Round-robin routing for teams is live in BookMyDay 2.0. See what's new
BookMyDay Logo
  • Platform

    Product OverviewHow the whole scheduling engine fits together All FeaturesEvery capability, in one index

    Scheduling & automation

    SchedulingBooking pages, availability and rules RoutingQualifying questions and smart assignment Meeting PollsPropose times and let people vote NotificationsConfirmations, reminders and follow-ups

    Features

    Calendar IntegrationsTwo-way sync with Google, Outlook and iCloud Team SchedulingPooled availability and round-robin routing PaymentsCollect deposits or full fees at booking

    Works with

    Google CalendarOutlookZoomMicrosoft TeamsStripeHubSpot
    See all integrations

    Discover more

    Plans & pricing Security & compliance
  • Integrations
  • Pricing
  • By team

    Customer SuccessKeep onboarding and reviews on schedule

    By industry

    HealthcarePatient appointments and multi-provider clinics Real EstateProperty visits, buyer and seller meetings B2B & SalesDemos, discovery calls and lead routing

    Start here

    All solutions Customer stories

    Talk to us

    Book a demo
  • Learn

    BlogScheduling, productivity and growth Customer StoriesHow teams run scheduling in practice Compare BookMyDaySide-by-side scheduling platform guides All FeaturesEverything BookMyDay can do, in one place

    Company

    About us Contact

    For developers

    Trust centre
  • Log in
  • Book a demo
  • Start Free

Data Processing Addendum

Last updated: May 2026

This Data Processing Addendum ("DPA") forms part of and supplements the Terms of Service ("Agreement") between you ("Controller", "Customer") and Offer18 Tracking Platform Pvt. Ltd., operating as BookMyDay ("Processor", "we", "us"), with respect to the processing of personal data by the Processor on behalf of the Controller through the BookMyDay platform.

This DPA applies to the extent that the Processor processes personal data on behalf of the Controller in the course of providing the Service, and such processing is subject to applicable data protection laws, including but not limited to the Information Technology Act, 2000 (India), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), and other relevant national or regional data protection legislation.

1. Definitions

In this DPA, the following terms shall have the meanings set out below. Capitalised terms not defined here have the meanings given in the Agreement.

  • Controller: The natural or legal person (Customer) that determines the purposes and means of the processing of personal data. In the context of BookMyDay, the Controller is the user or organisation that uses the Service to manage scheduling, bookings, and related activities involving personal data of their clients, employees, or other individuals.
  • Processor: The natural or legal person that processes personal data on behalf of the Controller. In this DPA, the Processor is Offer18 Tracking Platform Pvt. Ltd., operating as BookMyDay.
  • Data Subject: An identified or identifiable natural person whose personal data is processed. In the context of BookMyDay, Data Subjects include the Controller's clients, attendees, team members, and any other individuals whose information is entered into or processed through the Service.
  • Personal Data: Any information relating to a Data Subject that can be used to directly or indirectly identify them, including but not limited to names, email addresses, phone numbers, calendar data, IP addresses, and payment information.
  • Processing: Any operation or set of operations performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
  • Sub-processor: A third party engaged by the Processor to process personal data on behalf of the Controller.
  • Data Protection Laws: All applicable laws and regulations relating to the processing of personal data, including the GDPR, the Information Technology Act, 2000 (India), and any other relevant national or regional legislation.

2. Scope and Purpose of Processing

The Processor shall process personal data solely for the purpose of providing the Service as described in the Agreement. The scope of processing includes:

  • Storing and managing booking and scheduling data submitted by the Controller and their Data Subjects.
  • Syncing calendar data with third-party calendar providers (Google Calendar, Microsoft Outlook, Apple Calendar) as authorised by the Controller.
  • Sending email and SMS notifications, confirmations, and reminders on behalf of the Controller.
  • Processing payment transactions through integrated payment gateways when enabled by the Controller.
  • Generating analytics and reports based on booking data for the Controller's use.
  • Providing customer support related to the Controller's use of the Service.

The Processor shall not process personal data for any purpose other than as instructed by the Controller through the use of the Service, unless required to do so by applicable law.

3. Data Processing Details

3.1 Categories of Data Subjects

  • Controller's end users and clients who book appointments through the Service.
  • Controller's employees, team members, and collaborators with access to the Service.
  • Any other individuals whose personal data is entered into the Service by the Controller.

3.2 Types of Personal Data Processed

  • Contact information: names, email addresses, phone numbers.
  • Scheduling data: appointment dates, times, durations, locations, and event descriptions.
  • Calendar data: event metadata, free/busy status, and full calendar read/write access from connected Google Calendar accounts (used to create, update, and delete booking events and attach Google Meet links).
  • Account data: usernames, passwords (hashed), profile information, and preferences.
  • Payment data: billing names, addresses, and payment transaction records (full card details are processed by PCI-compliant third-party processors).
  • Communication data: messages, notes, and form responses submitted through the Service.
  • Technical data: IP addresses, browser types, device information, and usage logs.

3.3 Duration of Processing

Processing shall continue for the term of the Agreement. Upon termination, the Processor shall handle personal data in accordance with Section 9 of this DPA.

4. Security Measures

The Processor shall implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include, but are not limited to:

  • Encryption: Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256.
  • Access Controls: Role-based access controls (RBAC) ensure that only authorised personnel can access personal data, on a strict need-to-know basis. Multi-factor authentication is enforced for all administrative access.
  • Infrastructure Security: The Service is hosted on enterprise-grade cloud infrastructure with firewalls, intrusion detection systems, and DDoS protection.
  • Monitoring and Logging: Security events are logged and monitored continuously. Anomalous access patterns trigger automated alerts.
  • Employee Training: All personnel with access to personal data receive regular training on data protection and security practices.
  • Incident Response: The Processor maintains an incident response plan and will notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach.
  • Regular Testing: Security measures are tested through regular penetration tests, vulnerability assessments, and code reviews.
  • Business Continuity: Data is regularly backed up with geographically distributed redundancy to ensure availability and recoverability.

