Data Processing Agreement (DPA)
Last updated: 1 August 2025
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Bookingly Ltd (“Processor”) and the business customer (“Controller”) and applies to all personal data processed by Bookingly on behalf of the Controller through the Bookingly platform.
1. Definitions
- Controller — the business using Bookingly who determines the purposes and means of processing customer data.
- Processor — Bookingly Ltd, processing data on behalf of the Controller.
- Data Subject — end customers whose personal data is collected during booking.
- UK GDPR — the UK General Data Protection Regulation as it forms part of UK law.
2. Subject Matter and Duration
Bookingly processes personal data of Data Subjects (end customers) on behalf of the Controller for the purpose of providing the booking management platform. Processing continues for the duration of the Controller's subscription and thereafter as required for data retention obligations.
3. Nature and Purpose of Processing
Bookingly processes personal data to:
- Store and manage customer booking records
- Send booking confirmation and reminder emails
- Facilitate deposit collection via Stripe
- Provide the Controller with access to customer and booking data via the dashboard
4. Categories of Personal Data
- Names, email addresses, and phone numbers of Data Subjects
- Appointment history, dates, times, and service details
- GDPR consent records
- Payment references (no card data — held by Stripe)
5. Processor Obligations
Bookingly shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process data are bound by confidentiality
- Implement appropriate technical and organisational security measures (Article 32 UK GDPR)
- Not engage sub-processors without the Controller's prior written consent (see Schedule A)
- Assist the Controller in responding to Data Subject requests
- Delete or return all personal data upon termination of the agreement
- Make available all information necessary to demonstrate compliance
- Notify the Controller without undue delay (within 48 hours) of a personal data breach
6. Controller Obligations
The Controller shall:
- Have a lawful basis for processing Data Subject personal data
- Provide appropriate privacy notices to Data Subjects
- Obtain required consents (Bookingly provides the consent checkbox mechanism)
- Respond to Data Subject rights requests in accordance with UK GDPR
7. Sub-Processors
The Controller provides general authorisation for Bookingly to engage the following sub-processors:
- Neon Inc. — PostgreSQL database hosting
- Vercel Inc. — Application hosting and CDN
- Stripe Inc. — Payment processing
- Clerk Inc. — Authentication services
- Resend Inc. — Transactional email
Bookingly will notify the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.
8. Security Measures
Bookingly implements:
- Encryption of data in transit (TLS 1.2+) and at rest
- Tenant isolation at the database level (all queries filtered by tenant_id)
- Role-based access controls for staff and owners
- Regular security reviews
- Multi-factor authentication via Clerk
9. Data Retention and Deletion
On termination, the Controller may export their data via the dashboard. Bookingly will delete all Controller data within 30 days of termination, unless legally required to retain it longer.
10. Governing Law
This DPA is governed by the laws of England and Wales.
11. Contact
To exercise rights under this DPA or report a concern:
Email: dpa@bookingly.co.uk