Data Processing Agreement

Last updated: 25 July 2026

This page is for businesses that use Seatbooker to take bookings. It sets out the terms required by Article 28 of the UK GDPR for the personal data we handle on your behalf. If you are booking an appointment as a customer, the privacy policy is the page you want.

1. This agreement and how it is made

This agreement is between you, the business that has registered an account (the controller), and B McCormack, trading as Seatbooker, Upton, Corsebar Road, Paisley, PA2 9NA (the processor, "we" or "us").

It forms part of our terms and conditions and takes effect when you create a business account. Where this page and the terms conflict on the handling of personal data, this page takes precedence.

Words such as personal data, processing, controller, processor and data subject have the meanings given to them in the UK GDPR and the Data Protection Act 2018.

2. Our two roles, and which applies when

Seatbooker is not only a tool you operate. It is also a platform that customers join in their own right, with their own login, their own booking history across businesses, and a relationship with us that continues whether or not they ever book with you. That means we act in two different capacities, and it matters which one applies.

Where we are your processor

We process the following on your documented instructions and on your behalf:

  • the booking records for appointments made with you
  • notes you or your staff add to a booking
  • your record of customers you have blocked, and any reason you record
  • booking confirmations, cancellations and reminders that we send to your customers in your name

Where we are an independent controller

For the following we decide the purposes and means ourselves, and we are responsible for them under our privacy policy, not under this agreement:

  • a customer's own Seatbooker account and their booking history across the platform
  • the customer trust score, including how it is calculated and shared
  • search, category listings and how businesses are surfaced to customers
  • security, fraud prevention, service improvement and our own website analytics

The practical consequence: instructions you give us under this agreement apply to the first list. They do not let you require us to delete, alter or withhold a customer's own account, their trust score, or their records with other businesses.

3. Details of the processing

Required by Article 28(3) of the UK GDPR.

Subject matterProviding the Seatbooker booking service to your business.
DurationFor as long as your account is active, plus any retention period set out in section 9.
Nature and purposeCollecting, recording, storing, organising, retrieving, transmitting and erasing booking data so that your customers can book appointments with you and you can manage those appointments.
Types of personal dataName, email address, telephone number (where the customer provides one), appointment details (service, date, time, staff member), booking status and history with you, booking notes you add, and any email address and reason on your blocked list.
Categories of data subjectYour customers and prospective customers who make or request bookings with you through Seatbooker.
Data that must not be enteredHealth information, medical details, and financial or payment details must not be recorded anywhere in Seatbooker. See section 8.

4. What we agree to do

We will:

  • Process only on your instructions. We process the data in section 2 only on your documented instructions, including on transfers out of the UK, unless we are required to do otherwise by law. Your use of the service and the settings you choose are your instructions. If we believe an instruction breaches data protection law, we will tell you.
  • Keep it confidential. Anyone we authorise to process the data is under a duty of confidentiality.
  • Keep it secure. We maintain the measures described in section 6, appropriate to the risk, as required by Article 32.
  • Control sub-processors. We engage the sub-processors listed in section 5 on terms no less protective than these, and we remain liable to you for their performance.
  • Help you answer data subjects. Taking account of the nature of the processing, we will help you respond to requests to access, correct, erase, restrict, port or object. Most of this you can do yourself from your dashboard; where you cannot, contact us and we will assist.
  • Help you meet your other obligations. We will assist you with security, breach notification, impact assessments and prior consultation under Articles 32 to 36, taking account of the information available to us.
  • Delete or return the data. On the terms in section 9.
  • Demonstrate compliance. On the terms in section 10.

5. Sub-processors

You give us general authorisation to use the following sub-processors:

Google CloudHosting, database and file storage. Data is held in Google's europe-west2 region (London).
Resend Inc.Delivery of the transactional emails we send to your customers on your behalf. United States, under Standard Contractual Clauses.

If we intend to add or replace a sub-processor we will give you at least 30 days' notice by email. If you reasonably object on data protection grounds, tell us within that period and we will try to find a solution. If we cannot, you may cancel your subscription and we will refund any period you have paid for but not used.

