← Back

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between you (the business using Alignext, the "Controller") and the Alignext service operator ("Processor", "we", "us") for the provision of the Alignext booking platform (the "Service"). It governs our processing of personal data of your clients and staff on your behalf under Article 28 GDPR.

1. Roles

For personal data of your clients and staff that you process through the Service, you are the Controller and we are the Processor. The contracting Alignext entity is the legal entity identified in your subscription and on your invoices. We process such data only on your documented instructions, which are constituted by your use of the Service's features and this DPA. For your own account data (owner contact, billing), we act as an independent controller, governed by our Privacy Policy.

2. Subject-matter & details of processing

  • Subject-matter: provision of online booking, CRM, payments/POS accounting, and communications.
  • Duration: for the term of your subscription, plus the retention periods set out below.
  • Nature & purpose: storing and managing bookings, clients, staff, sales and sending transactional/marketing communications you initiate.
  • Categories of data subjects: your clients, your staff.
  • Categories of personal data: names, contact details (email, phone), booking and visit history, notes/tags you record, payment records (amounts, not card data), and message logs.
  • Special categories: none requested by us; if your vertical (e.g. clinics) records health-related booking data, you must ensure an Article 9 condition.

3. Our obligations

  • Process personal data only on your documented instructions, including for transfers, unless required by law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Section 5).
  • Respect the conditions for engaging sub-processors (Section 4).
  • Assist you, taking into account the nature of processing, in responding to data-subject requests and in your obligations under Articles 32–36 GDPR.
  • At your choice, delete or return personal data at the end of the Service (within 30 days, backups expiring on their normal cycle), save where storage is required by law — e.g. tax/accounting records have statutory retention that overrides an erasure request; in that case we pseudonymise the personal data and keep only the figures.
  • Make available the information necessary to demonstrate compliance and allow for audits — conducted no more than once per 12 months on reasonable prior notice (or more often if required by a supervisory authority), subject to confidentiality; we may satisfy an audit with an up-to-date third-party report where available.

4. Sub-processors

You provide general authorisation for us to engage the sub-processors listed in the Annex below. We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and remain liable for their performance. We will inform you of intended changes (additions/replacements) by email to your account address at least 30 days in advance. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the Service.

5. Security measures (Art. 32)

  • Logical separation: each business's data is logically separated from other businesses.
  • Encryption in transit: TLS for all connections.
  • Access control: role-based access on a least-privilege basis.
  • Resilience: regular backups.
  • Monitoring: operational monitoring with personal data minimised in logs.

6. International transfers

Hosting and email are within the EU/EEA. Where a sub-processor is located outside the EEA (e.g. the USA), transfers are made under the EU Standard Contractual Clauses or another valid transfer mechanism, as noted in the Annex.

7. Personal-data breaches

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification obligations under Articles 33–34 GDPR.

8. Data-subject requests

The Service provides export and erasure tools so you can fulfil access, rectification, erasure, portability and objection requests. Where a request reaches us directly for data we process on your behalf, we will refer it to you.

9. Liability, precedence & governing law

This DPA forms part of, and is subject to, our Terms of Service, including their limitation-of-liability provisions. In case of conflict on matters of personal-data processing, this DPA prevails over the Terms of Service. The governing law and jurisdiction are those of the Terms of Service. This DPA takes effect when you accept it in the app and remains in force while you use the Service.

Annex — Sub-processors

We engage a small number of vetted sub-processors, each bound by data-protection terms equivalent to this DPA. The categories below describe their role. A current, named list (with the specific entities and locations) is available to customers on request at privacy@alignext.io; we notify customers of additions or replacements at least 30 days in advance (Section 4).

CategoryPurposeLocationTransfer safeguard
HostingApplication & database hostingEU/EEAEU - n/a
Email deliveryTransactional emailEU/EEAEU - n/a
Content delivery networkStatic asset deliveryEU/global edgeSCCs
Error monitoringDiagnostics & observabilityOutside EEASCCs
AI-assisted featuresOptional AI features (not used for model training)Outside EEASCCs
SMS notificationsTransactional SMS (Ukraine market only)UkraineSCCs
Data Processing Agreement — Alignext | Alignext