Data Processing Agreement (DPA)
Last updated: 5 July 2026
This page is an English translation provided for convenience. In case of any discrepancy, the French version is the sole legally binding text. Read the French version
This agreement, entered into pursuant to article 28 of the GDPR, governs the processing by Daytio (processor) of end clients’ personal data on behalf of each registered professional (data controller). It forms an integral part of the contract entered into with the professional.
1. Roles
For end clients’ data entered or collected via the platform (client records, appointments, group first names, addresses for at-home appointments), the professional is the data controller and Daytio (Thomas Bonder, sole trader) acts as processor, on the professional’s documented instructions.
2. Purpose and nature of the processing
Hosting, storage, display and management of appointments and client records; sending confirmation, cancellation and rescheduling emails; synchronising appointments to calendars connected by the professional; automatic anonymisation of inactive records.
3. Data and data subjects concerned
- Data subjects: the professional’s end clients.
- Categories of data: identity (first name, last name), contact details (email, phone), postal address for at-home appointments, appointment history, notes entered by the professional. No sensitive data is requested by the platform; the professional undertakes not to enter any in free-text fields (notes).
4. Daytio’s obligations (as processor)
- Only process data to provide the service;
- Guarantee confidentiality (strict isolation between accounts, encryption in transit, least privilege);
- Assist the professional in responding to requests to exercise rights (access, rectification, erasure, portability);
- Notify the professional without undue delay in the event of a data breach concerning them;
- At the end of the contract: return the data (export) then delete it, in accordance with article 8 of the Terms of Sale.
5. Sub-processors
The professional generally authorises the use of the following sub-processors, which offer appropriate guarantees:
- Supabase (database, authentication, storage — EU, AWS eu-west-1);
- Vercel (application hosting);
- Resend (transactional email sending);
- Google (only if the professional connects Google Calendar).
Any change to this list is notified to the professional, who may raise legitimate objections.
6. Transfers outside the EU
Data is hosted within the European Union. Where certain providers (application hosting, emails) involve a transfer outside the EU, this is governed by the European Commission’s standard contractual clauses entered into with the providers concerned (notably Vercel and Resend).
7. Professional’s obligations (as data controller)
- Have a legal basis for its processing and inform its clients (Daytio’s privacy policy contributes to this information);
- Respond to its clients’ requests to exercise their rights — the platform notably allows it to rectify and delete a client record at any time;
- Not enter sensitive or irrelevant data.
8. Retention period
Unless otherwise instructed by the professional, inactive client records are automatically anonymised 36 months after the last appointment (see the privacy policy).
9. Audit
Daytio makes available the information necessary to demonstrate compliance with this agreement and allows, under reasonable conditions (frequency, notice, confidentiality), the audits required by applicable regulations.