Trust

Data Processing Addendum

The terms governing our processing of personal data on your behalf under the GDPR, UK GDPR, and equivalent laws.

Version 1.0 · Effective September 4, 2026

This Data Processing Addendum (the Addendum) forms part of the agreement between the merchant using Easy Appointment Booking (you, or Merchant) and Servicify (we, us, or Servicify) for the provision of the Easy Appointment Booking Shopify application (the Services).

It reflects the parties' agreement on the processing of personal data in connection with the Services, and applies to the extent Servicify processes personal data on your behalf that is subject to the GDPR, the UK GDPR, the Swiss FADP, or applicable US state privacy laws. Where this Addendum conflicts with the agreement, this Addendum prevails on data protection matters.

1Definitions

Affiliate
An entity that directly or indirectly controls, is controlled by, or is under common control with another entity, where control means ownership of more than 50% of voting interests.
Authorized Affiliate
An Affiliate of the Merchant that is permitted to use the Services under the agreement but has not signed its own agreement with Servicify.
Controller
The entity that determines the purposes and means of the processing of Personal Data.
Data Protection Laws
All laws applicable to the processing of Personal Data under this Addendum, including the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), Canadian PIPEDA, and applicable US state privacy laws.
Data Subject
An identified or identifiable natural person to whom Personal Data relates. Under this Addendum, principally the Merchant's own customers and the Merchant's staff.
Merchant Personal Data
Personal Data contained within Merchant Data that Servicify processes on the Merchant's behalf in providing the Services.
Personal Data Incident
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Merchant Personal Data processed by Servicify or a Sub-processor.
Processing
Any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
Processor
The entity that processes Personal Data on behalf of the Controller.
Shopify
Shopify Inc. and its affiliates, which operate the commerce platform on which the Merchant's store runs. The Merchant contracts with Shopify directly; Shopify is not a Servicify Sub-processor.
Standard Contractual Clauses
The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
Sub-processor
Any processor engaged by Servicify to process Merchant Personal Data in connection with the Services.
UK Addendum
The International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

2Processing of Personal Data

2.1Roles of the parties

The Merchant is the Controller of Merchant Personal Data and Servicify is the Processor. Where the Merchant is itself acting as a processor for a third-party controller, Servicify is a sub-processor and section 11.4 applies.

2.2The Merchant's obligations

The Merchant shall:

  • process Merchant Personal Data in accordance with Data Protection Laws, and be solely responsible for its accuracy, quality, and legality, and for the means by which it was acquired;
  • provide the notices and obtain the consents or other lawful basis required for Servicify to process Merchant Personal Data as contemplated by the agreement;
  • be responsible for the content of any intake questions it configures in the Services, and for establishing a lawful basis for any special category data those questions collect; and
  • not provide instructions that would cause Servicify to breach Data Protection Laws.

2.3Servicify's obligations

Servicify shall:

  • treat Merchant Personal Data as confidential, and process it only to provide the Services, on the Merchant's documented instructions, and as required by applicable law;
  • not sell Merchant Personal Data, share it for cross-context behavioural advertising, or retain, use, or disclose it outside the direct business relationship with the Merchant;
  • not use Merchant Personal Data to train generally available machine learning models;
  • not combine Merchant Personal Data with personal data received from other sources except as permitted by applicable US state privacy laws;
  • not attempt to re-identify data that has been pseudonymised or aggregated; and
  • promptly notify the Merchant if Servicify determines that it can no longer meet its obligations under Data Protection Laws.

The Merchant's instructions are given by its configuration and use of the Services, by the agreement, and by this Addendum. If Servicify believes an instruction infringes Data Protection Laws, it will inform the Merchant.

2.4Government and law enforcement requests

If Servicify receives a legally binding request from a public authority for disclosure of Merchant Personal Data, it shall notify the Merchant without undue delay unless prohibited from doing so by law. Servicify shall seek to challenge or narrow any request it considers unlawful or overbroad, and shall disclose only the minimum amount of data lawfully required.

