Skip to main content

Data Processing Agreement

How we process personal data on behalf of our business customers, under Article 28 GDPR

Last updated: 2026-09-25

§

Parties and scope

This Data Processing Agreement ("DPA") forms part of the yAppointment Terms of Service (the "Terms"). It is concluded between the business customer that uses yAppointment (the "Controller") and LohiSoft s. r. o. (the "Processor", "we"): • Komenskeho 317/135, 943 01 Štúrovo, Slovak Republic; • company registration No. (IČO) 53253914; • tax ID SK2121316725; • e-mail: info@yappointment.com. By accepting the Terms, the Controller also accepts this DPA. This DPA applies whenever the Processor processes personal data on behalf of the Controller in providing the yAppointment platform (the "Service"). The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR").

1

Roles

1.1 For the personal data that the Controller or its end customers enter into the Service ("Customer Personal Data"), the Controller is the controller and the Processor is its processor. Examples are customer records, bookings, invoices, loyalty data and reviews. 1.2 For the data the Processor needs to run its own business, the Processor acts as an independent controller under its Privacy Policy (https://yappointment.com/privacy). Examples are the Controller's account and billing data, sales-site analytics and fraud prevention. This DPA does not cover that processing. 1.3 The Controller is responsible for the lawfulness of the processing it instructs. This includes having a legal basis, informing its end customers, and obtaining any consent it needs, for example for marketing SMS.

2

Subject matter, duration, nature and purpose

2.1 Subject matter: hosting and processing Customer Personal Data to provide the Service. 2.2 Duration: the term of the Terms, and afterwards until the data is deleted under Section 11. 2.3 Nature of the processing: • collection through booking pages, the customer portal, the widget and the API; • storage, organisation, retrieval and display; • transmission by e-mail, SMS and push notification; • generation of invoices and reports; • optional AI-assisted features; • export and deletion. 2.4 Purpose: to provide the Service as described in the Terms and as configured by the Controller. This covers appointment scheduling, customer management, communications, payments, invoicing, loyalty, reviews and related business management functions. 2.5 Annex I lists the categories of data subjects and personal data.

3

Instructions

3.1 The Processor processes Customer Personal Data only on the Controller's documented instructions, including for transfers to third countries. The Terms, this DPA and the Controller's use and configuration of the Service constitute those instructions. 3.2 The Processor may also process Customer Personal Data where Union or Member State law requires it. In that case, it informs the Controller before processing, unless the law prohibits this. 3.3 The Processor informs the Controller without delay if, in its opinion, an instruction infringes the GDPR or other data protection law.

4

Confidentiality

The Processor ensures that the persons it authorises to process Customer Personal Data are bound by confidentiality obligations, contractual or statutory. Access is limited to persons who need it to provide, support or secure the Service.

5

Security

5.1 The Processor implements appropriate technical and organisational measures under Article 32 GDPR, as described in Annex II. The measures take into account: • the state of the art; • the costs of implementation; • the nature, scope, context and purposes of the processing. 5.2 The Processor may update these measures, provided the overall level of protection does not decrease.

6

Sub-processors

6.1 General authorisation. The Controller gives the Processor general written authorisation to engage sub-processors. The sub-processors in use at the date of this DPA are listed in Annex III and at https://yappointment.com/dpa#annexIII. 6.2 Notice and objection. 1. The Processor notifies the Controller at least 30 days before adding or replacing a sub-processor. It sends the notice by e-mail to the account owner and updates the public list. 2. Within that period, the Controller may object on reasonable data protection grounds by writing to info@yappointment.com. 3. The parties will discuss the objection in good faith. 4. If they cannot resolve it, the Controller may terminate the affected part of the Service before the change takes effect. The Processor refunds, pro rata, the fees prepaid for the period after termination. 6.3 Flow-down. The Processor imposes on each sub-processor, by written contract, data protection obligations that are materially the same as those in this DPA. The Processor remains liable to the Controller for its sub-processors' performance. 6.4 Services the Controller chooses. Some integrations are selected, connected and contracted directly by the Controller. These providers are not sub-processors of the Processor. They include: • invoicing or accounting software; • the Controller's own e-mail server; • the SMS Gateway app running on the Controller's own phone; • the Controller's own payment-provider account. By connecting one of them, the Controller instructs the Processor to send the relevant data to it.

