Skip to content

Legal

Data Processing Agreement

The Article 28 terms under which Booklino processes your customers' personal data on your instructions. This forms part of the Terms of Service, so you do not need to sign anything separately.

Last updated

Draft pending legal review. These documents describe how Booklino actually works and are written to be accurate, but they have not yet been reviewed by a qualified lawyer and are not legal advice. The company legal name and registered address are still placeholders. Both are gated before public launch.

1. Scope and roles

This agreement applies whenever Booklino processes personal data on behalf of a subscribing business. It supplements and forms part of the Terms of Service. It takes effect when you create an account and lasts as long as we process data for you.

  • You, the subscribing business, are the controller. You decide which appointments to accept, what to ask your customers, and how long to keep their records.
  • [Company legal name B.V.] is the processor. We process that data only to provide the service you have subscribed to.

Where we process data about you (your account, your billing, your logins) we are a controller in our own right, and the Privacy Policy governs that instead.

2. Subject matter of the processing

Details of processing required by GDPR Article 28(3)
Subject matterProviding online appointment booking and management software
DurationFor as long as your account is open, plus the retention periods in section 8
Nature and purposeCollecting, storing, organising, retrieving and erasing booking data; sending transactional email on your instruction; calculating availability
Categories of data subjectYour customers: people who book, or attempt to book, an appointment with you
Categories of personal dataName, phone number, email address, appointment history, no-show count, notes you add to a customer record, and payment status (never card details)
Special category dataNot requested by the platform. Do not enter health or other special-category data into free-text notes. See section 3

A warning about free-text notes

Booklino gives you a notes field on a customer record. Nothing stops you typing sensitive information into it, but the platform is not designed for special-category data under Article 9 (health, biometrics, beliefs). If your trade genuinely requires such records, a physiotherapist for example, you are the controller who must justify it, and you should satisfy yourself that the additional safeguards Article 9 requires are in place before you do.

3. Our obligations

We will:

  • process personal data only on your documented instructions (using the product is such an instruction) unless EU or Dutch law requires otherwise, in which case we tell you before processing unless the law forbids it;
  • ensure the people who handle the data are bound by confidentiality;
  • implement the technical and organisational measures in section 5;
  • not engage a new sub-processor without giving you notice and an opportunity to object (section 6);
  • help you respond to data subject requests, and to your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us;
  • delete or return personal data at the end of the service, as set out in section 8;
  • make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits (section 9);
  • tell you promptly if, in our opinion, an instruction from you infringes data protection law.

4. Your obligations

  • You must have a lawful basis for collecting your customers’ personal data and for having us process it.
  • You must give your customers the privacy information Articles 13 and 14 require, including that you use a booking platform.
  • Your instructions to us must not put us in breach of data protection law.
  • You are responsible for the accuracy of the data you or your customers enter, and for responding to your customers’ requests about it.

5. Security measures

Taking account of the state of the art, the costs of implementation, and the risks involved, we maintain measures including:

  • encryption of personal data in transit (TLS) and at rest;
  • authorisation checked on the server for every request: identity, then tenant membership, then role, then plan entitlement, then ownership of the specific record, so one business can never read another’s data;
  • booking-management tokens of at least 128 bits of entropy, stored only as hashes and never placed in logs, analytics or web addresses;
  • an append-only audit log of every change made by an account owner or by our own administrators;
  • access to production data limited to named personnel who need it, with multi-factor authentication;
  • regular backups within the EU region, and a documented restore procedure;
  • separation of duties between the platform and payment processing, card data never reaches our systems.

6. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. We remain fully liable to you for their performance.

Authorised sub-processors
Sub-processorPurposeLocationTransfer safeguard
Google Ireland Ltd (Firebase / Google Cloud)Database, authentication, file storage, hostingEU (europe-west)None needed, EU
Stripe Payments Europe LtdSubscription billing; payment facilitation via ConnectEU / USStandard Contractual Clauses
Resend Inc.Transactional email deliveryEU / USStandard Contractual Clauses

We will give at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service without penalty and receive a refund of prepaid fees for the unused period.

7. International transfers

Personal data is stored in the European Union. Where a sub-processor transfers data outside the EEA, that transfer relies on the European Commission’s Standard Contractual Clauses together with any supplementary measures the transfer risk assessment identifies.

8. Breach notification, deletion and return

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own 72-hour obligation to the supervisory authority. Notification is not an admission of fault.

On termination you may request an export of your booking and customer data at any time before closure. After you close your account we keep the data for 30 days so an accidental closure can be reversed, then delete or irreversibly anonymise it, except where EU or Dutch law requires us to keep it, principally invoices, which Dutch tax law requires us to retain for seven years.

9. Audit

On written request, and no more than once in any 12-month period unless a supervisory authority or a breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement. Where a documentary response is not sufficient, we will cooperate with an audit conducted by you or an independent auditor you appoint, on reasonable notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. You bear the cost of the audit unless it reveals a material breach on our part.

10. Liability and precedence

The liability limits in the Terms of Service apply to this agreement. Where this agreement conflicts with the Terms of Service on a data protection matter, this agreement prevails. Where it conflicts with the GDPR, the GDPR prevails.

11. Contact

Data protection contact: [Company legal name B.V.], [Registered address, Netherlands], KvK 91548640 — [email protected]. We have not appointed a Data Protection Officer; Article 37 does not require one at our scale, and we will appoint one if that changes.