Skip to content

Partner Data Processing Agreement

Effective 5 September 2026

This Data Processing Agreement (the "DPA") is concluded under Article 28 of Regulation (EU) 2016/679 (the "GDPR") and Albanian Law No. 9887 dated 10.3.2008 "On Personal Data Protection", as amended. It forms an integral part of the EasyBook Partner Terms of Service and applies to every organisation created on the EasyBook Partner platform. You accept it when you create an organisation, and the version you accepted is recorded against your account and your organisation.

1. Parties and roles

Processor. EasyBook AI shpk, a company registered in Albania, NUIS M56506203S, registered office Vlore, Rruga "Adem Abazi", zona kadastrale 8602, apartamenti me nr. pasurie 12/387-N2, Albania ("EasyBook", "we", "us"). Data protection contact: [email protected].

Controller. The business or professional that creates and operates an organisation on the EasyBook Partner platform (the "Partner", "you"). The Partner's identity, registered details and contact address are those recorded in the Partner's organisation profile.

Roles are split as follows and the split is not negotiable, because it follows who decides the purposes of the processing:

  • For client data — the personal data of the Partner's own clients that the Partner records, imports or receives through the platform — the Partner is the controller and EasyBook is the processor, acting only on the Partner's documented instructions.
  • For Partner account data — the identity, contact details, authentication credentials, device and session records of the Partner and its staff — EasyBook is an independent controller, because EasyBook decides how accounts are secured and administered. This processing is described in the EasyBook Partner Privacy Policy.
  • For platform analytics and platform security — aggregate usage measurement, fraud and abuse detection, rate limiting, audit logging and incident response across the whole platform — EasyBook is an independent controller.
  • Where a consumer books through the EasyBook discovery platform at easybook.ai, EasyBook is the controller of that consumer's account and of the booking record it holds as the operator of the marketplace, and the Partner is the controller of the client record created in the Partner's own organisation. The two roles run in parallel; neither party is the other's processor for that data.

2. Subject matter

EasyBook processes client personal data solely to provide the Partner Services: appointment booking and scheduling, class and event enrolment, client records, passes and memberships, payment records, notifications sent on the Partner's behalf, calendar synchronisation, reporting and support.

3. Duration

This DPA applies for as long as the Partner has an organisation on the platform, and for a further 30 days after the agreement ends, during which the Partner may export client data before deletion under section 12.

4. Nature and purpose of the processing

EasyBook carries out the following operations on client personal data on the Partner's behalf: collection through booking and client-management screens, structured storage, organisation-scoped retrieval, correction, transmission of notifications by email and push, synchronisation of appointment entries to a calendar the Partner has connected, aggregation into the Partner's own reports, backup, and erasure on instruction.

EasyBook does not use client personal data for its own purposes, does not sell it, does not use it to train models, and does not share it with other Partners. Client data is scoped to the organisation that recorded it and is not readable by another organisation.

5. Categories of personal data and data subjects

Data subjects: the Partner's clients and prospective clients; guests added to a booking by a client; the Partner's staff, in their capacity as users of the Partner's organisation.

Categories of personal data:

CategoryExamples
Identity and contactName, email address, telephone number, preferred contact channel
Booking recordsAppointments, classes, attendance, cancellations, no-shows, the staff member and venue assigned
HoldingsPasses, memberships, credits and their remaining balance
Financial recordsAmounts due and collected, payment method recorded by the Partner, invoices, refunds
Partner-authored contentClient notes, tags, VIP marks, and any free-text the Partner enters
Consent recordsMarketing consent, the source the Partner declared for it, and the date
ProvenanceWhether the client record was created manually, imported from a file, imported from Google Contacts, created by a booking, or created by the client's own sign-up
TechnicalTimestamps, the acting account, and audit entries recording who changed what

Special categories. The platform is not designed for health data. If the Partner enters health or other special-category data into a free-text field, the Partner remains solely responsible for the lawful basis under Article 9 GDPR and for informing the data subject. EasyBook does not analyse free-text fields.

