Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Time2Book Terms of Service (the "Agreement"). It sets out how Time2Book processes personal data for businesses that use the service, as required by Article 28 of the EU General Data Protection Regulation (GDPR).

1. Parties and scope

Processor: MB Timetobook ("Time2Book", "we", "us"), company code 307062655, T. Ševčenkos g. 16k-402, LT-03111 Vilnius, Lithuania. Contact: info@time2book.me.

Controller: the business, sole trader or organisation that opens a business account on Time2Book (the "Business", "you").

  1. This DPA applies whenever Time2Book processes Personal Data on your behalf while providing the Time2Book booking platform, websites, and iOS and Android apps (the "Service").
  2. You accept this DPA by creating a business account or by continuing to use the Service after this DPA is published. No signature is needed.
  3. This DPA stays in force for as long as Time2Book processes Personal Data on your behalf. It survives the end of the Agreement until that data is deleted or anonymised under Section 11.
  4. If this DPA and the Agreement conflict on anything about personal data, this DPA wins.

2. Definitions

Terms not defined here have the meaning given in the Agreement or the GDPR.

  • GDPR: Regulation (EU) 2016/679, plus the national laws that implement or add to it, including the Law on Legal Protection of Personal Data of the Republic of Lithuania.
  • Personal Data: any information about an identified or identifiable natural person that Time2Book processes on your behalf through the Service.
  • Controller, Processor, Data Subject, Processing, Supervisory Authority: as defined in Article 4 of the GDPR.
  • Sub-processor: a third party Time2Book engages that processes Personal Data for the Service.
  • Personal Data Breach: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • Clients: people who book, buy memberships or gift cards, or otherwise use the Business's booking page, including family members and child accounts managed by a parent.
  • Standard Contractual Clauses (SCCs): the clauses approved by European Commission Implementing Decision (EU) 2021/914.

3. Roles of the parties

The Business is the Controller of its Clients' and staff's Personal Data, and Time2Book is its Processor.

  1. You decide why and how your Clients' data is used: what services you offer, what you record about a client, whom you contact and how long you keep the relationship.
  2. We process that data only to run the Service for you. Annex 1 lists the purposes.
  3. We are an independent Controller of the data we process for our own purposes. This covers your account and login details, subscription billing, affiliate programme, product emails to business owners, fraud prevention, and analytics and advertising measurement on the Time2Book websites and apps. Our Privacy Policy describes that processing, not this DPA.
  4. Integrations you connect, such as your own MailerLite account or your own Google Analytics or Google Tag Manager ID on your booking page, are your choice. When you connect one, you instruct us to send Client data to that provider. The provider is your processor, not ours.

4. Your instructions and responsibilities

  1. The Agreement, this DPA and your use of the Service's settings and features are your complete documented instructions to Time2Book. Further instructions need written agreement.
  2. You confirm you have a lawful basis under Article 6 GDPR, and any notices or consents required, for the Personal Data you put into the Service. This includes client data you import from other systems.
  3. Special categories of data. The Service is not designed to hold health, religious, biometric or other special-category data (Article 9 GDPR). Do not enter it in free-text fields such as client notes, service descriptions or booking notes unless you have a valid legal basis and have assessed the risk yourself.
  4. Children. If Clients add child accounts, or you serve minors, you are responsible for getting parental consent where the law requires it.
  5. We will tell you promptly if, in our opinion, an instruction breaks the GDPR.

5. Time2Book's obligations

Time2Book will:

  1. Process Personal Data only on your documented instructions, unless EU or Lithuanian law requires otherwise. In that case we will tell you first, unless the law forbids it.
  2. Make sure everyone authorised to process Personal Data is bound by confidentiality, and give them access only when they need it to run or support the Service.
  3. Apply the technical and organisational measures in Annex 2 (Article 32 GDPR).
  4. Help you, as far as reasonably possible, with data protection impact assessments and prior consultations with a Supervisory Authority (Articles 35-36 GDPR), taking into account the nature of the processing and the information we hold.
  5. Keep a record of the processing we carry out on your behalf (Article 30(2) GDPR).
  6. Not sell Personal Data, and not use your Clients' data to market our own products to them.

6. Security

Time2Book keeps appropriate technical and organisational measures in place to protect Personal Data. They take into account the state of the art, the cost, and the nature, scope and purposes of the processing. Annex 2 lists the current measures. We may update them as long as the overall level of protection does not go down.