7

Assistance with data subject rights

7.1 Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures, in responding to data subjects' requests under Chapter III GDPR. In the Service: • the Controller can view, correct and delete customer records; • the Controller can export its company data; • end customers with a portal account can export and delete their own data. 7.2 If the Processor receives a request directly from a data subject about Customer Personal Data, it forwards the request to the Controller without undue delay. It does not respond itself unless the Controller authorises it.

8

Other assistance

The Processor provides reasonable assistance with the Controller's obligations under Articles 32–36 GDPR: security, breach notification, data protection impact assessments and prior consultation. The assistance takes into account the nature of the processing and the information available to the Processor.

9

International transfers

9.1 The Service's servers are hosted in the European Union. 9.2 Some sub-processors are located outside the EEA, or may access data from there (see Annex III). For such transfers, the Processor relies on one of the following: • an adequacy decision of the European Commission, including the EU–US Data Privacy Framework for certified recipients; • the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module 3 (processor to processor); • another transfer mechanism under Chapter V GDPR. The Processor also applies supplementary measures where they are needed.

10

Personal data breaches

10.1 The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the account owner's e-mail address. 10.2 The notice includes, as far as the information is then available: • the nature of the breach; • the categories and approximate number of data subjects and records concerned; • the likely consequences; • the measures taken or proposed; • a contact point. Information that is not yet available is provided in phases, without further undue delay. 10.3 The Processor takes reasonable steps to contain and remedy the breach, and documents it. Notifying supervisory authorities and data subjects remains the Controller's responsibility. The Processor assists as described in Section 8.

11

Deletion and return

11.1 While the Terms are in force, the Controller can export its company data from within the Service at any time. 11.2 After the Terms end, the Controller has 30 days to export its data. The Processor notifies the account owner by e-mail that this period has started and when deletion will take place. 11.3 When the 30-day period ends, the Processor automatically deletes Customer Personal Data from its live systems: • files stored for the Controller are deleted; • data about the Controller's customers and staff is deleted; • where a record itself must be kept under Section 11.4, the personal data in it is anonymised instead. 11.4 Kept for legal retention: • invoices and other accounting records; • the cash journal; • the fiscal tamper-evidence records required by fiscal law, such as NF525. The Processor keeps these only for the statutory period and uses them for no other purpose. 11.5 Earlier deletion. The Controller may request deletion before the period ends, through the account's self-service deletion function or by writing to info@yappointment.com. Deletion then starts after a 72-hour cooling-off period, during which the request can be cancelled. 11.6 Backups. Backups follow the managed backup rotation of the database provider. Copies of deleted data in backups are not restored for any purpose and expire with that rotation.

12

Information and audits

12.1 The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR. On request, this includes a description of its security measures and its current sub-processor list. 12.2 If that information is not sufficient, the Controller may audit the Processor's compliance with this DPA. The audit is carried out by the Controller or by an independent auditor bound by confidentiality, under these conditions: • at most once in any 12 months; • at the Controller's cost; • with at least 30 days' written notice. 12.3 Audits are carried out primarily as document reviews, based on questionnaires and the information in Section 12.1. On-site audits take place only: • where a supervisory authority requires one; or • after a personal data breach affecting the Controller's data. They are held during normal business hours, without disrupting the Service and without compromising other customers' data or the Processor's security. 12.4 Sub-processors are audited through their own certifications and reports where available.

13

Liability

Each party's liability under or in connection with this DPA is subject to the "Limitation of Liability" section of the Terms. That section limits total liability to the amount paid in the 12 months before the claim. This does not limit either party's liability to data subjects under Article 82 GDPR, or any liability that cannot be limited by law.

14

Order of precedence, changes, governing law

14.1 If this DPA conflicts with the Terms, this DPA prevails regarding the processing of Customer Personal Data. Where the Standard Contractual Clauses apply, they prevail over both. 14.2 The Processor may update this DPA to reflect changes in law, in the Service or in sub-processors. It follows the notice rules of the Terms (30 days for material changes) and of Section 6.2. An update does not reduce the protection given to Customer Personal Data. 14.3 This DPA is governed by the laws of the Slovak Republic. The competent courts of the Slovak Republic have jurisdiction, as set out in the Terms.

