Data Processing Agreement
Last updated: July 28, 2026
This Data Processing Agreement ("DPA") forms part of our Terms of Service and governs how BookZync processes personal data on behalf of our business customers. When your business uses BookZync, your customers' details (names, contact information, appointment requests, chat conversations) flow through our systems: you are the data controller of that personal data, and BookZync acts as your data processor. This DPA describes how we handle it. If your business requires a countersigned copy, email [email protected].
Roles and scope
You (the business subscribing to BookZync) are the controller of your customers' personal data, and you determine how that personal data is collected and used through BookZync. BookZync is your processor: we process customer data only to provide the services you request — answering chats, capturing leads, booking appointments, sending confirmations and reminders, and showing you analytics.
What we process for you
- Identity and contact data, including your customers' names, phone numbers, and email addresses.
- Booking data, including requested services, appointment dates and times, attendance, and visit history.
- Conversation data, including messages exchanged between your customers and the AI assistant.
- What we deliberately do NOT process: payment card numbers (payments run through secure checkout only) and medical details — the AI assistant is designed not to collect diagnoses, medical history, symptoms, or other Protected Health Information (PHI).
We apply data minimization: BookZync processes only the personal data necessary to respond to inquiries, qualify leads, schedule appointments, and provide the services you request. For dental, medical, and medspa practices, the business controls what its own clients are asked, and only finalized booking records are retained.
Our duties as your processor
- Process personal data only to deliver the service and in accordance with your documented instructions.
- Keep it confidential — staff access is role-based, limited using the principle of least privilege, and logged.
- Help you respond to data-subject requests: your dashboard can export or delete customer records, and we assist with anything it can't do yet.
- Tell you without undue delay if we become aware of a personal-data breach affecting your data.
- Delete or return your data when the agreement ends (see section 7).
Security measures
- Encryption in transit (HTTPS/TLS) and at rest on our managed database.
- Strict tenant isolation: every record is scoped to your business, and cross-tenant access is treated as not-found by design.
- Administrative access protected by two-factor authentication and step-up verification for sensitive actions.
- An audit log records every administrative change.
- Healthcare-adjacent practices (dental, medical, medspa): additional data-minimization and storage safeguards apply to the records you retain, and we continue to strengthen them as part of our healthcare-compliance program.
- SMS opt-outs are honored automatically: when one of your customers replies STOP, our systems record it and stop texting them across every feature.
Sub-processors
We use a small set of vetted providers to deliver the service. The current list is published at bookzync.com/sub-processors. Each is bound by obligations equivalent to this DPA. We will update that page before engaging a new sub-processor; if you object on reasonable data-protection grounds, you may cancel under our standard terms.
International transfers
Customer data may be processed outside your country, primarily in data centers located in the United States. Where your law requires it — for example for transfers out of the EU/UK — we rely on recognized safeguards such as the providers' standard contractual clauses and data-protection certifications.
For Canadian businesses: Personal Information processed outside Canada may become subject to the laws of the jurisdiction in which it is processed, including lawful access requests made by courts, law enforcement agencies, or other governmental authorities in accordance with applicable law. We apply the safeguards described in this DPA wherever the information is processed. Canadian businesses on eligible plans may request storage of their customer records in our Canadian database region; availability depends on the selected service plan and technical feasibility.
Term, return, and deletion
This DPA remains in effect for as long as your subscription remains active. After cancellation, your data remains available for export for 30 days, then is deleted unless we are required by law to retain specific records for a longer period (for example, tax records). You can also delete individual customer records from your dashboard at any time.
Contact
Data-protection questions or requests: [email protected].