Children. The platform is not intended for use by anyone under 18. The Partner must not create client records for children below the age at which consent is valid in the Partner's market without the consent of the holder of parental responsibility.

6. Processor obligations

EasyBook undertakes to:

  1. Process only on documented instructions. The Partner's instructions are this DPA, the Terms of Service, and the operations the Partner performs through the platform's interfaces and documented APIs. EasyBook will inform the Partner if it considers an instruction to infringe data protection law. Where EasyBook is required by Albanian or EU law to process client data otherwise, it will inform the Partner before processing unless that law forbids it.
  2. Bind everyone with access to confidentiality. Personnel authorised to process client data are subject to written confidentiality obligations that survive the end of their engagement.
  3. Implement the technical and organisational measures in section 7.
  4. Engage sub-processors only under section 9.
  5. Assist the Partner with data-subject requests (section 8), with security and breach obligations (section 10), and with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to EasyBook.
  6. Make available the information needed to demonstrate compliance with Article 28 and allow audits under section 11.
  7. Delete or return client data at the end of the agreement under section 12.

7. Security measures (Article 32)

The following measures are implemented today. They are described so the Partner can rely on them; EasyBook may replace a measure with one that is at least equivalent.

  • In transit: TLS for every connection between clients, the platform and its sub-processors.
  • At rest: AES-256-GCM encryption of OAuth refresh tokens, multi-factor authentication secrets, recovery codes and push tokens. Database and object storage are encrypted at rest by the cloud provider.
  • Passwords: stored only as BCrypt hashes. EasyBook never sees or stores a plaintext password.
  • Authentication: session and refresh tokens are held in encrypted, HTTP-only cookies; optional multi-factor authentication by time-based one-time password, passkey or hardware security key, and recovery codes; device registration with the ability to revoke a session.
  • Authorisation: every read and write is scoped to an organisation, and within an organisation to a role and a granular permission. There is no cross-organisation read path.
  • Audit: security and data-protection events — sign-in, permission change, client erasure, export, consent change — are written to an append-only audit log with the acting account and a retention period longer than routine records.
  • Segregation: production, staging and development run as separate environments with separate credentials and separate data.
  • Resilience and testing: dependency and vulnerability scanning on every build, and a documented incident-response path (section 10).

8. Assistance with data-subject requests

The Partner is the addressee for requests from its own clients. EasyBook will not respond to such a request directly; if one reaches EasyBook, EasyBook will forward it to the Partner without undue delay and tell the requester who the controller is.

The platform gives the Partner the means to satisfy the common requests itself, without contacting EasyBook:

  • Access and portability — export one client's record, bookings, holdings, financial history, consents and notes as a machine-readable file from the client's profile.
  • Rectification — edit any client field.
  • Erasure — erase a client's personal data from the client's profile. The record is anonymised, notes and tags are removed, and where the client also has an EasyBook account the account itself is untouched and only the organisation-side copy is anonymised.
  • Objection and consent withdrawal — turn off marketing consent, which stops marketing messages from that organisation.

Where a request cannot be satisfied through the platform, EasyBook will assist the Partner within 10 business days of a written request to [email protected].

9. Sub-processors

The Partner gives general written authorisation for EasyBook to engage the sub-processors listed in the Annex. EasyBook imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Partner for their performance.

EasyBook will give the Partner 30 days' notice, by email to the organisation's registered address and by a notice in the dashboard, before adding or replacing a sub-processor. The Partner may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Partner may terminate the agreement for the affected service without penalty and export its data under section 12.

10. Personal data breaches

EasyBook will notify the Partner within 48 hours of becoming aware of a personal data breach affecting client data, by email to the organisation's registered address, and will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. EasyBook will provide further information as the investigation proceeds, and will assist the Partner in meeting its own obligations under Articles 33 and 34 GDPR. The 72-hour clock towards the supervisory authority is the Partner's, as controller of the client data.

11. Audit rights

On reasonable written notice, and no more than once in any 12 months unless a breach or a supervisory authority requires otherwise, EasyBook will provide the Partner with the information necessary to demonstrate compliance with this DPA, including its current security documentation and the answers to a written security questionnaire. Where that is not sufficient for the Partner's regulator, the Partner may conduct or mandate an audit, at the Partner's cost, during business hours, subject to confidentiality and to not disrupting the platform or the data of other Partners.