I

Annex I — Data subjects and personal data

Categories of data subjects, as determined by the Controller's use of the Service: • the Controller's customers and clients, and prospective customers who book, register or enquire; • the Controller's staff members and users: employees, contractors and service providers shown on booking pages; • contact persons of the Controller's business customers and suppliers, where stored. Categories of personal data: • identity and contact data: name, e-mail address, phone number, postal or billing address, and tax ID where invoiced; • appointment data: bookings, services, times, locations, staff, notes, cancellations, waitlist entries, attendance; • customer account data: portal account, preferences, language, push-notification device tokens; • transaction data: orders, payments and payment status, passes and entitlements, invoices, credit notes. The payment provider handles card numbers, and the Service does not store them; • loyalty and marketing data: points, vouchers, consent flags; • reviews and feedback; • communication data: e-mail, SMS and chat messages sent through the Service, and their delivery status; • technical data: IP address, device and browser information, logs. Special categories: the Service is not designed for special categories of data under Article 9 GDPR. The Controller is responsible for not entering such data. Where its business makes this unavoidable, for example with health-related appointments, the Controller is responsible for having a legal basis and appropriate safeguards. Frequency: continuous, for the duration of the Terms.

II

Annex II — Technical and organisational measures

1. Tenant isolation. Every company's data is scoped by its company identifier. The data access layer requires a company filter on every tenant query, and deletion uses the same company scope. 2. Encryption in transit and at rest. Public endpoints use HTTPS with TLS 1.2/1.3 and HSTS. TLS certificate verification is on by default for outbound connections. Data at rest in the database and file storage is protected by the encryption at rest provided by the infrastructure provider. 3. Encryption of secrets. The following are stored encrypted with AES-256-GCM, using keys held outside the database: • OAuth tokens of connected invoicing providers; • third-party integration credentials, with versioned keys; • webhook signing secrets; • stored e-mail credentials. Tokens are never written to logs. 4. Authentication. Passwords are hashed with Argon2id. Two-factor authentication is available. The internal administration panel requires two-factor authentication and a separate API key. 5. Access control. The Controller can give its own users role- and permission-based access. Every API request is authenticated, with JWT for users, API keys for integrations and device tokens for mobile apps. 6. Abuse protection. • Rate limiting fails closed: requests are denied if the limit store is unavailable. • User input used in search patterns is escaped. • Outbound URLs are validated against server-side request forgery (SSRF). 7. Data minimisation and deletion. Deletion runs automatically after the post-termination export period, and on request after a 72-hour cooling-off period. It removes or anonymises all company-scoped data and files, keeps only records required by law, and leaves an audit trail. Self-service export and deletion are available for companies and end customers. 8. Availability and resilience. Several API nodes run behind a health-checked load balancer, on a managed database service. Backups follow the managed backup rotation of the database provider. Copies of deleted data in backups are not restored for any purpose and expire with that rotation. 9. Organisational measures. • Production access is limited to one person, the Processor's managing director. • Deployments are made only from the version-controlled main branch. • Staff are bound by confidentiality.

III

Annex III — Sub-processors

The Processor uses the following sub-processors. Integrations that the Controller chooses and connects itself are not sub-processors (Section 6.4). They include invoicing or accounting software, the Controller's own e-mail server, the SMS Gateway app on its own device, and its own payment-provider account.

Annex III — Sub-processors
Sub-processorServiceLocation of processingTransfer safeguard
Rackforest (Hungary)Server hosting and infrastructure: all production application servers (API nodes, load balancer, WebSocket, Redis and e-mail watcher server)Hungary (EU)Not needed (EU)
MongoDB, Inc. (MongoDB Atlas)Database hostingAWS region eu-central-1, Frankfurt, Germany (EU)Not needed for storage (EU); SCCs / EU–US DPF where support access from the USA applies
Amazon Web Services EMEA SARL (Amazon S3)File storageAWS region eu-central-1, Frankfurt, Germany (EU)Not needed for storage (EU); SCCs / EU–US DPF where support access from the USA applies
ASSIXO Kft. (Budapest, Hungary)Hosting of the platform's own mail server (mail.yappointment.com) for transactional e-mailHungary (EU)Not needed (EU)
Twilio, Inc.SMS deliveryUSAEU–US DPF; SCCs
Google LLC (Firebase Cloud Messaging)Push notificationsUSAEU–US DPF; SCCs
Mistral AI SASAI features (default provider)France (EU)Not needed (EU)
OpenAI, L.L.C.AI features and help-center searchUSAEU–US DPF; SCCs
Google LLC (Gemini API)AI featuresUSAEU–US DPF; SCCs
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing for platform-side paymentsIreland (EU) / USAEU–US DPF; SCCs