Langsung ke konten utama
14 hari gratis · Terbatas untuk 100 studioMulai Uji Coba Gratis
Beranda/Data Processing Agreement

Data Processing Agreement

How Pepperoni Booking processes personal data on behalf of studios (GDPR Article 28)

About This Agreement

This Data Processing Agreement ("DPA") is entered into between Pepperoni Booking (Processor) and each studio that uses the platform (Controller) in accordance with GDPR Article 28. By creating an account you accept this DPA. This document is in English only — AI-translated legal documents create liability.

Version 1.0 — Effective April 12, 2026
Covers EU/EEA, UK GDPR, and equivalent jurisdictions

Parties

Data Controller

The studio that subscribes to Pepperoni Booking. The Controller determines the purposes and means of processing its clients' personal data.

Data Processor

Pepperoni Booking — processes personal data solely on the Controller's instructions via the platform services. Contact: privacy@pepperonibooking.com

1. Scope and Purpose

This DPA applies to the processing of personal data by Pepperoni Booking on behalf of the Studio in connection with the platform services for the duration of the subscription agreement.

Data processed: Studio client names, email addresses, phone numbers, booking history, subscription records, health intake form data, and emergency contacts — solely to operate the booking and studio management platform.

2. Processing Instructions

Pepperoni Booking processes personal data only on documented instructions from the Controller (the Studio). The platform provides the tools; the Studio controls who is enrolled, what data is collected, and who has access. If Pepperoni Booking is required by law to process beyond these instructions, it will notify the Studio unless prohibited by law.

3. Confidentiality

All personnel with access to personal data are bound by confidentiality obligations (contractual or statutory). Access is restricted to those who need it to deliver the services. Confidentiality obligations survive termination of this DPA.

4. Security Measures (GDPR Art. 32)

  • • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • • Role-based access control — studio data is tenant-isolated at the database schema level
  • • JWT authentication with short-lived tokens and refresh rotation
  • • Automated security scanning and dependency updates (Renovate)
  • • Error monitoring with PII scrubbing before capture (Sentry)
  • • Infrastructure on Google Cloud Platform (ISO 27001 certified)

5. Sub-processors

The Studio grants general authorisation for the sub-processors listed at pepperonibooking.com/subprocessors. Pepperoni Booking will notify the Studio at least 30 days before engaging a new sub-processor. The Studio may object within that period on legitimate data protection grounds.

All sub-processors are bound by data protection terms at least as protective as this DPA. Pepperoni Booking remains fully liable for sub-processor compliance.

6. Data Subject Rights Assistance

Pepperoni Booking provides tools to assist the Studio in responding to data subject requests (Articles 15–22 GDPR):

  • Export (Art. 15 & 20): Admin dashboard → Settings → Privacy → Export student data
  • Erasure (Art. 17): 30-day grace period with automated execution. Admin or client-initiated.

7. International Data Transfers

Where personal data is transferred outside the EEA or UK, Pepperoni Booking relies on the European Commission's 2021 Standard Contractual Clauses (SCCs) or equivalent UK International Data Transfer Agreements (IDTAs) with each sub-processor. All sub-processors are listed with their transfer safeguard at pepperonibooking.com/subprocessors.

8. Data Return and Deletion at Termination

Within 30 days of termination or account deletion, Pepperoni Booking will, at the Controller's election, either return all personal data in machine-readable JSON format or permanently delete it. Anonymised booking records (no PII) may be retained for business analytics and legal/tax purposes.

9. Audit and Inspection Rights

The Controller may request an audit of Pepperoni Booking's data processing activities up to once per year with 30 days' written notice. Pepperoni Booking will provide documentation, and may satisfy audit obligations by sharing a current SOC 2 Type 2 report or equivalent third-party certification. The Controller bears the cost of any on-site audit.

10. Data Breach Notification

In the event of a personal data breach, Pepperoni Booking will notify the Controller without undue delay and within 48 hours of becoming aware, providing sufficient information to enable the Controller to meet its 72-hour supervisory authority notification obligation under GDPR Article 33.

DPA Updates

Pepperoni Booking uses semantic versioning for this DPA (e.g. v1.0, v1.1, v2.0). Minor updates (clarifications, security improvements) take effect immediately for new signups; studios with existing agreements are notified but not required to re-accept. Major updates (changes to processing scope, purposes, or data transfers) require re-acceptance with a 30-day transition window.

To receive notifications about DPA updates, contact privacy@pepperonibooking.com

Questions about this DPA or our data processing practices?

Contact Us