Skip to content
StudioBook
Back to home

Data Processing Agreement (DPA)

Last updated: September 2026 — version 2026-09-studio.1. Change: § 3 adds child profiles (family accounts) — first name, last name and an optional date of birth for a child a member adds to their own account in order to book them into classes; § 4 extends the "Minors" category accordingly. No account is created for the child, and a child profile is visible to the Controller only where that child has a booking with them. Adding a category of personal data is a substantive change; it alters no retention period, security measure, sub-processor or allocation of liability.

Previous version 2026-09-studio: § 3 added the member's postal address (collected when a member takes a membership with a minimum term of more than one month) and, as an optional field on the member's own account page, their date of birth. Adding categories of personal data is a substantive change; it alters no retention period, security measure, sub-processor or allocation of liability.

Previous version 2026-08-studio.3: § 6 added Urban Sports GmbH (Urban Sports Club) as a sub-processor, engaged only where the Controller has switched the Urban Sports Club integration on. Where it is on, the Controller's class schedule and the names of the instructors teaching those classes are transmitted to Urban Sports Club so the classes can be published in their app. Adding a sub-processor was a substantive change.

Previous version 2026-08-studio.2: § 3 added the telephone number as an optional member contact detail, whether the member enters it themselves or the Controller enters it for them.

Previous version 2026-08-studio: § 3 added the contact details of members entered by the Controller itself (walk-ins, telephone bookings, clients migrated from a previous system), which reach the Processor from the Controller rather than from the data subject (Art. 14 GDPR); § 4 added those members as a category of data subjects.

Previous version 2026-07-studio: § 3 covered free-text fields defined by the Controller (intake forms and per-class questions), which may contain special categories of data under Art. 9 GDPR; § 3.1 added the corresponding Controller obligations; § 4 added minors and invited guests as categories of data subjects; § 3 also covered the contact details of invited guests, obtained from the booking member rather than from the data subject (Art. 14 GDPR).

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service between the studio owner ("Controller") and StudioBook ("Processor") and governs the processing of personal data by the Processor on behalf of the Controller in accordance with Art. 28 GDPR.

1. Scope and Parties

This DPA applies between:
- Controller: The studio owner who uses StudioBook to manage their studio, classes, and member bookings.
- Processor: StudioBook, operated by Marcel Jurna, Am Glockenberg 52, 51515 Kürten, Germany. Contact: hello@studiobook.app, +49 1525 3619145.

The Controller determines the purposes and means of the processing of personal data. The Processor processes personal data only on behalf of the Controller and in accordance with the Controller's documented instructions.

2. Subject Matter and Duration

The Processor provides a cloud-based booking and studio management platform. In the course of providing this service, the Processor processes personal data on behalf of the Controller.

This DPA is effective for the entire duration of the service agreement between the Controller and the Processor. It terminates automatically when the service agreement ends and all personal data has been deleted or returned.

