Hopp til innholdet

Data Processing Agreement

Version 1.0 · in force from 2026-09-10

This is the agreement article 28 of the GDPR requires between a controller and a processor. It applies to the personal data your customers leave on your Buzzlink page.

It is in force automatically from the moment you create a Buzzlink account, and it forms part of the Terms of Service. It does not have to be signed to be valid — the GDPR accepts electronic form (art. 28.9) — but the fields below are here so you can print it, fill them in and send it on.

That is what it is for. When a municipality you clean for, an accountant or a data protection officer asks who processes the personal data, you should be able to send one document instead of a link to a paragraph in someone else's terms.

This agreement covers only your customers' data. How we handle your own account data is described in the Privacy Policy.

Printing it

Print the page or save it as a PDF with Ctrl+P (Cmd+P on a Mac). The layout is made for it — the navigation and the links drop out and only the agreement is printed.

The parties

Controller

You, the business whose customers are booking. Fill in before you send this on.

Company
Company registration number
Address
Contact person and email

Processor

Nordkod Media ABCompany registration number: 559591-6759Registered office: KungälvVAT number: SE559591675901Jordal 111, 444 92 JörlandaSwedenhello@buzzlink.app

The details you have given in the product apply even if you leave the fields empty. Filling them in is for the reader who receives the document on paper.

1. Subject matter, duration, nature and purpose

We host your booking page and run bookings, payments and the emails that go with them for you. That is the whole of the processing, and its only purpose. It runs for as long as you have an account, and ends when the account is deleted or the agreement between us ends.

2. Type of personal data and categories of data subjects

The data subjects are your customers, and the people they book on behalf of. The data is: name, email address, phone number, address where the work is to be done if you ask for it, appointment times, amounts and payment status, and whatever you or your customer writes in a booking note.

Don't put health data, personal identity numbers you don't need, or other special-category data in a booking note. The product isn't built for it, and putting it there makes your own processing harder to defend than it needs to be.

3. Your instructions, including transfers outside the EU/EEA

We process the data only on your documented instructions. Your instructions are these terms, the settings you choose in the product, and anything else you tell us in writing.

Your instruction includes transfer to a third country: some of our providers are US companies, so some data is processed outside the EU/EEA. Those transfers rest on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework. The providers are listed in annex A. We will not move your data to another country on any other basis without telling you first.

If a law requires us to process the data in some other way, we'll tell you before we do it, unless that same law forbids us to tell you. And if we believe an instruction from you breaks data protection law, we'll say so.

4. Your obligations and your rights

You decide why and how your customers' data is processed, and you are responsible for having a legal basis for it, for telling your customers what you do with their data, and for the content of your own instructions. You may change or withdraw an instruction at any time by writing to us.

You are entitled to everything this agreement gives you against us, and nothing in the Terms of Service limits that.

5. Confidentiality

Everyone with access to the data is bound by confidentiality, either by their employment contract or by a separate undertaking, and that duty survives the end of their work with us. Access is limited to the people who need it to run and support the service.

6. Security

We take the measures article 32 requires, judged against the risk. In practice: traffic encrypted in transit, access separated per account at the database level so one account can never read another's bookings, passwords stored hashed, card details never touching our servers — they go straight to Stripe — and production access limited to the people who need it.

Any database backups are made by our database host, Supabase, which states that they are kept available for at most 30 days, depending on the plan.

7. Sub-processors

You give us a general written authorisation to use the sub-processors in annex A. We impose the same data protection obligations on each of them by contract, and we remain fully liable to you for what they do with your customers' data.

We don't add or replace a sub-processor without first listing it in annex A, at least 30 days before it starts processing your customers' data, and the date at the top of this agreement changes at the same time. If you want to hear about it directly, write to hello@buzzlink.app and we'll email you when annex A changes. You may object during those 30 days. If we can't solve the objection, you can cancel and we'll refund the unused part of the period you've paid for.

8. Helping you answer your customers

If one of your customers wants their data erased, you do it yourself in the dashboard: look them up by email and erase the personal details, or remove the bookings entirely. You don't have to ask us first.

If they instead want a copy of their data or want it corrected, or the request needs more than the dashboard can do, write to hello@buzzlink.app and we'll help — as far as we can, and in time for your own deadline under the GDPR.

9. Incidents, impact assessments and the authority

If personal data you control is breached, we'll notify you without undue delay and within 72 hours of becoming aware of it, with what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we're doing about it. You are the one who reports to the supervisory authority; our job is to give you what you need in time to do it.

We also help you with a data protection impact assessment and with prior consultation of the authority, when one is needed for the processing we do for you — with the information we hold about how the service works.

10. Return and deletion

When the agreement ends, you choose: we return the data to you or we delete it. The export in Settings is the return — it gives you everything in your account as one file — and deleting the account is the deletion.

After a deletion we delete existing copies too, unless a law requires us to keep something. Deleted data can remain in the database host's backups for as long as those exist — according to Supabase, at most 30 days. Export before you delete: we can't promise to recover anything after a deletion.

11. Information and audits

We make available the information you need to show that this agreement is being kept, and we pass on the security documentation our providers publish. Ask at hello@buzzlink.app.

You may audit us, or have an auditor you appoint do it, once a year and after a security incident — by written questions, or on site with reasonable notice and during working hours. An auditor you send must be bound by confidentiality and must not be a competitor of ours. We contribute to the audit; you carry the cost of your own auditor.

12. Precedence, changes and term

This agreement runs for as long as we process personal data for you. If it and the Terms of Service disagree about the processing of your customers' data, this agreement wins.

We may update it as the law or the product changes, and we announce every change by email at least 30 days before it takes effect. The version and the date are at the top of this page.

Annex A — sub-processors

These are the providers that process your customers' data on our behalf. Every one of them is actually in use in the product; a provider we add appears here in the same change.

  • Supabase database, login and file storage — where your page, your services and your bookings live.
  • Stripe payments, subscriptions and payouts. Card details go straight to Stripe and never reach our servers.
  • Resend sends the emails about a booking — what your customer receives about their appointment, and what you receive about theirs.
  • Vercel hosting and delivery of the application.
  • Expo delivers the notification about a new booking to your phone, by way of Apple's and Google's own push services. It receives the device address and the one line you see on the lock screen — never your customer's details.
  • Anthropic writes the first draft of your page text when you sign up. We send your business name and the design you chose — never customer data — and it isn't used to train models.

All of them are US companies. The transfers rest on the Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework.

Questions about this agreement? Email hello@buzzlink.app and a person will answer.