This document is the contract required by article 28.3 of Regulation (EU) 2016/679 (GDPR) between the business that uses Bellioo and the provider of the platform. It forms part of the Business terms and is accepted on sign-up.
- Controller: the business that uses Bellioo (the "Business").
- Processor: Peacock Digital LLC, a company formed in the State of Florida, United States, with its registered address at 1032 E Brandon Blvd, #7001, Brandon, FL 33511, United States, and EIN 37-2167612 ("Bellioo"). We are appointing a representative in the European Union under article 27 of the GDPR; we will publish their details in the Legal notice as soon as the appointment is made.
1. Subject matter, duration, nature and purpose
Bellioo processes on the Business's behalf, and on its instructions, the personal data the Business enters or generates in the Service about its clients and contacts, for the sole purpose of providing it with the Service described in the Business terms: calendar, bookings, client management, reminders, communications, loyalty and statistics. The operations are hosting, storage, organisation, retrieval, communication by email and WhatsApp, production of statistics for the Business and erasure.
The processing lasts as long as the contract and ends with the deletion or return of the data under section 8.
2. Which data and whose
| Categories of data subjects | Categories of data |
|---|---|
| The Business's clients and prospective clients, including those who book as guests | Name, email, phone number, appointment history, services booked, amounts, attendance status, internal notes written by the Business's team, communication preferences, loyalty cards and stamps, block status |
| The Business's staff | Name, email, phone number, working hours, role and permissions |
Special categories. The Business will not process in Bellioo health data or other categories under article 9 of the GDPR in free-text fields such as client notes, except what is strictly essential to provide the service, with the client's explicit consent. The platform is not designed or secured for it, and doing so is the Business's decision and responsibility.
3. Bellioo's obligations as processor
In accordance with article 28.3 of the GDPR, Bellioo:
- Processes the data only on the Business's documented instructions, including as regards international transfers. These terms and the normal use of the Service are the initial instructions. If a Union or Member State law requires Bellioo to do otherwise, it will inform the Business beforehand, unless that law prohibits it. Bellioo will inform the Business if it considers an instruction infringes the regulations.
- Does not use the data for its own purposes, except what is necessary to operate, secure and improve the Service in aggregate or anonymised form, and what the law requires. It never uses it to sell to the Business's clients or to steer them to another business.
- Confidentiality: ensures that persons authorised to process the data have committed themselves to confidentiality.
- Security (article 32): encryption in transit and at rest, role-based access control, isolation between businesses, audit logging of relevant actions, encrypted backups, separation of environments, incident logging and vulnerability management.
- Notifies the Business without undue delay, and in any event within 48 hours of becoming aware, of any security breach affecting the Business's data, with the information available so the Business can comply with article 33.
- Assists the Business in responding to data subjects' rights (access, rectification, erasure, portability, objection, restriction) with the Service's features and, where they are not enough, with its reasonable help. If a data subject contacts Bellioo, Bellioo will inform the Business.
- Assists the Business with security, breach notification, impact assessments and prior consultations (articles 32 to 36), taking into account the nature of the processing and the information available to it.
- Returns or deletes the data at the end of the contract, at the Business's choice, under section 8.
- Makes available to the Business the information necessary to demonstrate compliance with these obligations and allows audits under section 6.
- Keeps a record of the categories of processing activities carried out on the Business's behalf.
4. Authorised sub-processors
The Business gives Bellioo general authorisation to engage the sub-processors in this table. Bellioo will inform the Business of any addition or replacement by email at least 30 days in advance; the Business may object on justified grounds and, if there is no alternative, terminate the contract without penalty. Bellioo imposes on each sub-processor obligations equivalent to those in this contract and is responsible for their compliance.
| Sub-processor | Service | Location | Transfer safeguard |
|---|---|---|---|
| DigitalOcean | Hosting of the application, the database and files | European Union (Frankfurt) | No transfer |
| Vercel | Hosting of the website and of business websites | United States and global network | DPF or standard contractual clauses |
| Stripe | Charging the subscription | Ireland and United States | DPF or standard clauses |
| Resend | Sending emails | United States | DPF or standard clauses |
| Zernio | Sending WhatsApp messages, only if the Business turns the channel on | Spain | No transfer |
| Meta Platforms | Delivering WhatsApp messages | Ireland and United States | DPF |
| Geocoding of addresses | United States | DPF | |
| Anthropic PBC | BellIA assistant, only if the Business's team uses it, and first explanation of technical errors with anonymised text | United States | DPF or standard clauses |
| Slack | Internal technical alerts | United States | DPF |
5. International transfers
Data is hosted in the European Union. Bellioo is established in the United States, so processing on the Business's behalf is in itself an international transfer, in addition to those of the sub-processors in the table above. All of them are covered by an adequacy decision, including the EU-US Data Privacy Framework for certified entities, or by the standard contractual clauses approved by the European Commission (Decision 2021/914) with appropriate supplementary measures, which Bellioo will provide to the Business on request. As controller, the Business must reflect this transfer in its own record of processing activities.
6. Audit
Bellioo will provide the Business with the security documentation it holds. The Business may request an audit once a year, or after a security breach affecting it, with 30 days' notice, during working hours, without interrupting the Service and without access to other businesses' data, bearing its cost unless it reveals a material breach by Bellioo.
7. The Business's obligations
The Business provides its clients with the information the GDPR requires, has a legal basis for each processing activity and for each marketing communication, handles data subjects' rights, ensures the accuracy of the data, does not enter data it is not entitled to process, and uses the Service in accordance with the regulations.
8. End of processing
On termination of the contract, the Business may obtain a copy of its data in a commonly used electronic format for 30 days. Afterwards, Bellioo will delete or anonymise the data, except what it must keep by legal obligation, which will remain blocked until the relevant liabilities expire.
9. Liability
Each party is liable for its own infringements under article 82 of the GDPR. Bellioo's liability to the Business is limited as provided in the Business terms.