Data Processing Agreement
Este documento se proporciona en inglés. La versión en inglés es la única versión que rige; todavía no hay una traducción certificada al español. This document is provided in English. The English version is the only authoritative version; a certified Spanish translation is not yet available.
Effective date: 2026-07-29
Version: 1.3
Amendment (2026-07-29, v1.3): the public DPA page now renders this master text exactly (LEGAL-002 — one canonical body drives the page, the registered hash, and the acceptance record). No substantive change to the processing terms.
Amendment (2026-07-29): added Section 12.3 (Language) — the English version governs; translations are for convenience only.
Amendment (2026-07-21): clinical/health-data clauses removed following the medical de-scope; PeasyBooking no longer offers clinical features. The no-sell / no-AI-training, security, breach-notification, and data-subject-assistance commitments continue to apply to all Client Data uniformly.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the PeasyBooking Business SaaS Terms of Service (the "Terms") between PeasyBooking Technologies Inc., a corporation incorporated under the Canada Business Corporations Act (Corporation No. 1804322-1) with its registered office at 150 Evergreen Mount SW, Calgary, Alberta T2Y 0L8, operating as "PeasyBooking" ("PeasyBooking", "we", "us", the "Processor"), and the customer business that has accepted the Terms ("Customer", "you", the "Controller").
This DPA governs PeasyBooking's processing of personal information about the Customer's clients, staff, and other individuals on the Customer's behalf ("Client Data") in the course of providing the PeasyBooking booking, client-management, payments, and communications services (the "Service"). It does not govern personal information for which PeasyBooking is itself the controller (for example, the Customer's own account-holder and billing information, or marketplace guest information), which is addressed in the PeasyBooking Privacy Policy.
If there is a conflict between this DPA and the Terms with respect to the processing of Client Data, this DPA prevails.
1. Definitions
In this DPA:
- "Applicable Privacy Law" means all privacy and data-protection laws applicable to the processing of Client Data, including the federal Personal Information Protection and Electronic Documents Act ("PIPEDA"), the Personal Information Protection Act (Alberta) ("Alberta PIPA"), Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25 (where it applies), and, for Customers in the United States, applicable US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
- "Client Data" has the meaning given above. Client Data is a subset of "Customer Data" as defined in the Terms.
- "Controller", "Processor", "processing", and "personal information" are to be read consistently with Applicable Privacy Law.
- "Sub-processor" means a third party engaged by PeasyBooking to process Client Data in connection with the Service.
- "Subprocessor List" means the PeasyBooking Subprocessor List, and "Data Retention Schedule" means the PeasyBooking Data Retention Schedule — each a separate document published and maintained by PeasyBooking and incorporated into this DPA by reference.
2. Roles and instructions
2.1 As between the parties, the Customer is the Controller of Client Data and is responsible for the lawful basis, notices, and consents required for its collection, use, and disclosure. PeasyBooking is the Processor of Client Data and acts on the Customer's behalf.
2.2 PeasyBooking will process Client Data only:
(a) to provide, maintain, secure, and support the Service;
(b) in accordance with the Customer's documented instructions, including the instructions expressed through the Customer's configuration and use of the Service and in this DPA and the Terms; and
(c) as required by applicable law, in which case PeasyBooking will, unless legally prohibited, inform the Customer of the legal requirement before processing.
2.3 PeasyBooking will not sell Client Data and will not use Client Data for advertising, profiling, building or training artificial-intelligence or machine-learning models, independent analytics, or product development, except in de-identified or aggregated form that cannot reasonably be re-identified.
2.4 If PeasyBooking believes an instruction infringes Applicable Privacy Law, it will promptly inform the Customer and may suspend the affected processing until the instruction is confirmed, modified, or withdrawn.
2.5 US Customers — CCPA/CPRA service provider. For Customers in the United States, PeasyBooking acts as a "service provider" (and, where the term is used, a "processor") with respect to Client Data under the CCPA/CPRA and comparable state laws. PeasyBooking processes Client Data only to provide the Service and for the business purposes described in this DPA; it does not sell or share Client Data, does not retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than performing the Service (except as the CCPA/CPRA permits), and does not combine it with personal information received from other sources except as the CCPA/CPRA permits. PeasyBooking will notify the Customer if it determines it can no longer meet these obligations, and the Customer may take the steps the CCPA/CPRA contemplates to stop and remediate unauthorized use. The Customer may take reasonable and appropriate steps to ensure that PeasyBooking uses Client Data consistently with the Customer's obligations under the CCPA/CPRA, including through the audit rights in Section 11.
