- Home
- Data Processing Agreement
Data Processing Agreement
Last updated: August 2026 · v1.1
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the business owner, the “Controller”) and Bookify Malta (“Processor”), operated by Christian Azzopardi trading as Bookify Malta (VAT MT30087118, Gcoe, Triq il-Mithna, Qala, Gozo, Malta). It governs the processing of personal data about your clients that you record or that is collected through self-booking on the Bookify Malta platform. This DPA reflects the requirements of Regulation (EU) 2016/679 (the “GDPR”) and the Maltese Data Protection Act (Chapter 586 of the Laws of Malta).
This DPA is accepted automatically by every business owner when they accept the Terms of Service. A signed paper copy can be requested from legal@bookify.mt.
1. Roles and scope
For client personal data processed on the platform:
- Controller: you, the business owner. You decide which client data to record and why.
- Processor: Bookify Malta, which processes that data on your documented instructions solely to provide the platform.
Bookify Malta remains the independent controller for data it collects about account holders themselves (name, email, billing details), which is governed by the Platform Privacy Policy, not this DPA. This DPA covers only the client and staff data the Controller uploads to or generates through the platform.
Directory research and unclaimed listing information are processed by Bookify Malta as an independent controller and are outside the scope of this DPA, including any listing of the Controller’s business in the Bookify Directory. Directory processing is described in section 6 of our Website Privacy Policy.
2. Categories of data and processing
The Processor processes the following categories of personal data on behalf of the Controller:
- Client names and phone numbers;
- Booking details: date, time, service, staff member, notes;
- Booking history and reschedule records;
- SMS delivery status where the Controller has enabled SMS reminders (the Controller is responsible for ensuring an appropriate lawful basis for each message — see our SMS Communications Policy).
Processing operations include recording, storing, retrieving, updating, transmitting (including to Epic Malta for SMS delivery via a Bookify-operated messaging relay hosted on DigitalOcean in Germany, and to SiteGround for email delivery) and deleting data, all for the purpose of operating the platform. The full description, categories of data subjects and retention details are set out in Annex A.
3. Processor obligations
- Process personal data only on documented instructions from the Controller, unless required to do otherwise by EU or Member State law (in which case we will inform you, where permitted);
- Ensure persons authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational security measures, as set out in Annex C;
- Assist the Controller in responding to data subject requests (Section 5);
- Return or delete data on termination of the service, per Section 7;
- Maintain records of processing activities as required by Article 30(2) GDPR;
- Assist the Controller with data protection impact assessments and prior consultations where required by Articles 35 and 36 GDPR.
4. Controller’s obligations
The Controller shall:
- comply with the GDPR and Maltese data protection law in its capacity as Controller;
- have an appropriate lawful basis (Article 6 GDPR) for every act of processing it instructs the Processor to carry out;
- provide its own clients with appropriate transparency information (Articles 13–14 GDPR) describing the processing carried out through Bookify Malta;
- ensure it has a valid lawful basis for processing the client’s telephone number and sending each message: strictly transactional appointment reminders will normally rely on performance of the booking relationship (Art. 6(1)(b)) or the Controller’s documented legitimate interests (Art. 6(1)(f)), subject to the Controller’s assessment, while any promotional or mixed promotional message requires compliance with the applicable direct-marketing consent and opt-out requirements;
- be solely responsible for the accuracy, quality and legality of client personal data it uploads to the platform;
- not upload special category data (Article 9 GDPR) except as strictly necessary to operate the booked service and where the Controller has a lawful basis under Article 9. The platform is designed for standard contact-and-booking data, not special category data.
5. Subprocessors
The Controller provides general authorisation for the Processor to engage subprocessors for the purpose of providing the platform. A current list of subprocessors, their purpose, region and transfer mechanism is published on our Subprocessor List and reproduced in Annex B.
We will notify the Controller at least 30 days before adding or replacing a subprocessor. If the Controller objects on reasonable data-protection grounds within that window, we will either refrain from engaging the proposed subprocessor, propose an alternative, or where neither is reasonably feasible, allow the Controller to terminate the affected portion of the service with a pro-rata refund of unused prepaid fees.
6. Data subject requests and assistance
Where a client of the Controller exercises a GDPR right (access, rectification, erasure, restriction, portability), we will assist the Controller, to the extent possible and by appropriate technical measures, in fulfilling that request. If we receive a request directly from a data subject, we will forward it to the Controller and will not respond to the data subject directly except to acknowledge receipt.
7. Security and breach notification
Taking into account the state of the art and the risks involved, the Processor applies the technical and organisational measures (TOMs) set out in Annex C, including:
- Encryption of data in transit (HTTPS/TLS) and at rest;
- Access controls and authentication for all platform accounts;
- EU-hosted infrastructure;
- Regular review of access to production systems.
