WantToBook
Appearance

Legal

Data Processing Agreement

Last updated: 2026-06-26

On this page

1. Roles of controller and processor

For booking/customer data entered by a customer organization, the customer organization is controller and the SaaS provider is processor. For provider account, billing, contract, and security data, the provider may act as controller.

2. Subject, duration, nature, and purpose

Processing covers the provision, maintenance, security, support, and improvement of WantToBook for the duration of the subscription and any legally required retention or agreed export period.

3. Processor instructions and confidentiality

The processor processes booking/customer data only on documented instructions from the controller unless law requires otherwise. Persons authorized to process data must be bound by confidentiality.

4. Government and tax authority requests

If a government or tax authority requests booking/customer data directly from the processor, the processor will verify the request's identity, legal basis, scope, and binding nature before disclosing data. Where legally permitted, the processor will notify the controller before disclosure and will reasonably direct the authority to request the data from the controller.

If disclosure is legally required, the processor will limit it to the data and period covered by the request, use an appropriate secure transfer method, and keep an internal record of the request and disclosure. The processor will not provide unrestricted platform access or disclose unrelated tenant data unless a binding legal requirement expressly requires it.

A legally binding preservation requirement or legal hold suspends deletion of the affected data for as long as the requirement applies. The processor will inform the controller of that restriction unless notification is prohibited by law.

5. Security measures

The processor applies appropriate technical and organizational measures, including access control, authentication, role separation, encrypted transport, logging, backup routines, vulnerability-aware maintenance, and operational monitoring.

6. Subprocessors

Subprocessors may be used for hosting, storage, email, payment processing, SMS, WhatsApp, monitoring, and backup services only where actually configured for the deployment.

  • Mollie: Payment processing.
  • Twilio: SMS verification and notifications.
  • DigitalOcean: Object storage and encrypted backups.

7. International transfers

International transfers require appropriate safeguards and must be documented when a configured provider processes data outside the European Economic Area.

8. Assistance, data-subject requests, and audits

The processor will reasonably assist the controller with data-subject requests, security documentation, and audit information, taking into account the nature of processing and the information available to the processor.

9. Breach notification

The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting booking/customer data processed on behalf of that controller.

10. Deletion, anonymization, or return

The controller may issue a documented instruction to delete, anonymize, or return booking/customer data. Before issuing that instruction, the controller is responsible for determining whether the data must be retained as part of its tax, accounting, contractual, dispute, or other legally required records. The processor may offer an export before carrying out the instruction.

The processor will carry out a valid instruction unless applicable law requires continued storage or the affected data is subject to a binding preservation requirement or legal hold. Any retained copy will be isolated from ordinary use and processed only for the applicable retention or preservation purpose. Deletion from backups may occur through the documented backup-expiry cycle, provided retained backups remain protected and are not restored for ordinary use.

Data is retained for 30 days after termination.

Liability under this agreement should align with the main agreement and requires legal review before production approval.

11. Processing details

Data subjects
Customer organization users, staff users, customers making booking requests, and contacts included in booking records.
Personal data categories
Names, email addresses, telephone numbers, appointment preferences, service selections, booking notes, status history, account roles, and technical identifiers.
Purpose
Online booking, appointment review, communication, subscription administration, support, security, and service operation.

12. Technical and organizational measures

  • role-based access in the administrative panel;
  • authenticated access for organization users;
  • transport encryption via HTTPS in production;
  • database-backed queues and operational health checks;
  • backup and retention procedures configured per deployment;
  • restricted provider credentials through environment configuration.