Legal
Data Processing Agreement
The data-protection terms that apply when BOOKSAFE processes personal data for a business customer.
Version 2026-06-28 · Last updated: 28 June 2026
1. Parties and application
This Data Processing Agreement (DPA) forms part of the BOOKSAFE Terms of Service between BOOKSAFE LTD (company number 17098929) and the business customer using BOOKSAFE (Customer). It applies where Customer is a controller and BOOKSAFE processes personal data on Customer's behalf. Capitalised terms have the meanings in applicable data-protection law or the Terms of Service.
2. Applicable law and roles
The parties will comply with the UK GDPR, Data Protection Act 2018 as amended, the Data (Use and Access) Act 2026, and other applicable data-protection law. Customer determines the purposes and means of processing its customer, booking, staff, and service data. BOOKSAFE acts as processor for that data and as an independent controller for its own account administration, billing, security, fraud prevention, and legal compliance.
3. Customer instructions
BOOKSAFE will process Customer Personal Data only on documented instructions from Customer, including the Terms, this DPA, Customer's configured settings, authorised use of features, and written support instructions, unless UK law requires otherwise. If legally permitted, BOOKSAFE will inform Customer before processing required by law.
BOOKSAFE will notify Customer if an instruction appears to infringe applicable data-protection law and may suspend that instruction while the parties resolve the issue.
4. Confidentiality and personnel
BOOKSAFE will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate data-protection and security guidance, and access data only as needed for their duties.
5. Security measures
BOOKSAFE will maintain measures appropriate to the risk, including where relevant:
- TLS in transit, protected secrets, encrypted integration tokens, and provider encryption at rest;
- role-based access, tenant scoping, authentication controls, session revocation, and least privilege;
- logging, monitoring, rate limiting, webhook verification, dependency checks, and incident response;
- backups, recovery procedures, change controls, and regular testing of service integrity;
- supplier assessment and contractual protections appropriate to each processing activity.
6. Subprocessors
Customer gives general written authorisation for BOOKSAFE to use the subprocessors listed on the Subprocessors page. BOOKSAFE will impose data-protection obligations providing an equivalent level of protection where required and remains responsible for its subprocessors' performance of those obligations.
BOOKSAFE will give reasonable advance notice of a material new subprocessor where practicable. Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a solution; if none is reasonably available, Customer may stop the affected feature or terminate the affected service.
7. International transfers
BOOKSAFE will not make a restricted transfer of Customer Personal Data without a lawful transfer mechanism. Where required, the parties incorporate the then-current UK International Data Transfer Addendum or enter an appropriate International Data Transfer Agreement, supplemented by risk and security measures. Customer authorises transfers needed for the listed subprocessors subject to these safeguards.
8. Individual rights
Taking account of the nature of processing, BOOKSAFE will provide reasonable assistance for Customer to respond to requests to access, correct, erase, restrict, object, or port personal data. If BOOKSAFE receives a request relating to Customer-controlled data, it will direct the requester to Customer unless legally prohibited.
9. Breaches and compliance assistance
BOOKSAFE will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provide available information reasonably needed for Customer's assessment and notifications. BOOKSAFE will reasonably assist with security obligations, data-protection impact assessments, prior consultation, and regulator enquiries, taking account of the processing and information available to BOOKSAFE.
10. Return and deletion
During the service term, Customer may export available data using product features or reasonable support. Following termination or a valid deletion request, BOOKSAFE will delete or return Customer Personal Data within the documented deletion lifecycle, normally after a 30-day recovery period, unless law requires retention. Data remaining in backups will be protected and deleted through normal secure rotation.
11. Information and audits
BOOKSAFE will make information reasonably necessary to demonstrate Article 28 compliance available to Customer. No more than once annually, unless a breach or regulator requires otherwise, Customer may request a reasonable audit by an independent, confidential auditor. Audits must avoid exposing other customers' data and unnecessary disruption. Customer bears its audit costs unless the audit identifies a material BOOKSAFE breach.
12. Customer responsibilities
Customer is responsible for lawful instructions, privacy information, lawful bases, data accuracy and minimisation, user permissions, responding to individuals, and avoiding prohibited data. Customer must not instruct BOOKSAFE to process data in breach of law and must configure retention and communications appropriately.
Annex A — Processing details
- Subject matter: provision of BOOKSAFE booking, customer-management, communication, payment-status, staff, content, and support features.
- Duration: the service term plus documented deletion, backup, legal, and dispute-retention periods.
- Nature and purpose: hosting, organising, retrieving, transmitting, synchronising, supporting, securing, and deleting data to provide the service.
- Data subjects: Customer's owners, staff, contractors, prospective customers, customers, booking participants, and support contacts.
- Personal data: identity and contact details; booking, availability, service, staff, address, note, communication, payment-status, device, calendar, media, and support information.
- Special data: not intentionally required. Customer must not submit special-category or criminal-offence data unless expressly supported and lawfully configured.
- Frequency: continuous or as initiated by Customer and its authorised users during the service term.
13. Order of precedence and contact
For processing of Customer Personal Data, this DPA prevails over conflicting general terms. The remainder of the Terms, including governing law and liability, continues to apply. Data-protection enquiries may be sent to hello@booksafe.co.uk.