2.6 Other US state privacy laws. For Customers subject to other US state privacy laws (including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and the Utah Consumer Privacy Act), this DPA is the contract those laws require between a controller and a processor: the processing instructions, subject matter, duration, nature and purpose of processing, and the types and categories of data are set out in this DPA and Annex A; PeasyBooking ensures that each person processing Client Data is subject to a duty of confidentiality (Section 4); at the Customer's direction, deletes or returns Client Data at the end of the provision of the Service (Section 10); makes available the information necessary to demonstrate compliance and allows and cooperates with reasonable assessments (Section 11); and engages Sub-processors only under written contracts meeting the requirements of this DPA (Section 6).
3. Customer obligations
3.1 The Customer represents and warrants that it has provided all required notices to, and obtained all required consents from, the individuals whose Client Data it processes through the Service, and that its instructions and use of the Service comply with Applicable Privacy Law.
3.2 The Customer is responsible for the accuracy, quality, and legality of Client Data and the means by which it acquired it, and for determining whether the Service is appropriate for the categories of data it chooses to store.
4. Confidentiality
PeasyBooking ensures that personnel authorized to process Client Data are bound by written confidentiality obligations (or are under an appropriate statutory duty of confidentiality) and access Client Data only as needed to perform their duties. These obligations survive termination of employment or engagement.
5. Security
5.1 PeasyBooking implements and maintains the technical and organizational measures described in Annex B, designed to protect Client Data against unauthorized or unlawful access, processing, disclosure, alteration, and accidental loss, destruction, or damage.
5.2 PeasyBooking may update its security measures from time to time, provided that it does not materially reduce the overall level of protection for Client Data during the term.
5.3 PeasyBooking makes no representation of certification under any specific external standard. It does not claim HIPAA compliance or SOC 2 certification, and PeasyBooking does not offer HIPAA-covered services.
6. Sub-processors
6.1 The Customer authorizes PeasyBooking to engage the Sub-processors identified in the Subprocessor List to process Client Data. A current snapshot is provided in Annex C for convenience; the Subprocessor List is the authoritative, maintained source and prevails over Annex C if they differ.
6.2 For each Sub-processor that processes Client Data, PeasyBooking enters into written data-processing terms with the Sub-processor (such as the Sub-processor's data-processing agreement or standard contractual clauses) that require protections comparable to those in this DPA to the extent applicable to the Sub-processor's role. This reflects PeasyBooking's accountability for Client Data transferred to a Sub-processor, consistent with PIPEDA's accountability principle. PeasyBooking remains responsible to the Customer for each Sub-processor's processing of Client Data. PeasyBooking will not enable a Sub-processor that processes Client Data (for example, an SMS provider) until appropriate data-processing terms with that Sub-processor are in place and the Subprocessor List and Annex C are updated accordingly.
6.3 PeasyBooking will give at least 30 days' notice of any intended addition or replacement of a Sub-processor that processes Client Data (for example, by updating the Subprocessor List and providing a notification mechanism), and a reasonable opportunity to object. If the Customer reasonably objects on data-protection grounds, the parties will work together in good faith to address the concern; if no resolution is reached, the Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees attributable to the terminated portion for the period after the termination takes effect.
7. Assisting the Customer
Taking into account the nature of the processing and the information available to it, PeasyBooking will provide reasonable assistance to help the Customer:
(a) respond to requests from individuals exercising their rights under Applicable Privacy Law (such as access and correction), including the Alberta PIPA response timeframe of approximately 45 days where applicable;
(b) meet its security, breach-notification, record-keeping, and privacy-assessment obligations; and
(c) make Client Data available for export in a commonly used, machine-readable format on request.
The Customer remains responsible for substantively responding to individuals and regulators in respect of Client Data.
