Skip to main content
Oraros
HomeFeaturesPricingContact
RomânăSign inGet started
HomeFeaturesPricingContactSign inGet started
Română

Data Processing Agreement

Effective from 1 June 2026

This Data Processing Agreement (the "DPA") forms part of the Oraros Business Terms. It applies whenever ORAROS LTD processes personal data on behalf of a business owner ("you") subscribing to the Oraros platform.

This DPA satisfies the requirements of Article 28 of the UK GDPR and Article 28 of the EU GDPR (Regulation (EU) 2016/679). It records the contractual terms between you, as controller of your customer and staff data, and ORAROS LTD, as your processor.

By accepting the Business Terms you accept this DPA. No separate signature is required, though enterprise customers may request a wet-signature copy by emailing support@oraros.com.

1. Definitions

Terms in bold below have the meaning given to them in Article 4 of the UK GDPR and the EU GDPR.

  • Controller — you, the business owner. You decide why and how customer and staff data is processed.
  • Processor — ORAROS LTD. We process data on your documented instructions.
  • Personal data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data: collection, storage, use, disclosure, deletion, and so on.
  • Subprocessor — a third party engaged by us to process personal data on our behalf.
  • Data subject — the natural person whose personal data is being processed.
  • Personal data breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Standard Contractual Clauses (SCCs) — the European Commission's clauses set out in Implementing Decision (EU) 2021/914.
  • UK Addendum — the Information Commissioner's Office International Data Transfer Addendum to the EU SCCs.

The "Agreement" means the Oraros Business Terms together with this DPA.

2. The parties and their roles

You are the controller of: personal data of your customers (names, contact details, booking history, notes); personal data of your staff members where you add them through Oraros, to the extent that data is used in your operational booking calendar; and any other personal data you upload, store, or process through Oraros. You decide why this data is processed and what happens to it.

ORAROS LTD is the processor for that data. We process it only as you instruct and as set out in this DPA.

We are a separate controller — and this DPA does not apply — in respect of: your business account credentials, billing and authentication data (covered by our Privacy Policy); staff members' login credentials and account-security data; and anonymised, aggregated platform analytics and product telemetry.

3. Subject matter, duration, nature, purpose

The information required by Article 28(3) GDPR is as follows.

Subject matter: provision of the Oraros booking and business-management platform. Duration: the term of your subscription, plus any post-termination grace and retention period set out in section 6.8 of this DPA and the Business Terms. Nature: hosting, displaying, computing on, and transmitting personal data through software-as-a-service infrastructure. Purpose: enabling you to take and manage customer bookings, schedule staff, communicate with customers about appointments, and operate the features of your business. Types of personal data: see section 4. Categories of data subject: your customers (registered or guest), your staff members, and any other individuals whose personal data you upload. Location of processing: the United Kingdom and the European Economic Area primarily; see section 7 for international transfers.

4. Personal data covered by this DPA

The personal data we process on your behalf includes:

  • Customer identity data: name, email address, telephone number, and profile photo where uploaded.
  • Customer booking data: services chosen, dates and times, staff selected, booking notes, cancellation history, no-show flags, and customer-supplied preferences.
  • Customer behavioural data: visit patterns, loyalty scores, frequency of visits, and contact-log entries computed by Oraros's rebooking and retention engines from the booking data you upload.
  • Customer communications: in-app messages between you and the customer, and transactional emails (confirmations, reminders, rebooking nudges) sent on your behalf.
  • Staff identity data: name, email, telephone (where the Business adds these), profile photo, role, working hours, and services assigned.
  • Operational metadata: timestamps, device identifiers, IP addresses, and audit-log entries.

We do not process special category data (Article 9 GDPR — health, religion, ethnicity, sexual orientation, biometrics, and so on) on your behalf as a routine matter. If you choose to load such data — for example, a customer note about a skin condition — you remain the controller and you are responsible for the Article 9 lawful basis. We treat it under the same security standard but make no representation that the platform is designed for special category processing.

