Data Processing Agreement

Effective date: August 14, 2026

1. Scope and Parties

This Data Processing Agreement (“DPA”) forms part of the Cartoply Terms of Service between Cartoply (“Processor”) and the customer accepting those Terms (“Controller”), and applies where and to the extent Cartoply processes personal data on the Controller's behalf that is subject to the EU or UK General Data Protection Regulation or similar data protection laws (“Data Protection Laws”).

In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of personal data.

2. Details of Processing

Subject matter and duration. Processing of personal data necessary to provide the scheduling Service, for the duration of the Controller's account plus the retention period described in the Privacy Policy.

Nature and purpose. Hosting booking pages; collecting appointment bookings; routing bookings to team members; sending booking-related emails; syncing bookings to calendars and integrations the Controller enables.

Categories of data subjects. The Controller's team members, and prospects or customers who book appointments through the Controller's booking pages (“guests”).

Categories of personal data. Names, email addresses, phone numbers, appointment times, service addresses, and answers to intake questions the Controller configures. The Controller agrees not to collect special categories of data or regulated data (including protected health information) through the Service, per the Terms of Service.

3. Processor Obligations

Cartoply will:

  • Process personal data only on the Controller's documented instructions — which are the Terms of Service, this DPA, and the Controller's configuration of the Service — unless required by law to do otherwise, in which case Cartoply will inform the Controller unless legally prohibited
  • Ensure persons authorized to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organizational measures, including encryption in transit (TLS), encrypted storage of credentials and tokens, and role-based access controls
  • Assist the Controller, insofar as reasonably possible, in responding to data subject requests (access, correction, deletion, portability, objection)
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Controller or its mandated auditor, at the Controller's expense and with reasonable notice, no more than once per year absent a demonstrated breach

4. Subprocessors

The Controller grants Cartoply general authorization to engage subprocessors to provide the Service. Current subprocessors are: Vercel (web hosting), Railway (API and database hosting), Resend (transactional email), Cloudflare (bot protection), Google (calendar sync, where enabled; analytics), Microsoft (calendar sync, where enabled), Stripe and PayPal (payments, where enabled), and Jobber (where the Controller connects it).

Cartoply will impose data protection obligations on subprocessors no less protective than those in this DPA and remains liable for their performance. Cartoply will notify the Controller of intended additions or replacements (by updating this page and, for material changes, by email), and the Controller may object on reasonable data-protection grounds within 30 days; if the objection cannot be resolved, the Controller may terminate the affected services.

5. International Transfers

Personal data is stored and processed in the United States. Where Data Protection Laws require a transfer mechanism for personal data originating in the EEA, UK, or Switzerland, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor), with the Controller as data exporter and Cartoply as data importer, together with the UK Addendum where applicable.

6. Deletion and Return

Upon termination of the Controller's account, Cartoply will delete personal data processed on the Controller's behalf in accordance with the retention schedule in the Privacy Policy (30 days), unless retention is required by law. Before deletion, the Controller may request an export of its data by contacting hello@cartoply.com.

7. Controller Obligations

The Controller is responsible for the lawfulness of the personal data it collects through the Service, including having a lawful basis for collection, providing required notices to guests, and ensuring the intake questions it configures do not solicit data prohibited by the Terms of Service.

8. Contact

Questions about this DPA, subprocessors, or to request a countersigned copy? Reach us at hello@cartoply.com.