Data Processing Agreement
Last updated: 7 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between you ("Customer") and Clyde Side Events Scotland Ltd, trading as BookAvi ("BookAvi", "we", "us"). It applies whenever BookAvi processes personal data about your own customers and contacts on your behalf. No signature is required: it takes effect automatically when you start using BookAvi. If your organisation needs a countersigned copy, email info@bookavi.com.
1. Roles
For personal data you enter into BookAvi about your enquirers, clients, staff and suppliers, you are the controller and BookAvi is the processor. For your own BookAvi account and billing data, BookAvi is the controller — see the Privacy Notice.
2. Subject matter and duration
BookAvi processes your customer data only to provide the booking and customer-management service described in the Terms, for as long as your account is active plus the retention period in clause 9.
3. Categories of data and data subjects
- Data subjects — your enquirers and clients, their guests where you record them, your staff and subcontractors, and your suppliers.
- Personal data — names, email addresses, phone numbers, event and venue addresses, enquiry and booking details, quotes, contracts and signatures, invoices and payment records, uploaded files, and messages exchanged through BookAvi.
- Special category data — BookAvi is not designed for special category data. Do not enter health, biometric or similar sensitive data into free-text fields.
4. Our obligations
- Process your customer data only on your documented instructions.
- Not use your customer data for our own purposes, and never sell it or use it to train third-party AI models.
- Ensure anyone with access is bound by confidentiality obligations.
- Implement the security measures in clause 6.
- Assist you with data subject requests, impact assessments and regulator queries.
5. Your obligations
- Have a lawful basis for the data you enter, and give your customers the privacy information they are entitled to.
- Keep your account credentials secure and manage who on your team has access.
- Only send marketing or review requests through BookAvi where you have the necessary permission.
6. Security measures
- Encryption in transit (HTTPS/TLS) and encryption of data at rest.
- Row-level database security so each business workspace can only read and write its own records.
- Passwords and portal credentials stored only as salted hashes; integration keys stored only as hashes and secrets held in a server-side secret store, never in the browser.
- Private file storage with short-lived signed links for uploads and downloads.
- Role-based access within a workspace, and audit logging of sensitive actions.
- Managed, backed-up infrastructure with access limited to the operator.
7. Subprocessors
You give general authorisation for BookAvi to engage the subprocessors listed on our Subprocessors page. Each is bound by written terms no less protective than this DPA. We will update that page before adding or replacing a subprocessor; if you object on reasonable data-protection grounds you may terminate the affected part of the service.
Email accounts you connect yourself. If you connect a Google Workspace, Gmail, Microsoft 365 or Outlook mailbox, that provider becomes a subprocessor for the emails sent through it. You sign in with the provider directly; BookAvi never receives your mailbox password. We request only permission to send email, and we store the resulting access credential encrypted at rest, accessible only to our server-side sending process. Recipient details and message content are transmitted to that provider so it can deliver the message. You may disconnect at any time, which deletes the stored credential; only non-content records of the connection and of past sends are retained for audit purposes. The same applies to any SMTP server you configure, which is a provider of your own choosing.
8. International transfers
Some subprocessors process data outside the UK/EEA. Where that happens we rely on UK adequacy regulations or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate additional safeguards.
9. Return, deletion and retention
You can export your workspace data at any time from Settings, and request deletion of your account from the same place. On termination we delete or return your customer data within 30 days, except where we must keep records to comply with a legal obligation (for example billing records). Backups age out within 30 days.
10. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your customer data, with the information you need to meet your own reporting duties.
11. Audit and information
On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this DPA.
12. Liability and governing law
The liability limits in the Terms and Conditions apply to this DPA. This DPA is governed by the law of Scotland, and the Scottish courts have exclusive jurisdiction, consistent with the Terms.
13. Contact
Data protection contact: info@bookavi.com.