Data Processing Agreement
Version 2026-09-15
This agreement is between the studio that uses Booqa (the controller) and [BOOQA LEGAL NAME], registered with the Dutch Chamber of Commerce under number [BOOQA KVK NUMBER], [BOOQA ADDRESS] (Booqa, the processor). It applies to the personal data Booqa processes for the studio when the studio uses Booqa to run its schedule, bookings, memberships, passes and online courses. It forms part of the agreement under which the studio uses Booqa. This is a draft pending legal review.
1. Definitions
Words such as personal data, processing, controller, processor, data subject, sub-processor and personal data breach have the meaning given in the General Data Protection Regulation (EU) 2016/679 (GDPR). The service is the Booqa booking and membership platform. Studio data is the personal data described in Annex 1.
2. Roles
The studio decides why and how its clients' personal data is used, and is the controller for it. Booqa processes studio data only to provide the service and is the processor (Art. 28 GDPR).
Booqa is itself the controller, not the processor, for the Booqa account a person uses to sign in (name, email address, language, sign-in sessions), for the security of the platform, and for access by Booqa support. Booqa's own privacy notice describes that processing.
When the studio connects its own Mollie account to take payments online, Mollie processes payment data as a separate controller under its own agreement with the studio. Mollie is not a sub-processor of Booqa.
3. Instructions (Art. 28(3)(a))
Booqa processes studio data only on the studio's documented instructions. This agreement, the settings the studio chooses in Booqa and the actions its owners take in the service are those instructions. Booqa does not use studio data for its own purposes, does not sell it and does not use it for advertising.
If Booqa is required by EU or Dutch law to process studio data otherwise, it tells the studio before doing so, unless that law forbids it. Booqa tells the studio straight away if it believes an instruction breaks the GDPR.
4. Confidentiality (Art. 28(3)(b))
Everyone at Booqa who can access studio data is bound by a duty of confidentiality, by contract or by law, and has access only as far as their work needs it.
5. Security (Art. 28(3)(c) and Art. 32)
Booqa takes the technical and organisational measures described in Annex 2 to protect studio data against loss and against unlawful processing, taking into account the state of the art, the cost and the risks to data subjects. Booqa may improve these measures, but never lowers the overall level of protection.
6. Sub-processors (Art. 28(2) and 28(3)(d))
The studio gives Booqa general permission to engage the sub-processors listed in Annex 3. Booqa informs the studio at least [TO CONFIRM: 30] days before adding or replacing a sub-processor, by email to the principal owner and on this page. The studio may object on reasonable grounds within that period. If the objection cannot be resolved, the studio may end its use of the service before the change takes effect.
Booqa imposes the same data protection obligations on each sub-processor as this agreement imposes on Booqa, and remains responsible to the studio for their work.
7. Transfers outside the EEA
Booqa hosts the service in the European Union. Studio data is transferred outside the European Economic Area only where Annex 3 says so, and only with a valid transfer mechanism under Chapter V GDPR, such as an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission's standard contractual clauses.
8. Helping with data subject rights (Art. 28(3)(e))
Booqa helps the studio respond to requests from its clients to access, correct, delete, restrict, move or object to the use of their data. Much of this the studio can do itself in the service. Where it cannot, Booqa assists on request. If a client of the studio contacts Booqa directly about studio data, Booqa passes the request to the studio and does not answer it itself, unless the studio asks it to.
9. Personal data breaches and other assistance (Art. 28(3)(f))
Booqa informs the studio without undue delay, and where possible within [TO CONFIRM: 48] hours, after becoming aware of a personal data breach affecting studio data. The notice says, as far as known, what happened, which data and how many people are affected, the likely consequences and what Booqa has done or proposes to do. Booqa keeps a record of breaches.
Booqa also helps the studio, as far as reasonable, with its own obligations on security, breach notification to the Autoriteit Persoonsgegevens and data subjects, data protection impact assessments and prior consultation (Art. 32 to 36 GDPR).