12. Return and deletion

On termination of the agreement, and at any time on the Partner's written instruction, EasyBook will delete client data within 30 days. During that window the Partner may export its client data from the dashboard. EasyBook may retain client data beyond that period only to the extent required by Albanian or EU law — in particular financial records retained for tax and accounting purposes — and will keep it protected under this DPA and process it only for that purpose. Backups are overwritten on their ordinary rotation.

13. International transfers

The platform is operated from Albania and its data is stored in the European Economic Area. Some sub-processors are, or have parent companies, in the United States. Where client data is transferred outside the EEA, EasyBook relies on:

  • the EU-U.S. Data Privacy Framework where the recipient is certified under it; and
  • the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), module 3 (processor to processor), together with the supplementary measures described in section 7.

Albania is not a member of the EEA. Transfers between the Partner and EasyBook are governed by Albanian data protection law, which the parties agree affords protection equivalent to the GDPR for the purposes of this DPA.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits either party's liability towards a data subject or a supervisory authority under Article 82 GDPR.

15. Governing law and jurisdiction

This DPA is governed by the law of the Republic of Albania. The courts of Tirana have exclusive jurisdiction, without prejudice to a data subject's right to bring proceedings where the GDPR permits.

16. Changes to this DPA

EasyBook may update this DPA where the law, the platform or the sub-processor list changes. The updated text is published on this page under a new "last updated" date, and the Partner is asked to accept it in the dashboard. Material changes are notified 30 days in advance.

Annex — Sub-processors

The sub-processors currently engaged for the Partner Services. Only providers that are actually in use are listed.

Sub-processorRolePersonal data processedLocation
Google Cloud (Google Ireland Limited, with Google LLC as onward processor)Managed PostgreSQL database and Cloud Storage bucket holding all platform data and uploaded imagesAll categories in section 5Frankfurt, Germany (europe-west3) — database and object storage
Hostinger International LtdHosting of the application servers and of the session and permission cache that runs alongside themAll categories in section 5, processed in memory while a request is served; session and permission cache entriesMeppel, Netherlands, with a standby cluster in Frankfurt, Germany — both in the European Union, no transfer outside the EEA
Resend Inc.Delivery of transactional email — booking confirmations, reminders, one-time codes, calendar invitationsRecipient name, email address, message contentUnited States (EU-U.S. Data Privacy Framework)
Google Ireland Limited / Google LLC — Firebase Cloud MessagingDelivery of push notifications to Partner devicesDevice push token, notification title and bodyEuropean Union and United States
Google Ireland Limited / Google LLC — Calendar API and People APITwo-way calendar synchronisation and one-off contact import, only where the Partner has connected the integrationAppointment time, title and participants; contact name, email and telephone at the moment of importEuropean Union and United States
Google Ireland Limited / Google LLC — Maps PlatformVenue address autocomplete and map display, only where functional consent is givenApproximate location and the address being searchedEuropean Union and United States
Google Ireland Limited / Google LLC — Analytics 4Aggregate platform usage measurement, only where analytics consent is given; IP anonymisation enabledTruncated IP address, device and usage eventsEuropean Union and United States
Apple Inc. / Apple Distribution International LimitedSign in with Apple and the Apple Push Notification serviceApple account identifier, name and email or Apple private relay address; device push tokenIreland and United States
Cloudflare, Inc.DNS resolution, content delivery, TLS termination and denial-of-service protection in front of every public domain of the platformIP address and request metadata processed at the edgeGlobal edge network (EU-U.S. Data Privacy Framework; Standard Contractual Clauses)

EasyBook AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

  • Company: EasyBook AI shpk
  • NUIS: M56506203S
  • Address: Vlore, Rruga "Adem Abazi", zona kadastrale 8602, apartamenti me nr. pasurie 12/387-N2, Albania
  • Data Protection Officer: [email protected]
  • Support: [email protected]