Skip to content

Data Processing Agreement (DPA)

Last updated: 2026-05-26

This document describes the contractual framework under which ScheduleBox, as Processor, processes personal data on behalf of its customers (Controllers) within the meaning of Art. 28 GDPR. The binding version is captured in the written agreement or the Terms of Service; this publicly available version reflects the current template as of the "Last updated" date below. A signed individual copy may be requested at privacy@schedulebox.cz.

1. Parties and Effective Date

This agreement applies between ScheduleBox s.r.o., ID No. 12345678, registered at Příkladná 1, 110 00 Praha 1 ("Processor" or "ScheduleBox"), and the Customer who has accepted the ScheduleBox Terms of Service or has entered into a separate written agreement ("Controller"). This DPA covers all processing of personal data carried out by the Processor on behalf of the Controller for the duration of the Service.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach", "sub-processor" and other terms used in this DPA have the meaning set out in Art. 4 GDPR (Regulation (EU) 2016/679) and Czech Act No. 110/2019 Coll. "Service" means the ScheduleBox cloud platform and all accompanying features provided by the Processor under the Terms of Service.

3. Subject Matter, Nature, Purpose and Duration

The Processor processes personal data exclusively for the purpose of providing the Service to the Controller, on the basis of the Controller's documented instructions consisting of the Terms of Service and the Controller's account configuration in the Service. The nature of processing includes storage, organisation, retrieval, disclosure to authorised persons, transmission to the sub-processors listed in Section 6, erasure and anonymisation. Processing lasts for the duration of the Service plus the retention period set out in the Privacy Policy (typically 30 days for the account after termination, 3 years for booking records, 10 years for invoicing data under Czech Act No. 235/2004 Coll.).

4. Data Categories and Data Subjects

Data categories: identification data (first name, surname), contact data (email, phone), booking and customer-interaction data, payment data (payment method type and transaction identifier — full card data is processed by the payment gateway, not by the Processor), communication data (email and SMS content, delivery logs), technical data (IP address, browser identifier, timestamps), and other data the Controller places into the Service. Data subjects: the Controller's customers making bookings, the Controller's employees and contractors managed in the account, visitors of the Controller's public booking pages, and the Controller themselves if a natural person.

5. Processor Obligations (Art. 28(3))

Pursuant to Art. 28(3) GDPR, the Processor:

  1. processes personal data only on the Controller's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law (in which case the Processor informs the Controller of that legal requirement, unless prohibited by that law);
  2. ensures that persons authorised to process the personal data are bound by a confidentiality undertaking or by an appropriate statutory duty of confidentiality;
  3. takes all measures required pursuant to Art. 32 GDPR — see Section 8 and Annex III;
  4. respects the conditions for engaging further sub-processors set out in Section 6;
  5. assists the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to data subject requests — see Section 9;
  6. assists the Controller in ensuring compliance with Art. 32–36 GDPR (security, breach notification, DPIA, prior consultation with the supervisory authority), taking into account the nature of processing and the information available to the Processor;
  7. at the choice of the Controller, deletes or returns all personal data after the end of the provision of services and deletes existing copies, unless Union or Member State law requires storage — see Section 12;
  8. makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in this article and allows for and contributes to audits — see Section 11.

6. Sub-Processors

The Controller grants general authorisation to the engagement of the sub-processors listed at /legal/subprocessors as of the effective date of this DPA. The current list is permanently available at that URL and contains, for each sub-processor, its identification, purpose and scope of processing, location, legal safeguard for any transfer outside the EEA, and links to its published privacy policy and DPA. The Processor will notify the Controller of the addition of a new sub-processor with at least 30 days' advance notice. Within that period the Controller has the right to lodge a reasoned objection; if the parties cannot reach agreement, the Controller may terminate the agreement with 30 days' notice. The Processor reserves the right to replace a sub-processor without prior notice where strictly necessary for security reasons, in which case it will inform the Controller without undue delay.

7. Transfers Outside the EEA

Some of the sub-processors listed in Section 6 are established in third countries outside the European Economic Area (particularly the United States). For such transfers, the Processor relies on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914, module 3 — processor-to-processor); a copy is available to the Controller on request. Transfers to the United Kingdom rely on the UK adequacy decision (June 2021). Where appropriate, the Processor applies supplementary technical measures (minimisation, pseudonymisation) in line with the Schrems II ruling (C-311/18).

