Data Processing Agreement (DPA)
Version 1.1 — 24 August 2026
This Data Processing Agreement (the “DPA”) forms part of the BookOS Terms of Service between the Customer (“Controller”) and BookOS, CVR 46540352, Denmark (“BookOS”, “Processor”) and applies whenever BookOS processes Personal Data on behalf of the Controller. It is designed to satisfy Article 28 of the EU General Data Protection Regulation 2016/679 (“GDPR”).
1. Definitions
“Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, “Sub-processor” and “Supervisory Authority” have the meanings given in the GDPR.
2. Subject matter and roles
The Controller has engaged BookOS to provide the Service described in the Terms of Service. In doing so, BookOS processes Personal Data submitted by or through the Controller’s account (“Customer Data”). The Controller is the controller and BookOS is the processor of such Customer Data. BookOS does not determine the purposes or means of Processing.
3. Duration
Processing under this DPA continues for the term of the Terms of Service and the post- termination period set out in Section 11.
4. Processor obligations
- Process Customer Data only on the Controller’s documented instructions, including the instructions embodied in configuring and using the Service. BookOS will inform the Controller if it believes an instruction violates EU or Member-State data-protection law.
- Ensure persons authorised to process Customer Data are bound by confidentiality.
- Implement appropriate technical and organisational measures set out in Schedule 2.
- Engage Sub-processors only in accordance with Section 6.
- Taking the nature of Processing into account, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to Data Subject requests.
- Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, DPIAs, prior consultation).
- At the Controller’s choice, delete or return all Customer Data after the end of the provision of services, and delete existing copies unless EU or Member-State law requires storage.
- Make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as described in Section 8.
5. Controller obligations
The Controller warrants that it has a valid legal basis for the Processing instructed, provides any required notices to Data Subjects, and is responsible for the accuracy, quality, and legality of Customer Data.
6. Sub-processors
The Controller grants BookOS general authorisation to engage the Sub-processors listed at bookos.dk/legal/subprocessors. BookOS will give 30 days prior notice of any intended addition or replacement by updating the page and emailing registered billing contacts. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the Service with a pro-rated refund. BookOS imposes data-protection obligations on each Sub-processor no less protective than those in this DPA.
7. International transfers
Where Processing involves a transfer of Personal Data outside the EEA, BookOS relies on (a) an adequacy decision under Article 45 GDPR (including the EU–US Data Privacy Framework where applicable), or (b) the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor), incorporated by reference. The optional docking clause (Clause 7) is deemed accepted. The Annexes to the SCCs are populated from Schedules 1, 2, and 3 of this DPA.
Where transfers fall within the scope of the UK GDPR, the parties incorporate the UK International Data Transfer Addendum (Version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018) to the SCCs, with Table 4 selecting both parties as Importer and Exporter respectively.
Where transfers fall within the scope of the Swiss Federal Act on Data Protection (revFADP), the parties incorporate the SCCs subject to (i) references to the GDPR being read as references to the revFADP where Swiss data is involved, (ii) references to EU Member State law being read as references to Swiss federal law, (iii) Annex I.C designating the Federal Data Protection and Information Commissioner (FDPIC) as competent supervisory authority for Swiss data, and (iv) Clause 18(c) being modified to recognise the right of Swiss data subjects to bring claims before Swiss courts. Pre-effective transfers of legal-entity data under the previous Swiss FADP remain covered until 1 September 2027.
BookOS conducts and documents transfer-impact assessments (TIAs) where required by EDPB Recommendations 01/2020. Summaries are available to the Controller on request under a confidentiality undertaking.
8. Audits
BookOS will, upon reasonable written request and no more than once per 12 months (or following a confirmed Personal Data Breach), respond to reasonable security questionnaires and make available a description of the measures in Schedule 2 together with summaries of any independent third-party security assessments it has obtained. On-site audits are limited to the Controller’s authorised representative, conducted during business hours, with at least 30 days notice, at the Controller’s cost, and subject to confidentiality undertakings.
9. Personal Data Breaches
BookOS notifies the Controller without undue delay and, where feasible, within 72 hours of becoming aware of a Personal Data Breach affecting Customer Data. The notification will include the information required by Article 33(3) GDPR to the extent then known, and updates will follow as more facts emerge.
10. Data Subject requests
Where a Data Subject contacts BookOS directly regarding Customer Data, BookOS forwards the request to the Controller without responding. BookOS provides the Controller with tools and APIs to fulfil access, rectification, erasure, restriction, portability, and objection requests within the Service.
11. Return or deletion
On termination of a paid subscription, the Controller may export Customer Data for 90 days. After that period, BookOS deletes Customer Data from production systems within 30 days. If the Controller cancels during a free trial, BookOS takes the trial site offline immediately and permanently deletes it and its Customer Data from production systems after a 14-day recovery period. The Controller must export any required data before that deadline. Deleted data leaves backups in the normal backup-rotation cycle (currently 35 days). BookOS may retain Customer Data where required by law (e.g. invoicing records under the Danish Bookkeeping Act). BookOS also retains non-identifying trial analytics in its role as controller for up to 24 months. This record excludes names, emails, exact domains, tenant and Stripe identifiers, end-customer records, bookings, uploads, and site content.
