Legal
Data Processing Agreement
Last updated: 2026-06-26
1. Roles of controller and processor
For booking/customer data entered by a customer organization, the customer organization is controller and the SaaS provider is processor. For provider account, billing, contract, and security data, the provider may act as controller.
2. Subject, duration, nature, and purpose
Processing covers the provision, maintenance, security, support, and improvement of Booking Tools for Techs for the duration of the subscription and any legally required retention or agreed export period.
3. Processor instructions and confidentiality
The processor processes booking/customer data only on documented instructions from the controller unless law requires otherwise. Persons authorized to process data must be bound by confidentiality.
4. Security measures
The processor applies appropriate technical and organizational measures, including access control, authentication, role separation, encrypted transport, logging, backup routines, vulnerability-aware maintenance, and operational monitoring.
5. Subprocessors
Subprocessors may be used for hosting, storage, email, payment processing, SMS, monitoring, and backup services only where actually configured for the deployment.
- Mollie: Payment processing.
- Twilio: SMS verification and notifications.
6. International transfers
International transfers require appropriate safeguards and must be documented when a configured provider processes data outside the European Economic Area.
7. Assistance, data-subject requests, and audits
The processor will reasonably assist the controller with data-subject requests, security documentation, and audit information, taking into account the nature of processing and the information available to the processor.
8. Breach notification
The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting booking/customer data processed on behalf of that controller.
9. Deletion or return after termination
Data is retained for 30 days after termination.
Liability under this agreement should align with the main agreement and requires legal review before production approval.
10. Processing details
- Data subjects
- Customer organization users, staff users, customers making booking requests, and contacts included in booking records.
- Personal data categories
- Names, email addresses, telephone numbers, appointment preferences, service selections, booking notes, status history, account roles, and technical identifiers.
- Purpose
- Online booking, appointment review, communication, subscription administration, support, security, and service operation.
11. Technical and organizational measures
- role-based access in the administrative panel;
- authenticated access for organization users;
- transport encryption via HTTPS in production;
- database-backed queues and operational health checks;
- backup and retention procedures configured per deployment;
- restricted provider credentials through environment configuration.