Business Terms · Data Processing Agreement · User Terms · Privacy Policy · Legal Notice
Download this DPA (plain text)
1. Scope and roles
This DPA applies when incorporated into a business agreement with Naayya S.A.R.L.-S (the Processor). The business is the Controller for customer data Naayya processes on its documented instructions. The Controller determines the lawful purposes and legal bases. Processing by Naayya as a separate controller, such as its own billing and account administration, is described in the Privacy Policy. Applicable data-protection law includes the GDPR and the Swiss Federal Act on Data Protection where applicable.
2. Processing details
Subject matter: provision of the subscribed business-management platform. Duration: the agreement and the return/deletion period below. Nature and purpose: hosting, organising, retrieving, communicating and exporting records for bookings, attendance, memberships, packages, credits, payment administration, customer communications and support, to the extent enabled by the Controller. Data subjects include customers, prospects, authorised staff and other individuals whose data the Controller lawfully supplies. Data may include identity and contact details, booking and attendance history, memberships, packages, credits, expiry dates, payment references and records, communications and account information. Optional health or safety disclosures may be processed only on lawful documented instructions with a valid additional legal condition where required. The Controller must limit sensitive data to what is necessary.
3. Instructions and confidentiality
Naayya processes personal data only on documented instructions, including for transfers, unless applicable law requires otherwise; we inform the Controller of such a requirement before processing unless prohibited by law. We inform the Controller if an instruction appears to infringe applicable data-protection law. Persons authorised to process the data must be bound by confidentiality duties. We do not use Controller data for unrelated purposes merely because we provide the platform.
4. Security measures
Taking account of the state of the art, implementation costs and the nature, scope, context, purposes and risks of processing, Naayya maintains appropriate technical and organisational measures. These include access restrictions based on role and need, authentication controls, protection of data in transmission, secure handling of credentials, incident-response procedures, and measures supporting availability and restoration. Naayya makes relevant details available to the Controller on request, including the applicable hosting, backup/restoration and security arrangements. Specific schedules supplied with an order form form part of this DPA; a public summary is not an independent audit or certification.
5. Subprocessors
The Controller grants general written authorisation for subprocessors identified in the list supplied or made available when this DPA is accepted. Naayya shall provide their identity, purpose and relevant processing-location information. Naayya shall notify the Controller at least thirty days before adding or replacing a subprocessor, allowing a reasoned data-protection objection during that period. The parties will seek a reasonable alternative; if none is available, the Controller may terminate the affected service before the change takes effect, with a refund of unused prepaid subscription fees for that service. Naayya imposes materially equivalent data-protection obligations on subprocessors and remains responsible for their performance as required by law.
6. Assistance and individual rights
Taking account of the nature of processing and information available, Naayya assists the Controller with data-subject requests, security obligations, breach notifications, impact assessments and prior consultations. Requests received directly are referred to the Controller where appropriate; Naayya does not independently decide the Controller’s response unless legally required. Assistance does not transfer the Controller’s responsibility for its own lawful processing.
7. Personal-data breaches
Naayya notifies the Controller without undue delay after becoming aware of a personal-data breach affecting data processed under this DPA. Available information will describe the nature of the breach, affected data and individuals where known, likely consequences, measures taken or proposed and a contact for follow-up. Information may be provided in phases as it becomes available. General support response windows do not delay this notification.
8. International transfers
Naayya uses a lawful transfer mechanism whenever applicable law requires one, including an applicable adequacy decision or appropriate contractual safeguards. The applicable subprocessor information identifies relevant locations. EU primary hosting does not mean that every provider operation or support access takes place exclusively in the EU. For Swiss-regulated transfers, references and safeguards are adapted as required by Swiss law. This DPA does not itself replace any international-transfer clauses required for a particular transfer.
9. Information and audits
Naayya makes available information necessary to demonstrate compliance with this DPA and allows and contributes to audits, including inspections, by the Controller or its mandated auditor. The parties first use reasonably sufficient documentation where appropriate. Routine inspections require reasonable notice, confidentiality and coordination to minimise disruption and protect other customers. Such arrangements must not prevent an audit reasonably required following a breach, suspected non-compliance or a regulator’s request. Each party bears its own routine costs unless otherwise agreed or required by law.
10. Return and deletion
The Controller may request a standard exit export during the agreement or within sixty days after termination. The export scope is described in the Business Terms; delivery is within thirty days of request through a secure method. If a timely request remains outstanding at the end of the sixty-day period, the requested data is retained until delivery and for at least fourteen days for retrieval. At the Controller’s choice, Naayya returns or deletes personal data after the end of the service and deletes remaining copies unless applicable law requires retention. Backup copies remain protected, are not used for active processing and are removed under the applicable backup-retention schedule made available to the Controller. Legally retained data is restricted to the required purpose.
11. Relationship to the agreement
The agreement’s liability provisions apply between the parties to the extent lawful. This DPA does not restrict the rights of data subjects, supervisory authorities or liabilities that cannot be limited. It prevails over inconsistent commercial terms concerning personal-data processing. Luxembourg law and the agreed courts apply subject to mandatory law. Contact support@naayya.com for data-protection matters or to request the applicable security and subprocessor schedules.