Data Processing Agreement

Last updated: 2026-08-04

This agreement applies automatically to every customer who processes personal data of their own clients through YourWay CRM. You do not need to sign anything for it to take effect — it forms part of our Terms of Service. If your organisation requires a countersigned copy, contact us at support@yourwaycrm.com.

1. Roles of the Parties

This Data Processing Agreement ("DPA") is made under Article 28 of Regulation (EU) 2016/679 ("GDPR") between:

  • You — the practitioner, practice or organisation using the Service — acting as the Controller.
  • YourWay CRM — acting as the Processor.

You decide why and how your clients' personal data is processed. We process it only to provide the Service to you. Nothing in this DPA transfers controllership of your client data to us.

Where this DPA conflicts with our Terms of Service in relation to the processing of your clients' personal data, this DPA prevails.

2. Subject Matter, Duration, Nature and Purpose

  • Subject matter: provision of appointment scheduling, client record keeping and related practice administration software.
  • Duration: for as long as your account is active, plus the retention period described in section 8.
  • Nature and purpose: storing, organising, retrieving and transmitting client data so that you can run your practice — including sending appointment confirmations and reminders on your behalf.

3. Categories of Data and Data Subjects

Data subjects: your clients, and any staff members you invite to your organisation.

Categories of personal data:

  • Identity and contact details (name, email address, telephone number, address, date of birth)
  • Appointment history, including scheduled, completed and cancelled appointments
  • Session notes and free-text entries you record
  • Files you upload against a client record
  • Session packages and payment status

Special categories (GDPR Article 9): depending on your profession, the above may constitute data concerning health. We process such data solely on your instructions and on the basis that you, as Controller, hold a valid Article 9 condition — normally the explicit consent of your client.

4. Our Obligations as Processor

We undertake to:

  • (a) process personal data only on your documented instructions, including as to transfers, unless required otherwise by EU or Member State law — in which case we will inform you before processing, unless that law prohibits it;
  • (b) ensure that anyone authorised to process the data is bound by an appropriate duty of confidentiality;
  • (c) implement the technical and organisational measures described in section 5;
  • (d) not engage another processor without the authorisation described in section 6;
  • (e) assist you, so far as possible, in responding to requests from data subjects exercising their rights;
  • (f) assist you in complying with your obligations on security, breach notification and data protection impact assessments (GDPR Articles 32–36);
  • (g) at your choice, delete or return the personal data at the end of the Service, as described in section 8;
  • (h) make available the information necessary to demonstrate compliance with Article 28 and allow for audits as described in section 9.

Your use of the Service, and the settings you choose within it, constitute your documented instructions to us.

5. Security Measures

Taking account of the state of the art, the costs of implementation and the risks to data subjects, we maintain the following measures:

  • All traffic encrypted in transit using TLS
  • Passwords stored using one-way hashing, never in readable form
  • Third-party integration credentials you provide stored encrypted in our database
  • Strict logical separation between organisations, so each practice can access only its own data
  • Session notes readable only by the practitioner who wrote them, including in list views
  • Access to production systems limited to personnel who require it
  • Regular security updates and daily backups

6. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. We remain fully liable to you for their performance.

Sub-processor Purpose Location
Hetzner Online GmbH Hosting of the application, database and uploaded files Germany 🇩🇪
Hostinger International Ltd Delivery of transactional email (appointment confirmations and reminders) Lithuania 🇱🇹
Stripe Payments Europe, Ltd. Subscription billing and, where you enable it, online payments from your clients Ireland 🇮🇪

Where you connect your own WhatsApp Business account to send reminders, those messages are sent using your own credentials under your own agreement with that provider. That provider is not our sub-processor.

We will give you reasonable notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the Service.

7. Data Subject Rights and Personal Data Breaches

If one of your clients contacts us directly to exercise their rights, we will not respond on your behalf. We will refer them to you and inform you promptly.

The Service provides export functionality so that you can satisfy access and portability requests yourself. Where you need further assistance, contact us at support@yourwaycrm.com.

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event in time to allow you to meet your own 72-hour obligation under Article 33. Our notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken.

8. Retention, Return and Deletion

You may export your data at any time while your account is active.

After you cancel, your data remains accessible for 30 days so that you can export it. After that period we delete it from our active systems. Residual copies in encrypted backups are removed on the normal backup rotation.

You may request earlier deletion at any time by contacting support@yourwaycrm.com.

9. Audits and Information

On reasonable written request, and no more than once per year unless required by a supervisory authority, we will provide the information necessary to demonstrate our compliance with Article 28. We will cooperate with audits carried out by you or an auditor you mandate, subject to reasonable confidentiality and scheduling arrangements.

10. International Transfers

Your client data is stored within the European Union. Where any sub-processor listed in section 6 processes data outside the European Economic Area, that transfer relies on appropriate safeguards under Chapter V of the GDPR, such as Standard Contractual Clauses or an adequacy decision.

11. Governing Law and Supervisory Authority

This DPA is governed by Greek law and Regulation (EU) 2016/679. The competent supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα).

12. Contact

Questions about this agreement, or requests for a countersigned copy: support@yourwaycrm.com