Skip to content

Data processing addendum

Last updated July 25, 2026

This addendum applies where BookRails processes personal data on your behalf — principally your customers' booking details. It sets out our obligations as processor and forms part of our terms of service.

Roles

For personal data about your customers, you are the controller and BookRails is the processor, acting only on your documented instructions. For data about your own account, BookRails is the controller and the privacy policy applies.

Details of processing

Subject matter: provision of the BookRails booking and visibility service. Duration: the term of your subscription plus the retention periods in the privacy policy.

  • Data subjects — your customers, and the staff you invite to your workspace.
  • Categories of data — name, phone, email, requested service, appointment time, booking notes, and payment status.
  • Purpose — creating, confirming, rescheduling, and cancelling appointments, and attributing them to their source.
  • Special category data — none is requested or required. Do not enter health or other special category data into booking notes.

Our obligations

We process personal data only on your instructions; ensure personnel with access are bound by confidentiality; implement the security measures below; assist you with data-subject requests and with data-protection impact assessments; and delete or return personal data at the end of the contract, except where retention is legally required.

Security measures

Encryption in transit and at rest; row-level security isolating each business's records; least-privilege service credentials, with MCP tools reaching data only through scoped procedures rather than raw table access; encrypted storage of third-party OAuth tokens; audit logging of booking operations; and access review.

Subprocessors

You authorise the subprocessors listed in our privacy policy. We will give notice before adding or replacing a subprocessor, and you may object on reasonable data-protection grounds.

TODO: set the notice period before launch.

Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.

TODO: set a specific notification window before launch.

Audits and transfers

We will make available the information needed to demonstrate compliance with this addendum and contribute to audits on reasonable notice. Where processing involves a transfer outside the UK or EEA, it relies on adequacy or Standard Contractual Clauses.