Informacje prawne
Umowa powierzenia przetwarzania
Umowa z art. 28 ust. 3, na podstawie której przetwarzamy dane osobowe Twoich klientów w Twoim imieniu.
Wersja 1 · projekt, jeszcze nie obowiązuje
This agreement is required by Article 28(3) of the GDPR, which says that a processor may handle personal data for a controller only under a written contract. It forms part of the terms of service and is accepted when you open a workspace.
It is written to be read. Where it uses a legal term, that is because the article it implements uses it.
1. The parties and their roles
You, the business running a workspace, are the controller of your clients' personal data. You decide what to collect about them and why.
We are the processor. We hold that data and act on your instructions.
This division follows from what the software actually does, not from a preference recorded here. Our platform administrators cannot open a client record, a staff note, a client label, a notification log or a delivery record: those tables are denied to the administrative interface outright, and that denial is a security measure under Article 32, not a configuration.
Where we act as a controller in our own right — your own account, your subscription, our administrative log, aggregate product statistics, and the analytics on your public page — this agreement does not apply. The privacy notice covers that, and states it separately so that it cannot be mistaken for joint controllership.
2. What is processed
Required by the opening words of Article 28(3). The detail is in Annex I.
- Subject matter: providing the revoo.me booking service to you.
- Duration: as long as you have a workspace, and then as section 10 provides.
- Nature and purpose: storing and organising your client and appointment records, sending the transactional messages you configure, publishing your public booking page, and taking bookings through it.
- Types of personal data: identification and contact details, appointment records, free-text notes which may contain health information, and message delivery records.
- Categories of data subject: your clients, and the members of your team who appear on your public page.
3. Our instructions come from you
Article 28(3)(a). We process your clients' personal data only on your documented instructions. Your instructions are: this agreement, the terms of service, and what you do in the product — a notification you switch on is an instruction to send it.
We transfer data outside the European Economic Area only as section 8 describes.
If we believe an instruction breaks data protection law, we will tell you before acting on it.
4. Confidentiality
Article 28(3)(b). Everyone we authorise to handle your data is bound to confidentiality, and access is granted only where a role requires it.
5. Security
Article 28(3)(c) and Article 32. We keep the technical and organisational measures set out in Annex II. We may change a measure for one that is at least as protective, and we will not weaken the set.
6. Subprocessors
Article 28(2) and 28(4). You give us general written authorisation to engage subprocessors. The current list is published at /legal/subprocessors and names each provider, what it does and where it is.
Before we add or replace one we will announce it on that page and notify workspace owners at least 30 days in advance. You may object within that period on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected part of the service and we will refund any period paid for and not used.
Every subprocessor is bound by written terms imposing the same obligations as this agreement, and we remain fully liable to you for their performance.
7. Helping you answer your clients
Article 28(3)(e) and (f). We help you meet your own obligations, so far as the nature of the processing allows:
| You need to | What we give you |
|---|---|
| answer an access or portability request | export one client's record in a machine-readable form, from the client profile |
| take your client book with you | export the whole book from the workspace settings |
| erase a client | an irreversible erasure that leaves the appointment history anonymous |
| stop contacting someone | a per-client block on email and SMS |
| limit how long you keep records | a retention period you set, with a default we ship |
If a data subject writes to us about a record you hold, we will not act on it. We will tell them that you are the controller and pass the request to you, promptly. We cannot verify who they are; you can.
We also assist you with security, with data protection impact assessments and with prior consultation, to the extent the information is ours to give.
8. Personal data breaches
Article 33(2). We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. Notifying your supervisory authority and your clients is yours to do, as controller.
9. Transfers outside the EEA
Some subprocessors are established outside the European Economic Area. Each such transfer is covered by the European Commission's standard contractual clauses under Article 46(2)(c), recorded against the provider on the subprocessor list. Infobip, which delivers your email and SMS, is established in Croatia, so message delivery involves no transfer at all.
10. Return and deletion
Article 28(3)(g). At the end of the service you choose: export your client book, erase it, or both. Export is available from workspace settings for as long as the workspace exists.
