1. Parties and relationship
This Data Processing Agreement ("DPA") forms part of the agreement between the practitioner or business customer ("Customer") and Welbeo — legal entity pending registration ("Welbeo"). For Customer Personal Data processed on the Customer's documented instructions, Customer is the controller and Welbeo is the processor, unless applicable law determines otherwise.
Welbeo may separately act as controller for account administration, security, fraud prevention, its own billing, service analytics that do not expose another tenant, legal compliance and other purposes described in the Privacy Policy.
2. Subject matter and duration
Welbeo processes Customer Personal Data to provide practitioner profiles, booking and client management, communications, calendar and messaging integrations, business tools, support and related contracted features. Processing lasts for the term of the Customer's use of the relevant services and any limited period required to return, delete, secure or lawfully retain data afterward.
3. Nature, purpose, data and people
- Processing: collection, organization, storage, retrieval, consultation, transmission, synchronization, support, deletion and other operations needed to provide the service.
- Purposes: appointment management, client administration, practitioner-requested communications and integrations, support and security.
- Data: identity and contact information, booking details, service selections, communications metadata, limited client notes if entered, and feature-specific integration data.
- Data subjects: the Customer's clients, prospects, staff and other people whose data the Customer lawfully submits to Welbeo.
Customers should not use general booking fields to collect unnecessary medical records or other special-category data. Where special-category data is necessary, the Customer is responsible for establishing the applicable Article 9 GDPR condition and giving required notices, while Welbeo applies the protections agreed for the service.
4. Customer instructions
Welbeo will process Customer Personal Data only on documented instructions from the Customer, including instructions expressed through use and configuration of the service, unless Union or Member State law requires processing. If legally permitted, Welbeo will inform the Customer before processing required by law.
If Welbeo believes an instruction infringes applicable data-protection law, it will inform the Customer and may suspend the affected processing while the parties resolve the issue.
5. Confidentiality and access
Welbeo will ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where needed for their role. Administrative and support access is limited and must respect tenant boundaries.
6. Security
Welbeo maintains technical and organizational measures appropriate to the risk, including encrypted transport, authentication, authorization, database row-level security, tenant isolation, restricted service credentials, security headers, logging controls, and encryption of selected credentials and private content.
Security measures are reviewed as the service evolves. The Customer remains responsible for securing its own accounts, devices, user permissions and exports.
7. Subprocessors
Customer gives Welbeo general authorization to use subprocessors needed to provide the service. The current list is published at Subprocessors and service providers. Welbeo will impose data-protection obligations appropriate to the processing on subprocessors acting as processors.
Welbeo will provide reasonable notice of a material new subprocessor where required by Article 28 GDPR so the Customer can raise a reasonable data-protection objection.
8. International transfers
Where Customer Personal Data is transferred outside the EEA, Welbeo will use a lawful transfer mechanism where required, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.
9. Data-subject requests
Taking into account the nature of the processing, Welbeo will provide reasonable assistance to help the Customer respond to requests for access, correction, deletion, restriction, objection or portability where the Customer cannot reasonably fulfill the request using the service. If Welbeo receives a request concerning Customer Personal Data, Welbeo may direct the requester to the Customer unless law requires otherwise.
10. Assistance and compliance
Taking into account the nature of processing and information available to Welbeo, Welbeo will provide reasonable assistance with security obligations, personal-data breach response, DPIAs and prior consultation obligations applicable to the Customer's use of the service.
11. Personal-data breaches
Welbeo will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data and will provide available information reasonably necessary for the Customer to meet its notification obligations. Notification does not constitute an admission of fault or liability.
12. Return and deletion
At the end of the service, Welbeo will delete or return Customer Personal Data in accordance with the service's export/deletion capabilities and documented retention schedule, unless applicable law requires continued retention. Data may remain temporarily in protected backups until normal expiry.
13. Audit information
Welbeo will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Where appropriate, this may include security documentation, questionnaires, certifications or a scoped audit process. Audits must protect other customers, confidential information and platform security and should avoid unnecessary disruption.
14. Precedence and contact
If this DPA conflicts with the commercial agreement on processing of Customer Personal Data, this DPA controls for that subject. Questions may be sent to [email protected].