The text below is the legally binding version. Where the headings or summaries we provide differ from the body of an article, the body controls. We've tried to use clear language wherever possible — if any clause confuses you, please contact us before agreeing.
1. Definitions
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the Serbian Law on Personal Data Protection, and the CCPA, in each case to the extent applicable.
"Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission Implementing Decision (EU) 2021/914.
↑ Back to top2. Subject Matter, Duration, Nature and Purpose
Subject matter: the processing of personal data necessary for the provision of the Services as described in the Terms and the applicable Order Form.
Duration: the term of the Order Form, plus the period required for return or deletion of personal data as set out in this DPA.
Nature and purpose: enabling the Controller to manage bookings, queues and customer notifications, and providing related support, billing and security operations.
Categories of data subjects and personal data, and other details, are set out in Annex 1.
↑ Back to top3. Roles of the Parties
The Controller determines the purposes and means of the processing of personal data. The Processor processes personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by law applicable to the Processor.
The Controller represents that it has all necessary lawful bases to instruct the processing and to make the personal data available to the Processor.
↑ Back to top4. Processor Obligations
The Processor will:
- Process personal data only on the Controller's documented instructions, including those in the Terms, the DPA and any Order Form;
- Ensure that personnel authorised to process personal data are subject to confidentiality obligations of a contractual or statutory nature;
- Implement and maintain the technical and organisational measures described in Annex 2;
- Engage Sub-processors only as set out in Annex 3 and Section 5 of this DPA;
- Assist the Controller, taking into account the nature of the processing, in responding to requests from Data Subjects exercising their rights;
- Assist the Controller in ensuring compliance with the Controller's obligations under Articles 32–36 GDPR (security, breach notification, data-protection impact assessments and prior consultation), taking into account the information available to the Processor;
- Make available all information necessary to demonstrate compliance with this DPA and contribute to audits as set out in Section 9;
- Inform the Controller without undue delay if, in the Processor's opinion, an instruction infringes Applicable Data Protection Law.
5. Sub-processors
The Controller authorises the Processor to engage the Sub-processors listed in Annex 3 and provides general written authorisation for the engagement of additional Sub-processors, subject to advance notice and the right to object.
Before engaging a new Sub-processor or replacing an existing one, the Processor will provide the Controller with at least thirty (30) days' notice (e.g. by email or through the Services). The Controller may object on reasonable grounds related to data protection within fourteen (14) days of the notice. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Services on written notice and receive a pro-rata refund of any prepaid fees relating to the unused portion.
↑ Back to top6. International Transfers
Where the Processor transfers personal data to a country outside the European Economic Area that is not the subject of an adequacy decision, the Processor will rely on the SCCs, hereby incorporated by reference, with Module Two (controller to processor) or Module Three (processor to processor) applying as appropriate, with the docking clause. Annex 1 to this DPA serves as Annex I to the SCCs and Annex 2 serves as Annex II.
For transfers from the United Kingdom, the parties incorporate the UK International Data Transfer Addendum to the SCCs. For transfers from Switzerland, the parties incorporate the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner.
↑ Back to top7. Data Subject Rights
The Processor will, taking into account the nature of the processing, provide reasonable assistance to the Controller (including by appropriate technical and organisational measures) to enable the Controller to respond to requests by Data Subjects to exercise their rights under Applicable Data Protection Law. If a Data Subject contacts the Processor directly, the Processor will redirect the Data Subject to the Controller and notify the Controller without undue delay.
↑ Back to top8. Personal Data Breach Notification
The Processor will notify the Controller of a Personal Data Breach without undue delay after becoming aware of it, and will provide the Controller with information reasonably required to meet its obligations under Articles 33 and 34 GDPR, including the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach.
↑ Back to top9. Audits
The Processor will make available to the Controller, on reasonable written request, a written summary of the technical and organisational measures described on the Security page. If, after reviewing this information, the Controller reasonably believes that further audit is necessary, the Controller may, at its expense and no more than once in any twelve-month period (except in the event of a Personal Data Breach affecting the Controller's data), conduct an on-site audit subject to (a) reasonable advance notice, (b) execution of a confidentiality agreement, (c) the audit being conducted during business hours, and (d) the audit being conducted in a manner that does not unreasonably interfere with the Processor's operations or the security or confidentiality of other customers' data.
↑ Back to top10. Return or Deletion of Personal Data
On termination or expiration of the Services, the Processor will, at the Controller's choice, return or delete all personal data processed on behalf of the Controller, except to the extent retention is required by law. Customer-initiated export tooling is provided in the Services. Any backup copies will be deleted in accordance with the Processor's standard retention schedule and remain subject to the obligations of this DPA until deletion.
↑ Back to topAnnex 1 — Details of Processing
Subject matter and duration: as set out in Section 2.
Nature and purpose: as set out in Section 2.
Categories of data subjects: the Controller's customers ("End Customers"), Users (employees, contractors and agents of the Controller authorised to use the Services), and other individuals whose personal data is provided by the Controller in connection with bookings, queues or notifications.
Categories of personal data: identifiers (name, email, phone), booking and queue data (appointment details, status, position), notes submitted by the Controller, communications (messages, support requests), device and usage data (IP, device, timestamps).
Sensitive data: the Services are not intended for the processing of special categories of personal data within the meaning of Article 9 GDPR. The Controller must not submit such data without the prior written agreement of the Processor and the implementation of additional safeguards.
↑ Back to topAnnex 2 — Technical and Organisational Measures
Annex 2 incorporates by reference the measures described on the Security page (/legal/security): hosting in the European Union, encryption in transit, hashed passwords, access control by workspace and role, and deletion of data on request. The Security page lists only measures that are in place and is updated when they change; updates will not materially diminish the overall level of protection.
↑ Back to topAnnex 3 — Sub-processors
The current list of Sub-processors and the processing they perform is published on the Sub-processors page (/legal/subprocessors) and is updated when it changes. Each Sub-processor is bound by data-protection terms no less protective than those in this DPA.
↑ Back to top