Skip to main content
SlotPaid

Data Processing Addendum

Last updated

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between SlotPaid (“SlotPaid,” the processor) and the provider using SlotPaid (“you,” the controller). It applies automatically — no signature needed — whenever SlotPaid processes personal data on your behalf. If you need a countersigned copy, email legal@slotpaid.com.

1. Definitions

“Data Protection Laws” means all laws that apply to the processing of Customer Personal Data under the Terms, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, Moroccan Law No. 09-08, and US state privacy laws such as the California Consumer Privacy Act. “Customer Personal Data” means personal data about your clients and staff that SlotPaid processes on your behalf. “Controller,” “processor,” “data subject,” “personal data breach,” and “processing” have the meanings given in the GDPR; under US law, SlotPaid is your “service provider” or “processor.”

2. Roles and instructions

  • You are the controller of Customer Personal Data and SlotPaid is your processor. SlotPaid is an independent controller only of provider account data, as described in the Privacy Policy.
  • SlotPaid processes Customer Personal Data only on your documented instructions. The Terms, this DPA, and your use and configuration of SlotPaid are your complete instructions. We'll tell you if we believe an instruction breaks Data Protection Laws.
  • SlotPaid won't sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than providing the service, or combine it with data from other sources except as Data Protection Laws permit for service providers.
  • You're responsible for the lawfulness of the data you give us and for having any notices and consents needed for us to process it.

3. Confidentiality

SlotPaid ensures that everyone it authorizes to process Customer Personal Data is bound by confidentiality obligations and accesses it only as needed to provide, support, and secure the service.

4. Security

SlotPaid maintains the technical and organizational measures in Annex 2, appropriate to the risk of the processing. We may update them as long as the overall level of protection doesn't decrease.

5. Subprocessors

  • You authorize SlotPaid to use the subprocessors listed on our Subprocessors page. SlotPaid binds each by a written contract with data protection obligations at least as protective as this DPA and remains responsible for their performance.
  • We'll give at least 30 days' notice before adding or replacing a subprocessor, by updating that page and emailing providers on paid plans. You may object on reasonable data protection grounds by emailing privacy@slotpaid.com within that period. If we can't reasonably resolve the objection, you may terminate the affected service and receive a refund of prepaid fees for the remaining term.

6. Data subject requests and assistance

You can view, correct, and delete most Customer Personal Data directly in the dashboard. If SlotPaid receives a request from one of your clients, we'll forward it to you without undue delay and won't respond ourselves except to redirect them to you. Taking into account the nature of the processing, SlotPaid will reasonably help you respond to requests, carry out data protection impact assessments, and consult supervisory authorities.

7. Personal data breaches

SlotPaid will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the data and data subjects affected, likely consequences, and the steps we're taking. We'll take reasonable steps to contain and remedy it and keep you updated.

8. Return and deletion

When your account closes, you have 30 days to request an export of Customer Personal Data. After that, SlotPaid deletes it within 30 days, and from backups within a further 30 days, unless the law requires us to keep it — in which case we keep it confidential and process it only for that purpose.

9. Audits

On written request, SlotPaid will provide the information reasonably necessary to demonstrate compliance with this DPA, such as answers to a security questionnaire. If that isn't sufficient, or a supervisory authority requires it, you may audit SlotPaid's compliance once a year on 30 days' notice, during business hours, at your cost, under confidentiality obligations.

10. International transfers

SlotPaid is operated from Morocco and stores Customer Personal Data with subprocessors in the United States. To the extent a transfer of data from the European Economic Area, the UK, or Switzerland to SlotPaid isn't covered by an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) are incorporated by reference — Module 2 (controller to processor), with Clause 7 (docking) included, Option 2 of Clause 9 (general authorization, with the notice period in section 5), the optional wording in Clause 11 omitted, Clauses 17 and 18 governed by the law and courts of Ireland, and Annexes I and II completed by Annex 1 and Annex 2 below. For UK transfers the UK International Data Transfer Addendum applies, and for Swiss transfers the Clauses apply with references to the GDPR read as references to the Swiss FADP.

11. Precedence and liability

If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data, and the Standard Contractual Clauses control over both. Each party's liability under this DPA is subject to the limitations in the Terms, to the extent Data Protection Laws allow.

Annex 1 — Details of processing

  • Data exporter: the provider, as controller. Data importer: SlotPaid, as processor. Contact: privacy@slotpaid.com.
  • Data subjects: the provider's clients and prospective clients (including people booking on a client's behalf), and the provider's staff.
  • Categories of data: names, email addresses, phone numbers, appointment details and history, answers to booking questions, notes and tags, referral information, pricing and package information, waitlist requests, payment status and references to cards saved with Stripe, message delivery records, and booking audit history.
  • Sensitive data: none intended. Providers may not use SlotPaid for special category data except as permitted by the Terms.
  • Nature and purpose: hosting, storing, and processing data to provide online booking, scheduling, calendar sync, payment collection, reminders and notifications, client records, and customer support.
  • Frequency: continuous, for the duration of the Terms.
  • Retention: for the duration of the Terms, then as described in section 8.
  • Subprocessors: as listed on the Subprocessors page, for the purposes stated there.
  • Competent supervisory authority: the authority of the EU member state where the provider is established, or where its EU representative is located.

Annex 2 — Security measures

  • Encryption: TLS for all data in transit; storage encrypted at rest by our database provider; calendar access tokens additionally encrypted at the application level.
  • Tenant isolation: row-level security policies in the database restrict each provider's data to that provider's authorized users.
  • Access control: least-privilege access to production systems, limited to personnel who need it, with strong authentication.
  • Payment data: card data is collected and stored only by Stripe (PCI DSS Level 1); SlotPaid never receives full card numbers.
  • Secrets management: credentials and API keys stored in the hosting provider's encrypted environment configuration, never in source code.
  • Integrity and verification: signature verification on payment webhooks and authenticated scheduled jobs; CSRF protection on calendar connections.
  • Auditability: an audit log of booking changes and a log of messages sent.
  • Availability and resilience: managed infrastructure with automated backups.
  • Vendor management: subprocessors are reviewed and bound by data protection terms.
  • Incident response: a process to investigate, contain, and notify customers of breaches as described in section 7.