Skip to main content

Data Processing Agreement

Version 0.4 — last updated: 2026-10-05

Unreviewed draft. This text was written from how the application actually works, but it has not yet been checked by a lawyer. None of these documents is in force or applies to any subscription yet, and none should be relied on as the operative document.

This agreement satisfies Article 28 of the GDPR and governs Tá Marcado's processing of the personal data in a business's bookings. It forms an integral part of the Terms and Conditions and applies to every business with an active subscription. The processor is GD Projects, Lda., Rua Dom Diniz, n.º 45, Burinhosa, Pataias, 2445-042 Pataias, freguesia de Pataias e Martingança, concelho de Alcobaça, distrito de Leiria, VAT 519433858.

1. Parties and scope

Controller: the subscribing business.

Processor: GD Projects, Lda..

This agreement applies only to personal data processed on the business's behalf — booking, customer and internal-note data. It does not apply to data we process as controller in our own right (account, subscription, billing, security and platform operation), which is covered by the Privacy Policy.

Where this agreement and the Terms and Conditions conflict on the processing of personal data, this agreement prevails.

2. Subject matter, duration, nature and purpose

Subject matter: provision of the booking platform.

Duration: for as long as the subscription lasts, plus the retention period set out in the deletion section.

Nature and purpose: collection, recording, organisation, consultation, disclosure and erasure of the data needed to publish the diary, accept bookings, verify the consumer contact detail, take online payments where enabled, send transactional messages once that channel is live, and allow the business to manage its operation.

3. Categories of data and of data subjects

Categories of data and of data subjects
Category of data subjectData processed
Consumers who bookName, email and/or mobile number where provided, language, booking history, no-show and cancellation counters, internal notes written by the business, and booking payment data limited to status, amount and references — never card data. Where applicable: birthday day and month, preferences and their evidence, Loyalty membership and movements, rewards and conditions, Reviews requests and relevant personal analytics derivatives
People with access to the business panelUser identifier, role in the business, association with a professional, and audit records of the actions taken. The account email is processed outside this agreement, under the Privacy Policy
The business's professionalsName, associated services, schedules and absences

Expressly outside the scope of this agreement is the processing of health data and of any other special category under Article 9 of the GDPR. The platform offers no clinical features and the business undertakes not to enter such data, including in internal notes.

4. Documented instructions

We process the data only on the business's documented instructions. The following constitute documented instructions: these terms, the configuration the business makes in the panel, and the requests it addresses to our support.

If we consider that an instruction infringes the GDPR or another data protection rule, we inform the business.

We do not use this data for our own purposes, in particular marketing, benchmarking between businesses, or training artificial intelligence models.

5. Confidentiality

People authorised to process this data are bound by a duty of confidentiality.

Support access to personal data is exceptional, justified and logged.

6. Security measures (Article 32)

Per-business isolation verified on the server on every read, action, API and asynchronous job.

Direct database access denied by rule: no client reads or writes data without going through the server.

Encryption in transit and at rest, as provided by the services used.

Authentication with an HttpOnly session cookie and origin checking on sensitive operations.

Distributed abuse limiting and an anti-bot challenge on public surfaces.

Verification codes never stored; contact details indexed by an irreversible value.

Technical logs without personal data; error reports configured to discard cookies, headers, request body, IP address and email.

Audit records, identifying the actor, of actions on roles, publication, policies, integrations, cancellations and refunds.

Secrets separated by environment, with rotation.

Daily Firestore database backups and point-in-time recovery within the defined window. Auth and Storage recovery and reopening after a restore require their own evidence; importing the database alone does not demonstrate complete recovery.

This section serves as the annex of technical and organisational measures. It may be updated provided the level of security is not reduced.

7. Sub-processors

The business gives general authorisation for the sub-processors listed below.

We give reasonable advance notice of any intention to add or replace a sub-processor. The business may object on reasonable grounds and, if the objection cannot be accommodated, terminate the subscription without penalty as to the unused period.

