Appointics
FeaturesIntegrationsAdd-onsPricingLive demo
Log inGet started
FeaturesIntegrationsAdd-onsPricingLive demoLog inGet started
Legal

Data Processing Agreement

How we process personal data on behalf of businesses, and who our subprocessors are.

Last updated · 12 July 2026

This Data Processing Agreement ("DPA") describes how Appointics ("we", "us" or "our") processes personal data on behalf of businesses that use the Service to take bookings. It supplements our Terms & Conditions and Privacy Policy, and applies where data-protection laws such as the GDPR apply.

Roles. For the personal data a business collects from its own customers through its booking page, the business is the data controller and Appointics is the data processor. For the business's own account data, Appointics is the controller — see our Privacy Policy.

1. Scope and subject matter

We process personal data only to provide the Service — hosting the booking page, managing appointments, sending confirmations and reminders, processing payments through the business's own provider, and syncing calendars — for as long as the business's account is active.

2. Categories of data and data subjects

  • Data subjects: the business's customers and staff.
  • Personal data: names, email addresses, phone numbers, appointment details and any notes the business or customer provides; limited payment metadata (never full card numbers).

3. Our obligations as processor

  • Process personal data only on the documented instructions of the business, unless required by law.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Apply appropriate technical and organisational security measures (encryption in transit, access controls, hashed passwords).
  • Assist the business, so far as reasonably possible, in responding to data-subject requests and in meeting its security, breach-notification and impact-assessment obligations.
  • Notify the business without undue delay after becoming aware of a personal-data breach affecting its data.
  • Delete or return the personal data at the end of the service, except where retention is required by law. Businesses can also delete their own records from their dashboard.

4. Subprocessors

We use trusted subprocessors to run the Service. Each is bound to process personal data only on our instructions and to keep it secure. Current categories include:

  • Google — authentication and calendar sync.
  • Microsoft — Outlook calendar sync (where enabled).
  • Stripe — payment processing.
  • Email and messaging providers — delivering confirmations, reminders and notifications.
  • Hosting and infrastructure providers — running the platform.

We will give businesses a way to learn of changes to our subprocessors and to object on reasonable data-protection grounds.

5. International transfers

Where personal data is transferred across borders, we use appropriate safeguards (such as standard contractual clauses) to keep it protected in line with applicable law.

6. Audits

On reasonable prior request and subject to confidentiality, we will make available the information reasonably necessary to demonstrate our compliance with this DPA.

7. Contact

For data-processing questions or to request our current subprocessor list, email privacy@appointics.com.

Appointics

The free booking platform for service businesses. Launch your branded scheduling page and grow.

Product
FeaturesIntegrationsAdd-onsPricing
Live demos
BarbershopCleaningReal estateConsulting
Company
AboutContactLog inGet started
© 2026 Appointics. All rights reserved.PrivacyTermsCookiesAcceptable useRefundsData processing