12. Liability
The limitations of liability in the Terms of Service apply to claims arising under this DPA, except that nothing limits liability that cannot be limited by law.
13. Order of precedence
In the event of a conflict between the Terms of Service and this DPA in relation to the Processing of Personal Data, this DPA prevails. If the SCCs apply and conflict with this DPA, the SCCs prevail.
14. Governing law
The laws of Denmark govern this DPA, except where the SCCs require otherwise.
15. Supervisory authority
For the purpose of Annex I.C of the SCCs and Clause 13, the competent supervisory authority is Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.
16. Aggregated and anonymised data
Notwithstanding any other provision of this DPA, BookOS may compile statistical, aggregated, or anonymised data derived from Customer Data, provided that the resulting data (i) does not directly or indirectly identify the Controller, any Data Subject, or any salon, and (ii) is rendered anonymous within the meaning of GDPR Recital 26 (irreversibly de-identified such that re-identification by any reasonably likely means is precluded). BookOS may use such aggregated and anonymised data for product improvement, benchmarking, analytics, and publication of industry trends. This DPA does not apply to data that has been anonymised in accordance with this section.
Schedule 1 — Details of Processing
- Subject matter: Provision of the BookOS salon management platform.
- Duration: For the term of the Terms of Service and the post-termination retention window.
- Nature and purpose: Hosting, processing, transmission, display, backup, and security of Customer Data to provide the Service.
- Categories of Data Subjects: Salon staff, salon owners, salon customers (end customers).
- Types of Personal Data: Name, email, phone, password hash, address (where provided), booking history, service preferences, photographs (where uploaded), staff role, customer notes, marketing consent flags, payment metadata (card data is handled directly by Stripe and not stored by BookOS).
- Special categories: None instructed. The Controller agrees not to upload special-category data (Art. 9 GDPR) into free-text fields without first agreeing additional safeguards in writing.
- Frequency: Continuous.
Schedule 2 — Technical and Organisational Measures
BookOS maintains a security programme including, at minimum:
- Encryption: TLS 1.2+ in transit on all public endpoints; AES-256 at rest for the production database, backups, and object storage.
- Access control: Role-based access; least-privilege; BookOS operator credentials are isolated in the environment (no operator account exists in the application database and none can be created through the UI); time-based one-time-password two-factor authentication is available on administrator accounts; access is reviewed whenever the set of personnel with production access changes.
- Tenant isolation: PostgreSQL row-level security enforced in the database itself, with the application connecting through a role that is neither a superuser nor permitted to bypass row-level security; a tenant-scoped database client; a build-time audit that fails the build on unscoped access to tenant-owned tables; and automated cross-tenant leakage tests gated in CI.
- Network & platform: The Service runs on Microsoft Azure in the EU (North Europe) using managed services — Azure Container Apps, Azure Database for PostgreSQL Flexible Server and Azure Blob Storage. The database does not accept connections from the public internet at large; secrets are held in Azure Key Vault and injected at runtime rather than stored in source. The application enforces HTTP Strict Transport Security, a nonce-based Content Security Policy, and request rate limiting. The current list of sub-processors is published at bookos.dk/legal/subprocessors.
- Backups & restore: Continuous point-in-time recovery on the managed database, retained for at least seven days, together with scheduled encrypted database dumps written to a private object-storage container that is not publicly readable. The restore procedure is documented in a disaster-recovery runbook and exercised by restore drills, the results of which are recorded.
- Logging & monitoring: Centralised application and platform logs; an append-only application audit log; error and exception tracking on production systems; and automated alerting on failures of backup, certificate renewal, and domain fulfilment.
- Vulnerability management: Automated dependency monitoring on every build, with a continuous-integration gate that fails the build on high or critical advisories affecting production dependencies; lower-severity advisories are tracked and patched on a routine basis; a published vulnerability-disclosure policy at bookos.dk/legal/vulnerability-disclosure.
- Personnel: Production access is limited to named personnel bound by confidentiality obligations, is protected by multi-factor authentication, and is withdrawn promptly when no longer required.
- Incident response: Documented playbook; suspected breaches are triaged without undue delay.
- Business continuity: Single-region EU deployment on managed services with provider-level redundancy within that region, a documented disaster-recovery runbook setting out recovery point and recovery time objectives, and logged recovery drills. The runbook is available to customers on request under a confidentiality undertaking.
Schedule 3 — Sub-processors
The current list of authorised Sub-processors is published at bookos.dk/legal/subprocessors and forms part of this DPA. The page records each Sub-processor’s name, role, location, and the safeguards applied to international transfers (where relevant).
How to execute: by signing up for BookOS and accepting the Terms of Service, the Customer accepts this DPA on behalf of itself. Customers requiring a counter-signed PDF copy may request one at admin+legal@bookos.dk.