The data is moderate-to-high sensitivity. It includes contact details, behavioural patterns, and free-text notes. By design it does not include payment card data (handled directly by Stripe), health data, or financial identifiers beyond what you supply.

5. Your obligations as controller

You agree:

(a) to process personal data only in accordance with applicable law (UK GDPR, EU GDPR, the Romanian implementing legislation including Law 190/2018 and Law 506/2004, the Privacy and Electronic Communications Regulations, and any other law applicable to your business);

(b) to establish and maintain a lawful basis under Article 6 (and Article 9 where applicable) for each type of processing you carry out through Oraros;

(c) to provide data subjects with the information required by Articles 13 and 14 — including the role of Oraros as your processor and the existence of subprocessors;

(d) to respond to data-subject requests for which you are the controller (typically requests from your own customers about their data within your account). Where the request reaches Oraros first, we will assist you under section 6;

(e) to use Oraros only for the purposes set out in section 3 and not to instruct us to process personal data in a way that would breach applicable law;

(f) to configure access controls within Oraros, granting staff only the access they need;

(g) to notify us at support@oraros.com without undue delay if you become aware of a personal data breach affecting data we process on your behalf, so we can act in line with section 8; and

(h) to honour third-party rights in the data you upload — you warrant that you have the right to upload it.

6. Our obligations as processor

We agree as follows.

6.1 Documented instructions

We will process personal data only on your documented instructions. Your instructions are: use of the platform's standard features as configured by you; specific instructions you give us in writing through your account or by emailing support@oraros.com; and anything required by law (in which case we will tell you, unless the law prohibits us from doing so). If we believe an instruction would breach applicable law, we will tell you.

6.2 Confidentiality

We will ensure that everyone we authorise to process your data is bound by confidentiality (employees by employment contract; contractors by written agreement).

6.3 Security

We will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The current measures are detailed in Schedule 1 at the end of this DPA.

6.4 Subprocessors

We engage subprocessors only for the purposes set out in section 3, under contractual terms providing data-protection obligations equivalent to those in this DPA, and after updating the published subprocessor list on our website.

We give you at least 30 days' prior notice of a new subprocessor by email and by updating the published list. You may object during that period at support@oraros.com. If you object on reasonable data-protection grounds and we cannot accommodate your objection, you may terminate the affected service under section 10 without further charge. We remain liable to you for the performance of our subprocessors as if we were performing the activity ourselves.

The current subprocessor list is incorporated into this DPA by reference. Material changes are notified as above.

6.5 Assistance with data-subject requests

We will assist you in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). Specifically we will: forward to you any request that reaches us directly relating to data we process on your behalf, within five working days of receipt (or sooner if the request is urgent); provide self-service tools where reasonably possible, such as data export from the dashboard; and maintain admin tooling so that you can fulfil requests within the legal time limits.

We may charge a reasonable fee for assistance that is manifestly unfounded, excessive, or beyond the scope of normal platform use — for example, a bespoke export request requiring engineering time. We will tell you in advance if a fee will apply and you can decline.

6.6 Assistance with broader controller obligations

We will provide reasonable assistance with your obligations under Articles 32 to 36 — in particular security (Article 32), breach notification (Articles 33 and 34), data protection impact assessments (Article 35), and prior consultation with regulators (Article 36). Reasonable assistance is provided at no charge for routine items; bespoke security questionnaires beyond a normal scope may be billed at our standard rates with prior agreement.

6.7 Audits

We will make available to you the information necessary to demonstrate compliance with Article 28. You have the right to audit, conducted as follows.

A documentation audit: on written request we will provide our most recent security summary, attestation, or equivalent. This is free of charge once per year.

An on-site or remote audit: with at least 30 days' written notice, you may audit our processing of your data. The audit must be conducted during our normal business hours; must not unreasonably disrupt our operations; must be carried out by you or a mutually agreed independent auditor bound by confidentiality; and must be limited to data and processing relevant to you — no access to other customers' data or our broader systems.

