Legal

Data Processing Agreement

Effective Date: 23 May 2026

This Data Processing Agreement (the “DPA”) forms an integral part of, and is governed by, the Terms and Conditions for Businesses Using Book2befit(the “Principal Agreement”) entered into between Alveras Ltd., a company registered under the Commercial Law of the Republic of Bulgaria with UIC 206057241, with its seat at Sofia, Yuzhen Park 24, Bulgaria (“Book2befit”), and the business, organisation or self-employed person that has accepted the Principal Agreement (the “Business”). Book2befit and the Business are each a “Party” and together the “Parties”.

This DPA records the Parties’ agreement with respect to the Processing of Business Personal Data by Book2befit on behalf of the Business in connection with the Principal Agreement, as required by Article 28(3) of the GDPR. By accepting the Principal Agreement, the Business accepts this DPA. No separate signature is required; however, either Party may request a counter-signed copy.

BACKGROUND

(A) In providing the Platform under the Principal Agreement, Book2befit Processes Personal Data relating to the Business’s clients and other individuals on behalf of the Business.

(B) In respect of that Personal Data, the Business acts as the Controller and Book2befit acts as the Processor.

(C) The Parties wish to set out the terms governing Processing in accordance with Regulation (EU) 2016/679 (the GDPR) and the applicable data protection law of the Republic of Bulgaria.

1. Definitions and Interpretation

1.1. In this DPA, the following terms have the following meaning; capitalised terms not defined here have the meaning given in the Principal Agreement:

“Controller” means the Business, which determines the purposes and means of the Processing of Business Personal Data.

“Processor” means Book2befit, which Processes Business Personal Data on behalf of the Controller.

“Business Personal Data” means any Personal Data Processed by Book2befit or a Sub-Processor on behalf of the Business pursuant to or in connection with the Principal Agreement, as described in Schedule 1.

“Data Protection Law” means the GDPR and all data protection and privacy law applicable to the Processing, including the Bulgarian Personal Data Protection Act and any law amending, replacing or supplementing them.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).

“Data Subject”means the individual to whom Business Personal Data relates, including the Business’s clients, prospective clients and other individuals whose data is Processed through the Platform.

“Sub-Processor” means any person (including any third party and any affiliate of Book2befit) appointed by or on behalf of Book2befit to Process Business Personal Data on behalf of the Business.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Business Personal Data.

“Restricted Transfer” means a transfer of Business Personal Data to, or access to it from, a country outside the European Economic Area that is not subject to an adequacy decision of the European Commission.

“EEA” means the European Economic Area.

“Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, as amended or replaced from time to time.

1.2. The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “special categories of personal data” and “Supervisory Authority” have the meaning given in the GDPR, and cognate terms are construed accordingly.

1.3. In the event of a conflict between this DPA and the Principal Agreement in matters of Processing of Business Personal Data, this DPA prevails. In all other matters the Principal Agreement continues to apply.

2. Roles of the Parties and Scope

2.1. The Parties acknowledge that, for the purposes of Data Protection Law in respect of the Processing of Business Personal Data under the Principal Agreement, the Business is the Controller and Book2befit is the Processor.

2.2. The Business retains control of the Business Personal Data and remains responsible for its compliance obligations as Controller, including establishing and maintaining a lawful basis for the Processing, ensuring the lawfulness of the instructions it gives, providing all required information and notices to Data Subjects, and handling Data Subject requests and complaints.

2.3. The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are described in Schedule 1. Book2befit Processes Business Personal Data only as Processor on behalf of the Business and not for its own purposes, except to the extent expressly set out in clause 2.4.

2.4. Processing carried out by Book2befit as Controller is outside the scope of this DPA and is governed by the Book2befit Privacy Policy. This may include Processing necessary for Book2befit’s own business administration, billing and invoicing, account management, security, fraud prevention, legal compliance, support communications, service improvement using aggregated or anonymised data, and management of Book2befit’s direct relationship with Business account owners and Staff as platform users.

2.5. Where Staff data is entered by the Business into the Platform for scheduling, access management, coach allocation, attendance records or similar functionality for the Business, Book2befit Processes such data as Processor. Where Staff interact directly with Book2befit for account administration, authentication, support, billing, security, legal compliance or similar purposes, Book2befit may Process the relevant data as Controller.

3. Processing of Business Personal Data

3.1. Book2befit shall Process Business Personal Data only on the documented instructions of the Business, including with regard to Restricted Transfers, unless required to Process by a law to which Book2befit is subject; in such a case Book2befit shall, to the extent permitted by that law, inform the Business of that legal requirement before Processing.

