Data Processing Addendum
Last updated: 19 May 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Alexander John Watts (ABN 72 732 848 534), the registered holder of the business name "Velobook" (“Velobook”, “us”) and the shop using the Service (“Shop”, “you”). It applies whenever Velobook processes Personal Data on the Shop's behalf. It is automatically accepted when the Shop accepts the Terms of Service and does not need to be separately signed.
Where the Shop is established in the EEA, the UK or Switzerland, or processes the data of individuals in those regions, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum referenced below are incorporated by reference and form part of this DPA.
1. Definitions
- “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach” have the meanings given to them in the GDPR.
- “Business”, “Service Provider”, “Sell”, “Share” have the meanings given to them in the CCPA/CPRA.
- “Customer Personal Data” means Personal Data of the Shop's customers that Velobook processes through the Service on the Shop's instructions.
- “Data Protection Laws” means all laws applicable to the Processing of Customer Personal Data, including (as applicable) the GDPR, UK GDPR, the Australian Privacy Act 1988, the NZ Privacy Act 2020, the CCPA/CPRA, and equivalent US state privacy laws.
2. Roles and scope
For the Customer Personal Data covered by this DPA, the Shop is the Controller (or Business) and Velobook is the Processor (or Service Provider). Velobook does not determine the purposes for which Customer Personal Data is processed; it processes the data only to provide the Service to the Shop and on the Shop's documented instructions.
The Shop is responsible for ensuring it has a lawful basis to collect and disclose Customer Personal Data to Velobook, and for the accuracy of any instructions it gives.
3. Subject matter and details of processing (Art. 28(3) GDPR)
- Subject matter: provision of the booking, scheduling and customer-records platform described in the Terms of Service.
- Duration: for as long as the Shop holds an active Velobook subscription, plus the wind-down and retention periods described in the Privacy Policy.
- Nature and purpose: hosting, transmission, storage, retrieval and deletion of Customer Personal Data to allow the Shop to accept bookings, communicate with its customers, run its business, and meet its own record-keeping obligations.
- Categories of Data Subjects: the Shop's customers and any other natural persons whose Personal Data the Shop chooses to enter into the Service (e.g. workshop co-attendees).
- Types of Personal Data: name, email, phone number, postcode (if collected by the Shop), item and job notes, photos and videos attached to a booking, booking history, optional integration identifiers (e.g. linked Google Calendar event IDs), IP and device metadata for abuse prevention.
- Special category / sensitive data: not intended to be processed under this DPA. The Shop must not submit special-category or sensitive data to the Service unless we've agreed in writing.
4. Velobook's obligations as Processor
- Process Customer Personal Data only on the Shop's documented instructions, including the Terms of Service and this DPA, except where required by law (in which case we will notify the Shop unless that law prohibits notification on important grounds of public interest).
- Ensure personnel authorised to process Customer Personal Data are under a duty of confidentiality.
- Implement appropriate technical and organisational security measures (see Schedule 1).
- Assist the Shop with responding to Data Subject requests and with the Shop's obligations under Arts. 32-36 GDPR (security, breach notification, DPIA, prior consultation).
- Make available the information necessary to demonstrate compliance, and allow for and contribute to audits, on reasonable notice, no more than once a year, and subject to confidentiality and the Shop bearing reasonable costs.
- On termination, return or delete Customer Personal Data per Section 8 below.
- CCPA/CPRA service-provider terms: Velobook will not sell or share Customer Personal Data, will not retain, use or disclose it for any purpose other than the business purposes set out in this DPA and the Terms of Service, will not combine it with personal information from other sources except as permitted by 11 CCR 7050(b), and will comply with applicable obligations under the CCPA/CPRA and provide the same level of privacy protection as the CCPA/CPRA requires of a Business.
5. Sub-processors
The Shop gives Velobook general written authorisation to engage Sub-processors. Velobook's current Sub-processors are listed at velobook.app/subprocessors.
Velobook will notify the Shop at least 30 days before engaging a new Sub-processor that processes Customer Personal Data, or replacing an existing one. The Shop may object on reasonable grounds within that period; if the parties can't resolve the objection, the Shop may terminate the affected portion of the Service without penalty for the remainder of the then-current billing period.
Velobook imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for each Sub-processor's performance.
6. International transfers
Where Customer Personal Data is transferred from the EEA, the UK or Switzerland to a country not covered by an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply on the following basis:
- Module Two (Controller to Processor) applies where the Shop is a Controller and Velobook is a Processor.
- Module Three (Processor to Processor) applies where the Shop acts as Processor for an upstream Controller and Velobook acts as Sub-processor.
- For UK transfers, the UK International Data Transfer Addendum (Version B1.0) to the EU SCCs applies.
- For Swiss transfers, the SCCs are read so that the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority and Swiss law governs in place of EU law.
- Optional Clause 7 (docking) and Option 1 of Clause 9 (prior authorisation of Sub-processors) apply with the notice period set in Section 5. Option 1 of Clause 11 (independent dispute resolution) does not apply. Clause 17 (Option 1): governing law is Irish law. Clause 18 (Option 1): venue is the courts of Ireland. Annexes I, II and III are populated by reference to this DPA and the Sub-processor list.
Velobook will make a transfer-impact summary available on request at privacy@velobook.app.
7. Personal Data Breach
Velobook will notify the Shop without undue delay (and where feasible within 72 hours) of becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information required by Art. 33(3) GDPR to the extent then known. Velobook will reasonably assist the Shop with the Shop's own breach-notification obligations.
8. Return and deletion
On termination of the Shop's Velobook subscription, the Shop may export its Customer Personal Data as CSV from the admin for at least 30 days. After that window, Velobook will delete Customer Personal Data from active systems, subject to retention required by law and to encrypted backup-aging cycles (no more than 90 days) after which backups are overwritten.
9. Data Subject requests
If Velobook receives a request from a Data Subject relating to Customer Personal Data, Velobook will route the request to the relevant Shop and assist as reasonably required, unless the request relates to data for which Velobook is itself the Controller (in which case Velobook will handle the request directly per its Privacy Policy).
10. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms of Service. To the extent of any conflict, this DPA takes precedence over the Terms of Service for matters relating to the Processing of Customer Personal Data, and the SCCs take precedence over both for transfers governed by them.
Schedule 1: Technical and organisational measures
Velobook maintains the following measures:
- Access control: production database access restricted to authorised personnel using individual accounts with multi-factor authentication. Row-level security enforces tenant isolation for every row.
- Transport security: TLS for all traffic to and from Velobook endpoints.
- Storage encryption: data and backups encrypted at rest by the underlying storage provider.
- Input validation: writes pass through server-side edge functions that validate input and enforce authorisation.
- Rate limiting and abuse prevention: per-endpoint rate limits and a self-hosted proof-of-work bot challenge on public forms.
- Monitoring and logging: server-side audit and error logs retained for 30 days.
- Backup and recovery: automated daily backups; point-in-time recovery available within the provider's retention window.
- Personnel: contractual confidentiality obligations and least-privilege production access.
- Vendor management: Sub-processors selected for security posture and bound by written agreements no less protective than this DPA.