For completeness, two providers are not sub-processors under this agreement. Stripe processes your own billing details, where we are the controller. Google Analytics operates on our website in relation to visitors to seatbooker.co.uk, again where we are the controller. Neither receives the booking data we hold on your behalf.

6. Security

The measures we currently maintain include:

  • encryption in transit using HTTPS, and encryption at rest for the database and file storage
  • passwords stored only as bcrypt hashes, never in a readable form
  • access controls, so a business account can reach only its own data
  • rate limiting on sign-in and other sensitive endpoints, to slow credential guessing
  • sessions revalidated against our records, so access can be withdrawn promptly
  • an audit log of administrative actions
  • alerting on unusual authentication activity
  • a managed, patched hosting platform, with production access limited to the smallest workable number of people

We may change these measures as the service develops, provided we do not materially reduce the level of protection.

7. Personal data breaches

If we become aware of a personal data breach affecting the data we process for you, we will tell you without undue delay and in any event within 72 hours. We will give you what we know about the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we are taking.

Reporting to the Information Commissioner's Office and, where required, to the individuals affected is your responsibility as controller. We will give you reasonable help to do it.

8. Your responsibilities

Data you must not put into Seatbooker

Seatbooker is a booking system, not a clinical or financial record system, and it is not built to hold either. You must not record, in a booking note, a customer name, a blocked list reason, or any other field:

  • health or medical information, including conditions, symptoms, injuries, treatments, medication, diagnoses or clinical notes
  • financial or payment information, including card numbers, bank details and account numbers
  • any other special category data under Article 9 of the UK GDPR, such as information revealing racial or ethnic origin, religious beliefs, sexual orientation or trade union membership

Keep notes to what the appointment needs: the service, the time, and practical arrangements. If you need to hold clinical or payment records, keep them in a system designed for that purpose.

We do not ask for this data and we have no need for it. If we become aware that it has been entered, we may remove it, and we may suspend your account if it continues. Doing so is not a breach of our obligations to you.

Everything else

As controller you are responsible for:

  • having a lawful basis for the personal data you collect and record through Seatbooker, including anything you type into a booking note or a blocked-customer reason
  • giving your customers the information they are entitled to about how you use their data
  • the accuracy of the data you enter, and of any instruction you give us
  • keeping your account credentials secure, and removing staff access promptly when someone leaves
  • your own registration with the Information Commissioner's Office and payment of the data protection fee, if that applies to you

9. Deletion and return

You can export or delete data from your dashboard at any time while your account is active.

When your subscription ends, we will delete or return the personal data we process on your behalf within 90 days of your written request, unless we are required by law to keep it. We keep booking records for up to three years from the appointment date for our own purposes as controller, as explained in our privacy policy, and to defend legal claims.

As set out in section 2, deleting your account does not delete a customer's own Seatbooker account or their history with other businesses, because those are not ours to delete on your instruction.

10. Audits and information

On reasonable written request, and no more than once a year unless there has been a breach affecting your data or the ICO requires it, we will provide the information reasonably necessary to demonstrate our compliance with this agreement.

Where that is genuinely not enough, we will allow an audit by you or an independent auditor you appoint, on at least 30 days' notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or the security and privacy of other customers. You bear the cost unless the audit reveals a material breach of this agreement.

11. International transfers

The booking data we hold for you is stored in the United Kingdom. The one routine transfer outside the UK is to Resend for email delivery, which relies on Standard Contractual Clauses together with the UK Addendum. We will not transfer the data elsewhere without a valid transfer mechanism.

12. Changes to this agreement

We may update this agreement, for example to reflect a change of sub-processor or a change in the law. If a change materially affects your rights we will give you at least 30 days' notice by email, and you may cancel your subscription before it takes effect if you do not accept it.

13. Contact

Data protection questions, requests for assistance, and audit requests: privacy@seatbooker.co.uk.