Legal

Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the business owner, the “Controller”) and Bookify Malta (“Processor”), operated by Christian Azzopardi trading as Bookify Malta. It governs the processing of personal data about your clients that you record or that is collected through self-booking on the Bookify Malta platform.

1. Roles and scope

For client personal data processed on the platform:

  • Controller: you, the business owner. You decide which client data to record and why.
  • Processor: Bookify Malta, which processes that data on your documented instructions solely to provide the platform.

This DPA does not cover data about your own account, which is processed by Bookify Malta as controller under the Platform Privacy Policy.

2. Categories of data and processing

The Processor processes the following categories of personal data on behalf of the Controller:

  • Client names and phone numbers;
  • Booking details: date, time, service, staff member, notes;
  • Booking history and reschedule records;
  • SMS delivery status where the Controller has enabled SMS reminders (and the client’s consent is the Controller’s responsibility).

Processing operations include recording, storing, retrieving, updating, transmitting (including to SMS and email delivery providers) and deleting data, all for the purpose of operating the platform.

3. Processor obligations

  • Process personal data only on documented instructions from the Controller, unless required to do otherwise by EU or Member State law (in which case we will inform you, where permitted);
  • Ensure persons authorised to process the data are bound by confidentiality;
  • Implement appropriate technical and organisational security measures, as set out in Section 6;
  • Assist the Controller in responding to data subject requests (Section 5);
  • Return or delete data on termination of the service, per Section 7;
  • Maintain records of processing activities as required by Article 30(2) GDPR.

4. Subprocessors

The Controller provides general authorisation for the Processor to engage subprocessors for the purpose of providing the platform. A current list of subprocessors, their purpose and region is published on our Subprocessor List. We will notify the Controller at least 14 days before adding or replacing a subprocessor, and you may object within that window on reasonable grounds.

5. Data subject requests and assistance

Where a client of the Controller exercises a GDPR right (access, rectification, erasure, restriction, portability), we will assist the Controller, to the extent possible and by appropriate technical measures, in fulfilling that request. If we receive a request directly from a data subject, we will forward it to the Controller. We will also assist with data protection impact assessments and consultations with supervisory authorities where required by Articles 35 and 36 GDPR.

6. Security

Taking into account the state of the art and the risks involved, the Processor applies appropriate measures, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest;
  • Access controls and authentication for all platform accounts;
  • EU-hosted infrastructure;
  • Regular review of access to production systems.

The Processor will notify the Controller without undue delay (and within 72 hours of becoming aware, where feasible) of a personal data breach affecting client data processed under this DPA, providing available details so the Controller can meet its own notification obligations.

7. Termination and deletion

On termination of the service, the Controller may export their data during the notice period. After termination, the Processor will delete client personal data, unless EU or Member State law requires retention (for example, invoicing records, which are kept only as long as legally required). See the Account Deletion Policy for more detail.

8. Liability

Each party is liable for damage caused by its own breach of this DPA, as set out in the GDPR. The Processor’s aggregate liability is limited as provided in the Terms of Service, except where the GDPR provides otherwise.

9. Contact

Questions about this DPA? Email legal@bookify.mt.