Data Processing Agreement
Last updated 2 October 2026
This agreement forms part of the Terms of Service between ACCLER8 AUTOMATION LIMITED (“Acceler8”, the processor) and each business that uses acceler8appointments (the controller). It applies automatically, and sets out how we process personal data on your behalf, as GDPR Article 28 requires.
1. Subject matter, duration and purpose
We process personal data only to provide acceler8appointments to you: taking and managing bookings, keeping your client list, sending the appointment text messages your plan includes, and supporting you. Processing lasts for as long as you use the service, and ends as described in section 9. Annex 1 lists the data and the people it is about.
2. Your instructions
We process the data only on your documented instructions — these terms, and what you do in the service — unless EU or Cypriot law requires otherwise, in which case we tell you first unless that law forbids it. If we believe an instruction breaks data protection law, we tell you.
3. Confidentiality
Everyone at Acceler8 who can access the data is bound by confidentiality, and accesses it only when needed to run or support the service.
4. Security
We maintain the technical and organisational measures in Annex 2, appropriate to the risk (GDPR Art. 32), and review them as the service changes.
5. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex 3. Each is bound by a written agreement with data protection obligations no less protective than these, and we remain responsible to you for them. We will email you at least 30 days before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel without penalty before the change takes effect.
6. International transfers
Where a sub-processor processes data outside the European Economic Area, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses, as listed in Annex 3.
7. Helping you meet your obligations
- Your clients' rights: the service lets you find a client and their appointments (Clients, Search), correct their details, and erase them. For a copy of a client's data in a portable format, ask us and we provide it. If a request reaches us, we pass it to you without delay and help you answer it.
- Security, impact assessments and consultations with a supervisory authority (GDPR Art. 32 to 36): we give you the information we have.
- Personal data breaches: we notify you without undue delay, and within [notification window, e.g. 48 hours] of becoming aware, with what we know and what we are doing, and we update you as we learn more.
8. Audits
We make available the information needed to show that we meet these obligations, and allow and contribute to audits by you or an auditor you appoint, on reasonable notice, at most once a year unless a breach or a supervisory authority requires otherwise.
9. End of processing
When your subscription ends, we delete your clients’ personal data and the rest of your business’s data within [deletion period after an account closes, e.g. 30 days], unless law requires us to keep it. Before then you can ask us for a copy. Backups are overwritten on their normal cycle ([backup retention period]).
Annex 1 — The data and the people it is about
- Your clients: first and last name, phone number, and their appointments (service, staff member, date and time). For text messages, the message sent to them. If a message fails, the number, sender name and text are kept so we can investigate, until the case is closed.
- Your team: names, email addresses, roles, working hours and days off.
- No special categories of data (such as health data) are needed or requested. Do not enter them in names or notes.
Annex 2 — Security measures
- Encryption in transit (HTTPS only, with HSTS) and at rest (database provider).
- Strict separation of businesses: every request is checked against the signed-in business, and roles limit team members to what they may see.
- Passwords stored as one-way bcrypt hashes; sign-in attempts rate-limited; sessions re-checked against the database on every request, so a removed team member is signed out at once.
- Acceler8 staff use a separate console with two-factor authentication, an optional IP allowlist, and a record of every change they make.
- Public booking and sign-in endpoints rate-limited against abuse; dependencies kept up to date and audited for known vulnerabilities.
- Minimisation: text message scheduling receives only an appointment's internal identifier; sent messages keep no phone number or text.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Vercel Inc. | Hosting the application and running its server functions | All data the application handles, in transit while a request is served | United States and EU edge network; functions run in [Vercel function region] | Standard Contractual Clauses and the EU–US Data Privacy Framework |
| Supabase Inc. | Database | All stored data: accounts, calendars, appointments, client names and phone numbers | European Union (AWS eu-west-1, Ireland) | Hosted in the EU; Standard Contractual Clauses for support access |
| Microsms | Sending appointment confirmation and reminder text messages | The client's phone number and the message text (business name, service, date and time) | Cyprus | Processed in the EU |
| Stripe Payments Europe, Ltd. | Subscription billing for businesses | Business billing contact, email, payment details (held by Stripe, never by us) | Ireland, with transfers to Stripe, Inc. (United States) | Standard Contractual Clauses and the EU–US Data Privacy Framework |
| Resend | Account emails: sign-in details for new team members, and our notification of a new enquiry | The recipient's name and email address, and the business name | United States | Standard Contractual Clauses |
| Upstash, Inc. (QStash) | Scheduling the time a reminder text is sent | An appointment's internal identifier only — no name, phone number or message | [Upstash QStash region] | No personal data is sent |
Questions about this agreement: contact@acceler8.cy.