Data Processing Agreement
These are the terms on which we handle personal information about your clients because you use BookIQ.ai. For that information you decide what is collected and why, and we handle it on your behalf. They are commitments we make to you; they add to the Terms of Service and take nothing away from it. They do not cover information about you and your own account — for that we decide the purposes ourselves and our Privacy Policy is the document that applies.
1. Who is who
You are the entity responsible for your clients’ personal information — the APP entity under the Privacy Act 1988 (Cth) where that Act applies to you, the business under the California Consumer Privacy Act where that Act applies to you, and the controller in the language most privacy laws use. We are the processor, and for the purposes of the CCPA as amended by the CPRA we are your service provider.
Whether Australian privacy law applies to your business at all is a question for you: the Privacy Act generally does not cover a small business with an annual turnover of A$3 million or less, but there are exceptions, including a business that provides a health service and holds health information. We do not decide that for you and we do not assume it either way. These terms apply regardless.
2. Scope: Australia and the United States
BookIQ.ai is operated from Australia and sold in Australia and the United States. These terms are written to the Australian Privacy Principles and to the CCPA/CPRA service-provider requirements. Where the GDPR or UK GDPR happens to apply to information you put into BookIQ.ai, sections 3b, 4b, 6 and 6a of the Privacy Policy describe what we do; we do not offer our own standard contractual clauses and we have not appointed an EU or UK representative. If you need either of those, tell us before you subscribe.
3. What we process, and why
| Subject matter | Providing BookIQ.ai to you under the Terms of Service. |
|---|---|
| Duration | For as long as your account exists, plus the retention periods set out in section 5 of the Privacy Policy. |
| Nature and purpose | Hosting, storing, displaying, transmitting, backing up and processing your client data so that the product works: taking and managing bookings, sending reminders and messages, running your client records, invoicing and taking payment, reporting, and the AI features you choose to turn on. |
| Types of personal information | Name and contact details; booking and appointment history; notes, photographs and documents you record against a client; communication and marketing preferences and consent records; message content; payment and invoice records and payment-method metadata; and, where you record it, information about a client’s health, treatments or other sensitive matters that you choose to put into a note or a form. |
| Categories of people | Your clients, your staff, and people who contact your business through BookIQ.ai. |
4. We act on your instructions
We process your client data only in order to provide BookIQ.ai to you, to keep it secure and working, and where a law that applies to us requires otherwise. Your instructions are the Terms of Service, the Privacy Policy, this document, and what you do in the product. If we think an instruction from you would break a law, we will tell you rather than carry it out.
Specifically, and for as long as these terms are published:
- we do not sell your client data and we do not share it for cross-context behavioural advertising;
- we do not use it for our own marketing, and we do not market to your clients;
- we do not combine it with data from our other customers, or with data from anywhere else, except where doing so is part of providing the service to you;
- we do not retain, use or disclose it for any purpose other than the ones listed in section 3, including outside our direct business relationship with you;
- we do not use it to train machine-learning models. Where you use an AI feature, the content you submit is sent to the provider named in section 3a of the Privacy Policy so that it can produce the result you asked for, and we do not authorise that provider to use your content for training.
5. Confidentiality
Access to your client data is limited to the people at PairOx Pty Ltd who need it in order to operate and support the service, and we require confidentiality of anyone who has that access, on a basis that continues after their engagement ends.
6. Security
These are the measures we actually apply, stated so that you can check them:
- Where it is. Your account data is stored in a database hosted in Sydney, Australia. Parts of the service — hosting at the edge, payments, email delivery, error monitoring, the AI features — run on providers outside Australia. Section 3a of the Privacy Policy names every one of them and section 3b explains the overseas disclosure.
- In transit and at rest. Traffic to and from BookIQ.ai is carried over TLS, and the database and file storage encrypt data at rest.
- Separation between businesses. Records are scoped to the business in two places rather than one: row-level security in the database, which refuses a read the requesting session is not entitled to, and a role check in the application layer, which is what stops a request naming a business the caller has no role in. We are stating the design, not certifying that neither layer can ever have a gap in it; where we find one we treat it as a defect and fix it.
- Files. Everything you upload is stored privately and served through short-lived signed links, except the images you deliberately publish as part of your public presence — your logo, banner and service photos — which are publicly readable by anyone with the link. Section 4a of the Privacy Policy says the same thing.
- Card data. Where a card payment is taken through BookIQ.ai the number is typed into Stripe’s own hosted fields and goes to Stripe. BookIQ.ai does not receive or store a full card number. One older screen — the payment box on a shared invoice link — still draws card fields of its own; it takes no payment and submits nothing, section 5 of the Acceptable Use Policy tells businesses not to use it, and it is on our list to remove.
- Audit trails. Security, access and change events are logged, with the retention periods set out in sections 2b and 5 of the Privacy Policy.