2.5Assistance with assessments

Taking into account the nature of the processing and the information available to it, Servicify shall provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities relating to the Services.

3Data Subject Requests

3.1Notification

If Servicify receives a request from a Data Subject to exercise a right of access, rectification, restriction, erasure, portability, or objection in respect of Merchant Personal Data, it shall not respond to that request directly except as legally required, and shall promptly forward the request to the Merchant.

3.2Assistance

The Services give the Merchant direct means to fulfil most requests without involving Servicify. Bookings and customer records can be exported to CSV from the admin, booking records can be edited in place, and individual bookings can be cancelled or deleted. End customers can cancel their own bookings through Shopify customer accounts.

Where a request cannot be fulfilled through the admin, Servicify will assist on written request to the address in section 4.4. This includes compiling the data held for an individual, applying bulk corrections, and running a customer-wide or store-wide deletion.

Servicify implements Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, and shop/redact). A request the Merchant raises through Shopify reaches Servicify automatically and is actioned under this section.

3.3Timeframes

Servicify shall acknowledge a request from the Merchant within 5 business days of receipt and complete it within 30 days, confirming completion in writing.

4Servicify Personnel

4.1Confidentiality

Servicify shall ensure that any person authorised to process Merchant Personal Data is subject to a duty of confidentiality that survives the end of their engagement.

4.2Reliability and training

Servicify is a small team and access to production systems is limited to its founders. Servicify does not today operate a formal background screening programme or a structured security and privacy training programme. Servicify undertakes to apply documented background screening and security and privacy training to any future personnel granted access to production systems or Merchant Personal Data.

4.3Limitation of access

Access to Merchant Personal Data is limited to personnel who require it to provide the Services or to support the Merchant. Internal access is exercised through authenticated tooling with role separation and is recorded in an audit log, as described in Annex II.

4.4Contact

Data protection enquiries, data subject requests, and incident notifications should be sent to hey@getservicify.com. Servicify has not appointed a formal Data Protection Officer; day-to-day accountability for data protection and security sits with Servicify's co-founder and CEO, who is the named escalation point for any incident.

5Sub-processors

5.1Appointment

The Merchant gives Servicify general written authorisation to engage Sub-processors. Servicify shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this Addendum, and remains liable to the Merchant for the performance of each Sub-processor's obligations.

5.2Current list and notice of changes

Servicify maintains the current list of Sub-processors, including the service each provides and the region in which it processes, at getservicify.com/trust/subprocessors. That list forms Annex III to this Addendum.

Servicify shall give the Merchant at least 30 days' notice before a new Sub-processor begins processing Merchant Personal Data, by updating that page and notifying the Merchant.

5.3Objection

The Merchant may object to a new Sub-processor on reasonable data protection grounds within 10 business days of notice. The parties shall discuss the objection in good faith. If Servicify cannot make the Services available without the objected-to Sub-processor within 30 days, the Merchant may terminate the affected Services and receive a pro-rata refund of prepaid fees, without penalty.

5.4Merchant-connected integrations

The Services can send booking data to third-party destinations that the Merchant chooses to connect, including Klaviyo, Google Calendar and Google Meet, Microsoft Outlook Calendar, Zoom, Shopify Flow, and custom webhook endpoints. These receive data only once the Merchant connects them, transmission is at the Merchant's instruction, and they are the Merchant's own processors rather than Servicify Sub-processors.

6Security

6.1Technical and organisational measures

Servicify shall implement and maintain the technical and organisational measures set out in Annex II, designed to protect Merchant Personal Data against a Personal Data Incident. Servicify shall not materially decrease the overall security of the Services during a subscription term.

6.2Certifications and audits

Servicify does not hold SOC 2, ISO 27001, or an equivalent independent attestation, and is not currently enrolled in a certification process. Servicify does not commission third-party penetration testing, and does not operate automated dependency vulnerability scanning in its build pipeline. Servicify states this plainly rather than describing a programme it does not run; the compensating controls it does operate are set out in Annex II.

