Legal
Data Processing Agreement
Last updated: 2026-06-26
On this page
- 1. Roles of controller and processor
- 2. Subject, duration, nature, and purpose
- 3. Processor instructions and confidentiality
- 4. Government and tax authority requests
- 5. Security measures
- 6. Subprocessors
- 7. International transfers
- 8. Assistance, data-subject requests, and audits
- 9. Breach notification
- 10. Deletion, anonymization, or return
- 11. Processing details
- 12. Technical and organizational measures
1. Roles of controller and processor
For booking/customer data entered by a customer organization, the customer organization is controller and the SaaS provider is processor. For provider account, billing, contract, and security data, the provider may act as controller.
2. Subject, duration, nature, and purpose
Processing covers the provision, maintenance, security, support, and improvement of WantToBook for the duration of the subscription and any legally required retention or agreed export period.
3. Processor instructions and confidentiality
The processor processes booking/customer data only on documented instructions from the controller unless law requires otherwise. Persons authorized to process data must be bound by confidentiality.
4. Government and tax authority requests
If a government or tax authority requests booking/customer data directly from the processor, the processor will verify the request's identity, legal basis, scope, and binding nature before disclosing data. Where legally permitted, the processor will notify the controller before disclosure and will reasonably direct the authority to request the data from the controller.
If disclosure is legally required, the processor will limit it to the data and period covered by the request, use an appropriate secure transfer method, and keep an internal record of the request and disclosure. The processor will not provide unrestricted platform access or disclose unrelated tenant data unless a binding legal requirement expressly requires it.
A legally binding preservation requirement or legal hold suspends deletion of the affected data for as long as the requirement applies. The processor will inform the controller of that restriction unless notification is prohibited by law.
5. Security measures
The processor applies appropriate technical and organizational measures, including access control, authentication, role separation, encrypted transport, logging, backup routines, vulnerability-aware maintenance, and operational monitoring.
6. Subprocessors
Subprocessors may be used for hosting, storage, email, payment processing, SMS, WhatsApp, monitoring, and backup services only where actually configured for the deployment.
- Mollie: Payment processing.
- Twilio: SMS verification and notifications.
- DigitalOcean: Object storage and encrypted backups.
7. International transfers
International transfers require appropriate safeguards and must be documented when a configured provider processes data outside the European Economic Area.
8. Assistance, data-subject requests, and audits
The processor will reasonably assist the controller with data-subject requests, security documentation, and audit information, taking into account the nature of processing and the information available to the processor.
9. Breach notification
The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting booking/customer data processed on behalf of that controller.
10. Deletion, anonymization, or return
The controller may issue a documented instruction to delete, anonymize, or return booking/customer data. Before issuing that instruction, the controller is responsible for determining whether the data must be retained as part of its tax, accounting, contractual, dispute, or other legally required records. The processor may offer an export before carrying out the instruction.
The processor will carry out a valid instruction unless applicable law requires continued storage or the affected data is subject to a binding preservation requirement or legal hold. Any retained copy will be isolated from ordinary use and processed only for the applicable retention or preservation purpose. Deletion from backups may occur through the documented backup-expiry cycle, provided retained backups remain protected and are not restored for ordinary use.
Data is retained for 30 days after termination.
Liability under this agreement should align with the main agreement and requires legal review before production approval.
11. Processing details
- Data subjects
- Customer organization users, staff users, customers making booking requests, and contacts included in booking records.
- Personal data categories
- Names, email addresses, telephone numbers, appointment preferences, service selections, booking notes, status history, account roles, and technical identifiers.
- Purpose
- Online booking, appointment review, communication, subscription administration, support, security, and service operation.
12. Technical and organizational measures
- role-based access in the administrative panel;
- authenticated access for organization users;
- transport encryption via HTTPS in production;
- database-backed queues and operational health checks;
- backup and retention procedures configured per deployment;
- restricted provider credentials through environment configuration.