Data Processing Agreement

Version 1.0.1 · Effective

Revision history (1 prior version)
  • v1.0.0 — Initial published version. Promised response and counter-signature times (5, 2 and up to 30 business days, and a counter-signature before the first record) before counsel had set any, offered a pre-signed DPA as a stand-in for a Business Associate Agreement that cannot yet be signed, claimed compliance with four countries' data-protection laws, stated when a SOC 2 observation period begins, named AWS and evidence tooling that are not in place, and offered access to internal security records; corrected in 1.0.1.
Engineering template — counsel review pending. The signed DPA PDF and its response times are set by counsel before Slotlyy publicly launches. Until then, contact [email protected] for the draft template and the signature timeline. This notice is removed once counsel has reviewed the page.

1. When you need a DPA

You need a signed Data Processing Agreement with Slotlyy if any of these apply:

  • Your business is a covered entity under HIPAA (medical practice, dental office, spa/wellness provider handling treatment data, etc.) — a BAA is required in addition to the DPA.
  • Your business is a data controller under Ghana DPA 2012, Nigeria NDPA 2023, Kenya DPA 2019, or POPIA — and Slotlyy is processing personal data on your behalf.
  • Your business's internal procurement / compliance team requires a signed DPA before onboarding to a SaaS platform (typical for enterprise + government-adjacent tenants).
  • You are migrating from a competitor (Fresha / Booksy / Mindbody) that had a DPA with you, and you require the same with Slotlyy as part of the transition.

2. What the DPA covers

Slotlyy's DPA template addresses the standard data-processor obligations:

  • Scope of processing + categories of personal data + categories of data subjects
  • Slotlyy's obligations as processor (security, confidentiality, breach notification)
  • Subprocessor list + 30-day advance-notice commitment for changes
  • Data subject rights handling (access / rectification / erasure / portability per applicable jurisdiction)
  • Technical + organizational security measures (encryption at rest + in transit; access control; audit logging; personnel training)
  • International data transfer mechanisms (Standard Contractual Clauses where applicable; African data residency notes)
  • Audit and inspection rights. Slotlyy holds no SOC 2 report or ISO 27001 certificate of its own today. On request we share the SOC 2 Type II and ISO 27001 reports our infrastructure vendors publish (Supabase, Vercel, Cloudflare). When Slotlyy's own audit reports, its report replaces this clause.
  • Term + termination + post-termination data handling
  • Liability + indemnification

3. Request flow

To request the DPA:

  1. Email [email protected] from your business / billing email address. Include:
    • Your Slotlyy tenant slug (e.g. your-salon-name from your booking URL)
    • Legal entity name + registered address
    • Whether you require a BAA (HIPAA covered entity)
    • Whether you require Standard Contractual Clauses (cross-border data transfer)
  2. Slotlyy replies with the DPA template as a counter-signable PDF and the signature timeline. Response times are set when counsel finalises the DPA, before launch.
  3. Review, sign and return it. Slotlyy counter-signs once counsel has approved the final text, and you keep the executed copy.
  4. The DPA goes into effect on the date of the last signature. No retroactive coverage (per standard contract law); the DPA covers data processing FROM the effective date forward.

4. Covered entities (HIPAA)

A DPA does not replace a Business Associate Agreement. Slotlyy will offer one to covered entities (medical-adjacent salons) once its company registration and its vendors' agreements are complete; it cannot sign one today. If you are a covered entity, email [email protected] with the subject "HIPAA covered entity" and a contact at your organisation, and we will tell you when it is available.

5. Variations + custom terms

Slotlyy's template DPA is designed to be acceptable to the vast majority of tenants without modification. We recognize that some enterprise + regulated tenants have a specific contracting playbook that requires custom language. Slotlyy will consider reasonable custom variations in good faith, but the more the terms deviate from the template, the longer the counter-signature takes, because modified terms go to external counsel.

6. Versioning + future updates

Slotlyy's DPA follows the same versioning convention as every other legal document: semver + ISO effective date + revision history (visible at the top of this page). Material changes to the DPA template trigger 30-day advance notice to all tenants with an executed DPA on file; existing executed DPAs remain in force unchanged unless a new version is mutually signed.

Related documents

Contact

All DPA inquiries: [email protected]

For data subject requests (access / rectification / erasure / portability): [email protected]

For security incidents: [email protected]