On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Incident, Servicify shall provide the information reasonably necessary to demonstrate compliance with this Addendum. The parties shall agree the scope and timing in advance, and any such request is subject to confidentiality.

6.3Merchant responsibilities

The Merchant is responsible for its own use of the Services, including securing its Shopify account and staff credentials, configuring staff permissions appropriately, safeguarding any API credentials it issues, and deciding which integrations to connect. API credentials are displayed once at creation and cannot be retrieved afterwards.

7Personal Data Incidents

7.1Notification

On becoming aware of a Personal Data Incident affecting Merchant Personal Data, Servicify shall notify the Merchant without undue delay, and in any event within 48 hours, at the contact address on the Merchant's account. This is intended to leave the Merchant inside its own 72-hour regulatory notification window.

7.2Contents

The notification shall describe the nature of the incident, the categories and approximate volume of Merchant Personal Data and Data Subjects concerned, the likely consequences, and the measures taken or proposed. Where the full picture is not available at the time of notification, Servicify shall provide what it knows and update the Merchant as the investigation progresses rather than delaying notification until the assessment is complete.

7.3Remediation and incident response

Servicify shall make reasonable efforts to identify the cause of the incident, take the steps necessary to contain and remediate it, and document the outcome. Servicify does not today maintain a formally documented incident response plan; incidents are handled directly by the founders, who hold all production access, supported by centralised application logging and platform monitoring. Servicify undertakes to produce a documented incident response plan, and accepts that its existence and content may be made a condition of this Addendum.

This section does not apply to incidents caused by the Merchant or its end users.

8Retention, Return, and Deletion

8.1Retention during the term

While the Services are installed, Merchant Personal Data is retained so the Merchant can operate and report on its bookings. Servicify does not apply an automatic age-based deletion schedule to bookings during the term.

8.2Deletion on uninstall

On uninstall, access tokens and integration credentials are revoked and the Merchant is sent a data deletion notice. Merchant Personal Data becomes eligible for permanent deletion 90 days after uninstall. Reinstalling within that window preserves the data, which exists for mistaken uninstalls and seasonal businesses.

The Merchant should be aware that the 90-day purge is currently initiated by an operator rather than by a scheduled job, so deletion is not guaranteed to occur on day 90 without intervention. Servicify is automating it and is willing to commit to an automated purge and a defined retention period as a term of this Addendum.

8.3Deletion on request

The Merchant may request deletion at any time by writing to the address in section 4.4. On a verified request, Servicify performs a transactional hard delete of the store's bookings, customer records, staff records, settings, and integrations. Billing records are retained where required for tax and accounting compliance. Servicify shall confirm completion in writing, and shall certify deletion on request.

8.4Backups

Deletion removes data from the live database immediately. Data persists in encrypted platform backups until those backups age out of the managed database provider's retention window, as is standard for managed database services. Backups are held in the same region and under the same encryption as production.

9Authorized Affiliates

An Authorized Affiliate that uses the Services agrees to be bound by this Addendum. The Merchant remains responsible for coordinating all communication with Servicify under this Addendum and is entitled to make and receive communications on behalf of its Authorized Affiliates. An act or omission by an Authorized Affiliate that would breach this Addendum is treated as a breach by the Merchant. Rights under this Addendum are exercised by the Merchant on a combined basis for itself and its Authorized Affiliates.

10Limitation of Liability

Each party's liability arising out of or related to this Addendum is subject to the exclusions and limitations of liability in the agreement. Any reference in the agreement to the liability of a party means the aggregate liability of that party and all of its Affiliates under the agreement and all addenda together. Nothing in this Addendum limits either party's liability to Data Subjects under the third-party beneficiary provisions of the Standard Contractual Clauses.

11International Data Transfers

11.1Where data is processed

Merchant Personal Data is stored and processed in the United States. The application and its primary database are hosted in the US East (Northern Virginia) region. Servicify operates from Canada, and its personnel access production systems from Canada. Sub-processor processing locations are listed in Annex III.

