data requests should usually be directed to the customer organization that controls that data.
Complaints may be submitted to the Dutch Data Protection Authority.
9. International transfers
Where providers process data outside the European Economic Area, appropriate safeguards must be assessed and documented before production approval.
11. Changes
This statement may be updated when the service, legal requirements, or providers change. The last updated date shows the maintained publication date.