Data Processing Agreement
StartBook — operated by XaniaCode SRL Version 1.0 · Last updated 31 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between XaniaCode SRL and the business using StartBook. It satisfies Article 28(3) of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
It applies automatically from the moment you start using the Service. You do not need to sign a separate document. If your own compliance file requires a signed copy, write to info@startbook.be and we will provide one.
1. The parties and their roles
| Controller | The business using StartBook ("you") |
| Processor | XaniaCode SRL, TO BE COMPLETED, TO BE COMPLETED TO BE COMPLETED, Belgium — company number TO BE COMPLETED |
You decide why and how the personal data of your clients is processed. We process it only on your behalf and on your instructions.
Where we process data for our own purposes — running your account, taking payment, keeping the platform secure — we act as controller, and our Privacy Policy applies instead of this DPA.
2. Subject matter, duration, nature and purpose
Subject matter. Providing an online appointment booking platform.
Duration. For as long as you have an account, plus the retention period in clause 11.
Nature of the processing. Collection, recording, organisation, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction, by automated means.
Purpose. Enabling your clients to book appointments with you; letting you manage those appointments; and, where you switch it on, sending confirmations and reminders by email and text message.
3. Categories of data subjects and personal data
Data subjects
- Your clients, who book appointments with you.
- Your staff and other people you add as bookable resources.
- The users you give access to your account.
Categories of personal data
| Category | Examples |
|---|---|
| Identification | Name of the client |
| Contact details | Email address, telephone number |
| Appointment data | Service booked, date and time, location, assigned staff member, reference, price, status |
| Free text | Notes written by the client or by you, and answers to any custom question you configure |
| Staff data | Name, photograph, working hours, absences |
| Account users | Name, email address, hashed password, last sign-in |
| Technical | IP address and timestamps in security logs |
Special categories. The Service is not designed for special categories of personal data within the meaning of Article 9 GDPR, including health data. If your activity means that the service name or a client's note reveals such data — for example in a clinic or therapy practice — you remain responsible for assessing that risk, informing your clients, and having a valid basis under Article 9. You must not enter medical records, diagnoses, treatment details or similar information into free-text fields.
Children. If you accept bookings for minors, you are responsible for the legal basis, including parental consent where the law requires it.
4. Our obligations as processor
We undertake to:
(a) Process only on documented instructions. We process the personal data only on your documented instructions, including on transfers to a third country, unless required otherwise by EU or Member State law. Your instructions are given by the settings you configure in the Service and by these documents. If we are legally required to process beyond your instructions, we will inform you before doing so unless the law forbids it.
(b) Tell you if an instruction seems unlawful. If in our opinion an instruction infringes the GDPR or other data protection law, we will inform you without delay. We may suspend the instruction until it is resolved.
(c) Ensure confidentiality. Everyone we authorise to process the data is bound by confidentiality obligations and has been instructed on how to handle personal data.
(d) Take security measures. We implement appropriate technical and organisational measures under Article 32 GDPR, described in Annex 2.
(e) Respect the rules on sub-processors set out in clause 5.
(f) Assist you with data subject requests. Taking into account the nature of the processing, we assist you with appropriate measures to fulfil your obligation to respond to requests under Chapter III GDPR. In practice, most requests can be answered by you directly from your dashboard, where you can view, correct, export and delete client records. If a data subject contacts us directly about data belonging to you, we will not answer on your behalf; we will refer them to you and inform you.
(g) Assist you with your wider obligations. We assist you, taking into account the nature of the processing and the information available to us, with your obligations under Articles 32 to 36 GDPR: security, breach notification, data protection impact assessments and prior consultation.
(h) Delete or return the data. At the end of the Service, we delete or return the personal data as set out in clause 11.
(i) Make information available. We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in clause 10.
5. Sub-processors
General authorisation. You give us a general authorisation to engage sub-processors, subject to the conditions below.
Current sub-processors:
| Provider | What they do | Where |
|---|---|---|
| Xania Hosting | Server hosting and storage of all platform data | European Union |
| Mollie B.V. | Payment processing for subscriptions and credit purchases | Netherlands, European Union |
| CM.com | Delivery of text messages, when the SMS add-on is switched on | Netherlands, European Union |
Our obligations. Before engaging any sub-processor, we impose on it, by contract, data protection obligations that are no less protective than those in this DPA. We remain fully liable to you for the performance of the sub-processor's obligations.
Changes. We will inform you at least 30 days in advance of any intended addition or replacement of a sub-processor, by email to the address on your account. You may object on reasonable data protection grounds within that period. If you object and we cannot offer a reasonable alternative, you may terminate the affected part of the Service without penalty, with a pro-rata refund of any prepaid amount for the unused period.
6. Security
We implement and maintain the measures in Annex 2. We review them periodically and may update them, provided the level of protection is not reduced.
You are responsible for the security choices within your own control: who you give account access to, the strength of the passwords chosen, and how you handle data once you export it from the Service.
7. Personal data breaches
We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you.
