Data Processing Agreement
Last updated: 1 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Veridical Data Systems Ltd (company number 17139455, registered office at 66 Paul Street, London, England, United Kingdom, EC2A 4NA), trading as "Axiom Booking" ("we", "us", or "our", the "Processor"), and any business, organisation, or individual using the Services to manage their own customers' bookings (the "Controller", "you", or "your"). It applies wherever we process personal data on your behalf as a data processor under the UK GDPR.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given to them in the UK GDPR and the Data Protection Act 2018. "Sub-processor" means any third party engaged by us to process personal data on your behalf in connection with the Services.
2. Roles of the Parties
Where you use the Services to store or manage information about your own customers (for example, names, contact details, and booking information), you are the controller of that data, and we act as your processor. This is separate from our role as controller of your own account data, which is described in our Privacy Policy.
3. Details of Processing
- Subject matter: provision of the booking and scheduling platform (the "Services")
- Duration: for as long as your account remains active, plus the retention period described in our Privacy Policy following closure
- Nature and purpose: processing necessary to enable you to manage bookings, scheduling, and related communications with your customers
- Types of personal data: names, contact details (such as email address or phone number), appointment or booking details, and any notes you enter into the platform
- Categories of data subjects: your customers and any other individuals you book through the platform
4. Our Obligations as Processor
We will:
- process personal data only on your documented instructions, including as set out in these Terms, unless required to do otherwise by law (in which case we will inform you of that legal requirement first, unless the law prohibits us from doing so)
- ensure that anyone we authorise to process the data is subject to a duty of confidentiality
- implement appropriate technical and organisational security measures, taking into account the nature of the data and the risks involved
- assist you, where reasonably possible, in responding to requests from data subjects exercising their rights under data protection law
- assist you in meeting your own obligations relating to the security of processing, breach notification, and data protection impact assessments, taking into account the nature of the processing and information available to us
- notify you without undue delay after becoming aware of a personal data breach affecting your data
- at your choice, delete or return your data at the end of the relationship, in line with the retention terms in our Privacy Policy, except to the extent we are required to retain it by law
- make available to you the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you (at your expense and subject to reasonable confidentiality undertakings)
5. Sub-processors
You give us general authorisation to engage sub-processors to support our provision of the Services. Our current sub-processors include Stripe (payment processing) and Microsoft Entra ID (authentication and identity management). We impose data protection obligations on our sub-processors that are equivalent to those set out in this DPA.
If we intend to add or replace a sub-processor, we will give you at least 14 days' prior notice by email before the change takes effect. If you reasonably object to a new sub-processor on data protection grounds, you may terminate your account in accordance with the Termination clause of our Terms & Conditions.
6. International Transfers
Where a sub-processor is located outside the UK, we rely on legally recognised safeguards, such as the UK Extension to the EU-U.S. Data Privacy Framework or UK-approved Standard Contractual Clauses, as described further in our Privacy Policy.
7. Liability
Our liability under this DPA is subject to the liability provisions set out in our Terms & Conditions.
8. Term
This DPA applies for as long as we process personal data on your behalf under the Terms & Conditions, and ends automatically when that processing ends.
9. Contact
If you have questions about this DPA, contact us at:
info@axiombooking.com
