Data Processing Addendum

The processing, security, assistance and deletion commitments that apply when Schedmo handles data for a business customer.

Effective 2026-08-03

This Addendum forms part of the agreement between the business customer and Schedmo when applicable data-protection law requires processor terms.

1. Roles and scope

The customer is the controller of personal data submitted to Schedmo for its clients, staff and business operations. Schedmo is the processor for that data and acts only on documented customer instructions, including product configuration and support requests. Each party remains a controller for information it independently processes for contracting, billing, security and legal compliance.

2. Processing details

Processing includes hosting, organising, retrieving, transmitting, backing up, securing, supporting, exporting and deleting appointment, client, staff, form, communication and transaction data for the term of the service. Data subjects may include customers, prospective customers, staff and authorised users. Data may include contact, booking, preference, form, payment-status and usage information, and may include sensitive information when the customer chooses to collect it.

3. Confidentiality and security

Schedmo restricts access to authorised personnel and uses technical and organisational safeguards appropriate to the risk, including encryption in transit, encrypted storage, tenant isolation, least-privilege access, logging, backups and incident procedures. Personnel with access are bound by confidentiality obligations.

4. Subprocessors and transfers

Schedmo may use vetted infrastructure, identity, communications, payment and support providers to deliver the service. Schedmo remains responsible for processor obligations delegated to subprocessors and uses lawful transfer safeguards where required. Material subprocessor changes will be notified through the service or published legal materials where required.

5. Individual rights and incidents

Schedmo will provide reasonable assistance for access, correction, portability, restriction and erasure requests relating to customer-controlled data. Schedmo will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide information reasonably needed for the customer’s obligations.

6. Return, deletion and retention

Customers can export workspace data while authorised. Subscription cancellation does not itself delete data. An authenticated workspace-closure instruction enters restricted settlement mode while invoices, processing payments, refunds, disputes, liabilities or payout balances remain; new acquisition activity is stopped while settlement and export functions remain available. Once clear, production personal data is deleted or de-identified without undue delay and backup copies expire on the documented backup cycle. Limited financial, consent, security and compliance evidence may be retained where law or legal claims require it, with access restricted and unnecessary identifiers removed.

7. Audit and deletion assurance

Schedmo maintains proportionate evidence of high-risk access, exports and erasure operations. On reasonable written request, Schedmo will provide information necessary to demonstrate compliance, subject to confidentiality, security and protection of other customers.