Data Processing Agreement
Version 1.1 · in force from 30 August 2026. Between you (the business using Adalie) and Adalie.
Why this exists
When your customers book with you through Adalie, they give you their name, contact details and appointment history. Under the GDPR that data is yours: you decide why it is collected and what happens to it. You are the controller.
Adalie stores and processes that data on your instructions, and nothing else. That makes us your processor, and Article 28(3) requires the arrangement to be written down. This is that document. It takes effect when you create an Adalie account and lasts as long as you have one.
Who we are
Adalie is operated by Momelab Unipessoal Lda, Av. 24 1019 3I, 4500-201 Espinho, Portugal, VAT 518890554. Questions about this agreement, or any request under it, go to [email protected].
What we process, and for whom
Subject matter and purpose: providing the Adalie appointment-booking service — taking bookings, holding your calendar, sending confirmations and reminders on your behalf, and showing you your own records.
Duration: for as long as your account exists, plus the deletion period below.
Categories of data subject: your customers, your staff, and the people you give dashboard logins to.
Types of personal data:
- name, email address and, where given, phone number;
- appointment records — service, location, staff member, date, time, status and any note attached to the booking;
- the record that a customer accepted your privacy policy and terms, with the date and time;
- review text and ratings, where a customer leaves one;
- for your staff: name, email, photo where uploaded, working hours and login credentials.
We do not ask for and do not want special-category data — health, biometrics, anything under Article 9. The free-text note on a booking is the one place a customer could volunteer some. Do not solicit it there.
Our obligations
- We act only on your instructions. Using the service is the instruction. We do not use your customers' data for our own purposes, we do not sell it, we do not use it to train models, and we do not market to your customers. If a law obliges us to process it some other way, we tell you first unless that law forbids it.
- Confidentiality. Everyone with access is bound to keep it confidential, and access is limited to the people who need it to run and support the service.
- Security. We take the measures Article 32 requires, in proportion to the risk. In concrete terms: data is encrypted in transit; each business's records are isolated at the database level, not merely filtered by application code; access to production is restricted and key-based; passwords are stored hashed and never in plain text; backups are taken and access to them is restricted.
- Assistance with your obligations. If one of your customers exercises a right — access, correction, erasure, portability, objection — the dashboard lets you handle it yourself. Where it cannot, we help, at no charge for reasonable requests.
- Breach notification. If we become aware of a personal-data breach affecting your data, we tell you without undue delay and in any case within 48 hours, with what we know and what we are doing about it, so you can meet your own 72-hour obligation to the supervisory authority.
- Records and information. We keep the Article 30(2) records and give you the information you need to show your own compliance.
Sub-processors
You give us general authorisation to use the sub-processors below. Each is bound by terms no less protective than these.
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Sending confirmation, reminder and account emails; DNS and protection for the booking pages. | EU data centres; US company under SCCs |
| Stripe Payments Europe, Ltd. | Taking subscription payments from the business. Receives the business's own billing details, never its customers' data. | Ireland (EEA) |
We will tell you at least 30 days before adding or replacing one. If you object on reasonable data-protection grounds, you may terminate without penalty for the remainder of any prepaid term.
Where the data lives
Your data is stored in the European Economic Area. Where a sub-processor above involves a transfer outside it, that transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses, which are incorporated here by reference.
Getting your data back, and deletion
Ask us for a copy of your data at any time while your account is open and we will send it to you. If you close your account, tell us within 30 days and we will return or delete it as you choose; after 30 days we delete it, along with backup copies as those backups expire on their normal cycle. We keep only what the law requires us to keep — invoicing records, for the retention period Portuguese tax law sets.
Audits
You may satisfy yourself that we are meeting this agreement. In the first instance we answer questions and provide documentation. Where that is genuinely not enough, you may audit — once a year, on 30 days' notice, at your cost, without disrupting the service or exposing another customer's data.
Your side of it
You are responsible for having a lawful basis for the data you put into Adalie, for telling your customers how their data is used — the booking page carries a privacy notice for exactly this — and for keeping your staff's dashboard logins to the people who should have them.
Changes
If we change this agreement in substance we publish a new version and ask you to accept it. The version you accepted, and when, is recorded against your account; this page always shows the current one.
Language versions
This agreement is available in English, Portuguese and Spanish. All three are intended to carry the same meaning; this English version is the original. The Portuguese text is at adalie.app/legal/dpa/?lang=pt, and the Spanish at adalie.app/legal/dpa/?lang=es.
This document is drafted to cover what Article 28(3) requires and is not legal advice. If your processing is unusual, have it reviewed.