8. Personal data breach notification
8.1 Notice to the Customer. A "Security Incident" means a confirmed breach of security leading to unauthorized access to, or unauthorized acquisition, loss, use, or disclosure of, Client Data. PeasyBooking will notify the Customer of a Security Incident that affects or may affect the Customer's Client Data without undue delay, and in any event within 24 hours of confirming the Security Incident. This 24-hour notice obligation is the controlling breach-notification commitment for Client Data. Routine blocked or unsuccessful attempts, and other security events that do not result in unauthorized access to Client Data, are not Security Incidents and are handled through PeasyBooking's internal breach-record process under Section 8.6 rather than individual 24-hour notices. Where the Privacy Policy or other documents describe PeasyBooking notifying individuals or a privacy commissioner directly, that describes PeasyBooking's role only for information of which PeasyBooking is itself the controller (such as account-holder and marketplace-guest information), not for Client Data.
8.2 Allocation of decision-making. For Client Data, the Customer (as Controller) is responsible for determining whether and how to notify affected individuals, the relevant privacy commissioner(s), and any professional or regulatory bodies. PeasyBooking will not notify the Customer's clients or regulators about a Security Incident affecting Client Data without the Customer's prior written direction, except where independently required by law.
8.3 Contents of notice. PeasyBooking's notice will include, to the extent then known and as information becomes available:
(a) a description of the nature of the Security Incident, including the categories and approximate number of individuals and records affected;
(b) the date or period of the incident and the date of discovery and confirmation;
(c) the likely consequences and PeasyBooking's assessment of the risk of significant harm;
(d) the measures taken or proposed to contain and remediate the incident; and
(e) a point of contact at PeasyBooking for further information.
8.4 Ongoing updates. PeasyBooking will provide reasonable updates to the Customer as the investigation progresses and as new material facts are confirmed, so the Customer can make and update its own notification decisions.
8.5 Containment and cooperation. PeasyBooking will take reasonable steps to contain and mitigate the Security Incident, preserve relevant evidence and logs, investigate root cause, and cooperate with the Customer's reasonable investigation and response requirements.
8.6 PeasyBooking's own records. PeasyBooking will keep and maintain a record of all breaches of security safeguards affecting Client Data — including Security Incidents and security events that do not rise to the level of a Security Incident — consistent with PIPEDA's breach-record-keeping requirement, and will make summary information available to the Customer on reasonable request.
9. Location of processing
9.1 Core Client Data — including the application database and file storage — is hosted in Canada on Google Cloud Platform in region northamerica-northeast1 (Montréal). The automated database backups and point-in-time-recovery copies of that data are stored in the United States, in Google Cloud's us multi-region. Those copies exist for disaster recovery only and age out on the rolling schedule in the Data Retention Schedule.
9.2 Certain Sub-processors necessarily process limited Client Data outside Canada to deliver their functions — for example authentication, payment processing, and message delivery. PeasyBooking does not represent that all Client Data remains in Canada. The categories, locations, and purposes of such processing are described in the Subprocessor List and summarized in Annex C. Where a Sub-processor processes Client Data outside Canada, PeasyBooking remains accountable for that data and addresses cross-border processing through the contractual measures described in Section 6.2, consistent with PIPEDA's accountability principle.
9.3 Customers outside Canada. For Customers in the United States (and other Customers outside Canada), Client Data is processed and stored in Canada as described in Section 9.1 — and backed up in the United States, also as described in Section 9.1 — and the Customer authorizes this cross-border processing. The Customer's acknowledgment of Canadian hosting with United States backups is captured at signup and recorded with its date and version.
10. Return, retention, and deletion
10.1 Access on termination. On expiry or termination of the Customer's subscription, the Customer's access to the Service ends in accordance with the Terms. Loss of access does not by itself delete Client Data.
10.2 Standard deletion lifecycle. PeasyBooking will retain, return, or delete Client Data in accordance with the Customer's documented instructions and the PeasyBooking Data Retention Schedule. On account closure or termination, PeasyBooking's standard lifecycle applies: a 30-day grace period during which the account and its data can be recovered, followed by permanent deletion from active systems.
10.3 Earlier deletion on documented instruction. The Customer may instruct earlier permanent deletion of its account and Client Data. Before PeasyBooking acts on such an instruction, the Customer must confirm that its retention, preservation, and legal-hold obligations have been satisfied. The Customer acknowledges it is responsible for determining and meeting any statutory, professional, or contractual retention duties that apply to its business.
