Data Processing Agreement

BookIQ.ai, operated by PairOx Pty Ltd · Published 10 September 2026

These are the terms on which we handle personal information about your clients because you use BookIQ.ai. For that information you decide what is collected and why, and we handle it on your behalf. They are commitments we make to you; they add to the Terms of Service and take nothing away from it. They do not cover information about you and your own account — for that we decide the purposes ourselves and our Privacy Policy is the document that applies.

1. Who is who

You are the entity responsible for your clients’ personal information — the APP entity under the Privacy Act 1988 (Cth) where that Act applies to you, the business under the California Consumer Privacy Act where that Act applies to you, and the controller in the language most privacy laws use. We are the processor, and for the purposes of the CCPA as amended by the CPRA we are your service provider.

Whether Australian privacy law applies to your business at all is a question for you: the Privacy Act generally does not cover a small business with an annual turnover of A$3 million or less, but there are exceptions, including a business that provides a health service and holds health information. We do not decide that for you and we do not assume it either way. These terms apply regardless.

2. Scope: Australia and the United States

BookIQ.ai is operated from Australia and sold in Australia and the United States. These terms are written to the Australian Privacy Principles and to the CCPA/CPRA service-provider requirements. Where the GDPR or UK GDPR happens to apply to information you put into BookIQ.ai, sections 3b, 4b, 6 and 6a of the Privacy Policy describe what we do; we do not offer our own standard contractual clauses and we have not appointed an EU or UK representative. If you need either of those, tell us before you subscribe.

3. What we process, and why

Subject matterProviding BookIQ.ai to you under the Terms of Service.
DurationFor as long as your account exists, plus the retention periods set out in section 5 of the Privacy Policy.
Nature and purposeHosting, storing, displaying, transmitting, backing up and processing your client data so that the product works: taking and managing bookings, sending reminders and messages, running your client records, invoicing and taking payment, reporting, and the AI features you choose to turn on.
Types of personal informationName and contact details; booking and appointment history; notes, photographs and documents you record against a client; communication and marketing preferences and consent records; message content; payment and invoice records and payment-method metadata; and, where you record it, information about a client’s health, treatments or other sensitive matters that you choose to put into a note or a form.
Categories of peopleYour clients, your staff, and people who contact your business through BookIQ.ai.

4. We act on your instructions

We process your client data only in order to provide BookIQ.ai to you, to keep it secure and working, and where a law that applies to us requires otherwise. Your instructions are the Terms of Service, the Privacy Policy, this document, and what you do in the product. If we think an instruction from you would break a law, we will tell you rather than carry it out.

Specifically, and for as long as these terms are published:

5. Confidentiality

Access to your client data is limited to the people at PairOx Pty Ltd who need it in order to operate and support the service, and we require confidentiality of anyone who has that access, on a basis that continues after their engagement ends.

6. Security

These are the measures we actually apply, stated so that you can check them:

What we do not claim. We hold no SOC 2 report, no ISO 27001 certification and no independent security audit or penetration-test report, and BookIQ.ai is not a HIPAA environment: we are not a business associate and we do not offer a business associate agreement. If any of those is a requirement for you, tell us before you subscribe rather than after. Nothing on the internet is perfectly secure, and section 4 of the Privacy Policy says so as well.

7. Sub-processors

You give us a general authorisation to engage sub-processors. The complete current list is section 3a of the Privacy Policy, which names each one, where it processes, what it receives, and whether it is engaged for every account or only if you turn a feature on or connect an account. That list is incorporated into this document by reference and is kept complete rather than illustrative — a third party that receives personal information from BookIQ.ai and is not on it is a defect we want to hear about.

We engage each sub-processor under its own published data-processing terms, and we update section 3a before we engage a new one. If you object to a new sub-processor, tell us at privacy@bookiq.ai. If we cannot offer you a way to keep using BookIQ.ai without it, you may cancel; the Refund & Cancellation Policy governs what that means for money already paid.

8. Helping you answer your clients

If one of your clients asks you for access, correction or deletion, this is what is available:

We will also give you, on request, the information you reasonably need to complete a privacy impact assessment or to answer a regulator about the part we play.

9. Data breaches

If we become aware that your client data has been lost, or accessed or disclosed without authorisation, we will tell you without undue delay and give you what you need to meet your own obligations — what happened, what information was involved, what we have done about it and what we suggest. Section 4b of the Privacy Policy sets out the commitments we make and the timescales we work to, including the assessment and notification duties under Part IIIC of the Privacy Act 1988 (Cth), and it applies here.

Where you have your own notification duty to your clients or to a regulator, that duty is yours; our job is to make sure you are not doing it blind.

10. Getting your data back, and having it deleted

11. Checking that we are doing this

On request we will give you the information you reasonably need to satisfy yourself that we are meeting these terms: what categories of information we hold for you, where they are, who our sub-processors are, and what security measures we apply. We do not offer on-site audits and we hold no third-party audit report to hand over — section 6 says so plainly rather than leaving you to discover it during a procurement review.

12. What these terms do not cover

13. Changes, and how to reach us

These terms are republished at this address whenever they change and each version carries the date it was published above. We will not narrow a commitment made here without telling you first. If a change would alter your obligations rather than ours, we will make it in the Terms of Service, which carries the notice clause 7 of the Terms promises.

Privacy and data-protection questions, including anything in this document: privacy@bookiq.ai. Contractual questions: legal@bookiq.ai.