Data Processing Agreement
Last updated: 23 February 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between timeslot.ie (“Processor”) and the business using the timeslot.ie platform (“Controller”). This DPA sets out the terms under which the Processor processes personal data on behalf of the Controller in accordance with the GDPR.
1. Roles and Responsibilities
- Controller
- The business (tenant) that uses timeslot.ie to manage bookings and customer data. The Controller determines the purposes and means of processing personal data of their end customers.
- Processor
- timeslot.ie, which processes personal data on behalf of the Controller solely for the purpose of providing the booking and scheduling Service.
2. Scope of Processing
The Processor shall process personal data only on documented instructions from the Controller, which includes:
- Storing and managing booking records and customer contact details.
- Sending email and SMS notifications on behalf of the Controller.
- Processing payments via Stripe as directed by the Controller.
- Generating reports and analytics for the Controller’s use.
3. Sub-processors
The Controller authorises the Processor to engage the following categories of sub-processors:
- Stripe — payment processing.
- Email delivery provider — transactional email delivery.
- SMS delivery provider — transactional SMS delivery.
- Infrastructure hosting provider — cloud hosting and database services.
The Processor shall notify the Controller at least 30 days in advance of any changes to sub-processors via email. The Controller may object to a new sub-processor within 14 days of notification. If the objection cannot be resolved, the Controller may terminate the Service.
4. Security Measures
The Processor implements appropriate technical and organisational measures, including:
- Encryption of personal data in transit (TLS 1.2+) and at rest.
- Role-based access controls with least-privilege principles.
- Regular backups with tested restoration procedures.
- Audit logging of all data access and modifications.
- Network segmentation and firewall protection.
- Employee training on data protection obligations.
5. Data Subject Access Requests (DSAR)
The Processor shall assist the Controller in fulfilling data subject requests under Articles 15–22 of the GDPR, including:
- Providing data export functionality for access and portability requests.
- Supporting data deletion for erasure requests.
- Restricting processing upon request.
The Processor shall notify the Controller without undue delay upon receiving a DSAR directly from a data subject.
6. Breach Notification
In the event of a personal data breach, the Processor shall:
- Notify the Controller without undue delay, and in any event within 48 hours of becoming aware of the breach.
- Provide sufficient information to enable the Controller to meet its notification obligations under Article 33 of the GDPR (notification to the Data Protection Commission within 72 hours).
- Cooperate with the Controller in investigating and remediating the breach.
- Document the breach, its effects, and the remedial actions taken.
7. Data Return and Deletion
Upon termination of the Service, the Processor shall:
- Make the Controller’s data available for export for 30 days following termination.
- Delete all personal data within 90 days of termination, except where retention is required by law.
- Provide written confirmation of deletion upon request.
8. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits, subject to reasonable notice and confidentiality obligations.
9. Governing Law
This DPA is governed by the laws of Ireland and the GDPR. Disputes shall be subject to the exclusive jurisdiction of the Irish courts.
10. Contact
For DPA-related enquiries, contact privacy@timeslot.ie.