Data Processing Agreement in Accordance with Art. 28 GDPR, CCPA, and PIPEDA

This Agreement is incorporated into the Terms of Service and applies whenever we process personal data on your behalf. It is made under Article 28 of the UK and EU GDPR, and reflects our obligations under PIPEDA in Canada and the CCPA/CPRA in California.

Last updated: 6 September 2026.

Controller: the business using 2BookNow (“you”).
Processor: GoGold Apps Inc, 5863 Leslie St, Unit 318, North York, Ontario, M2H 1J8, Canada (“we”, “us”).

1. Roles of the Parties

You decide what personal data to collect from your customers and why. We process it only to provide the Service and only on your documented instructions — which, for ordinary use, are the settings you choose and the actions you take in the app. We are the controller only of your own account data, which is covered by our Privacy Policy.

2. Duration

This Agreement takes effect when you create an account and continues until your account is closed and our deletion obligations under clause 12 are complete.

3. Subject Matter, Nature and Purpose of Processing

Providing appointment scheduling software: publishing your availability, accepting and storing bookings, sending transactional emails about those bookings, and giving you tools to manage the resulting records.

4. Categories of Data Subject

Your customers, the people they book on behalf of, and any staff members whose details you enter.

5. Categories of Personal Data

Name, email address, telephone number and appointment history, and — where you choose to collect them — postal address, answers to up to ten booking-form questions of your own wording, an uploaded photo, and private notes you write about a client.

Where you are a health, wellness or personal-care practitioner, an appointment record may itself reveal information about a person’s health by inference — a named person, a time, and the service they booked. We treat that data with the measures in clause 7 and process it only to run your bookings.

The Service is a scheduling system, not a clinical or medical records system. Do not use booking-form questions, client notes or any other free-text field to record diagnoses, treatment or medication records, insurance or health-plan numbers, national health identifiers, or payment card details. Nor should they be used for biometric data, racial or ethnic origin, political or religious beliefs, trade union membership, or sex life or sexual orientation. Keep clinical records in a system built for them.

6. Obligations of the Processor

We will: process personal data only on your instructions and as required by law; ensure that everyone with access is bound by confidentiality; maintain the technical and organisational measures in clause 7; assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with regulators; and inform you if we believe an instruction breaches data protection law.

7. Technical and Organisational Measures

  • Encryption in transit (TLS) for every connection, and encryption at rest for the database and file storage.
  • Access enforced by the database itself, row by row, so no business can read another’s data.
  • Uploaded files held in private storage buckets with per-business access rules.
  • Passwords stored only as a bcrypt hash; email sign-in by single-use code with rate limits.
  • Managed, patched infrastructure with automated failover at the provider level.
  • Least-privilege administrative access, and no use of production personal data for testing.

8. Sub-processors

You authorise the following sub-processors. We will give you notice, by email or in the app, before adding or replacing one, and you may object on reasonable data protection grounds, in which case you may terminate without penalty.

  • Supabase Inc (on Amazon Web Services) — database, authentication and file storage. United States (Oregon).
  • Zoho Corporation (ZeptoMail) — transactional email delivery. Canada.
  • Cloudflare, Inc. — CDN, DNS and DDoS protection. Global edge network.
  • RevenueCat, Inc. — subscription entitlement status. United States.
  • Expo (650 Industries, Inc.), Apple Inc. and Google LLC — push notification delivery. United States.

We remain responsible to you for our sub-processors’ performance, and each is engaged under terms no less protective than this Agreement.

9. International Data Transfers

Personal data is processed principally in the United States, with transactional email routed through Canada. For transfers from the UK or the EEA we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, which are incorporated into this Agreement by reference and prevail over it in the event of a conflict.

10. Personal Data Breaches

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification deadlines, and will cooperate with you in investigating and remediating it.

11. Data Subject Requests

Most requests you can satisfy yourself in the app — view, correct, export or delete any record. If a customer contacts us directly we will not act on the request; we will refer them to you and tell you that it happened.

12. Deletion and Return of Data

You may export all of your data to a spreadsheet at any time. On closing your account, we permanently delete your business, its bookings, its client records and its uploaded files after a seven-day grace period, except where law requires us to retain something. Backups are overwritten on their normal cycle.

13. Audit

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this Agreement.

14. Liability

Each party’s liability under this Agreement is subject to the limitations set out in the Terms of Service, and to Article 82 GDPR where it applies.

15. Health Practitioners, HIPAA and Children’s Data

We do not offer a Business Associate Agreement and the Service is not HIPAA-compliant. If you are a covered entity or business associate under the U.S. Health Insurance Portability and Accountability Act — which includes any U.S. practitioner who transmits health information electronically in connection with a claim — do not use the Service to store protected health information. We will not sign a BAA, and our sub-processors are not engaged under one.

Outside the United States, health and wellness practitioners may use the Service on the terms of this Agreement: you are the controller, you hold your own lawful basis for providing care, and you keep clinical records elsewhere. Note that in some jurisdictions a health service provider is covered by privacy law regardless of its size, and that professional bodies may impose record-keeping duties this Service does not meet on its own.

Children. If your bookings involve people under the age of majority — lessons, tuition, classes and coaching commonly do — you are responsible for obtaining any parental or guardian consent your law requires before collecting their details, and for collecting no more than the booking needs. Some jurisdictions, India among them, require verifiable parental consent for anyone under 18.

16. Contact

Email support@gogoldapps.com or use our contact page.
GoGold Apps Inc, 5863 Leslie St, Unit 318, North York, Ontario, M2H 1J8, Canada.