Data Processing Agreement

Last updated 2 October 2026

This agreement forms part of the Terms of Service between ACCLER8 AUTOMATION LIMITED (“Acceler8”, the processor) and each business that uses acceler8appointments (the controller). It applies automatically, and sets out how we process personal data on your behalf, as GDPR Article 28 requires.

1. Subject matter, duration and purpose

We process personal data only to provide acceler8appointments to you: taking and managing bookings, keeping your client list, sending the appointment text messages your plan includes, and supporting you. Processing lasts for as long as you use the service, and ends as described in section 9. Annex 1 lists the data and the people it is about.

2. Your instructions

We process the data only on your documented instructions — these terms, and what you do in the service — unless EU or Cypriot law requires otherwise, in which case we tell you first unless that law forbids it. If we believe an instruction breaks data protection law, we tell you.

3. Confidentiality

Everyone at Acceler8 who can access the data is bound by confidentiality, and accesses it only when needed to run or support the service.

4. Security

We maintain the technical and organisational measures in Annex 2, appropriate to the risk (GDPR Art. 32), and review them as the service changes.

5. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 3. Each is bound by a written agreement with data protection obligations no less protective than these, and we remain responsible to you for them. We will email you at least 30 days before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel without penalty before the change takes effect.

6. International transfers

Where a sub-processor processes data outside the European Economic Area, the transfer is covered by an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses, as listed in Annex 3.

7. Helping you meet your obligations

  • Your clients' rights: the service lets you find a client and their appointments (Clients, Search), correct their details, and erase them. For a copy of a client's data in a portable format, ask us and we provide it. If a request reaches us, we pass it to you without delay and help you answer it.
  • Security, impact assessments and consultations with a supervisory authority (GDPR Art. 32 to 36): we give you the information we have.
  • Personal data breaches: we notify you without undue delay, and within [notification window, e.g. 48 hours] of becoming aware, with what we know and what we are doing, and we update you as we learn more.

8. Audits

We make available the information needed to show that we meet these obligations, and allow and contribute to audits by you or an auditor you appoint, on reasonable notice, at most once a year unless a breach or a supervisory authority requires otherwise.

9. End of processing

When your subscription ends, we delete your clients’ personal data and the rest of your business’s data within [deletion period after an account closes, e.g. 30 days], unless law requires us to keep it. Before then you can ask us for a copy. Backups are overwritten on their normal cycle ([backup retention period]).

Annex 1 — The data and the people it is about

  • Your clients: first and last name, phone number, and their appointments (service, staff member, date and time). For text messages, the message sent to them. If a message fails, the number, sender name and text are kept so we can investigate, until the case is closed.
  • Your team: names, email addresses, roles, working hours and days off.
  • No special categories of data (such as health data) are needed or requested. Do not enter them in names or notes.

Annex 2 — Security measures

  • Encryption in transit (HTTPS only, with HSTS) and at rest (database provider).
  • Strict separation of businesses: every request is checked against the signed-in business, and roles limit team members to what they may see.
  • Passwords stored as one-way bcrypt hashes; sign-in attempts rate-limited; sessions re-checked against the database on every request, so a removed team member is signed out at once.
  • Acceler8 staff use a separate console with two-factor authentication, an optional IP allowlist, and a record of every change they make.
  • Public booking and sign-in endpoints rate-limited against abuse; dependencies kept up to date and audited for known vulnerabilities.
  • Minimisation: text message scheduling receives only an appointment's internal identifier; sent messages keep no phone number or text.

Annex 3 — Sub-processors

Sub-processorPurposeData receivedLocationTransfer safeguard
Vercel Inc.Hosting the application and running its server functionsAll data the application handles, in transit while a request is servedUnited States and EU edge network; functions run in [Vercel function region]Standard Contractual Clauses and the EU–US Data Privacy Framework
Supabase Inc.DatabaseAll stored data: accounts, calendars, appointments, client names and phone numbersEuropean Union (AWS eu-west-1, Ireland)Hosted in the EU; Standard Contractual Clauses for support access
MicrosmsSending appointment confirmation and reminder text messagesThe client's phone number and the message text (business name, service, date and time)CyprusProcessed in the EU
Stripe Payments Europe, Ltd.Subscription billing for businessesBusiness billing contact, email, payment details (held by Stripe, never by us)Ireland, with transfers to Stripe, Inc. (United States)Standard Contractual Clauses and the EU–US Data Privacy Framework
ResendAccount emails: sign-in details for new team members, and our notification of a new enquiryThe recipient's name and email address, and the business nameUnited StatesStandard Contractual Clauses
Upstash, Inc. (QStash)Scheduling the time a reminder text is sentAn appointment's internal identifier only — no name, phone number or message[Upstash QStash region]No personal data is sent

Questions about this agreement: contact@acceler8.cy.