3.2. The Principal Agreement, this DPA and the Business’s configuration and use of the Platform constitute the Business’s documented instructions for the Processing. Additional instructions must be agreed in writing and may be subject to adjustment of fees or timelines where they require effort beyond the standard functionality of the Platform.

3.3. Book2befit shall inform the Business if, in its opinion, an instruction infringes Data Protection Law, without being obliged to carry out a comprehensive legal review of the Business’s instructions or Processing purposes.

3.4. The Business shall provide special categories of personal data to Book2befit only through the fields and features the Platform provides for that purpose, and shall not place health, medical, disability, injury, pregnancy or similar special-category information in general free-text fields. The Business remains solely responsible for ensuring that any such Processing is necessary and proportionate and is supported by a valid lawful basis and, where required, explicit consent or another applicable condition under Article 9 of the GDPR, together with the required transparency notices.

3.5. Emergency contact details are not special categories of personal data merely because they are emergency contact details, but the Business shall nonetheless Process them lawfully, fairly and transparently, use special-category and sensitive fields only where genuinely necessary for the provision, safety or administration of its services, keep such information accurate, and delete or anonymise it when no longer necessary.

4. Book2befit Personnel

4.1. Book2befit shall ensure that access to Business Personal Data is limited to those of its personnel who need access to it for the provision, maintenance, security or support of the Platform, and shall ensure that such persons are bound by appropriate obligations of confidentiality, whether contractual or statutory.

5. Security of Processing

5.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing, as well as the risks for the rights and freedoms of Data Subjects, Book2befit shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR. The measures in place as at the date of this DPA are described in Schedule 2.

5.2. Book2befit may update or modify the security measures from time to time, provided that such updates do not materially reduce the overall level of security of the Business Personal Data.

5.3. The Business is responsible for configuring the Platform securely within its own account, including managing Staff permissions, removing access for Staff who no longer need it, keeping login credentials confidential, using available security features, and ensuring that data is entered only where necessary.

6. Sub-Processing and Payment Service Providers

6.1. The Business grants Book2befit general written authorisation to engage Sub-Processors to Process Business Personal Data for the provision, security, support and improvement of the Platform. The Sub-Processors and relevant categories authorised as at the date of this DPA are listed in Schedule 3.

6.2. Book2befit shall maintain an itemised list of Sub-Processors and shall make the current list available to the Business on request or through the Platform or Book2befit website. The list shall identify, at least, the Sub-Processor, the relevant service or function, and the location or transfer mechanism where reasonably available.

6.3. Book2befit shall inform the Business of any intended addition or replacement of a Sub-Processor, thereby giving the Business the opportunity to object on reasonable data-protection grounds within ten (10) calendar days from the notice, unless a shorter period is necessary due to security, continuity or legal reasons. If the Business raises a reasonable objection that cannot be resolved, either Party may terminate the affected part of the Platform or the Principal Agreement as its sole remedy in respect of that objection.

6.4. Book2befit shall impose on each Sub-Processor, by a written contract, data-protection obligations that are in substance no less protective than those set out in this DPA, and shall remain fully liable to the Business for the performance of each Sub-Processor’s obligations, to the extent required by Article 28 of the GDPR.

6.5. Payment service providers, including Stripe, may Process certain Personal Data as independent controllers, processors or service providers depending on the relevant payment flow, connected-account configuration and applicable payment-service terms. To the extent Stripe or another payment service provider Processes Business Personal Data on behalf of Book2befit for the provision of the Platform, it is treated as a Sub-Processor. To the extent such provider Processes Personal Data as an independent or separate controller, such Processing is governed by its own terms and privacy documentation and is outside the scope of this DPA.

6.6. The Business is responsible for providing all notices, obtaining all consents and maintaining all lawful bases required for payment-related Processing performed in connection with its Stripe connected account, client payments, refunds, chargebacks, verification, fraud prevention and compliance obligations, except to the extent Book2befit is independently responsible under Data Protection Law for its own controller Processing.

7. Data Subject Rights

7.1. Taking into account the nature of the Processing, Book2befit shall assist the Business by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Business’s obligation to respond to requests by Data Subjects exercising their rights under Data Protection Law, including through the self-service, correction, deletion and export functionality of the Platform where available.

7.2. Book2befit shall promptly notify the Business if it receives a request from a Data Subject in respect of Business Personal Data, and shall not respond to that request itself except on the documented instructions of the Business or as required by a law to which Book2befit is subject. Book2befit may respond to confirm that the request should be addressed to the Business where appropriate.

8. Assistance to the Business

8.1. Book2befit shall provide the Business with reasonable assistance, taking into account the nature of the Processing and the information available to Book2befit, with the Business’s obligations relating to the security of Processing, notification of Personal Data Breaches, data protection impact assessments and prior consultation with a Supervisory Authority under Articles 32 to 36 of the GDPR.

