Data Processing Agreement (DPA)
Version 1.0 — 3 June 2026
This Data Processing Agreement (the “DPA”) forms part of the BookOS Terms of Service between the Customer (“Controller”) and BookOS, CVR 46540352, Denmark (“BookOS”, “Processor”) and applies whenever BookOS processes Personal Data on behalf of the Controller. It is designed to satisfy Article 28 of the EU General Data Protection Regulation 2016/679 (“GDPR”).
1. Definitions
“Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, “Sub-processor” and “Supervisory Authority” have the meanings given in the GDPR.
2. Subject matter and roles
The Controller has engaged BookOS to provide the Service described in the Terms of Service. In doing so, BookOS processes Personal Data submitted by or through the Controller’s account (“Customer Data”). The Controller is the controller and BookOS is the processor of such Customer Data. BookOS does not determine the purposes or means of Processing.
3. Duration
Processing under this DPA continues for the term of the Terms of Service and the post- termination period set out in Section 11.
4. Processor obligations
- Process Customer Data only on the Controller’s documented instructions, including the instructions embodied in configuring and using the Service. BookOS will inform the Controller if it believes an instruction violates EU or Member-State data-protection law.
- Ensure persons authorised to process Customer Data are bound by confidentiality.
- Implement appropriate technical and organisational measures set out in Schedule 2.
- Engage Sub-processors only in accordance with Section 6.
- Taking the nature of Processing into account, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to Data Subject requests.
- Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, DPIAs, prior consultation).
- At the Controller’s choice, delete or return all Customer Data after the end of the provision of services, and delete existing copies unless EU or Member-State law requires storage.
- Make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as described in Section 8.
5. Controller obligations
The Controller warrants that it has a valid legal basis for the Processing instructed, provides any required notices to Data Subjects, and is responsible for the accuracy, quality, and legality of Customer Data.
6. Sub-processors
The Controller grants BookOS general authorisation to engage the Sub-processors listed at bookos.io/legal/subprocessors. BookOS will give 30 days prior notice of any intended addition or replacement by updating the page and emailing registered billing contacts. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the Service with a pro-rated refund. BookOS imposes data-protection obligations on each Sub-processor no less protective than those in this DPA.
7. International transfers
Where Processing involves a transfer of Personal Data outside the EEA, BookOS relies on (a) an adequacy decision under Article 45 GDPR (including the EU–US Data Privacy Framework where applicable), or (b) the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor), incorporated by reference. The optional docking clause (Clause 7) is deemed accepted. The Annexes to the SCCs are populated from Schedules 1, 2, and 3 of this DPA.
Where transfers fall within the scope of the UK GDPR, the parties incorporate the UK International Data Transfer Addendum (Version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018) to the SCCs, with Table 4 selecting both parties as Importer and Exporter respectively.
Where transfers fall within the scope of the Swiss Federal Act on Data Protection (revFADP), the parties incorporate the SCCs subject to (i) references to the GDPR being read as references to the revFADP where Swiss data is involved, (ii) references to EU Member State law being read as references to Swiss federal law, (iii) Annex I.C designating the Federal Data Protection and Information Commissioner (FDPIC) as competent supervisory authority for Swiss data, and (iv) Clause 18(c) being modified to recognise the right of Swiss data subjects to bring claims before Swiss courts. Pre-effective transfers of legal-entity data under the previous Swiss FADP remain covered until 1 September 2027.
BookOS conducts and documents transfer-impact assessments (TIAs) where required by EDPB Recommendations 01/2020. Summaries are available to enterprise customers under NDA.
8. Audits
BookOS will, upon reasonable written request and no more than once per 12 months (or following a confirmed Personal Data Breach), make available summaries of independent third-party security assessments and respond to reasonable security questionnaires. On-site audits are limited to the Controller’s authorised representative, conducted during business hours, with at least 30 days notice, at the Controller’s cost, and subject to confidentiality undertakings.
9. Personal Data Breaches
BookOS notifies the Controller without undue delay and, where feasible, within 72 hours of becoming aware of a Personal Data Breach affecting Customer Data. The notification will include the information required by Article 33(3) GDPR to the extent then known, and updates will follow as more facts emerge.
