Data Processing Agreement
Effective date: 12 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between a Business using MultiBooking ("Controller") and Serhii Miroshnyk, operating MultiBooking, Hviezdoslavov, Slovakia ("MultiBooking" or "Processor").
This DPA applies where MultiBooking processes personal data on behalf of the Business.
1. Scope
The Business acts as Controller for personal data for which it determines the purposes and means of processing.
MultiBooking acts as Processor to the extent it processes such personal data on behalf of the Business.
This DPA does not apply to processing for which MultiBooking independently acts as Controller, including certain processing necessary for MultiBooking account administration, Platform security, fraud prevention and compliance with legal obligations.
2. Compliance with applicable law
Each party will comply with the data-protection laws applicable to its respective role.
For processing subject to the GDPR, this DPA is intended to satisfy the requirements applicable to controller-processor agreements under Article 28 GDPR.
3. Processing instructions
MultiBooking will process Controller Personal Data only:
- to provide and operate the MultiBooking services;
- according to the Business's use and configuration of the Platform;
- according to other documented instructions from the Business; or
- where processing is required by applicable law.
If MultiBooking is legally required to process Controller Personal Data contrary to the Business's instructions, MultiBooking will inform the Business before processing unless prohibited by law.
If MultiBooking reasonably believes that an instruction infringes applicable data-protection law, it may suspend the relevant processing and inform the Business.
4. Confidentiality
MultiBooking will ensure that persons authorised to process Controller Personal Data are subject to appropriate confidentiality obligations.
Access to Controller Personal Data will be limited to persons who reasonably require access to operate, maintain, support or secure the Platform.
5. Security
MultiBooking will implement appropriate technical and organisational measures designed to protect Controller Personal Data.
Measures will take into account:
- the nature of the processing;
- available technology;
- implementation costs;
- the risks associated with the processing;
- the nature of the personal data involved.
Current categories of measures are described in Annex B.
6. Business obligations
The Business is responsible for:
- ensuring that its processing of personal data is lawful;
- providing appropriate privacy information to Customers and employees;
- establishing an appropriate legal basis for processing;
- ensuring that its instructions to MultiBooking comply with applicable law;
- determining appropriate retention periods;
- responding to data-subject requests as Controller;
- controlling access granted to Business Users;
- avoiding unnecessary collection of personal data.
The Business must not instruct MultiBooking to process personal data for unlawful purposes.
7. Special-category data
MultiBooking is designed as a general booking and business-management platform and does not normally require special-category personal data.
The Business should not enter health information or other special-category data unless:
- it is genuinely necessary for its service;
- the Business has an appropriate lawful basis;
- applicable additional GDPR requirements are satisfied; and
- the processing is compatible with the Platform's intended use.
The Business remains responsible for determining whether special-category processing is lawful.
8. Subprocessors
The Business provides general authorisation for MultiBooking to engage subprocessors necessary to provide the Platform.
MultiBooking will require subprocessors processing Controller Personal Data to be subject to data-protection obligations appropriate to the services they provide.
MultiBooking remains responsible for its obligations under this DPA where processing is delegated to a subprocessor to the extent required by applicable law.
Current subprocessors are listed in Annex C.
If a new subprocessor materially affecting Controller Personal Data is added, MultiBooking will make reasonable efforts to provide notice before the change takes effect.
A Business may object to a new subprocessor on reasonable data-protection grounds.
The parties will attempt in good faith to resolve such an objection. If no reasonable alternative is available, either party may terminate the affected services.
9. International transfers
MultiBooking will ensure that transfers of Controller Personal Data outside the EEA are made in accordance with applicable data-protection law.
Where required, appropriate safeguards may include European Commission Standard Contractual Clauses.
Where a subprocessor relies on another lawful transfer mechanism, MultiBooking may rely on that mechanism where legally permitted.
10. Data-subject rights
Taking into account the nature of the processing, MultiBooking will provide reasonable assistance to the Business in responding to requests concerning rights under applicable data-protection law.
These may include requests for:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection.
Where MultiBooking receives a request relating primarily to data controlled by a Business, MultiBooking may refer the requester to the Business and will not independently respond on the Business's behalf unless authorised or legally required.
11. Data-protection impact assessments and regulatory assistance
Taking into account the nature of the processing and information available to MultiBooking, MultiBooking will provide reasonable assistance where the Business is required to:
- conduct a data-protection impact assessment;
- consult a supervisory authority;
- demonstrate compliance concerning processing performed through MultiBooking.