7. Personal Data Breaches

  1. We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach that affects your data. This leaves you time to meet your own 72-hour deadline under Article 33 GDPR.
  2. The notice will describe, as far as we know at the time, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the steps we have taken or propose. We will send more information as it becomes available.
  3. We will take reasonable steps to contain the breach and limit its effects.
  4. Notices go to the email address of the Business owner's account.
  5. Notifying you is not an admission of fault or liability.

8. Data Subject requests

  1. Self-service first. You can view, correct and remove Client data in the Service. Clients can edit their own profile and delete their own account in their settings.
  2. If a Data Subject contacts Time2Book directly about data we process for you, we will send them to you and will not answer the request ourselves, unless the law requires us to.
  3. For requests you cannot handle with the Service's features, such as a full export of one Client's data, email info@time2book.me. We will help within a reasonable time, and in any case in time for you to meet the one-month deadline in Article 12(3) GDPR.

9. Sub-processors

  1. You give Time2Book general written authorisation to engage the Sub-processors listed in Annex 3.
  2. Each Sub-processor is bound by a written contract with data protection obligations at least as protective as this DPA. Time2Book remains fully liable to you for its Sub-processors' performance.
  3. Changes. We will give at least 30 days' notice before adding or replacing a Sub-processor. We do this by updating Annex 3 and emailing Business owners.
  4. Objections. You may object in writing to info@time2book.me within those 30 days, on reasonable data protection grounds. We will then discuss a solution in good faith. If we cannot reach one, you may end the affected part of the Service, and we will refund any fees you prepaid for the period after termination.

10. International transfers

Your data is stored in the EU. Our application servers and database are hosted by Hostinger in Lithuania.

  1. Some Sub-processors in Annex 3 are based outside the European Economic Area (EEA), mainly in the United States, or may access data from there.
  2. We transfer Personal Data outside the EEA only when one of these safeguards applies:
    • an adequacy decision under Article 45 GDPR, including the EU-US Data Privacy Framework for US companies certified under it; or
    • the Standard Contractual Clauses (Module 2 or 3, as applicable) together with supplementary measures where needed.
  3. You can ask info@time2book.me for a copy of the relevant transfer safeguards.

11. Deletion and return of data

  1. Before you leave: you can export your invoices as CSV from the Service. For other exports, email info@time2book.me before you delete your account.
  2. Deleting your account: you can delete your business account in Settings at any time. It is deactivated right away. There is a 30-day grace period in which you can ask us to restore it.
  3. After 30 days, we automatically anonymise the business's identifying data and the deleted user accounts, and delete their uploaded images and access tokens.
  4. Kept by law: we may keep invoices and payment records for as long as Lithuanian tax and accounting law requires (generally up to 10 years). They are protected under this DPA and used for no other purpose.
  5. Backups: copies of deleted data can remain in backups until those backups are overwritten in the normal rotation.
  6. Routine clean-up during use: copies of sent emails are deleted after 30 days and in-app notifications after 90 days.

12. Audits

  1. On request, Time2Book will give you the information reasonably needed to show that it complies with Article 28 GDPR and this DPA. This may include completed security questionnaires and Sub-processors' certifications, such as Stripe's PCI-DSS attestation.
  2. If that information is not enough, or a Supervisory Authority requires it, you or an independent auditor bound by confidentiality may audit Time2Book. You must give at least 30 days' written notice, audit no more than once in any 12 months, audit during business hours and keep disruption to a minimum. You pay for the audit.

13. Liability

Each party's liability under this DPA is subject to the limits and exclusions in the Agreement, unless the GDPR does not allow such limits.

14. Governing law and jurisdiction

This DPA is governed by the laws of the Republic of Lithuania. The courts of Vilnius, Lithuania have exclusive jurisdiction, unless the GDPR or the SCCs require otherwise. Time2Book's lead Supervisory Authority is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt).

15. Changes to this DPA

We may update this DPA to reflect changes in the law or in the Service. We will give at least 30 days' notice of material changes by email to Business owners. The version published on this page is the one in force.

