Data Processing Agreement
Last updated: September 8, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Bokalio Legal Entity Name] ("Processor", "Bokalio") and the business Owner ("Controller") using Bokalio to manage bookings. It applies whenever Bokalio processes personal data of the Controller's customers on the Controller's behalf, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Roles
The Controller determines the purposes and means of processing its customers' personal data (deciding what to collect at booking, and why). Bokalio acts as Processor, processing that data only to provide the booking platform to the Controller, and on the Controller's documented instructions (which include these Terms and the Controller's own configuration of their Bokalio account).
2. Subject matter and duration
Subject matter: hosting and processing of booking data as part of operating the Bokalio platform. Duration: for as long as the Controller's Bokalio account is active, plus any retention period described in Section 8.
3. Nature and purpose of processing
Storing, displaying, and transmitting booking data so the Controller can manage their bookings; processing payment-related data via Stripe/PayPal; sending booking confirmations and related communications on the Controller's behalf.
4. Categories of data subjects
The Controller's customers who make a booking through the Controller's Bokalio-powered widget.
5. Categories of personal data
Name, email address, phone number, and booking details (date, time, party size, any notes the customer provides). Payment card details are handled directly by Stripe/PayPal and aren't processed or stored by Bokalio itself.
6. Bokalio's obligations as Processor
- Process personal data only on the Controller's documented instructions, unless required to do otherwise by law (in which case we'll inform the Controller where legally permitted).
- Ensure people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Article 32 GDPR) — including encryption in transit, access controls, and regular review of these measures.
- Assist the Controller in responding to data subject rights requests (access, deletion, correction, portability) relating to their customers' data.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's customers' data.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Controller or an appointed auditor on reasonable notice.
- Delete or return all personal data to the Controller at the end of the relationship, except where retention is required by law (see Section 8).
7. Sub-processors
The Controller authorizes Bokalio to use the following categories of sub-processor, each bound by data protection terms at least as protective as this DPA:
- Payment processing — Stripe, PayPal
- Hosting / infrastructure — [Hosting Provider]
- Email/SMS delivery — [Email/SMS Provider]
We'll notify Controllers of any new sub-processor category with a materially different function (e.g. via the dashboard or by email) so they can raise an objection before it's used.
8. International transfers
Where personal data is transferred outside the EEA/UK to a sub-processor, that transfer is covered by an appropriate safeguard — Standard Contractual Clauses, the UK Addendum, or an adequacy decision, as applicable to that sub-processor's location.
9. Retention and deletion
Personal data is retained for as long as the Controller's account is active. On termination, Bokalio will delete or return the data within [30 days] of the Controller's request, except for copies we're legally required to retain (e.g. for tax or fraud-prevention records), which are kept only for that purpose and deleted once no longer required.
10. Liability
Each party is liable for its own compliance with applicable data protection law. This DPA doesn't expand either party's liability beyond what's set out in the Terms of Service, except where mandatory data protection law requires otherwise.
11. Contact
Data protection contact: [privacy@bokalio.example].