Bookify will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data. Where reasonably practicable, Bookify’s operational target is to provide an initial notification within 24 hours of confirmed awareness. Bookify will provide further information in phases where all details are not yet available.
8. Termination, return and deletion
On termination of the service, the Controller may export their data during the notice period in a structured, commonly used, machine-readable format (CSV/JSON). After termination, the Processor will delete client personal data, unless EU or Member State law requires retention (for example, invoicing records, which are kept only as long as legally required and in pseudonymised form where technically feasible). A certificate of deletion is available on written request to legal@bookify.mt. See the Account Deletion Policy for more detail.
Audit rights: the Controller may, no more than once per twelve-month period and on reasonable written notice, audit the Processor’s compliance with this DPA, subject to confidentiality and without access to other customers’ data.
9. International transfers
Data is stored in the EU wherever possible. Where a subprocessor operates outside the EU/EEA, transfers rely on EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), an applicable adequacy decision, or other safeguards permitted under Chapter V GDPR. The Controller authorises the Processor to enter into SCCs with subprocessors on the Controller’s behalf. A copy of the relevant safeguards is available on request from legal@bookify.mt.
10. Liability and precedence
Each party is liable for damage caused by its own breach of this DPA, as set out in the GDPR. Liability between Controller and Processor for damages claimed by data subjects under Article 82 GDPR shall be apportioned in accordance with each party’s responsibility for the damage. The Processor’s aggregate liability is further limited as provided in the Terms of Service, except where the GDPR provides otherwise.
In the event of any conflict between this DPA, the Terms of Service and the privacy policies, this DPA prevails with respect to the processing of client personal data.
Annex A — Description of processing
| Element | Detail |
|---|---|
| Subject matter of processing | Provision of the Bookify Malta platform to the Controller for managing bookings, clients, staff and services. |
| Duration of processing | The term of the Controller’s subscription, plus legally required retention periods. |
| Nature of processing | Recording, storage, retrieval, structuring, hosting, transmission and deletion. |
| Purpose of processing | Enabling the Controller to operate its business through the Service. |
| Type of personal data | Client first name and (optional) last name; client phone number; booking date, time, service, staff member and notes; booking history; reschedule records; SMS delivery status; staff names. |
| Special category data | None expected. The Controller shall not upload special category data (Article 9 GDPR) save where strictly necessary and where the Controller has a lawful basis. |
| Categories of data subjects | The Controller’s own clients; the Controller’s staff members. |
Annex B — Subprocessors
| Subprocessor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Google Cloud / Firebase | Hosting, authentication, storage, backend logic, SMS task scheduling | EU | Data stays in EU |
| Epic Communications Ltd (Epic Malta) | SMS reminder delivery (final delivery to recipients) | Malta, EU | Data stays in EU |
| DigitalOcean, LLC | Cloud infrastructure hosting Bookify’s SMS messaging relay (processing region: Frankfurt, Germany) | Frankfurt, Germany (processing region); legal entity in the United States | DigitalOcean DPA (entered automatically with its Terms of Service) incorporating EU SCCs 2021/914; EU-U.S. DPF certification for transfers from the EEA |
| SiteGround Hosting Ltd (SiteGround EU) | Transactional email delivery | EU (Bulgaria) | Data stays in EU |
The current canonical list, including purpose, region and privacy-policy links for each provider, is published on our Subprocessor List.
Annex C — Technical and organisational measures
- Confidentiality: production access is restricted to the operator on a least-privilege basis; subprocessors are bound by confidentiality obligations.
- Integrity: data encrypted in transit (HTTPS/TLS) and at rest; passwords stored securely hashed via Firebase Authentication.
- Availability: EU-hosted infrastructure with redundancy; automated backups.
- Access control: authentication on all platform accounts, staff-account permissions, rate limiting on sensitive endpoints.
- Incident response:security incidents are investigated on detection and affected Controllers notified without undue delay (Bookify’s operational target is an initial notification within 24 hours of confirmed awareness, where reasonably practicable, with further information provided in phases as details become available), per Section 7.
- Vendor management: subprocessors are selected for EU data-protection commitments; the list is reviewed at least annually.
11. Changes to this DPA
We may update this DPA to reflect changes in law, processing operations or subprocessors. Material changes will be notified by email at least 30 days before they take effect.
12. Governing law and contact
This DPA is governed by the laws of Malta. Questions about this DPA, audit requests or requests for a signed copy? Email legal@bookify.mt.
Version history
| Version | Date | Summary of changes |
|---|---|---|
| v1.1 | August 2026 | Clarified that directory research and unclaimed listing information are processed by Bookify Malta as an independent controller and are outside the scope of this DPA. |
| v1.0 | August 2026 | Original published version. Archived; available on request from legal@bookify.mt. |