Annex 1: Details of processing

Item

Details

Subject matter

Providing the Time2Book online booking, scheduling, payments and client-management Service to the Business

Duration

The term of the Agreement, plus the deletion period in Section 11

Nature and purpose

Taking and managing bookings, class slots and waitlists; sending booking confirmations, reminders and notifications by email and in-app; taking card and terminal payments for the Business; issuing invoices; running memberships and recurring payments; selling and redeeming gift cards; publishing calendar feeds; client records and notes; importing client lists; syncing to integrations the Business connects

Data Subjects

Clients (including family members and child accounts managed by a parent), gift-card recipients, the Business's staff and service providers, visitors to the Business's booking page

Personal Data

Name; email; phone; date of birth (if provided); profile photo; country and time zone; booking history (service, provider, date, time, location, price, attendance, cancellations); memberships and renewals; invoices and payment status; Stripe customer and payment-method references (never full card numbers); gift-card sender and recipient names, email and personal message; policy acceptance date; notes the Business writes about a Client; IP address and browser details

Special categories

None intended. See Section 4.3

Frequency

Continuous, for as long as the Service is used

Annex 2: Technical and organisational measures

  • Hosting: production servers and database in the EU (Hostinger, Lithuania).
  • Encryption in transit: all traffic to the websites, apps and API uses HTTPS/TLS.
  • Passwords: stored only as one-way salted hashes, never in plain text. Sign-in with Google, Apple or Facebook is also available.
  • Access control: each Business can reach only its own Clients, bookings and financial records. Staff permissions are controlled by roles. API access uses revocable personal tokens, which are deleted when an account is deleted.
  • Payment data: card details are entered straight into Stripe (PCI-DSS Level 1) and never touch Time2Book servers.
  • Data minimisation: sent-email copies are deleted after 30 days, in-app notifications after 90 days, and unconfirmed bookings and memberships are cleaned up daily.
  • Deletion: self-service account deletion, with automatic anonymisation after a 30-day grace period.
  • Monitoring: application errors are monitored in real time so incidents are found quickly.
  • Staff access: limited to the people who need it to run and support the Service, who are bound by confidentiality.
  • Backups: regular backups by the hosting provider, kept in the EU.
  • Development: code review and automated tests before each release. Production changes are deployed from version control.

Annex 3: Sub-processors

Last updated: 24 September 2026.

Sub-processor

Purpose

Personal Data

Location

Transfer safeguard

Hostinger, UAB

Application and database hosting, backups

All Service data

Lithuania (EU)

Not needed (EU)

Stripe Payments Europe Ltd. / Stripe, Inc.

Card and terminal payments, recurring billing, connected payout accounts

Name, email, payment details, amounts, what was purchased

Ireland (EU), USA

EU-US DPF, SCCs

MailerSend (MailerLite group)

Sending transactional email (confirmations, reminders, invoices, gift cards)

Name, email, email content

EU

Not needed (EU)

Functional Software, Inc. (Sentry)

Error monitoring

IP address, user ID and email, request data at the time of an error

USA

EU-US DPF, SCCs

Google Ireland Ltd. / Google LLC

Website analytics and ad measurement (Google Analytics, Google Ads); Sign in with Google

Device, browser and usage data, IP address; name and email when signing in with Google

Ireland (EU), USA

EU-US DPF, SCCs

Hotjar Ltd.

Website usage analytics (heatmaps, session recordings)

Device, browser and usage data, IP address

Malta (EU)

Not needed (EU)

Meta Platforms Ireland Ltd.

Ad measurement (Facebook SDK); Facebook login

Device and usage data, IP address; name, email and photo when using Facebook login

Ireland (EU), USA

EU-US DPF, SCCs

OpenAI, L.L.C.

Ad conversion measurement for Time2Book sign-ups (not loaded on Business booking pages)

Hashed email, phone and name, country, page views

USA

EU-US DPF, SCCs

Apple Distribution International Ltd.

Sign in with Apple; iOS app distribution

Name, email (or Apple private relay address)

Ireland (EU), USA

EU-US DPF, SCCs

ip-api.com

Guessing a new user's country from their IP address at sign-up

IP address

Germany (EU)

Not needed (EU)

Integrations you control (not our Sub-processors): if you connect your own MailerLite account, we send your Clients' name, email, phone and booking count to it. If you add your own Google Analytics or Google Tag Manager ID to your booking page, your visitors' browsing data goes to your Google account. You are the Controller of these transfers, and your own agreement with that provider applies.