- Backups. Encrypted backups of the production database are kept, and data you delete can remain in a backup for up to 30 days before it is cycled out.
What we do not claim. We hold no SOC 2 report, no ISO 27001 certification and no independent security audit or penetration-test report, and BookIQ.ai is not a HIPAA environment: we are not a business associate and we do not offer a business associate agreement. If any of those is a requirement for you, tell us before you subscribe rather than after. Nothing on the internet is perfectly secure, and section 4 of the Privacy Policy says so as well.
7. Sub-processors
You give us a general authorisation to engage sub-processors. The complete current list is section 3a of the Privacy Policy, which names each one, where it processes, what it receives, and whether it is engaged for every account or only if you turn a feature on or connect an account. That list is incorporated into this document by reference and is kept complete rather than illustrative — a third party that receives personal information from BookIQ.ai and is not on it is a defect we want to hear about.
We engage each sub-processor under its own published data-processing terms, and we update section 3a before we engage a new one. If you object to a new sub-processor, tell us at privacy@bookiq.ai. If we cannot offer you a way to keep using BookIQ.ai without it, you may cancel; the Refund & Cancellation Policy governs what that means for money already paid.
8. Helping you answer your clients
If one of your clients asks you for access, correction or deletion, this is what is available:
- What you can do yourself. View, correct and update a client’s record; record and change their communication and marketing preferences; unsubscribe them from marketing.
- What Delete does today, precisely. Deleting a client in BookIQ.ai marks that client inactive and takes them out of your working lists. It does not erase the underlying record, and it is not irreversible. We would rather tell you that than let you rely on it when answering a client.
- What to ask us for. Erasure of a client’s personal information, or a copy of what we hold about them, so that you can give it to them. Email privacy@bookiq.ai with enough detail to identify the client and the business. We will action it within 30 days, which is the same commitment section 7 of the Privacy Policy makes.
- If a client comes to us directly about information you hold, we will not act on it as if we decided it. We will pass the request to you and tell them we have, unless a law requires otherwise.
We will also give you, on request, the information you reasonably need to complete a privacy impact assessment or to answer a regulator about the part we play.
9. Data breaches
If we become aware that your client data has been lost, or accessed or disclosed without authorisation, we will tell you without undue delay and give you what you need to meet your own obligations — what happened, what information was involved, what we have done about it and what we suggest. Section 4b of the Privacy Policy sets out the commitments we make and the timescales we work to, including the assessment and notification duties under Part IIIC of the Privacy Act 1988 (Cth), and it applies here.
Where you have your own notification duty to your clients or to a regulator, that duty is yours; our job is to make sure you are not doing it blind.
10. Getting your data back, and having it deleted
- While the account exists your client data stays in BookIQ.ai and you can work with it there.
- If you cancel your subscription, your account moves to the Free plan at the end of the period you have paid for. Your data is not deleted, and we will not delete it without being asked.
- To get a copy, use Settings → Privacy & Security → Download my data. It is a real data-access request and is actioned within 30 days.
- To have it erased, use Delete my account. That schedules an irreversible erasure 30 days out, which you can cancel at any point in that window, and before you confirm it shows you the exact list — generated from your own account — of what will be removed and what will be kept. Section 5 of the Privacy Policy explains what an erasure keeps, on what basis, and how to ask us to assess a specific file.
- If you want your client data erased without closing the account, email privacy@bookiq.ai and say what you want erased. There is no self-service control for that today.
11. Checking that we are doing this
On request we will give you the information you reasonably need to satisfy yourself that we are meeting these terms: what categories of information we hold for you, where they are, who our sub-processors are, and what security measures we apply. We do not offer on-site audits and we hold no third-party audit report to hand over — section 6 says so plainly rather than leaving you to discover it during a procurement review.
12. What these terms do not cover
- Your own account information. The Privacy Policy covers it, and there we are the controller.
- Payments you take from your clients. Stripe is the processor of the payment itself and you accept Stripe’s own agreement directly with it. Schedule 1 of the Terms of Service governs the money side of that relationship.
- A service you connect. Where you connect an accounting package, a calendar, a marketing tool or a messaging channel, information flows to it because you chose to connect it. Section 3a of the Privacy Policy names those services and what each receives.
- What you do with the information yourself. Your obligations as the business holding it — having a lawful basis, telling your clients what you do with their information, and honouring their requests — are yours. Clause 4a of the Terms of Service already requires the first of those, and the Acceptable Use Policy sets out the rest of what we ask of you.
13. Changes, and how to reach us
These terms are republished at this address whenever they change and each version carries the date it was published above. We will not narrow a commitment made here without telling you first. If a change would alter your obligations rather than ours, we will make it in the Terms of Service, which carries the notice clause 7 of the Terms promises.
Privacy and data-protection questions, including anything in this document: privacy@bookiq.ai. Contractual questions: legal@bookiq.ai.