How we process personal data on behalf of businesses, and who our subprocessors are.
Last updated · 12 July 2026
This Data Processing Agreement ("DPA") describes how Appointics ("we", "us" or "our") processes personal data on behalf of businesses that use the Service to take bookings. It supplements our Terms & Conditions and Privacy Policy, and applies where data-protection laws such as the GDPR apply.
Roles. For the personal data a business collects from its own customers through its booking page, the business is the data controller and Appointics is the data processor. For the business's own account data, Appointics is the controller — see our Privacy Policy.
We process personal data only to provide the Service — hosting the booking page, managing appointments, sending confirmations and reminders, processing payments through the business's own provider, and syncing calendars — for as long as the business's account is active.
We use trusted subprocessors to run the Service. Each is bound to process personal data only on our instructions and to keep it secure. Current categories include:
We will give businesses a way to learn of changes to our subprocessors and to object on reasonable data-protection grounds.
Where personal data is transferred across borders, we use appropriate safeguards (such as standard contractual clauses) to keep it protected in line with applicable law.
On reasonable prior request and subject to confidentiality, we will make available the information reasonably necessary to demonstrate our compliance with this DPA.
For data-processing questions or to request our current subprocessor list, email privacy@appointics.com.