Data Processing

Data Processing Addendum

1. Scope

This Data Processing Addendum (“DPA”) applies where a business customer uses LeisureOS to process personal information for which that business determines the purposes and means of processing and LeisureOS processes the information on the business’s behalf. In this DPA, the business customer is referred to as the “Customer” and LeisureOS / Aiby Technologies as the “Processor”.

2. Processing instructions

The Processor will process Customer-controlled personal information only to provide LeisureOS, maintain and secure the service, comply with documented Customer instructions, and meet applicable legal obligations. The normal use of LeisureOS, the Customer’s configuration choices and support requests constitute documented instructions for the processing necessary to provide the service.

3. Processing details

Join the waitlist

4. Confidentiality

The Processor will take reasonable steps to ensure that people authorized to access Customer-controlled personal information are subject to confidentiality obligations and access the information only as required for their role.

5. Security measures

The Processor will maintain appropriate technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure or destruction. Current LeisureOS controls include, where applicable, password hashing, authenticated sessions, server-side permissions, tenant and branch separation, CSRF protections, signed QR links, rate limiting, audit records, prepared database statements, transaction locking and HTTPS in production.

6. Service providers and subprocessors

The Processor may use infrastructure and service providers to operate LeisureOS, such as hosting, backup, email, monitoring or security providers. Before commercial launch, LeisureOS should maintain a current list of subprocessors and ensure appropriate contractual safeguards are in place where required.

7. Data subject requests

Where the Customer receives a valid request relating to personal information processed in LeisureOS, the Processor will provide reasonable assistance, taking into account the nature of the processing and the functionality available in the platform.

8. Security incidents

If the Processor becomes aware of a confirmed personal-data breach affecting Customer-controlled data, the Processor will notify the affected Customer without undue delay where required by applicable law and will provide reasonably available information needed for the Customer’s response.

9. Return and deletion

On termination of the service, Customer data should be returned or deleted in accordance with the final commercial agreement, applicable law and reasonable backup-retention procedures. The production launch should define a clear export and deletion process before paid contracts rely on this clause.

10. International transfers

Where Customer personal information is transferred across borders and applicable law requires transfer safeguards, the parties will use an appropriate lawful transfer mechanism.

11. Compliance information

On reasonable request and subject to confidentiality and security restrictions, the Processor will provide information reasonably necessary to demonstrate compliance with its processor obligations. Any on-site audit rights, frequency limits, costs and independent audit-report process should be finalized in the commercial version of this DPA.

12. Relationship with other terms

If there is a conflict between this DPA and the general Terms concerning the processing of Customer-controlled personal information, the DPA should control to the extent of that conflict once formally incorporated into the Customer agreement.

13. Contact

Questions about data processing can be raised through the LeisureOS contact page until dedicated legal/privacy contact information is published.