Audit costs are borne by you unless the audit identifies a material breach of this DPA, in which case we bear our own remediation costs. We may decline parts of an audit that would breach our obligations to other customers or to applicable law (for example, third-party confidentiality), and will offer a reasonable alternative such as third-party attestation.

6.8 Data return or deletion at end of processing

On expiry or termination of the Agreement, we will, at your choice: return the personal data to you in a structured, commonly used, machine-readable format (typically JSON or CSV via the dashboard export); or delete or anonymise the personal data within 90 days after termination, except where retention is required by law or for active legal claims.

We provide a 30-day post-termination grace window during which the data is read-only and exportable. After that window, deletion or anonymisation begins in line with our retention practices. Written confirmation of completion is provided on request.

7. International transfers

Oraros is established in the United Kingdom. Our subprocessors are based in the United Kingdom, the European Economic Area, and (for some) the United States. The current subprocessor list shows the location of processing for each.

Where personal data is transferred outside the UK or the EEA to a country without a UK or EU adequacy decision, we rely on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), the UK Addendum to those SCCs, the EU–US Data Privacy Framework where the recipient is certified, a transfer risk assessment, and supplementary measures including encryption and access controls where required.

The clauses are deemed signed. By entering into this DPA you and Oraros are deemed to have entered into the EU SCCs Module 2 (Controller-to-Processor) and the UK Addendum for any transfer of your personal data from the EEA or UK to a third country, with the following selections: Module 2 — Controller to Processor; Clause 7 (docking) — applies; Clause 9 (subprocessors) — Option 2, General Authorisation, with 30 days' notice (see 6.4); Clause 11(a) (independent dispute resolution) — does not apply; Clause 17 (governing law) — the law of the Republic of Ireland for the EU SCCs; Clause 18 (forum) — the courts of Ireland; UK Addendum optional clauses — none. Where there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs and Addendum prevail to the extent necessary to comply with applicable transfer law.

8. Personal data breaches

We will notify you of a personal data breach affecting your data without undue delay and in any event within 48 hours of becoming aware of it. Notification will be sent to the email address on your account and will include, to the extent then known, a description of the breach (nature, scope, what happened); the categories and approximate number of data subjects affected; the categories and approximate number of records affected; the likely consequences; the measures taken or proposed; and a point of contact for further information. We may provide information in stages as it becomes available.

You are responsible for assessing whether the breach is notifiable to your supervisory authority (Article 33) and to data subjects (Article 34) — we assist but do not make that determination on your behalf. Each party will cooperate reasonably in the other's investigation, regulatory notifications, and communications with affected data subjects. A breach notification is not an admission of fault by either party.

9. Liability

The Business Terms set out the liability cap that applies between you and Oraros. That cap applies to claims under this DPA as well, with the following Article 82 considerations: where data subjects bring direct claims, each party is liable in accordance with Article 82(2) — the controller is liable for damage caused by processing that infringes the GDPR; the processor is liable only where it has not complied with obligations specifically directed at processors or has acted outside or contrary to lawful instructions of the controller. The parties indemnify each other in the proportions set out in Article 82(5). Nothing in the Business Terms cap limits or excludes liability for any breach of SCC Clause 12 (Liability) or Clause 14 (Local laws and practices).

10. Term and termination

This DPA enters into force on the effective date of the Business Terms and continues for as long as we process personal data on your behalf. If the Business Terms are terminated, this DPA terminates automatically on the same date — except that obligations relating to confidentiality, security of any retained data, return or deletion under section 6.8, and any subsisting assistance obligations survive termination for as long as they need to.

You may terminate this DPA (and the underlying subscription) immediately by written notice if we materially breach this DPA and fail to remedy the breach within 14 days of written notice from you. Termination does not relieve either party of obligations accrued before termination.