11.2EU Standard Contractual Clauses

For transfers of Merchant Personal Data from the EEA to a country without an adequacy decision, the Standard Contractual Clauses are incorporated into this Addendum and completed as follows: Module Two (controller to processor) applies where the Merchant is a controller, and Module Three (processor to processor) applies where the Merchant is a processor; the optional docking clause in Clause 7 applies; Option 2 (general written authorisation) applies for sub-processors, with the notice period in section 5.2; the optional redress language in Clause 11(a) does not apply; Annex I and Annex II to the Clauses are completed by the Annexes to this Addendum.

The Standard Contractual Clauses are governed by the law of Ireland, and disputes arising from them shall be resolved before the courts of Ireland. This differs from the law governing this Addendum generally, which is set out in section 12: Clause 17 of the Standard Contractual Clauses requires the law of an EU Member State, so Irish law applies to the Clauses themselves and Ontario law applies to the remainder of this Addendum.

11.3UK transfers

For transfers subject to the UK GDPR, the UK Addendum applies to the Standard Contractual Clauses and takes precedence over any conflicting term. The start date is the effective date of this Addendum, the parties and key contacts are as set out in Annex I, and neither party may end the UK Addendum as set out in its section 19.

11.4Swiss transfers

For transfers subject to the Swiss FADP, the Standard Contractual Clauses apply with the following modifications: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term member state does not prevent Data Subjects habitually resident in Switzerland from bringing proceedings in Switzerland; and until the revised FADP takes effect, Personal Data also covers data about identifiable legal entities.

11.5Processor-to-processor transfers

Where Module Three applies, the Merchant acknowledges that Servicify has no direct relationship with, and is unlikely to be able to identify, the Merchant's own controllers. The Merchant shall fulfil Servicify's obligations to those controllers on Servicify's behalf.

11.6Sub-processor agreements

On request, Servicify shall provide a copy of its agreement with a Sub-processor, with commercial terms redacted.

12Term and General

This Addendum takes effect on the date the Merchant accepts it or begins using the Services, whichever is earlier, and continues until Servicify has ceased all processing of Merchant Personal Data. Sections that by their nature should survive termination do so. If any provision is held invalid, the remainder continues in effect.

This Addendum is entered into with 2851428 Ontario Inc. (operating as Servicify Appointments), a corporation incorporated in the Province of Ontario, Canada, with registered address at 42 Genuine Lane, Ontario, Canada.

This Addendum is governed by the laws of the Province of Ontario and the federal laws of Canada applicable in that province, and the parties submit to the exclusive jurisdiction of the courts of Ontario. Section 11.2 sets out the separate law that governs the Standard Contractual Clauses.

Annex IList of Parties and Description of Transfer

I.AList of parties

Data exporter: the Merchant identified in the agreement, at the address associated with its account, acting as controller (or as processor, where Module Three applies). Contact details are those on the Merchant's account.

Data importer: 2851428 Ontario Inc. (operating as Servicify Appointments), 42 Genuine Lane, Ontario, Canada. Activities relevant to the transfer: provision of the Easy Appointment Booking Shopify application, which processes personal data on the Merchant's instruction to operate an appointment booking service. Contact: hey@getservicify.com. Role: processor.

I.BDescription of transfer

Categories of Data Subjects: the Merchant's customers who make, hold, or attend bookings, and the Merchant's own staff members to whom bookings are assigned.

Categories of Personal Data processed for each booking: first and last name; customer email address; a separate contact email address where given; contact phone number; booking date, time, duration, and timezone; the assigned staff member; quantity or attendee count; the Shopify customer ID, order ID, and order name; a shipping address where the order carries one; internal notes recorded by the Merchant; and the answers to intake questions submitted with the booking.

For the Merchant's staff: name, email address, working hours and availability, assigned locations and services, and account credentials for staff-facing tools.

Sensitive data: intake questions are authored by the Merchant, so their content varies by store and may include special category data where the Merchant chooses to collect it. Servicify does not require, inspect, or specially classify these answers; they are stored alongside the booking under the measures in Annex II. The Merchant is responsible for the lawful basis for any such collection and should not configure intake questions that collect special category data without one.

