Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement (the "DPA") applies where you use the Services to process personal data about your own customers. It forms part of the Terms of Service between you and Codesignx Limited ("MakesBooking", "we", "us", "our").

You do not need to sign anything separately: accepting the Terms of Service accepts this DPA. If your organisation requires a signed copy, ask us and we will provide one.

Words We Use

Hong Kong and European law use different words for the same two roles. In this DPA, data user means the same as controller, and data processor means the same as processor. Personal data, processing, data subject and personal data breach carry the meanings given in the Personal Data (Privacy) Ordinance (Cap. 486) and, where it applies, the GDPR.

Roles

For the personal data of your own customers that you put into the Services, you are the data user and we are your data processor. You decide what is collected and why; we hold and process it on your instructions.

For your own account and billing data — the personal data of you and your staff as our customer — we are the data user, and the Privacy Policy governs it.

What We Process for You

  • Subject matter and purpose: providing the booking platform you have subscribed to.
  • Duration: for as long as your account is open, then as set out in the Privacy Policy.
  • Nature of the processing: collecting, storing, organising, displaying, transmitting, backing up and deleting.
  • Types of personal data: names, contact details, booking and attendance records, purchase and payment records, notes you choose to record, and access data such as IP addresses.
  • Categories of data subject: your customers and the people they book for, and your staff.
  • We do not ask for, and the Services are not designed to hold, sensitive categories such as health or biometric data. If you record such data in a free-text field you do so as data user and at your own risk.

Our Obligations

  • We process the data only on your documented instructions. Your use of the Services, and these terms, are those instructions. If we believe an instruction breaks the law, we will tell you and may decline it.
  • Everyone who can access the data is under a duty of confidentiality.
  • We keep appropriate security measures, including encryption in transit, access controls, and separation of each merchant's data from every other merchant's.
  • We help you respond when one of your customers exercises a right — access, correction, deletion — by passing the request to you and giving you the tools and information to act on it.
  • We help you meet your own breach-notification and impact-assessment obligations, taking account of what we know and what you can reasonably expect us to know.
  • We delete or return the data when the agreement ends, as set out below.

Your Obligations

  • You must have a lawful basis to collect the data and to give it to us.
  • You must tell your customers what you do with their data — including publishing your own privacy notice on your booking page.
  • You are responsible for the accuracy of what you enter, and for keeping your own access under control.
  • Your instructions to us must be lawful.

Sub-processors

You give us general authorisation to engage sub-processors. The current list is published in the Privacy Policy under “Who We Share It With”, and it is the authoritative list.

We will give you at least 30 days' notice before adding or replacing a sub-processor that processes your customers' personal data. If you reasonably object on data-protection grounds within that period, we will discuss it with you; if we cannot resolve it, you may terminate the affected Services and we will refund any fees you have paid for a period you no longer receive.

We remain responsible to you for a sub-processor's performance of these obligations.

If There Is a Breach

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and give you what we know: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. We will keep you updated as we learn more.

Notifying your own regulator or your customers is your decision as data user, and we will support it.

Where the Data Is, and Transfers

Your customers' records are held in Hong Kong, as described in the Privacy Policy. Some sub-processors necessarily operate across borders — a content delivery network, a payment processor, an analytics provider — and the Privacy Policy says which.

Where the GDPR or UK GDPR Applies

This section applies only if, and to the extent that, the GDPR or the UK GDPR applies to your processing. It does not otherwise change this DPA.

  • The obligations above are given as our Article 28 commitments, and are to be read as such.
  • For transfers out of the EEA or the UK, the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant) apply, with MakesBooking as data importer and you as data exporter. The executed annexes are provided on request.
  • If a supervisory authority or a change in law requires a different transfer mechanism, we will put one in place rather than continue without.

Information and Audit

We will give you the information you reasonably need to show that we are meeting these obligations. If that is not enough, you may audit us — once in any twelve months, on 30 days' written notice, during business hours, without disrupting the Services, and subject to confidentiality. You bear the cost unless the audit finds a material breach by us.

Return and Deletion

When the agreement ends, we will on request give you your customers' records in a machine-readable format, and then delete or anonymise them on the schedule in the Privacy Policy. Ask for the copy before requesting deletion — afterwards we cannot produce one.

We may keep data where the law requires it, and it stays subject to this DPA for as long as we hold it.

Liability and Precedence

Liability under this DPA is subject to the limitation of liability in the Terms of Service. Where this DPA and the Terms of Service differ on the protection of personal data, this DPA prevails.

Language Versions

This document is published in English, Traditional Chinese and Simplified Chinese. If there is any inconsistency or ambiguity between the versions, the English version prevails.

Contact Us

For anything under this DPA, contact [email protected].