10. End of the service (Art. 28(3)(g))
When the studio stops using the service, Booqa deletes studio data within [TO CONFIRM: 90] days, or returns it first if the studio asks for that before it ends. Copies in backups are deleted when those backups expire, within [TO CONFIRM: retention period of backups]. Booqa may keep data only where EU or Dutch law requires it, and then only for that purpose.
11. Information and audits (Art. 28(3)(h))
Booqa makes available the information the studio needs to show that this agreement is being met, and allows and contributes to reasonable audits, including inspections, by the studio or an auditor it appoints. The studio gives reasonable notice, bears its own costs and keeps what it learns confidential. Audits take place at most once a year, unless a breach or a supervisory authority gives reason for more.
12. Liability, duration and changes
Liability under this agreement follows the agreement under which the studio uses Booqa, [TO CONFIRM: liability cap and terms of service reference]. This agreement lasts as long as Booqa processes studio data.
Booqa may update this agreement, for example when the law or the service changes. A new version gets a new version date and is shown to the principal owner in the service, who is asked to accept it. Dutch law applies, and disputes go to the competent court in [TO CONFIRM: city].
Annex 1. Description of the processing
Subject and duration. Providing the Booqa service to the studio, for as long as the studio uses it and until the data is deleted under clause 10.
Nature and purpose. Storing, organising, displaying and sending studio data so the studio can publish its schedule and prices, take bookings and waitlist places, manage passes, memberships and weekly places, record attendance and sales, offer online courses, and send its clients transactional email (booking confirmations, reminders, cancellations, waitlist and membership notices).
Data subjects. The studio's clients and prospective clients, its teachers, and the owners and staff who use the studio's backend.
Categories of personal data.
- name, email address, mobile number (optional) and preferred language
- how a client heard about the studio (optional), which version of the studio's terms they accepted, and whether they agreed to receive news and offers from the studio
- membership, tier, status and the studio's own notes such as a reason for blocking
- bookings, waitlist places, cancellations, attendance and weekly places
- passes, orders and sales records, including amounts, payment method and, for direct debit, up to four digits of an account number
- online course progress
- teacher profiles and photographs the studio uploads
- when a member last visited the studio's pages
Special categories. The service does not ask for special categories of personal data (such as health data) and the studio should not enter them in free text fields.
Annex 2. Security measures
- Every studio's data is separated from every other studio's in the application: each read and write is limited to the studio of the signed-in person, and this is enforced centrally and covered by automated tests.
- Every action that changes data checks who is signed in, which studio they belong to, their role and whether they may act on that specific record.
- All traffic uses TLS encryption.
- Nobody signs in with a password to book or run a studio. Sign-in uses a six-digit code sent by email, which is stored only as a hash, expires after 5 minutes and allows 3 attempts. Sign-in attempts and actions are rate limited.
- The studio's payment provider credentials are encrypted at rest with AES-256-GCM and decrypted only when a payment needs them, and every decryption is logged.
- An append-only audit log records sensitive actions, including every access by Booqa support.
- Booqa support can see a studio's data only by entering it as its owner for a limited time (30 or 60 minutes), with a written reason, read-only by default, while the studio's owners are emailed and a banner is shown. Some acts, such as selling, refunding or accepting agreements, are refused even then.
- Location data (EXIF) is removed from uploaded photographs.
- The database and uploaded files are backed up daily to separate storage, and the backup job is monitored.
- The service runs in data centres in the European Union.
Annex 3. Sub-processors
- Hetzner Online GmbH, Gunzenhausen, Germany. Hosting of the application, database, uploaded files and backups, in data centres in Germany and Finland [TO CONFIRM: exact locations of the server and the backup storage]. No transfer outside the EEA.
- Resend [TO CONFIRM: legal entity name and address], United States. Sending transactional email (sign-in codes and the studio's booking and membership emails): recipient email address, name and message content. Transfer outside the EEA: [TO CONFIRM: EU sending region / EU-US Data Privacy Framework certification / standard contractual clauses].
Coolify, which Booqa uses to deploy the service, is software Booqa runs on its own servers and is not a sub-processor.