We impose on each sub-processor data protection obligations equivalent to those in this agreement and remain answerable for their performance.

Sub-processors
Sub-processorProcessingLocation
Google (Firebase Firestore)Storage of booking dataEuropean multi-region
Google (Firebase Authentication)Authentication of people accessing the panelUnited States
VercelApplication execution and hostingFrankfurt
StripeProcessing booking payments in the business's accountIreland and United States
CloudflareAnti-bot challenge on public surfacesGlobal network
SentryError reports, configured without personal dataEuropean Union region
Arpoone (SEND IT, S.A.)Transactional booking email and SMS deliveryEuropean Economic Area
Google (Calendar and Meet)Optional synchronisation of a professional's diary, where enabledUnited States

The last two rows correspond to features that are not live as of this version. Kapta and Moloni are deliberately absent from this list: they handle only subscription invoicing, where we are the controller, and never booking data.

8. Assistance to the controller

We assist the business, so far as reasonable and taking the nature of the processing into account, in meeting its duties under Articles 32 to 36 of the GDPR.

If a data subject addresses a request about booking data directly to us, we forward it to the business and do not answer substantively without its instruction, save where the law requires otherwise.

The owner has a complete self-service export and a journey to decide verified access, portability, correction and erasure requests, limited to their business. The data subject’s copy is distinct from the global export and excludes third-party data and usable credentials. Erasure and anonymisation can proceed only with a verified instruction and an approved retention policy; sending the code depends on activation of the corresponding delivery channel.

9. Personal data breaches

We notify the business without undue delay after becoming aware of a breach affecting data processed on its behalf.

The notification includes the information available to us: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken.

Notification to the supervisory authority and to data subjects, where due, is the business's responsibility as controller.

10. Deletion and return at the end

After normal access under the base subscription effectively ends, the owner keeps restricted access to authorised operational data still retained for 90 elapsed days, measured in UTC. They can request the complete self-service export, independently of keeping any add-ons. A temporary payment restriction does not start that period; signing in or downloading does not restart it. Operational access closes when the period ends.

Export and report files remain available for 1 hour after becoming ready, subject to current authorisation and the end of applicable access. Every download checks permissions again; the link does not extend the file’s validity. After expiry, generating a new file requires current authorisation and source data that is still retained.

After the 90 days, erasure or anonymisation follows the approved policy by class, purpose and context, respecting obligations and pending proceedings. There is no additional operational archive for commercial recovery. Bookings retain only the permitted anonymised record; the 90 days of access do not determine legal retention periods for retained classes. Reactivation does not recover data already erased.

The Privacy Policy matrix distinguishes technical limits from legal proposals. Erasure or anonymisation requires an approved, versioned policy by class and context; the commercial 90-day window and 1-hour file validity do not approve the other periods. Backups and provider copies have their own lifecycles, and a restore stays blocked until applicable deletions and corrections have been reconciled.

The periods in the matrix marked as proposals are not yet legally validated. This point must be closed before the agreement is used with real businesses.

11. Information and audits

We make available to the business the information needed to demonstrate compliance with the obligations of Article 28.

We allow audits, including inspections, conducted by the business or by an auditor it mandates, on reasonable notice, during business hours, at most once a year save for a security incident or a requirement of an authority, and without compromising the confidentiality of other businesses' data.

12. International transfers

Transfers outside the European Economic Area are identified in the sub-processor table and in the Privacy Policy.

Those transfers rest on the mechanisms provided for in Chapter V of the GDPR, in particular Standard Contractual Clauses and, where applicable, adequacy decisions.

The specific mechanisms, sub-processor by sub-processor, must be confirmed and cited in the legal review of this document.

13. Acceptance and version

This agreement applies from the creation of the subscription, without the need for a separate signature.

The version and date in force are those shown at the top of this page. Material changes are communicated to businesses with an active subscription.