12. Personal-data breaches
MultiBooking will notify the Business without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data.
Where information is available, the notification will include information reasonably necessary to help the Business meet its regulatory obligations.
MultiBooking may provide information in stages where complete details are not immediately available.
Notification of an incident does not constitute an admission of fault or liability.
13. Deletion and return of data
Following termination of the relevant Business account, MultiBooking will, at the Business's choice and where technically and legally feasible, delete or return Controller Personal Data that MultiBooking is no longer required to process.
MultiBooking may retain information:
- where required by applicable law;
- where it independently acts as Controller;
- in secure backups until overwritten in the ordinary backup cycle.
Any retained Controller Personal Data remains subject to applicable protection obligations.
14. Audit and compliance information
MultiBooking will make information reasonably necessary to demonstrate compliance with this DPA available to the Business.
Where such information is insufficient, the Business may request a reasonable audit relating specifically to processing under this DPA.
Audits must:
- be proportionate;
- protect the security and confidentiality of other customers;
- avoid unnecessary disruption;
- ordinarily occur no more than once in a 12-month period unless required by a supervisory authority or following a material security incident;
- be subject to reasonable confidentiality requirements.
Where an audit creates substantial costs beyond ordinary compliance assistance, the parties may agree reasonable reimbursement of those costs.
15. Order of precedence
If there is a conflict concerning processing of Controller Personal Data:
- mandatory data-protection law applies first;
- this DPA applies second;
- the MultiBooking Terms & Conditions apply third.
16. Duration
This DPA remains in effect for as long as MultiBooking processes Controller Personal Data on behalf of the Business.
Provisions that by their nature should survive termination remain effective for as long as relevant personal data continue to be processed.
17. Governing law
Unless mandatory data-protection law requires otherwise, this DPA is governed by the laws of the Slovak Republic.
Annex A — Details of Processing
Subject matter
Provision of the MultiBooking booking, scheduling, customer-management and Business-management Platform.
Duration
For the duration of the Business's use of MultiBooking and for any limited period thereafter required for deletion, backup expiry, legal obligations or legitimate technical purposes.
Nature of processing
Processing may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- updating;
- transmission;
- restriction;
- deletion.
Purposes
Processing personal data as necessary to:
- maintain Business and employee records;
- manage services;
- maintain schedules and availability;
- create and manage Bookings;
- manage Customer records;
- send Booking-related communications;
- operate relevant Business functionality;
- secure and maintain the service.
Categories of data subjects
May include:
- Customers;
- prospective Customers;
- Business owners;
- Business administrators;
- managers;
- employees;
- other authorised Business personnel.
Categories of personal data
May include:
- names;
- email addresses;
- telephone numbers;
- addresses where provided;
- Business roles;
- employee profiles;
- photographs;
- working schedules;
- availability and absence information;
- service information;
- Booking dates and times;
- Booking status;
- Booking history;
- Customer notes and related operational information;
- technical identifiers relevant to Platform operation.
Special-category data
Not required by default.
Special-category data may only be processed where independently introduced by the Business or Customer and where the Business has determined that such processing is lawful and necessary.
Annex B — Technical and Organisational Measures
Access control
- authenticated Platform access;
- role-based Business permissions;
- restriction of administrative access;
- controlled production access.
Transmission security
- encrypted HTTPS/TLS communications;
- secure connections between Platform components where supported.
Application security
- input validation;
- authentication and authorisation controls;
- security-related logging;
- dependency and software maintenance;
- controlled deployment processes.
Infrastructure security
- managed infrastructure providers;
- network and application security controls;
- environment separation where appropriate;
- secrets and credential management.
Availability and recovery
- data backups where appropriate;
- recovery procedures;
- infrastructure monitoring.
Organisational controls
- confidentiality obligations;
- access based on operational need;
- incident handling procedures;
- review of provider access and security requirements.
Security measures may evolve as technology, risk and the Platform change.
Annex C — Current Subprocessors
| Provider | Purpose |
|---|---|
| Railway | Application hosting, compute, databases and related infrastructure |
| Cloudflare | DNS, network delivery, security and related infrastructure |
| Cloudinary | Storage, transformation and delivery of images and media |
| Resend | Transactional email delivery |
| Google / Firebase | Mobile services, push-notification infrastructure, tag management and related functionality as configured |
MultiBooking may replace or add providers as the Platform evolves, subject to the subprocessor provisions of this DPA.