Data Processing Agreement
Last updated 30 Sep 2026
This agreement (Art. 28 GDPR) is between the business using RightSchedule ("Controller") and [Company legal name] ("Processor") and applies to personal data of the Controller's customers processed through the service. It forms part of the Terms of Service.
1. Subject matter, duration and nature
The Processor hosts and processes customer, booking and quote-request data on the Controller's behalf to provide online scheduling, for as long as the Controller has an account.
2. Data and data subjects
- Data subjects: the Controller's customers and prospects.
- Data: name, phone, email, booking details, free-text notes and quote-request descriptions.
- Special categories (Art. 9) must not be entered, as set out in the Terms.
3. Processor obligations
- Process data only on the Controller's documented instructions (the Terms and the Controller's use of the service), and tell the Controller if an instruction appears to breach the law.
- Ensure that authorized personnel are bound by confidentiality.
- Apply appropriate technical and organizational measures (Art. 32): encryption in transit, hashed credentials, HttpOnly session cookies, per-business data separation, access control, rate limiting and logging without personal data.
- Assist the Controller with data subject requests: customer records can be exported and erased in the application.
- Assist the Controller with security, breach notification, impact assessments and consultations, taking into account the nature of processing.
- Notify the Controller without undue delay, and within 48 hours where feasible, after becoming aware of a personal data breach.
- At the end of the service, delete the data (or return it via export) unless the law requires storage.
- Make available the information needed to demonstrate compliance and allow reasonable audits with prior notice.
4. Sub-processors
The Controller gives general authorization to use the sub-processors listed on the sub-processors page. The Processor will inform the Controller of intended changes so it may object, and will impose equivalent data protection obligations on each sub-processor.
5. International transfers
Transfers outside the EEA occur only with a valid mechanism (adequacy decision, EU-US Data Privacy Framework or Standard Contractual Clauses).
6. Retention
Unless the Controller deletes data earlier, bookings are anonymized 24 months after the appointment and quote requests are deleted 12 months after receipt. Deleted data is removed from backups within [backup retention period].
7. Controller obligations
The Controller is responsible for the lawfulness of the processing, for informing its customers and for not entering special-category data.
8. Liability and governing law
[Liability terms and governing law to be defined by counsel.]