11. Order of precedence

If there is a conflict between documents, the order of precedence is: (1) mandatory provisions of applicable law and the SCCs or UK Addendum; (2) this DPA; (3) the Business Terms; (4) any non-mandatory documents.

12. Notices

Notices under this DPA go to ORAROS LTD at support@oraros.com. Notices to you go to the email address on your business account. Romanian-resident customers may correspond with us in Romanian; we will respond in Romanian or English as appropriate.

13. Variations and signature

This DPA is incorporated into the Business Terms, which you accept on signup. No separate signature is required to make this DPA binding. If you require a wet-signature copy for your records, email support@oraros.com and we will provide a PDF version pre-signed by us for you to countersign and return.

We may update this DPA from time to time. Material changes are notified by email at least 30 days in advance. Updates required to comply with new law or regulator guidance take effect immediately on notice.

14. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales, except that any dispute about the SCCs or UK Addendum is subject to the law and forum stated in section 7. For Romanian-resident business owners, the rights granted by Law 190/2018 and the jurisdiction of ANSPDCP for complaints about the processing of Romanian data subjects' data remain in force.


Schedule 1 — Technical and organisational security measures

This Schedule describes the security measures ORAROS LTD maintains under section 6.3 and Article 32 GDPR. It is updated as our practices change. The current version is always published at https://www.oraros.com/legal/dpa.

Pseudonymisation and encryption. All communications between client and platform are secured with TLS 1.2 or higher. Database storage is encrypted with AES-256 at the storage layer. Customer passwords are stored as one-way salted hashes — we do not store, see, or transmit plain-text passwords. Backups are encrypted at rest and in transit, with access restricted to platform engineering on call.

Confidentiality, integrity, availability, resilience. Infrastructure is isolated within our hosting provider's managed network; public access is restricted to defined edge endpoints. Every table containing personal data is protected by row-level security at the database. Role-based access controls separate platform administrators, business owners, staff, customers, and ambassadors. Administrative actions on personal data are audit-logged with actor, timestamp, action, and target. Our availability target is 99.5% monthly. Daily backups are retained for 30 days; weekly backups are retained for six months. Infrastructure runs across multiple availability zones. Recovery time objective is four hours; recovery point objective is 24 hours.

Restoration after incident. A documented disaster-recovery plan covers platform downtime, database corruption, and regional outage. Backup restoration is tested quarterly. An incident-response runbook defines escalation and external communication.

Testing and evaluation. All production code changes are reviewed by at least one engineer other than the author. Automated dependency scanning runs continuously for known vulnerabilities. Penetration testing is conducted before major releases and annually thereafter, and after any material change to the platform's security architecture. The breach-response procedure is tested at least annually.

Personnel. Everyone with access to personal data is bound by written confidentiality obligations. Access is granted on a least-privilege basis and revoked promptly on role change or termination. Security-awareness training is provided on hire and annually. Background checks are performed for personnel in security-sensitive roles in line with applicable law.

Third parties. Subprocessors are selected under written due diligence covering security, data protection, and breach notification. Each subprocessor is bound by terms equivalent to the processor obligations in this DPA. The published subprocessor list identifies each subprocessor's security certifications where available.

Stack-specific measures. Database row-level security policies are reviewed before each major release. Stripe Connect handles customer card data — we have no PCI scope for customer payment cards beyond metadata. Stripe handles subscription card data on the same basis. Our email provider handles transactional email delivery; no email content containing personal data is stored beyond the provider's standard log retention. Our hosting provider serves the application; only static assets are stored at the edge, with no personal data at the edge.


For any question about this DPA, email support@oraros.com.

Oraros

Professional appointment scheduling for modern businesses.

Română

Product

  • Features
  • Pricing
  • Browse the directory

Company

  • Contact
  • Sign in
  • Get started

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy

© 2026 Oraros. All rights reserved.

Operated by ORAROS LTD (company no. 17227040).