Data Processing Agreement
This DPA forms part of the Terms of Service between Booki7 (Processor) and the Booki7 customer (Controller). By accepting the Terms, the Controller accepts this DPA. Both documents together constitute the written agreement required by Art. 28(3) GDPR.
1. Parties and roles
- Controller: the Booki7 customer (the business identified by the account).
- Processor: Booki7 — Darren Morrissey, trading as Booki7, a business name registered in Ireland (no. 789582) — (and where Booki7 itself acts under instructions, our sub-processors listed at /legal/sub-processors).
Processing is carried out only on the Controller's documented instructions. The Terms of Service and the Booki7 product configuration constitute those instructions, as updated by the Controller from their admin panel.
2. Subject-matter, nature, purpose, duration
- Subject-matter: provision of an AI receptionist service for the Controller's customers and prospects.
- Nature of processing: collection, storage, transmission, automated analysis (AI inference), routing, deletion.
- Purpose: to handle inbound conversations, capture bookings, product orders and contact requests, and notify the Controller; and, where the Controller enables the relevant features, to send messages outbound to the Controller's own clients on the Controller's behalf — appointment reminders, follow-up and aftercare messages, and offers of last-minute availability. The Controller determines whether those outbound features are enabled and is responsible for the lawful basis for them (see clause 5 of the Terms of Service).
- Duration: for the term of the Terms of Service plus a 90-day data retention window.
3. Categories of data subjects and personal data
- Data subjects: end-visitors of the Controller's website / Facebook page / WhatsApp / phone number.
- Categories of data: name, email, phone, message content, IP address, browser/device string, page URL, booking details (service, date, time), order details (items, quantity, personalisation notes, collection/delivery date, and a delivery address where delivery is chosen), notes the visitor provides.
- No special-category data: the Controller agrees not to process Art. 9 GDPR data (health, biometrics, etc.) without prior written notice. Incidental details a visitor volunteers in free text (e.g. a dietary or allergy note on an order) are processed only as part of the message or order they appear in, on the Controller's instructions.
4. Processor obligations
- Process personal data only on documented instructions from the Controller (Art. 28(3)(a)).
- Ensure persons authorised to process the data are subject to confidentiality (Art. 28(3)(b)).
- Implement appropriate technical and organisational measures (Art. 32) — see Section 7 below.
- Engage sub-processors only with prior authorisation and a written contract imposing equivalent obligations (Art. 28(2), 28(4)).
- Assist the Controller in responding to data-subject requests (Art. 28(3)(e)).
- Assist the Controller with security, breach notification, DPIAs, and consultation with the supervisory authority (Art. 28(3)(f)).
- At the Controller's choice, delete or return all personal data at the end of processing, save copies required by law (Art. 28(3)(g)).
- Make available all information necessary to demonstrate compliance and allow audits (Art. 28(3)(h)).
5. Sub-processors
The Controller authorises Booki7 to use the sub-processors listed at /legal/sub-processors. Booki7 will give at least 30 days' notice by email of any intended addition or replacement. The Controller may object on reasonable data-protection grounds, in which case the Controller may terminate without penalty for the affected service.
6. International transfers
Some sub-processors are located outside the EU/EEA (notably the United States). Where this is the case, transfers are based on the European Commission's Standard Contractual Clauses (Module 3, processor-to-processor or Module 2, controller-to-processor as appropriate), supplemented by the technical and organisational measures listed in Section 7. Booki7 has performed a transfer impact assessment for each US sub-processor in the list.
7. Technical and organisational measures (Art. 32)
- Encryption in transit: TLS 1.2+ enforced on all public endpoints, including the chat connection; HSTS. Webhooks from Meta and Stripe are accepted only with a valid signature.
- Data at rest: stored on a single production server operated by Hetzner Online GmbH in Falkenstein, Germany. The database is readable only by the server's administrator account and the application itself; backups and logs only by the administrator account. They are not encrypted at rest.
- Access control: a separate sign-in key per customer account and per team member, stored only as a one-way fingerprint; each signed-in device holds its own sign-in, which the customer can end from their dashboard and which lapses after 90 days unused; a super-admin key held only in the server environment; administrator access to the server by SSH key only, behind a firewall that blocks every other port, with repeated failed logins blocked automatically.
- Logging: every change a super-admin makes to a customer account or a content report, and every data export, is recorded in an audit log with actor, action, target, IP, user-agent and timestamp. Application logs show visitors' email addresses and phone numbers only in masked form and are kept for 14 days.
- Backups: a daily automated backup of the database and uploaded files, keeping 14 daily and 8 weekly copies, stored on the production server in the EU. A restore of the newest backup is tested automatically every month.
- Resilience: process supervisor auto-restart, health monitoring with operator alerts, structured error logging.
- Vulnerability management: operating-system security updates installed automatically every night, with an automatic restart when an update requires one; a monthly review of dependencies and third-party services; security patches applied within 30 days of vendor release for high-severity issues.
- Data minimisation: only the data the AI needs for its task is sent to inference sub-processors; sub-processors do not train on customer data (see Sub-processors page for vendor-specific commitments).
8. Personal data breach
Booki7 will notify the Controller of any personal data breach affecting their data without undue delay and within 72 hours of becoming aware, and will provide the information required by Art. 33(3) (nature, categories, numbers, likely consequences, measures taken). The Controller is responsible for any onward notification to the supervisory authority and to data subjects.
9. Audit
The Controller may, on 30 days' written notice and no more than once per calendar year, request a written description of Booki7's controls or a copy of the most recent third-party security report (if any). On-site audits require the Controller to bear reasonable costs and may be replaced, at Booki7's discretion, by a SOC 2 / ISO 27001 / penetration test report once available.
10. Liability
Liability under this DPA is subject to the limitation in the Terms of Service.
11. Termination, return and deletion
On termination of the Agreement, Booki7 will, at the Controller's choice, return or delete all personal data within 90 days, except where law requires retention. The Controller may export their data at any time from Settings → My Data.
12. Order of precedence
If there's a conflict between the Terms and this DPA on data-protection matters, the DPA prevails.
13. Governing law
This DPA is governed by Irish law and forms a binding part of the Terms.