Data Processing Agreement
Effective 1 October 2026
This Data Processing Agreement (DPA) is concluded between the Business using WonderBy (the Business, as controller) and Siiware, Pl. Solny 14 lok. 3, 50-062 Wrocław, Poland, NIP 8992994343 (WonderBy, as processor). It forms part of our Terms of Use and meets the requirements of Article 28 of the GDPR and the UK GDPR.
The Business accepts this DPA when it creates a Business profile or continues to use the Platform after this DPA takes effect.
1. Subject matter, nature and purpose
WonderBy processes personal data on behalf of the Business to provide the booking, calendar, client management, notification and campaign features of the Platform (the Services) described in the Terms. Processing includes collecting, recording, storing, organising, displaying, transmitting (for example sending SMS, email and push messages), and erasing data.
This DPA does not cover data WonderBy processes as a controller for its own purposes, such as Client accounts, the Marketplace, reviews, security and billing, which are described in our Privacy Policy.
2. Data subjects and categories of data
| Data subjects | Categories of personal data |
|---|---|
| The Business's clients, including people added or imported by the Business | Name, phone number, email, the name the Business uses for them, booking and visit history, spend, services, notes, social media links, marketing opt-out and blocked status, messages sent to them |
| Team members | Name, phone number, photo, role, schedule, bookings assigned, notification settings |
| People who message the Business on Instagram, if the AI assistant is connected | Instagram identifier and message content |
The Business must not use the Services to process special categories of personal data or data about criminal convictions unless it has a lawful basis and it is strictly necessary. If it does, the Business is responsible for the additional safeguards required.
3. Duration
This DPA applies for as long as WonderBy processes personal data on behalf of the Business, and ends when that data has been deleted in accordance with section 11.
4. Instructions
WonderBy processes personal data only on documented instructions from the Business. The Terms, this DPA and the Business's use and configuration of the Services are the Business's complete instructions. WonderBy will inform the Business if it believes an instruction infringes data protection law, and may suspend that processing.
If EU or Member State law requires WonderBy to process data otherwise, it will inform the Business first, unless the law prohibits it.
5. Obligations of the Business
The Business is responsible for the lawfulness of the processing, including having a legal basis for adding each client and for any marketing message, informing data subjects, keeping records of consents where required, and handling data subjects' requests. The Business ensures its Team members use the Services in line with the law and this DPA.
6. Confidentiality and security
WonderBy ensures that people authorised to process the data are bound by confidentiality and access it only as needed to provide the Services, provide support requested by the Business, or investigate abuse; such support access is logged.
WonderBy implements the technical and organisational measures described in Annex 1 and may update them provided the overall level of protection is not reduced.
7. Sub-processors
The Business gives WonderBy general authorisation to engage the sub-processors listed in Annex 2. WonderBy imposes on each sub-processor data protection obligations equivalent to this DPA and remains liable for their performance.
WonderBy will announce any intended addition or replacement of a sub-processor at least 30 days in advance by email or in the app, and by updating Annex 2. The Business may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Business may terminate the affected Services and receive a refund of prepaid fees for the unused period.
8. International transfers
Where processing involves a transfer of personal data outside the European Economic Area to a country without an adequacy decision, WonderBy ensures an appropriate safeguard, such as the European Commission's Standard Contractual Clauses (module 3, processor to processor, with sub-processors) or certification under the EU-US Data Privacy Framework, together with supplementary measures where needed.
9. Assistance
Taking into account the nature of the processing, WonderBy assists the Business with appropriate technical and organisational measures in responding to data subjects' requests, primarily through features in the apps (editing and deleting clients, marking marketing opt-outs, exporting data). If WonderBy receives a request directly from a client of the Business, it forwards it to the Business without undue delay and does not respond itself except to confirm the forwarding.
WonderBy also provides reasonable information to help the Business with security, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
10. Personal data breaches
WonderBy notifies the Business without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Business's data. The notice describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. WonderBy takes reasonable steps to contain the breach and mitigate its effects.
11. Deletion and return of data
During the term the Business can export and delete its data in the apps. When the Business deletes its profile or the Services end, WonderBy deletes the personal data processed on the Business's behalf within 90 days, unless EU or Member State law requires it to be kept. Before deletion the Business may request an export by writing to [email protected]. Backup copies are deleted as the backup cycle rotates.
12. Information and audits
WonderBy makes available the information necessary to demonstrate compliance with this DPA, including answers to reasonable security questionnaires. Where that is not sufficient, the Business may, at its own cost and no more than once a year (or after a breach or at a supervisory authority's request), carry out an audit through an independent auditor bound by confidentiality, with at least 30 days' notice and without disrupting WonderBy's operations or accessing other customers' data.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where the GDPR does not allow such limitation. If this DPA conflicts with the Terms regarding personal data, this DPA prevails. This DPA is governed by Polish law.
Annex 1. Technical and organisational measures
- Hosting on Amazon Web Services in the EU (Frankfurt) with provider-managed physical security and encryption of stored data where supported.
- Encryption of all data in transit (TLS); encrypted sign-in handshake; HTTP-only session cookies.
- Authentication with one-time SMS codes, short-lived access tokens, limits on the number of active sessions and rate limits on sign-in attempts.
- Role-based access control inside the Platform (owner, administrator, Team member) and least-privilege access for WonderBy staff, with logging of support access.
- Separation of production, development and test environments; secrets stored in a managed secrets service.
- Removal of personal data from application logs and error reports; server logs kept for 30 days.
- Automatic retention limits: sign-in codes 24 hours, message contents 90 days, AI request logs 30 days.
- Regular backups of the database managed by the database provider.
- Protection against attacks and abuse by Cloudflare, dependency updates and code review of changes.
- A documented process for handling incidents and personal data breaches.
Annex 2. Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, storage, cache, logs | EU (Germany) |
| PlanetScale, Inc. | Database hosting | EU/USA |
| Cloudflare, Inc. | Content delivery and security | Global |
| Twilio Inc. (including SendGrid) | SMS and email delivery | USA |
| AlphaSMS | SMS delivery, including campaigns | Ukraine |
| Omnicell | SMS delivery | Ukraine |
| OneSignal, Inc. | Push notifications | USA |
| OpenAI, L.L.C. | AI features, including the Instagram assistant | USA |
| Meta Platforms Ireland Ltd. | Instagram and Messenger integration, when connected by the Business | Ireland/USA |
| Functional Software, Inc. (Sentry) | Error monitoring | USA |
| OpenStreetMap Foundation | Geocoding of business addresses | United Kingdom |