Skip to main content

Data Processing Agreement (DPA)

Last updated: 21/09/2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Andrea Faccioli ("Processor", operator of Placeful) and each company that uses the platform to manage bookings ("Controller", the "Company"). It applies whenever the Processor processes personal data on behalf of the Company in the provision of the booking service, pursuant to Article 28 GDPR.

By creating or using a company workspace, the Company's legal representative accepts this DPA on the Company's behalf.

1. Subject matter, scope, duration

  • Subject matter: hosting and operation of the Company's booking workspace: events, availability, bookings, end-customer contact details, notifications, payments via the Company's own Stripe Connect account.
  • Duration: for as long as the Company uses the platform, subject to the deletion terms in Section 8.
  • Nature and purpose: storage, organization, display, transmission (emails, widget embeds) and payment facilitation of booking-related data, strictly as instructed through the application's features.

2. Categories of data and data subjects

  • Data subjects: the Company's customers and guests (bookers, attendees), the Company's staff members.
  • Data categories: names, email addresses, phone numbers, booking details (dates, headcounts, notes provided by the booker), payment status metadata, authentication data of staff users.
  • Special categories: the platform is not designed for special-category data. If the Company or its customers voluntarily insert such data (e.g. dietary or accessibility needs in booking notes), the Company remains responsible for a lawful basis; the Processor processes it solely as instructed.

3. Processor obligations

The Processor shall:

  1. process personal data only on the Company's documented instructions, including this DPA and the Company's use of platform features, unless required otherwise by EU or Member State law;
  2. ensure persons authorized to process data are bound by confidentiality;
  3. implement and maintain the technical and organizational measures described in Section 9;
  4. engage sub-processors only as listed in Section 5, with equivalent obligations, and notify the Company of intended changes (the Company may object within 14 days);
  5. assist the Company, by appropriate technical measures, in fulfilling data-subject requests (access, rectification, erasure, portability) — the platform provides self-service data export and deletion tools for this purpose;
  6. assist the Company in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIA support) to the extent reasonably possible;
  7. notify the Company without undue delay after becoming aware of a personal data breach affecting Company data.

4. Controller obligations

The Company warrants that:

  1. it has a lawful basis for processing its customers' data collected through the platform;
  2. it provides its own privacy notice to its customers (the platform offers a configurable privacy_url shown to customers before and after booking);
  3. it is responsible for the accuracy and legality of data it instructs the platform to process, including booking notes and custom information fields;
  4. it will not use the platform to process data it is not entitled to process.

5. Sub-processors

The Company authorizes the sub-processors listed in the platform's Privacy Policy ("Data recipients" / sub-processor list), which are maintained in config/legal.php and displayed in the Privacy Policy. Any change to that list will be notified through the application; continued use after the notice period constitutes acceptance.

Stripe acts on the Company's own account for payment processing; the Company's customers' payment data is processed under the Company's direct relationship with Stripe.

6. International transfers

Where sub-processors are located outside the EEA, transfers are covered by adequacy decisions or Standard Contractual Clauses, per Section 8 of the Privacy Policy.

7. Audits and information

The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA (this document, the security measures in Section 9, sub-processor list). On-site audits are replaced by written questionnaires and documentation, unless a supervisory authority requires otherwise.

8. Return and deletion of data

  • The Company may export its bookings and customer data at any time through the platform's export features.
  • Upon termination of the Company's workspace, personal data processed on its behalf is deleted or anonymized within 90 days, except where longer retention is required by law (e.g. fiscal records, Art. 2220 Civil Code — max 10 years).
  • Deleted-account backups purge on their normal retention schedule (see Privacy Policy §9).

9. Technical and organizational measures (TOMs)

  • TLS in transit; session cookies Secure/HttpOnly; CHIPS-partitioned cookies inside embed iframes
  • Password hashing (bcrypt), optional 2FA (TOTP) and passkeys for staff accounts; mandatory-security-setup enforcement for privileged roles
  • OAuth tokens for third-party integrations (Google Calendar) stored encrypted at rest
  • Role/permission-based access control within each company workspace
  • Record-history (audit) trail of create/update/delete actions with actor, timestamp and IP; impersonation events are audited
  • Encrypted (AES-256) nightly database backups with bounded retention; periodic restore → erasure re-application
  • Automated retention pruning of logs, audit rows, email threads and webhook payloads
  • Data-export (Art. 15) and deletion/anonymization tooling (Art. 17) built into the application

10. Liability and precedence

Liability is governed by the Terms of Service. If this DPA conflicts with the Terms, the DPA prevails for data-protection matters.

11. Contact

Data-protection contact for the Processor: [email protected].

Company contact: the legal email registered in the Company's workspace settings.

Data controller: Andrea Faccioli — Via Madonnina 2505A, 40024 Castel S. Pietro Terme (BO), Italia CF: FCCNDR89E12A944E [email protected]

Cookies and privacy

We use essential cookies to keep the application secure and working correctly. Optional cookies will only be used with your consent.

Read the privacy policy Read the cookie policy

Essential

Essential cookies are required for the website to function and cannot be switched off.

Always on

Functional

Functional cookies enable enhanced functionality and personalisation, such as remembering your language and preferences.

Analytics

Analytics cookies help us understand how visitors interact with the application so we can improve it.

Marketing

Marketing cookies are used to track visitors across websites to display relevant and engaging advertisements.