Legal
Data Processing Addendum
This DPA forms part of the Terms of Service and governs how Bookable processes personal data on your behalf when you use the Service. You are the controller; Bookable is the processor.
1. Roles & scope
This Data Processing Addendum (DPA) supplements the Terms of Service between you (the controller/ “business”) and Worldview Industries LLC, doing business as Bookable (the processor/ “service provider”). It applies to personal data we process on your behalf when you use the Service. Defined terms track both the GDPR/UK GDPR (controller, processor, personal data, data subject, subprocessor) and U.S. state privacy laws (business, service provider, sale, share).
2. Processing on your instructions
We process personal data only to provide the Service and on your documented instructions, which include the Terms, this DPA, and your configuration and use of the Service. We will tell you if we believe an instruction violates applicable data-protection law.
3. Our obligations as processor
- Process personal data only for the purposes described in this DPA and your instructions.
- Ensure personnel who process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Annex II).
- Assist you, taking into account the nature of the processing, with data-subject requests, security, breach notification, and impact assessments.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
4. U.S. service-provider terms
With respect to personal data subject to U.S. state privacy laws, we act as your service provider. We will not: (a) sell or share the personal data; (b) retain, use, or disclose it for any purpose other than performing the Service or as permitted by law; (c) retain, use, or disclose it outside our direct business relationship with you; or (d) combine it with data from other sources except as permitted. We certify that we understand and will comply with these restrictions.
5. Security measures (Annex II)
We maintain measures including: password hashing (bcrypt); encryption of certain sensitive fields at rest; encryption in transit (TLS); logical tenant isolation; a tamper-evident audit log; access controls and available multi-factor authentication; and secrets managed through a dedicated secrets manager. These measures may evolve, but we will not materially decrease the overall level of protection during the term.
6. Subprocessors
You authorize us to engage the subprocessors listed on our Subprocessor List. We impose data-protection obligations on each subprocessor that are materially no less protective than this DPA, and we remain responsible for their performance. We will provide a mechanism to receive notice of new subprocessors and a reasonable period to object.
7. International transfers
We process personal data in the United States (Amazon Web Services, US East / Ohio region). Where you transfer personal data subject to EEA, UK, or Swiss law to us, the applicable Standard Contractual Clauses (EU Commission 2021/914, module controller-to-processor) and the UK International Data Transfer Addendum are incorporated into this DPA by reference, with the annexes completed using the information in this DPA and the Subprocessor List.
8. Assisting with data-subject requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures — including account-level export, correction, and deletion tools — to help you respond to requests from data subjects to exercise their rights.
9. Personal-data breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting personal data we process for you, and will provide information reasonably available to help you meet your own notification obligations.
10. Return & deletion
On termination, and subject to the export window in the Terms, we will delete or return personal data we process for you in the ordinary course. Following account deletion, tenant data is permanently purged after 30 days, except where retention is required by law.
11. Audits
On reasonable written request, we will make available information necessary to demonstrate compliance with this DPA, ordinarily through documentation and completed security questionnaires. Any on-site audit is subject to reasonable scope, notice, confidentiality, and frequency limits.
12. Annexes
- Annex I — Parties & processing. Controller: you. Processor: Worldview Industries LLC, doing business as Bookable. Data subjects: your End Users, staff, and leads. Categories of data: contact details, booking and transaction details, communications content and metadata, and other data you submit. Purpose: providing the Service. Duration: the term of the agreement.
- Annex II — Security measures. As described in section 5.
- Annex III — Subprocessors. As listed on our Subprocessor List.
This DPA is accepted as part of your acceptance of the Terms. In case of conflict regarding personal data, this DPA controls over the Terms.
Questions about this document? Contact us at contact@bookable.co. See our other policies: Terms, Privacy, Cookies, DPA, Subprocessors, Acceptable Use, Messaging, DMCA.