8.2. Assistance requiring material work outside the standard functionality of the Platform may be subject to reasonable fees, unless the assistance is required due to Book2befit’s breach of this DPA or Data Protection Law.

9. Personal Data Breach

9.1. Book2befit shall notify the Business without undue delay after becoming aware of a Personal Data Breach affecting Business Personal Data, and shall provide the Business with information reasonably available to Book2befit to enable the Business to meet its obligations to notify the Supervisory Authority and, where applicable, Data Subjects.

9.2. The notification shall, where reasonably available at the time, describe the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address and mitigate the breach. Book2befit may provide this information in phases where all details are not immediately available.

9.3. Book2befit shall co-operate with the Business and take such reasonable steps as are directed by the Business to assist in the investigation, mitigation and remediation of the Personal Data Breach. Book2befit’s notification of or response to a Personal Data Breach shall not be construed as an acknowledgement by Book2befit of any fault or liability.

10. Deletion or Return of Business Personal Data

10.1. On termination of the Principal Agreement, or earlier on the Business’s written request, Book2befit shall, at the choice of the Business, delete or return all Business Personal Data and delete existing copies, unless storage is required by a law to which Book2befit is subject.

10.2. The Business may export Business Personal Data through the Platform during the term and during the post-termination period described in the Principal Agreement. After expiry of that period Book2befit shall delete or anonymise the Business Personal Data within a reasonable time, except for data that must be retained by law or for the establishment, exercise or defence of legal claims, which Book2befit shall continue to protect in accordance with this DPA for as long as it is retained.

10.3. Deletion or return obligations do not apply to anonymised data that no longer constitutes Personal Data, or to back-up copies that are overwritten in accordance with Book2befit’s ordinary backup cycle, provided that such copies remain protected and are not actively Processed except for restoration, continuity, security or legal purposes.

11. Audit and Records

11.1. Book2befit shall make available to the Business information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Business or an auditor mandated by the Business.

11.2. Audits shall be conducted on reasonable prior written notice, no more than once in any twelve-month period, save where required by a Supervisory Authority or following a Personal Data Breach affecting Business Personal Data. Audits shall take place during business hours, in a manner that does not disrupt Book2befit’s operations or compromise the confidentiality, availability or security of the Platform or the data of other customers, and subject to appropriate confidentiality undertakings.

11.3. Book2befit may satisfy an audit request by providing existing third-party certifications, reports, security summaries, policies or audit responses where these reasonably address the request. Book2befit shall not be required to disclose source code, trade secrets, security-sensitive information, information relating to other customers, privileged materials, or third-party confidential information, except to the extent strictly required by Data Protection Law and subject to appropriate safeguards.

12. International Transfers

12.1. Book2befit shall not carry out a Restricted Transfer of Business Personal Data without ensuring that an appropriate transfer mechanism under Data Protection Law is in place, such as an adequacy decision, a valid certification framework, the Standard Contractual Clauses, or another lawful transfer mechanism, together with any supplementary measures required by Data Protection Law.

12.2. Where the Standard Contractual Clauses apply to a Restricted Transfer from Book2befit to a Sub-Processor, the applicable module shall be Module Three (Processor to Processor), unless another module is required by the circumstances of the transfer. Where the Standard Contractual Clauses apply to any other Restricted Transfer under this DPA, the module corresponding to the actual roles of the Parties shall apply.

12.3. For the purposes of the Standard Contractual Clauses, the information in Schedules 1, 2 and 3 shall be used to complete the relevant annexes, the governing law shall be the law of the Republic of Bulgaria where the SCCs permit this choice, and the competent Supervisory Authority shall be the Bulgarian Commission for Personal Data Protection, unless another EU Supervisory Authority is competent under Data Protection Law.

12.4. If a transfer mechanism relied upon for a Restricted Transfer is amended, replaced, invalidated or determined by a competent authority to be insufficient, the Parties shall cooperate in good faith to implement an alternative lawful transfer mechanism or supplementary measures where reasonably required.

13. Liability

13.1. Each Party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, and any reference in the Principal Agreement to a Party’s liability means the aggregate liability of that Party under the Principal Agreement and this DPA together.

13.2. Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under Data Protection Law, including the mandatory liability regime under Article 82 of the GDPR where applicable.

14. General

14.1. This DPA takes effect on the date the Business accepts the Principal Agreement and continues for as long as Book2befit Processes Business Personal Data on behalf of the Business. Provisions that by their nature should survive termination survive.