10. Data Subject requests
Where a Data Subject contacts BookOS directly regarding Customer Data, BookOS forwards the request to the Controller without responding. BookOS provides the Controller with tools and APIs to fulfil access, rectification, erasure, restriction, portability, and objection requests within the Service.
11. Return or deletion
On termination, the Controller may export Customer Data for 90 days. After that period, BookOS deletes Customer Data from production systems within 30 days, and from backups in the normal backup-rotation cycle (currently 35 days). BookOS may retain Customer Data where required by law (e.g. invoicing records under the Danish Bookkeeping Act).
12. Liability
The limitations of liability in the Terms of Service apply to claims arising under this DPA, except that nothing limits liability that cannot be limited by law.
13. Order of precedence
In the event of a conflict between the Terms of Service and this DPA in relation to the Processing of Personal Data, this DPA prevails. If the SCCs apply and conflict with this DPA, the SCCs prevail.
14. Governing law
The laws of Denmark govern this DPA, except where the SCCs require otherwise.
15. Supervisory authority
For the purpose of Annex I.C of the SCCs and Clause 13, the competent supervisory authority is Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.
16. Aggregated and anonymised data
Notwithstanding any other provision of this DPA, BookOS may compile statistical, aggregated, or anonymised data derived from Customer Data, provided that the resulting data (i) does not directly or indirectly identify the Controller, any Data Subject, or any salon, and (ii) is rendered anonymous within the meaning of GDPR Recital 26 (irreversibly de-identified such that re-identification by any reasonably likely means is precluded). BookOS may use such aggregated and anonymised data for product improvement, benchmarking, analytics, and publication of industry trends. This DPA does not apply to data that has been anonymised in accordance with this section.
Schedule 1 — Details of Processing
- Subject matter: Provision of the BookOS salon management platform.
- Duration: For the term of the Terms of Service and the post-termination retention window.
- Nature and purpose: Hosting, processing, transmission, display, backup, and security of Customer Data to provide the Service.
- Categories of Data Subjects: Salon staff, salon owners, salon customers (end customers).
- Types of Personal Data: Name, email, phone, password hash, address (where provided), booking history, service preferences, photographs (where uploaded), staff role, customer notes, marketing consent flags, payment metadata (card data is handled directly by Stripe and not stored by BookOS).
- Special categories: None instructed. The Controller agrees not to upload special-category data (Art. 9 GDPR) into free-text fields without first agreeing additional safeguards in writing.
- Frequency: Continuous.
Schedule 2 — Technical and Organisational Measures
BookOS maintains a security programme including, at minimum:
- Encryption: TLS 1.2+ in transit on all public endpoints; AES-256 at rest for the production database, backups, and object storage.
- Access control: Role-based access; least-privilege; BookOS operator credentials are isolated in the environment (no operator account exists in the application database and none can be created through the UI); quarterly access reviews.
- Tenant isolation: Row-level isolation enforced by a scoped database client; automated tests in CI to detect cross-tenant leakage; per-request tenant resolution audited in logs.
- Network & platform: The Service is hosted on reputable managed cloud infrastructure in the EU, with managed Postgres, private network paths between application and database, and a web application firewall and rate limiting at the application edge. The current list of sub-processors is published at bookos.io/legal/subprocessors.
- Backups & restore: Daily encrypted backups with point-in-time recovery; restore procedure documented and tested at least quarterly.
- Logging & monitoring: Centralised application logs, security event logs, and immutable audit trails; error tracking and anomaly alerting on production systems.
- Vulnerability management: Automated dependency monitoring; security patches applied promptly, with critical issues prioritised; periodic independent penetration testing.
- Personnel: Confidentiality agreements; security training on hire and annually; background checks for personnel with production access.
- Incident response: Documented playbook; suspected breaches are triaged without undue delay.
- Business continuity: Geographically redundant hosting; documented recovery point and recovery time objectives available to enterprise customers under NDA.
Schedule 3 — Sub-processors
The current list of authorised Sub-processors is published at bookos.io/legal/subprocessors and forms part of this DPA. The page records each Sub-processor’s name, role, location, and the safeguards applied to international transfers (where relevant).
How to execute: by signing up for BookOS and accepting the Terms of Service, the Customer accepts this DPA on behalf of itself. Customers requiring a counter-signed PDF copy may request one at legal@bookos.io.