8. Technical and Organisational Measures (Art. 32)

The Processor implements measures appropriate to the risk within the meaning of Art. 32 GDPR. Specific measures include:

  • Encryption in transit (TLS 1.2 and above) and at rest (AES-256 on database and backup storage).
  • Role-, tenant- and end-user-scoped access control; principle of least privilege; segregation of production and development environments.
  • Audit log of access and privileged operations with 18-month retention.
  • Multi-factor authentication (MFA) for internal administrators and privileged roles; periodic rotation of access keys and tokens.
  • Regular security testing: static and dynamic analysis, dependency audits (Trivy, CodeQL, Dependabot), penetration tests.
  • Incident response plan with defined roles, escalation paths and notification procedures.
  • Regular encrypted backups with periodically tested restoration; geo-redundancy within the EEA.
  • Regular staff training on security, GDPR and personal-data handling.

9. Assistance with Data Subject Requests

The Processor provides the Controller with tools to satisfy data subject requests (right of access, rectification, erasure, restriction of processing, portability, objection, and the right not to be subject to a solely automated decision within the meaning of Art. 22 GDPR) through self-service functions in the Service administration (GDPR export, customer deletion, anonymisation) and on request via email at privacy@schedulebox.cz with a response time of no more than 5 business days. Requests the Processor receives outside the Service administration are forwarded to the Controller without undue delay; the Processor does not respond to them unless explicitly authorised by the Controller.

10. Personal Data Breach Notification

The Processor notifies the Controller of any personal data breach affecting it without undue delay, and no later than 48 hours after becoming aware of the breach. The notification contains the information required by Art. 33(3) GDPR to the extent available at that time (nature of the breach, categories and approximate number of data subjects affected, likely consequences, measures taken or proposed) and is supplemented as the investigation progresses. The Processor does not itself notify the supervisory authority (the Czech Office for Personal Data Protection) or the data subjects — those obligations remain with the Controller.

11. Audits and DPIA

Once per year, on request, the Processor provides the Controller with a current summary of its security findings — typically an extract from the penetration test, the results of external dependency review, and the status of certifications (SOC 2 Type II and ISO 27001 — certification planned for Q4 2027). Pending completion of formal certification, the Processor provides an equivalent in-house security questionnaire. An on-site physical audit by the Controller is possible against reimbursement of reasonable costs, subject to prior written agreement on scope and timing, no more than once a year unless a specific reasonable suspicion of breach of this DPA exists. For DPIA purposes under Art. 35 GDPR, the Processor provides the necessary information on request.

12. Return or Deletion on Termination

On termination of the Service, the Processor retains data for 30 days to allow account reinstatement on the Controller's request. After 30 days, hard-deletion is performed across all production systems, and the deletion is completed within the backup rotation cycle of at most 90 days. On the Controller's express request before the 30-day window expires, the Processor provides a data export in machine-readable format (JSON or CSV) at no additional charge. Exceptions apply to data that must be retained under applicable law (in particular invoicing data for 10 years under the Czech Accounting Act).

13. Liability

Liability for damage arising from a breach of this DPA is governed by the Service Terms of Service and the general provisions of Czech law. The liability cap is set in the Terms of Service; the cap does not apply to damage caused by wilful misconduct or gross negligence, or to liability that is unlimited by mandatory law.

14. Amendments

The Processor may amend this DPA unilaterally. Material changes (expansion of sub-processor categories, reduction of safeguards for the Controller, change of governing law) will be notified to the Controller by email to the account contact or by publication on this page with 30 days' advance notice. Continued use of the Service after the notice period expires constitutes the Controller's acceptance. If the Controller does not agree, it may terminate the agreement with 30 days' notice.

15. Governing Law

This DPA is governed by Czech law and directly applicable EU regulations (in particular GDPR). The courts of the Czech Republic have exclusive jurisdiction. The parties undertake to attempt amicable resolution before initiating court proceedings.

16. Annexes

Annex I — Description of Processing: see Sections 3 and 4 above. Annex II — Sub-processors: the current list is permanently available at /legal/subprocessors; an excerpt as of the signing date will be provided on request for the purposes of an individual DPA. Annex III — Technical and Organisational Measures: see Section 8 above; a more detailed description is shared with prospects under NDA.

17. Contact

For questions about this DPA, requests for a signed individual copy or for supplementary information, contact privacy@schedulebox.cz. A standard request is handled within 5 business days.