Processing Addendum (General)
Last updated: 2026-04-12
This Data Processing Addendum (“DPA“) is incorporated into, and forms part of, the Hapio Terms of Service available at hapio.io/policies/terms-of-service/, or any other written or electronic agreement between the customer using the Hapio Services (“Customer“) and Viström Digital Development AB (org. no. 556914-1921), trading as Hapio, registered in Sweden at Hertig Johans Gata 16, 541 31 Skövde, Sweden (“Hapio“) (together, the “Agreement“).
This DPA applies automatically, without requiring a countersigned copy, from the moment Customer first Processes Controller Data using the Services, and continues to apply for as long as Hapio Processes Controller Data on Customer’s behalf. If your organization requires a signed, individually negotiated DPA — for example, for your own vendor-compliance or audit records — please contact us.
1. Definitions
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations.
“Controller Data” means Personal Data that Hapio Processes on Customer’s behalf through the Services — i.e., data submitted to, stored in, or generated by the Services relating to Customer’s resources, bookings, and the individuals associated with them. It does not include data about Customer’s own personnel who access the Hapio developer portal, which Hapio Processes as an independent controller under its own Privacy Policy.
“Data Protection Laws” means all laws applicable to the Processing of Controller Data under this DPA, including the EU GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss FADP, the CCPA, and other applicable US state privacy laws, in each case as amended or superseded from time to time.
“GDPR” means Regulation (EU) 2016/679.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “sell”, and “share” have the meanings given in Data Protection Laws.
“Restricted Transfer” means a transfer of Personal Data that requires a specific safeguard under Data Protection Laws to leave the jurisdiction where it originated — for example, a transfer from the EEA to a country the European Commission has not recognized as adequate.
“SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
“Services” means the Hapio API, developer portal, and related booking/scheduling functionality provided under the Agreement.
“Sub-processor” means a third party engaged by Hapio to Process Controller Data, as listed at hapio.io/policies/sub-processors/.
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
2. Roles of the Parties
2.1 As between the Parties, Customer is the Controller (or, where it instructs Hapio on behalf of a third-party controller, a Processor) and Hapio is the Processor of Controller Data — or, for purposes of US state privacy law, the “service provider.”
2.2 Customer is solely responsible for: the accuracy and lawfulness of Controller Data and how it was collected; ensuring its instructions to Hapio comply with Data Protection Laws; responding to Data Subjects and Supervisory Authorities in its capacity as Controller; and not submitting special categories of Personal Data (e.g., health, biometric data) through the Services’ free-text or metadata fields unless it has confirmed with Hapio in writing that appropriate safeguards are in place.
2.3 The subject matter, duration, nature, and purpose of Processing, the categories of Data Subjects, and the categories of Controller Data are set out in Schedule 1.
3. Hapio’s Processing of Controller Data
3.1 Hapio will Process Controller Data only: (a) to provide and support the Services under the Agreement; (b) in accordance with Customer’s documented instructions, including instructions given through the Services’ configuration, dashboard, and API; and (c) as required by law, in which case Hapio will inform Customer of that requirement first, unless prohibited from doing so.
3.2 Hapio will not sell or share Controller Data, use it for its own marketing or advertising, or Process it for any purpose other than providing the Services, except that Hapio may create aggregated or anonymized data derived from Controller Data — which does not identify Customer or any Data Subject — and use that aggregated/anonymized data to operate, improve, and benchmark the Services.
3.3 If Hapio believes an instruction from Customer would infringe Data Protection Laws, Hapio will notify Customer promptly and may pause acting on that instruction until it is confirmed or revised.
4. Confidentiality
Hapio will ensure that personnel authorized to Process Controller Data are bound by a duty of confidentiality and Process Controller Data only as necessary for their role.
5. Security
5.1 Hapio will implement and maintain appropriate technical and organizational measures to protect Controller Data, as described in Schedule 2, taking into account the state of the art, implementation cost, and the risk to Data Subjects. Hapio may update these measures over time, provided it does not materially reduce their overall level of protection.
5.2 On reasonable written request, no more than once per calendar year, Hapio will provide Customer with information reasonably necessary to demonstrate compliance with this Section 5, which may include a security summary, completed questionnaire, or relevant third-party certification then held by Hapio.
6. Personal Data Breach
6.1 Hapio will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Controller Data, describing (to the extent then known) its nature, likely consequences, and the steps taken or proposed to address it.
6.2 Hapio will take reasonable steps to contain and mitigate the breach and will cooperate with Customer’s own notification obligations. Hapio’s notification under this Section is not an admission of fault.
6.3 Customer is responsible for keeping its account notification contact current; Hapio is not liable for a delayed notification caused by outdated contact details.
7. Data Subject Rights
7.1 Hapio will, through the standard functionality of the Services, enable Customer to access, export, correct, and delete Controller Data.
7.2 If Hapio receives a request directly from a Data Subject concerning Controller Data, it will not respond substantively (other than to acknowledge receipt) and will instead direct the individual to Customer without undue delay.
7.3 Taking into account the nature of Processing, Hapio will provide reasonable assistance, through the Services’ functionality and reasonable additional support on request, to help Customer respond to Data Subject requests under Data Protection Laws. Hapio may charge a reasonable fee, agreed in advance, for assistance beyond standard functionality.