14.2. If any provision of this DPA is found to be invalid or unenforceable, the remainder is unaffected and the invalid provision is replaced by a valid provision reflecting the Parties’ intention as closely as possible.

14.3. Notices under this DPA are given in writing through the Platform or by e-mail to privacy@book2befit.comfor Book2befit and to the e-mail address registered for the Business’s account.

14.4. This DPA is governed by the law of the Republic of Bulgaria, and the courts competent under the Principal Agreement have jurisdiction, without prejudice to mandatory rules of Data Protection Law.

Schedule 1 – Details of the Processing

Subject-matter: the provision, maintenance, support and security of the Book2befit Platform to the Business under the Principal Agreement.

Duration: the term of the Principal Agreement and any post-termination export, backup, deletion or legal-retention period described in the Principal Agreement or this DPA.

Nature and purpose: hosting, storage and Processing of Personal Data to operate scheduling, bookings, member and client management, payment facilitation, communications, check-in functionality, waitlists, memberships, attendance records, analytics, reporting, support, security and related Platform functionality on behalf of the Business.

Frequency:continuous for the duration of the Business’s use of the Platform and otherwise as required for the relevant Platform functionality.

Categories of Data Subjects:the Business’s clients and prospective clients; persons for whom a booking is made; parents or guardians where relevant; emergency contacts where recorded by the Business; and Staff configured on or using the Platform in connection with the Business.

Types of Personal Data: identification and contact data, such as name, e-mail address and telephone number; account, booking, waitlist, attendance, check-in, membership, pass, credit and session history; communications and correspondence; staff role and access data; payment status, transaction reference, invoice or receipt information and other payment-related metadata, but not full card details unless expressly made available through the payment provider; and Platform usage or audit data insofar as Processed on behalf of the Business.

Optional and special-category data: where the Business chooses to record it, optional notes, health-related notes, injury or limitation information, accessibility or participation requirements and similar information, which may constitute special categories of personal data. The Business is solely responsible for the lawful basis, necessity assessment, transparency notice and any explicit consent or other Article 9 condition required for such Processing.

Schedule 2 – Technical and Organisational Security Measures

Book2befit implements and maintains appropriate technical and organisational measures, which include, as appropriate to the nature of the relevant Processing and Platform functionality:

  • encryption of Personal Data in transit and, where appropriate, at rest;
  • access controls, authentication and the principle of least privilege for personnel and systems;
  • logical separation of customer data within the Platform;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems;
  • regular backup and the ability to restore availability and access to Personal Data in a timely manner following an incident;
  • logging and monitoring of relevant access and activity;
  • vulnerability management and timely application of security updates;
  • incident detection, escalation and response processes;
  • use of vetted Sub-Processors and service providers subject to appropriate contractual safeguards;
  • internal policies and confidentiality obligations binding on personnel;
  • processes for testing, assessing and evaluating the effectiveness of the measures.

The specific measures may evolve over time provided the overall level of security of Business Personal Data is not materially reduced.

Schedule 3 – Authorised Sub-Processors and Payment Service Providers

As at the date of this DPA, Book2befit engages or may engage the following Sub-Processors and service-provider categories to Process Business Personal Data for the provision, security, support and operation of the Platform. Book2befit shall maintain a current itemised list and make it available to the Business in accordance with clause 6.

A. Identified provider

Stripe– payment processing and payment-related services. Stripe may Process payment-related Personal Data for client payments, refunds, chargebacks, fraud prevention, verification, connected-account functionality and platform billing. Stripe may act as an independent controller, separate controller, processor or service provider depending on the payment flow, connected-account configuration and applicable Stripe terms. To the extent Stripe Processes Business Personal Data on behalf of Book2befit for the provision of the Platform, it is treated as a Sub-Processor under this DPA.

B. Provider categories to be itemised and kept current by Book2befit

  • Cloud hosting and infrastructure– hosting the Platform, storing Business Personal Data, backups, infrastructure security and availability.
  • Transactional email and communications– delivering booking confirmations, reminders, operational messages, account and support communications.
  • Analytics and reporting– supporting dashboard functionality, operational analytics, reporting, product diagnostics and service improvement, to the extent involving Business Personal Data.
  • Security, monitoring and error-reporting tooling– detecting errors, monitoring availability, maintaining security, logging incidents and supporting incident response.
  • Customer support and administrative tooling– managing support requests, account administration and operational communications, to the extent involving Business Personal Data.

The current itemised list of Sub-Processors, including provider identity, role or function, processing location and applicable transfer mechanism where reasonably available, is maintained separately by Book2befit and is made available to the Business in accordance with clause 6. Book2befit shall update the list when providers are added or replaced.