Booking Tools for Techs

Legal

Data Processing Agreement

Last updated: 2026-06-26

1. Roles of controller and processor

For booking/customer data entered by a customer organization, the customer organization is controller and the SaaS provider is processor. For provider account, billing, contract, and security data, the provider may act as controller.

2. Subject, duration, nature, and purpose

Processing covers the provision, maintenance, security, support, and improvement of Booking Tools for Techs for the duration of the subscription and any legally required retention or agreed export period.

3. Processor instructions and confidentiality

The processor processes booking/customer data only on documented instructions from the controller unless law requires otherwise. Persons authorized to process data must be bound by confidentiality.

4. Security measures

The processor applies appropriate technical and organizational measures, including access control, authentication, role separation, encrypted transport, logging, backup routines, vulnerability-aware maintenance, and operational monitoring.

5. Subprocessors

Subprocessors may be used for hosting, storage, email, payment processing, SMS, monitoring, and backup services only where actually configured for the deployment.

  • Mollie: Payment processing.
  • Twilio: SMS verification and notifications.

6. International transfers

International transfers require appropriate safeguards and must be documented when a configured provider processes data outside the European Economic Area.

7. Assistance, data-subject requests, and audits

The processor will reasonably assist the controller with data-subject requests, security documentation, and audit information, taking into account the nature of processing and the information available to the processor.

8. Breach notification

The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting booking/customer data processed on behalf of that controller.

9. Deletion or return after termination

Data is retained for 30 days after termination.

Liability under this agreement should align with the main agreement and requires legal review before production approval.

10. Processing details

Data subjects
Customer organization users, staff users, customers making booking requests, and contacts included in booking records.
Personal data categories
Names, email addresses, telephone numbers, appointment preferences, service selections, booking notes, status history, account roles, and technical identifiers.
Purpose
Online booking, appointment review, communication, subscription administration, support, security, and service operation.

11. Technical and organizational measures

  • role-based access in the administrative panel;
  • authenticated access for organization users;
  • transport encryption via HTTPS in production;
  • database-backed queues and operational health checks;
  • backup and retention procedures configured per deployment;
  • restricted provider credentials through environment configuration.