The notification will describe, as far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where information is not yet available, we provide it in phases as it becomes known.
We will assist you in meeting your own obligations to notify the supervisory authority under Article 33 and, where required, the data subjects under Article 34. The decision to notify, and the notification itself, remain your responsibility as controller.
8. Data protection impact assessments
If your processing requires a data protection impact assessment or prior consultation with a supervisory authority under Articles 35 and 36 GDPR, we will provide the information about the Service that is reasonably necessary for you to carry it out.
9. International transfers
We store and process the personal data within the European Union. We will not transfer it outside the European Economic Area without your prior instruction or authorisation, and never without a valid transfer mechanism under Chapter V GDPR.
If a sub-processor were to introduce such a transfer, we would inform you in advance under clause 5 so that you can object.
10. Audits and information
On your written request, and no more than once per twelve months unless a supervisory authority requires otherwise or a breach has occurred, we will:
- provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of our technical and organisational measures and any relevant certifications or reports we hold;
- answer a reasonable security questionnaire;
- allow an audit or inspection conducted by you or an independent auditor mandated by you, subject to at least 30 days' written notice, during business hours, in a manner that does not disrupt the Service or compromise the confidentiality of other customers' data, and subject to the auditor signing a confidentiality agreement.
You bear the cost of an audit you initiate, unless it reveals a material breach of this DPA by us, in which case we bear the reasonable cost.
11. Deletion and return of the data
When the Service ends, or earlier at your written request:
- you may export your data at any time from your dashboard or by asking us at info@startbook.be;
- we delete the personal data from our live systems within 90 days of account closure, unless EU or Member State law requires us to keep it;
- copies in backups are overwritten within a further 30 days;
- we keep invoices and accounting records for 7 years, as Belgian law requires. Those records contain your business details, not your clients' appointment data.
On request, we confirm the deletion in writing.
12. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR or other mandatory law provides otherwise. Nothing in this DPA limits a data subject's rights or the powers of a supervisory authority. Article 82 GDPR applies to claims by data subjects.
13. Term and precedence
This DPA takes effect when you start using the Service and continues while we process personal data on your behalf.
In case of conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails. In case of conflict with any other agreement between us, this DPA prevails unless the other agreement expressly says otherwise and is signed by both parties.
Annex 1 — Details of the processing
Categories of data subjects: clients booking appointments; staff and resources published by the controller; users of the controller's account.
Categories of personal data: identification and contact details; appointment details; free-text notes and answers to custom questions; staff names, photographs and schedules; account credentials in hashed form; technical and security log data.
Special categories: not intended; see clause 3.
Processing operations: collection through the public booking page and the dashboard; storage in a relational database on EU servers; retrieval and display to authorised users; transmission of confirmations and reminders by email and, where enabled, by text message; export at the controller's request; deletion.
Duration: for the life of the account, plus the retention window in clause 11.
Frequency: continuous, as bookings are made and managed.
Annex 2 — Technical and organisational measures
Encryption and transport
- All connections to the platform use TLS. Plain HTTP is redirected.
- Outgoing email is authenticated with SPF, DKIM and DMARC.
Access control
- Passwords are stored only as salted one-way hashes.
- Sessions are protected against cross-site request forgery.
- Access to production systems is limited to named individuals who need it, with individual credentials.
- Administrative interfaces are separated from the public application and require authentication.
Separation of customers
- Every record carries the identifier of the business it belongs to, and queries are scoped to it, so one business cannot read another's data.
- Each business is served on its own subdomain and its session is bound to it.
Payment data
- Card details are never transmitted to or stored on our servers. Payments are handled entirely by a PCI-DSS compliant payment provider.
Resilience and recovery
- Regular backups, retained for 30 days.
- Restoration procedures are documented, and backups are stored separately from the live system.
Logging and monitoring
- Security-relevant events, including failed sign-ins and administrative actions, are logged and retained for 90 days.
- Application errors are recorded for diagnosis; error output is never shown to visitors in production.
Software maintenance
- The platform and its dependencies are kept up to date, with security fixes applied promptly.
- Changes are tested before being applied to the live system.
Organisational
- Staff with access to personal data are bound by confidentiality.
- Access is removed when it is no longer needed.
- Sub-processors are assessed before engagement and bound by written data protection terms.
Data minimisation
- We collect only the fields needed to make and manage an appointment.
- Free-text fields are optional, and the controller decides what to ask for.
Annex 3 — Sub-processors
| Provider | What they do | Where |
|---|---|---|
| Xania Hosting | Server hosting and storage of all platform data | European Union |
| Mollie B.V. | Payment processing for subscriptions and credit purchases | Netherlands, European Union |
| CM.com | Delivery of text messages, when the SMS add-on is switched on | Netherlands, European Union |
The current list is always available on this page. Changes are announced in advance under clause 5.
Contact for anything in this DPA: privacy@startbook.be — XaniaCode SRL, TO BE COMPLETED, TO BE COMPLETED TO BE COMPLETED, Belgium.