Payment data: Servicify does not store or process payment card data at any point. All payment is handled by Shopify.

Frequency of transfer: continuous, for the duration of the agreement.

Nature and purpose of processing: operating an appointment booking service on the Merchant's Shopify store, including scheduling and capacity management, sending booking notifications on the Merchant's behalf, and delivering booking data to integrations the Merchant connects.

Retention: as set out in section 8.

I.CCompetent supervisory authority

Where the Merchant is established in an EEA member state, the competent supervisory authority is the authority of that member state. Where the Merchant is not established in the EEA but has designated a representative there under Article 27 of the GDPR, it is the authority of the member state in which that representative is established. In any other case, and consistent with the choice of Irish law in section 11.2, it is the Irish Data Protection Commission.

Annex IITechnical and Organisational Measures

The measures below are those Servicify operates today. They are stated as implemented, not as aspiration; the gaps Servicify has not closed are named in section 4.2, section 6.2, and section 7.3 rather than omitted here.

II.1Encryption

  • All traffic to the application and to the Shopify APIs is transmitted over TLS, with certificates managed by the hosting platform.
  • The production database is a managed PostgreSQL service providing encryption at rest, with connections secured by SSL. Backups are held on the same platform under the same encryption.
  • Staff and team-portal passwords are stored as bcrypt hashes.
  • API credentials issued to the Merchant are stored only as SHA-256 hashes; the plaintext is shown once at creation and is not retrievable afterwards.
  • Incoming Shopify webhooks are verified by HMAC-SHA256 signature. Session tokens are cryptographically signed and verified.
  • Integration tokens for connected third-party services are stored server-side and are redacted from API responses returned to the browser.

II.2Access control

  • Production access is limited to Servicify's founders. Multi-factor authentication is enforced on hosting, Shopify Partners, and workspace accounts.
  • Merchants authenticate through Shopify OAuth. Each store can access only its own data; tenant isolation is enforced at the data access layer.
  • Internal support tooling uses individual named accounts with role separation, time-limited session tokens, and permission checks at the route level.
  • The Merchant's own staff access the team portal with individual logins and granular permissions, so a staff member sees only what the Merchant grants.
  • API access uses scoped, revocable credentials. Privileged and destructive server operations require a separate authorisation token that is not exposed to the browser.
  • Secrets and credentials are held in platform-managed configuration, not in source code.

II.3Logging and auditability

  • Every internal administrative action taken against a merchant account is written to an audit log recording the internal user, the action, the target record, arbitrary action metadata, the source IP address, and the timestamp. The log covers read access as well as changes, so Servicify can evidence who viewed a merchant's data and when.
  • Booking records carry their own change timeline.
  • Application logs are centralised with a managed log aggregation provider for monitoring and alerting.
  • API credential usage is tracked.

II.4Data minimisation in the storefront

The booking widget presented to the Merchant's own customers contains no analytics, session replay, advertising, or tracking code. It communicates only with Servicify's API and with Shopify. Product analytics and error monitoring run exclusively in the merchant-facing admin interface, on merchant usage rather than on end-customer booking activity.

II.5Resilience and change management

  • The database is a managed service with managed backups in the same region as production.
  • Operating system and platform patching, including for the managed database, is performed by the hosting provider.
  • Application changes pass through continuous integration before release. Database migrations run as part of the release process.
  • Application dependencies are updated by the engineering team during ongoing development and when an advisory affects a package in use. Servicify does not currently operate to a documented remediation SLA by severity, and is willing to define one.
  • Rate limiting is applied to public API endpoints.

II.6Measures applied to Sub-processors

Servicify engages Sub-processors under written agreements imposing data protection obligations no less protective than those in this Addendum, and transmits data to them over encrypted connections. The current list, with the service provided and the processing region for each, is Annex III.

Annex IIISub-processors

The current list of Sub-processors, including the service each provides and the region in which it processes Merchant Personal Data, is published and maintained at getservicify.com/trust/subprocessors and forms part of this Addendum.

Annex III is maintained at our sub-processor page.