piklo booking

Data Processing Agreement

Template · Last updated: 18 May 2026

This data processing agreement ("DPA") is entered into between you as the Data Controller ("the Customer") and Piklo Systems as the Data Processor ("Piklo"). The agreement is entered into automatically when you create an account on Piklo Booking and accept the terms of use.

1. Subject matter and duration

Piklo processes personal data on behalf of the Customer in connection with the provision of the Piklo Booking platform (booking system, client records, payments, SMS/email and calendar management). The agreement runs for as long as the Customer uses Piklo's services.

2. Nature of the processing

  • Storage and structuring of client, booking and payment data
  • Sending email and SMS notifications
  • Online payment facilitation (via Stripe)
  • Operation, maintenance, troubleshooting and logging
  • Backup and security measures

3. Categories of data subjects and data

Data subjects: The Customer's clients, staff and users.
Ordinary data: name, email, phone number, address, booking history, payment method (card data is processed by Stripe, not Piklo).
Sensitive data: Only if the Customer chooses to record health information as internal notes. Such data must be handled with extra care and shared only on a need-to-know basis.

4. Piklo's obligations

Piklo:

  • Processes data only on documented instructions from the Customer (Piklo's terms)
  • Ensures staff confidentiality via NDA
  • Implements appropriate technical and organisational measures (article 32)
  • Assists the Customer in fulfilling requests from data subjects (articles 12-22)
  • Notifies the Customer of data breaches within 24 hours of detection
  • Deletes or returns data upon termination of the contract
  • Makes documentation available for audit

5. Technical and organisational measures

  • HTTPS/TLS encryption in transit
  • Encrypted database storage at Supabase (AES-256)
  • Row-Level Security (RLS) on all data tables
  • Two-factor authentication for staff accounts
  • Append-only audit log on all data-modifying actions
  • Daily backup with 30-day retention
  • Secure deletion upon termination of the contract
  • Encrypted refresh tokens for third-party integrations (AES-256-GCM)

6. Sub-processors

Piklo uses the following approved sub-processors:

  • Supabase Inc.database, auth, storage (EU region, Frankfurt)
  • Vercel Inc.hosting (EU region, Frankfurt)
  • Stripe Payments Europepayments (EU)
  • Resend Inc.transactional email (EU)
  • BulkGate s.r.o.SMS delivery (EU)
  • Sentry GmbHerror monitoring (EU)

Changes to sub-processors are announced with 30 days' notice via email.

7. Transfer to third countries

All sub-processors are primarily located within the EU/EEA. Where data temporarily crosses the border (e.g. during Stripe support), this takes place under the EU's standard contractual clauses (SCCs).

8. Supervision and audit

Once a year the Customer may request documentation of Piklo's security measures. Larger audits are agreed at least 30 days in advance.

9. Liability and compensation

The parties' liability is governed by the general terms of use. Piklo's liability for losses caused by data processing errors is limited to an amount equal to the Customer's payment for the last 12 months.

10. Complaints

You can complain to the Danish Data Protection Agency at datatilsynet.dk if you disagree with Piklo's or the Customer's processing of your personal data.

Signature

The agreement is accepted by creating an account and accepting Piklo's terms. A signed PDF copy can be requested at dpa@piklo.dk.

Piklo Systems · CVR 32709192 · Denmark