10.4 Backups and residual copies. After deletion from active systems, residual copies may persist for a limited period in encrypted, access-controlled backups before aging out on a rolling schedule (currently up to approximately 30 daily backups plus a point-in-time-recovery window of approximately 7 days). PeasyBooking does not restore deleted data from backups except to recover from an incident. Certain records may also persist outside PeasyBooking's active systems where required for legitimate or legal reasons — for example, transaction and tax records held by Stripe; message-delivery logs held by email and SMS providers; and PeasyBooking's own invoices, security logs, and breach records — as described in the Privacy Policy and the Subprocessor List.
10.5 Export before closure. Before deletion, the Customer may export its Client Data, and PeasyBooking will make Client Data available for export in a commonly used format on request.
10.6 Legal holds. PeasyBooking may retain Client Data where required by a legal hold, a payment dispute or chargeback, a complaint or regulatory investigation, or other legal obligation, for so long as reasonably necessary, after which the deletion lifecycle in this Section resumes.
11. Audit
On reasonable written request, no more than once per twelve months (or more frequently if required by a regulator or following a Security Incident), and subject to confidentiality and to not compromising the security of other customers, PeasyBooking will make available the information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, architecture and hosting descriptions, access-control and audit-logging summaries, and the Subprocessor List.
12. Liability and term
12.1 Each party's liability under this DPA is subject to, and counts toward, the limitations and exclusions of liability in the Terms.
12.2 This DPA takes effect on the effective date of the Terms and remains in effect for as long as PeasyBooking processes Client Data, after which the surviving provisions (including confidentiality, deletion, audit-record, and breach-record obligations) continue to apply.
12.3 Language. This DPA is drafted in English. The English version is the only authoritative version and governs for all purposes; any translation that may be provided is for convenience only.
Annex A — Details of processing
- Subject matter: PeasyBooking's provision of the scheduling, CRM, payments, messaging, and related services.
- Duration: the term of the Customer's subscription, plus the retention periods described in Section 10 and the Data Retention Schedule.
- Nature and purpose: storing and processing Client Data to enable online booking and scheduling, client and CRM records, email and (optional) SMS reminders and confirmations, secure messaging, payments, memberships, marketing campaigns, reviews, financial reporting, and data import.
- Categories of data subjects: the Customer's clients, and the Customer's staff to the extent their information is processed through the Service.
- Categories of Client Data: contact and identity details; appointment, service, and purchase history; communications and messaging content; payment-related metadata (card data is processed by Stripe, not stored by PeasyBooking); and any notes, form responses, or records the Customer chooses to store.
Annex B — Security measures
These measures describe PeasyBooking's current safeguards. Items marked "where enabled/available" describe capabilities that apply when the relevant feature is enabled and available for the Customer's account.
- Encryption of Client Data in transit (TLS) and at rest.
- Role-based access controls and least-privilege staff access.
- Network isolation, including private connectivity to the database.
- Audit logging of access and administrative actions.
- Automated backups with point-in-time recovery; backup restoration is tested periodically, with the most recent restoration test performed on 26 July 2026.
- Secure software-development and change-management practices.
- Incident response, evidence/log preservation, and breach record-keeping processes.
These measures are not, and should not be read as, a claim of certification under HIPAA, SOC 2, or any other external standard.
Annex C — Sub-processors (snapshot)
This snapshot is provided for convenience only. The authoritative list, including data categories, locations, and purposes, is the PeasyBooking Subprocessor List and Data Retention Schedule, which prevails if it differs from this Annex. A Sub-processor that processes Client Data is enabled only once appropriate data-processing terms with that Sub-processor are in place (see Section 6.2).
| Sub-processor | Role / purpose | Region (Client Data) |
|---|---|---|
| Google Cloud Platform | Application hosting, PostgreSQL database, file storage | Canada (northamerica-northeast1, Montréal); database backups and point-in-time-recovery copies in the United States (us multi-region) |
| Google Identity Platform / Firebase Authentication | Account sign-in and authentication | United States / global |
| Stripe, Inc. | Subscription billing; and, where a Customer enables the optional online-payments feature, processing of client→business payments via direct charges on the Customer's own Stripe connected account (Customer is merchant of record) | United States / global |
| Resend | Transactional email delivery | United States |
| Twilio Inc. | Text-message (SMS) reminders, confirmations, and two-way replies for the optional SMS add-on (when enabled by the Customer) | United States / global |
Contact
DPA inquiries: PeasyBooking Technologies Inc., Attn: Privacy Officer, 150 Evergreen Mount SW, Calgary, Alberta T2Y 0L8, or info@peasybooking.com.