5. Sub-processors

5.1 Authorisation

The Controller provides general authorisation for the Processor to engage Sub-processors to assist in providing the Service, subject to the conditions set out in this section.

5.2 Obligations

The Processor shall:

  • Enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA.
  • Remain fully liable to the Controller for the performance of each Sub-processor's obligations.
  • Conduct due diligence on Sub-processors to ensure they provide sufficient guarantees to implement appropriate technical and organisational measures.

5.3 Notification of Changes

The Processor shall notify the Controller at least 30 days in advance of any intended addition or replacement of a Sub-processor, providing the name, location, and nature of processing. The Controller may object on reasonable grounds within 14 days of notification. If the objection cannot be resolved, the Controller may terminate the affected portion of the Service.

5.4 Current Sub-processors

Key sub-processors currently engaged by the Processor include:

  • Google LLC (United States) — Google Calendar API (calendar event management), Google Meet (video conference links), Google Sign-In (authentication). Google Privacy Policy
  • Amazon Web Services, Inc. (United States / global) — Cloud infrastructure and hosting.
  • Stripe, Inc. / Razorpay Software Pvt. Ltd. (United States / India) — Payment processing.
  • SendGrid (Twilio Inc.) (United States) — Transactional email delivery.

A complete and up-to-date list of Sub-processors is available upon request by contacting contact@bookmy.day.

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests to exercise their rights under applicable Data Protection Laws. These rights may include:

  • Right of access to personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.

The Processor shall promptly notify the Controller if it receives a request directly from a Data Subject and shall not respond to the request without the Controller's instructions, unless required by law.

The Service provides self-service tools enabling the Controller to access, export, rectify, and delete Data Subject data directly. Where automated fulfilment is not possible, the Processor shall provide reasonable assistance within 10 business days.

7. International Data Transfers

The Processor is based in India. Where personal data is transferred to or processed in jurisdictions that do not provide an adequate level of data protection as determined by applicable law, the Processor shall ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) as adopted by relevant regulatory authorities.
  • Binding Corporate Rules, where applicable.
  • Compliance with recognised data protection certification mechanisms or codes of conduct.

The Processor shall inform the Controller of the specific safeguards applied upon request.

8. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and applicable Data Protection Laws. The Controller (or an independent third-party auditor appointed by the Controller) may conduct audits, subject to the following conditions:

  • The Controller must provide at least 30 days' written notice of an audit request.
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations.
  • The scope of audits shall be limited to the processing activities covered by this DPA.
  • The Controller shall bear the costs of the audit unless the audit reveals a material breach by the Processor.
  • Audit findings and any Processor confidential information accessed during the audit shall be treated as confidential.

The Processor may satisfy audit requests by providing relevant third-party audit reports, certifications (e.g., SOC 2, ISO 27001), or evidence of compliance, where such documentation reasonably addresses the Controller's audit objectives.

9. Term and Termination

9.1 Term

This DPA shall remain in effect for the duration of the Agreement between the Controller and the Processor.

9.2 Effects of Termination

Upon termination or expiry of the Agreement, the Processor shall:

  • Cease all processing of personal data on behalf of the Controller.
  • At the Controller's election (to be communicated within 30 days of termination), return all personal data to the Controller in a structured, commonly used, machine-readable format (e.g., JSON, CSV), or securely delete all personal data.
  • If no election is made within 30 days, the Processor shall securely delete all personal data and certify deletion in writing.
  • Retain personal data only to the extent required by applicable law, and solely for the legally mandated retention period.

9.3 Survival

The obligations of the Processor with respect to confidentiality, security, and data deletion shall survive the termination of this DPA.

10. Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA shall limit either party's liability for breaches of applicable Data Protection Laws to the extent such limitation is not permitted by law.

11. Contact

For questions, concerns, or requests related to this Data Processing Addendum, please contact:

Offer18 Tracking Platform Pvt. Ltd.
0354, Street No - 3, DCM Colony,
City - Malout, Punjab, India - 152107
Email: contact@bookmy.day
Website: bookmy.day

BookMyDay

Smart event booking and appointment scheduling platform that helps businesses and individuals manage their schedules effortlessly.

Start free — no credit card

Offer18 Tracking Platform Pvt. Ltd.

0354, Street No - 3, DCM Colony,

City - Malout, Punjab, India - 152107

contact@bookmy.day

Product

  • Product Overview
  • Features
  • Scheduling
  • Routing
  • Meeting Polls
  • Notifications
  • Integrations
  • Pricing
  • Security

Solutions

  • All Solutions
  • Customer Success
  • Healthcare
  • Real Estate
  • B2B & Sales

Resources

  • Blog
  • Customer Stories
  • All Comparisons
  • BookMyDay vs Calendly
  • BookMyDay vs Calendar.com
  • All Features
  • Integrations

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA
  • Acceptable Use

© 2026 BookMyDay by Offer18 Tracking Platform Pvt. Ltd. All rights reserved.

English
  • English
  • 中文
  • Español
  • Français
  • Deutsch
  • Italiano
  • Português
  • العربية
  • हिन्दी
  • Bahasa Melayu
GDPRReady
ISO27001
SOC 2Type 2