Skip to content

Data Processing Agreement

Version: 1.1 · Effective date: September 11, 2026

1. Roles

This agreement is entered into between the business customer ("Controller") and F9.contact ("Processor"). The Controller determines the purposes and means of processing the personal data of its own clients and staff; the Processor processes that personal data only on the Controller's documented instructions, as set out in this agreement and the platform's configuration.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller for the duration of the subscription and any post-termination retention period, solely to deliver the F9.contact service.

3. Nature and purpose of processing

Processing comprises the storage, organisation, retrieval, transmission and erasure of personal data through booking, client-records, scheduling, point-of-sale and compliance features.

4. Categories of data and data subjects

  • Data subjects: the Controller's clients, staff and workers.
  • Categories: contact details, appointment and transaction history, preferences, optional profile photos and, where the Controller uses clinical features, intake-questionnaire answers that may include special-category health data.

5. Controller and processor obligations

The Controller is responsible for the lawfulness of the data it enters and for having a valid lawful basis for processing. The Processor will process only on documented instructions, ensure persons authorised to process are bound by confidentiality, and assist the Controller in meeting its obligations under Articles 32 to 36.

6. Technical and organisational measures (Art. 32)

The Processor implements measures appropriate to the risk, including:

  • AES-256-GCM envelope encryption of personal data at rest, with a per-record Data Encryption Key wrapped by a Key Encryption Key.
  • A three-tier key hierarchy that isolates business-contact, staff and customer data under separate keys, so that the customer-data key is independent of the keys used for tenant-level data.
  • Keyed-hash lookup of searchable identifiers such as email, so a plaintext email address is never stored.
  • Per-business data isolation, EU-sovereign hosting, append-only audit logging of access, and signed, time-limited URLs for media.

The Privacy Policy records two deliberate exceptions concerning a business's clients, and this agreement records the same. A client's date of birth, where the Controller records one, is stored unencrypted in a table of its own, because its only use is to be searched, compared and sorted by date, which encrypted values cannot be; it is the only detail about the client themselves kept that way, and it sits under the same access controls and EU-sovereign hosting as every other record. The Controller's own operational records about its clients — for example when a client last visited, or which services and professional they prefer — are ordinary business records held in the clear as the Controller's records; they are not part of the encrypted client record.

One further exception concerns the Controller's staff. A professional's public profile — the display name, which the platform fills with the professional's first name when the record is created unless the Controller sets another, the short biography and the photo — exists to be shown on the Controller's public booking page, and is therefore stored unencrypted wherever it is set, whether or not the Controller currently shows that professional on that page. A professional's full name, email address and telephone number stay under the encryption described above.

7. Sub-processing

The Processor may engage sub-processors for infrastructure, storage, email delivery and payment processing. Sub-processors are bound by equivalent data-protection obligations and selected for EU data residency where personal data is involved. The Processor maintains a current list of sub-processors and will inform the Controller of intended changes, giving the Controller the opportunity to object.

8. Assisting with data-subject rights

The platform provides self-service tooling that helps the Controller meet data-subject requests, including data portability (Art. 20) through asynchronous export archives and erasure (Art. 17) through cryptographic destruction of the relevant Data Encryption Key, with the unencrypted date of birth deleted outright in the same operation.

9. Personal-data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification obligations.

10. Return and deletion

On termination, and subject to statutory retention obligations such as Croatian fiscal-record law, the Processor will delete personal data through the platform's retention process. Erasure is performed cryptographically: the relevant Data Encryption Key is destroyed, rendering personal data irrecoverable while legally required structural records are preserved without readable personal content. Data held unencrypted by design is handled as follows: the date of birth is deleted outright in the same operation, with the same effect for the data subject; the Controller's own operational records about a client are not part of erasure and are cleared by the platform's retention process described in this section, not by key destruction; a professional's public profile (see Section 6) is deleted outright in the same operation as the key destruction.

11. Audits

The Processor will make available the information necessary to demonstrate compliance with this agreement and will contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and security safeguards.

12. Effect

This agreement forms part of the Terms of Service. In the event of conflict on data-protection matters, this agreement prevails.