Back to legal documents

Provider legal document

Data Processing Addendum

Beta provider-facing data processing addendum covering controller/processor roles, provider instructions, subprocessors, security, international transfers, assistance, deletion, and audit rights.

Version 2026.06.08-betaEffective date 2026-06-08

1. Roles, subject matter, and duration

Providers generally act as controllers for personal data they decide to collect and use for their own customers, staff, services, products, policies, messages, notes, reviews, and business operations.

FoundBookings acts as a processor where it processes provider-controlled customer data for booking, messaging, checkout, loyalty, coupon, gift-card, review, complaint, support, and platform services on the provider's documented instructions.

FoundBookings may act as an independent controller for its own account, security, billing, legal, analytics, support, complaint administration, fraud prevention, and platform operations. The processing lasts for the term of the provider's use of the platform and any legally required retention period.

2. Categories of data, data subjects, and processing purposes

Data may include customer account and contact data, booking data, services, staff assignments, messages, notes, reviews, payment identifiers and status, refund status, loyalty, gift-card and coupon data, support and complaint records, device/security logs, and provider-configured customer information.

Provider-controlled customer data may also include campaign form submissions, answers, question context, and reward status where providers configure optional marketing or reward forms.

Data subjects may include customers, provider owners, managers, staff, provider contacts, complainants, support users, and other people whose data is submitted through provider use of the platform.

Processing purposes include account operation, booking management, staff scheduling, customer communications, checkout support, payment status recording, refunds, reviews, loyalty, coupons, gift cards, support, complaints, security, fraud prevention, troubleshooting, compliance, and platform operation.

3. Processor obligations and provider instructions

FoundBookings will process provider-controlled personal data only on documented provider instructions, including instructions contained in the product configuration and applicable terms, unless required by law.

FoundBookings will inform the provider if an instruction appears to infringe applicable data protection law, where required and permitted by law.

Providers are responsible for ensuring their instructions are lawful and that they have an appropriate legal basis, notices, consents where needed, and customer/provider policies for their use of the platform.

4. Confidentiality, security, and subprocessors

FoundBookings will ensure authorised personnel who process provider-controlled personal data are subject to confidentiality obligations.

FoundBookings will apply appropriate technical and organisational security measures for a SaaS platform, including access controls, least-privilege administration, logging, secure credential handling, encryption where appropriate, backups, monitoring, and operational safeguards.

Subprocessors may include hosting providers, database providers, cache providers, email and notification providers, analytics providers where consented or lawfully enabled, payment processors including Stripe, storage providers, support tools, security tools, and professional advisers.

FoundBookings will use subprocessors only under appropriate contractual and security commitments and will provide notice of material subprocessor changes where practical.

5. International transfers, assistance, incidents, and DPIAs

Where personal data is transferred internationally, FoundBookings will use appropriate safeguards where required by applicable law, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.

FoundBookings will provide reasonable assistance for data-subject rights, security incident response, data protection impact assessments, regulator cooperation, and provider compliance obligations, taking into account the nature of processing and information available to FoundBookings.

6. Deletion, return, audit, liability, and precedence

At the end of service, FoundBookings will delete or return provider-controlled personal data where reasonably possible, subject to retention required for legal obligations, accounting, disputes, fraud prevention, security, backups, payment records, complaint records, or legitimate platform needs.

FoundBookings will make reasonable information available to demonstrate compliance with this DPA. Provider audit and information rights must be proportionate to a SaaS service and may be satisfied through policies, certifications, questionnaires, security summaries, or other reasonable information rather than unrestricted system access.

This beta DPA applies with the Business Terms for provider-controlled personal data processed through the beta platform.