If a workspace becomes dormant — twelve months with no member signing in and no booking arriving — we write to the owner and every administrator, offer the export, give sixty days' notice, and then erase every client record in it. A cancelled subscription alone is never treated as the end of the service.
Erasure is irreversible anonymisation, not a row delete: identifying data is destroyed and the appointment survives with nobody attached to it. Backups are retained for 30 days, are never edited selectively, are restored only whole and only after an incident, and erasures are re-applied after any restore. Within that 30-day window a restored backup may briefly contain data already erased in production; this is the honest limit of the promise, and it is stated rather than concealed.
11. Audits
Article 28(3)(h). On reasonable written notice, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will give you the information needed to demonstrate our compliance with this agreement. We may satisfy a request with existing documentation, an independent report or a completed questionnaire before an on-site audit. Audits must not compromise the confidentiality or security of other customers' data, and you bear your own costs.
12. Special category data
The note fields — the note your client writes when booking, and the note your staff write about a client — are free text and in your line of work will contain health information. We treat them as special category data under Article 9 by default: excluded from all administrative access, excluded from our logs, given a shorter retention period, excluded from the bulk export, and deleted first on erasure.
The lawful basis under Article 9(2) is yours to hold, not ours to supply. We provide the mechanics; you decide whether you may record what you record.
revoo.me is not a medical information system and must not be used as a clinical record. This is stated so that no regulated record-keeping regime is attached to us by the way a workspace is used.
13. Liability and precedence
This agreement forms part of the terms of service, whose limits on liability apply to it. Where this agreement and the terms conflict on the processing of your clients' personal data, this agreement prevails. Where either conflicts with the standard contractual clauses, the clauses prevail.
Annex I — Details of the processing
| Item | Detail |
|---|---|
| Categories of data subject | your clients; members of your team shown on your public page |
| Categories of data | name, telephone, email, preferred language; appointment date, time, service, price at booking, staff member, status; free-text notes; message delivery records |
| Special categories | health information, where it appears in a note field — see section 12 |
| Frequency | continuous, for as long as the workspace exists |
| Nature of processing | collection, storage, organisation, retrieval, transmission of transactional messages, publication of a booking page, erasure |
| Purpose | providing the booking service you contracted for |
| Duration | the life of the workspace, then section 10 |
Annex II — Technical and organisational measures
Article 32.
- Separation of workspaces. Every record carries the workspace it belongs to, and every authenticated route is scoped to the workspace in the session token. There is no query path that spans workspaces.
- No platform access to client data. Client records, staff notes, client labels, notification logs, delivery records and account tokens are denied to our administrative interface outright, enforced by an allow-list that the build fails if anyone widens it silently.
- Roles inside a workspace. A capability model governs who may do what; irreversible operations on client data are the owner's alone.
- Notes are private to their author. A staff note is visible only to the person who wrote it.
- Encryption. TLS in transit; encryption at rest at the hosting provider.
- Authentication. Passwords are hashed with bcrypt and checked against a breach corpus;
short-lived access tokens with refresh tokens held in an
httpOnlycookie; a challenge on sign-in and on the public booking form; rate limiting on sensitive routes. - Bulk export is treated as a security event. Owner only, re-authenticated, rate-limited, recorded, with a short-lived signed link, and staff notes excluded by default.
- Logging. Note fields are never written to logs. Administrative actions are recorded in an audit log that records the fact of an erasure and never its content.
- Backups. Retained 30 days, restored only whole, with erasures re-applied after any restore.
- Written assessment. We maintain a record of processing activities and a data protection impact assessment, both reviewed at least annually and whenever the processing changes.
Annex III — Subprocessors
The list is published and kept current at /legal/subprocessors, with the Chapter V safeguard for each. It is part of this agreement by reference so that a change to it is announced rather than requiring a new signature.
Nasze dane
Nasze dane rejestrowe i skrzynka do spraw ochrony danych nie zostały jeszcze opublikowane. Dopóki ich nie ma, ten dokument jest projektem.