8. Data Protection Impact Assessments
On written request, Hapio will provide reasonable assistance with data protection impact assessments and related prior consultations with Supervisory Authorities that Customer reasonably requires under Data Protection Laws, to the extent the relevant information is available to Hapio and not otherwise available to Customer.
9. Sub-processors
9.1 Customer gives Hapio general written authorization to engage Sub-processors to Process Controller Data in connection with the Services.
9.2 Hapio maintains a current list of Sub-processors at hapio.io/policies/sub-processors. Hapio will give notice — by email or by updating that page with a change log — before authorizing a new Sub-processor to Process Controller Data.
9.3 Customer may object to a new Sub-processor on reasonable data-protection grounds by notifying Hapio in writing within 14 days of the notice in Section 9.2. If the parties cannot resolve the objection, Customer’s sole remedy is to terminate the portion of the Services that cannot be provided without that Sub-processor, without penalty.
9.4 Hapio will enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA, to the extent relevant to the services that Sub-processor provides, and remains liable to Customer for each Sub-processor’s performance.
10. International Data Transfers
10.1 Hapio primarily Processes Controller Data in the EU (AWS eu-central-1].
10.2 Where Processing involves a Restricted Transfer, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two applies where Customer is a Controller, and Module Three applies where Customer is a Processor acting for a third-party controller; the optional docking clause in Clause 7 is included; Option 2 (general authorization, per Section 9 above) applies under Clause 9; the optional language in Clause 11 is excluded; the SCCs are governed by the law of Sweden under Clause 17 (Option 1); and disputes are subject to the courts of Sweden under Clause 18(b). Annexes I–III of the SCCs are deemed completed with the information in Schedules 1, 2, and 3 of this DPA.
10.3 Where UK GDPR applies to a Restricted Transfer, the Parties are deemed to have entered into the UK Addendum on the same elections as Section 10.2, with Hapio as the “Importer.”
10.4 Where the Swiss FADP applies, the SCCs are read to also protect Data Subjects in Switzerland, with the Swiss Federal Data Protection and Information Commissioner as the competent authority to the extent required.
11. Return or Deletion of Controller Data
11.1 Customer can export or delete Controller Data at any time through the Services’ standard functionality; using that functionality to delete data is an instruction to Hapio to delete it from Hapio’s systems.
11.2 On termination or expiry of the Agreement, Hapio will delete remaining Controller Data within 90 days, except where applicable law requires longer retention or where data remains in encrypted backups pending their standard rotation, and will make it available for export for 14 days following termination if Customer requests it in writing before the Agreement ends.
12. Liability
Each Party’s liability arising out of this DPA is subject to the limitation-of-liability terms in the Agreement, and any reference in those terms to a Party’s liability means that Party’s aggregate liability under the Agreement and this DPA together. Nothing in this DPA limits either Party’s liability to a Data Subject or Supervisory Authority to the extent such liability cannot lawfully be limited.
13. Additional CCPA / US State Law Terms
To the extent Controller Data includes personal information protected under the CCPA or another applicable US state privacy law, Hapio, acting as “service provider” (or equivalent), will not: sell or share such data; retain, use, or disclose it for any purpose other than providing the Services; or combine it with personal information from other sources except as permitted by that law. Hapio certifies that it understands and will comply with these restrictions, and will provide assistance with consumer rights requests consistent with Section 7.
14. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA governs with respect to the Processing of Controller Data. If there is a conflict between this DPA and the SCCs or UK Addendum incorporated under Section 10, the SCCs or UK Addendum govern.
15. Effective Term
This DPA takes effect when Customer first Processes Controller Data using the Services and continues for as long as Hapio Processes Controller Data on Customer’s behalf, subject to Section 11.
16. Updates to this DPA
Hapio may update this DPA from time to time to reflect changes in Data Protection Laws, the Services, or Hapio’s operations. Updates will be posted at this same URL with a new “Last updated” date. Material changes take effect 30 days after posting. If a material change adversely affects Customer, Customer may terminate the Agreement without penalty by notifying Hapio in writing within 10 days of the change’s effective date. Continued use of the Services after a change takes effect constitutes acceptance of the updated DPA. If Customer and Hapio separately execute a signed DPA (e.g., an Enterprise DPA), the terms of that signed agreement control over this general DPA to the extent of any conflict.
17. Contact
Questions about this DPA, and notices under it, should be sent to hi@hapio.io. As a company established in the EU, Hapio does not require an Article 27 GDPR representative.
Schedule 1 – Details of Processing
Categories of Data Subjects: End users of Customer’s application who make, manage, or are the subject of a booking; individuals identified as “resources” where a resource represents a natural person (e.g., staff, practitioners);
Categories of Controller Data: Identity/contact details submitted as booking or resource metadata (e.g., name, email, phone); booking details (service, date/time, location, status, notes); resource details where the resource is a person; any additional fields Customer chooses to populate via metadata — Customer controls what is submitted and should not include special category data absent prior written agreement with Hapio.
Special categories of Personal Data: None expected by default;
Nature and purpose: Providing API-based booking, scheduling, resource, and availability management functionality that Customer integrates into its own application.
Duration: For the term of the Agreement, plus any retention period under Section 11.
Frequency: Continuous, for as long as Customer uses the Services.
Schedule 3 – Sub-processors
See the current list at hapio.io/policies/sub-processors