3. Types of Personal Data Processed

The following categories of personal data are processed:
- Member/client names
- Member/client email addresses
- Booking history (classes booked, cancellations, waitlist entries)
- Attendance records
- Credit pack and membership usage
- Payment references (Stripe customer/charge IDs — no card numbers or bank details)
- Account creation method (email, Google OAuth)
- Postal address: collected when a member takes a membership with a minimum term of more than one month. It is processed for invoicing (§ 14 UStG requires the recipient's full address on invoices of €250 or more) and for the enforcement of that contract, where § 690 ZPO requires the debtor's address in an order for payment. It is not used for advertising. Legal basis: Art. 6(1)(b) GDPR. Members who take no membership with a minimum term are not asked for it.
- Date of birth: optional, and offered only on the member's own account page — never requested at checkout, never a condition of any purchase, and never entered by the Controller on a member's behalf. Visible to the Controller. Not used for advertising or for any automated decision. Legal basis: Art. 6(1)(a) GDPR — consent, given by entering it and withdrawn by clearing the field.
- Contact details of invited guests: the name and, where supplied, the email address of a third party whom a member adds to their own booking. This data reaches the Processor from the booking member rather than from the data subject (Art. 14 GDPR), is used solely to inform that person about the seat reserved in their name, and is erased within three days of the class.
- Contact details of members entered by the Controller: the name, email address and — where the Controller enters one — telephone number of a client whom the Controller adds to its own member list directly, rather than the client registering themselves — for example a walk-in, a booking taken by telephone, or a client migrated from a previous booking system. This data reaches the Processor from the Controller rather than from the data subject (Art. 14 GDPR). The Processor creates a passwordless account record and, if the Controller asks it to, sends that person a single transactional notice stating who entered their details and offering a link that removes them without requiring an account. The Controller alone decides whose details are entered and is responsible for the legal basis for doing so. Neither acceptance of the member terms nor consent to marketing can be given by the Controller on the data subject's behalf; both remain unset until the person acts on them.
- Free-text information whose content is defined by the Controller: answers to intake forms and to additional questions the Controller may attach to individual classes, together with the associated record of consent (wording shown, timestamp). The Controller alone decides which questions are asked and therefore which data is collected. This category is open-ended by design and may include special categories of personal data under Art. 9 GDPR — in particular health data such as injuries, medical conditions, allergies, or care-relevant needs.
- Child profiles (family accounts): first name, last name and — where the holder of parental responsibility enters it — the date of birth of a child that a member adds to their own account in order to book them into classes. This data reaches the Processor via the holder of parental responsibility rather than from the data subject themselves (Art. 14 GDPR). No account is created for the child: no email address, no password, no login, and no direct relationship arises between the child and the Processor. The Controller cannot create a child profile on the member's behalf. A child profile is visible to the Controller only where that child has a booking with them. The consent of the holder of parental responsibility is recorded together with the exact wording displayed and the timestamp. Health- or care-related information is not stored on the profile; it belongs to the individual booking (see above).

3.1 Controller obligations for Controller-defined fields

Because the Controller determines the wording of intake and per-class questions, the Controller is responsible for ensuring that:
- only data necessary for the stated purpose is requested (data minimisation, Art. 5(1)(c) GDPR);
- a valid legal basis exists for the data requested — where special categories are collected, the explicit consent of the data subject under Art. 9(2)(a) GDPR. StudioBook provides the consent mechanism and records each consent together with the exact wording displayed at the time;
- no data relating to criminal convictions or offences (Art. 10 GDPR) is collected through these fields.

StudioBook does not inspect, evaluate or otherwise use the content of these fields, and processes it solely on the documented instructions of the Controller.

4. Categories of Data Subjects

  • Studio members and clients: individuals who book classes, purchase credits or memberships, or otherwise interact with the studio's booking page.
  • Studio staff and instructors: individuals assigned to classes by the Controller.
  • Invited guests: individuals whom a member adds to their own booking and who have no account with the Controller or the Processor. Their contact details are supplied by the booking member, not by them.
  • Members entered by the Controller: individuals whom the Controller adds to its member list directly instead of them registering themselves. Their contact details are supplied by the Controller, not by them, and the account created for them holds no password and no accepted terms until they choose to set them.
  • Minors: children and adolescents about whom a parent or legal guardian provides information when booking on their behalf (e.g. care-relevant details for children's offerings), and children for whom a parent or legal guardian creates a child profile in their account in order to book them into classes. All such information is provided and consented to by the parent or legal guardian; the child itself has no account and no direct relationship with the Processor.

5. Processor Obligations

5.1 Processing on Instructions

The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 Confidentiality

The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3 Security Measures (Art. 32 GDPR)

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures are described in detail in the Annex (Technical and Organisational Measures) of this DPA.

5.4 Sub-Processors

The Controller grants the Processor general authorisation to engage sub-processors listed in Section 6 of this DPA. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes within 14 days. If the Controller objects on reasonable grounds, the parties shall negotiate in good faith to find a solution. If no solution is found, the Controller may terminate the service agreement.

The Processor shall impose the same data protection obligations as set out in this DPA on any sub-processor by way of a contract. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

5.5 Data Subject Rights

The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).

5.6 Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach. The notification shall include:
- A description of the nature of the personal data breach
- The categories and approximate number of data subjects and records concerned
- The likely consequences of the breach
- The measures taken or proposed to address the breach

5.7 Data Protection Impact Assessment

The Processor shall assist the Controller with data protection impact assessments and prior consultations with supervisory authorities (Art. 35–36 GDPR), taking into account the nature of processing and the information available to the Processor.

5.8 Deletion or Return of Data

Upon termination of the service agreement, the Processor shall, at the choice of the Controller, delete or return all personal data and delete existing copies unless Union or Member State law requires storage of the personal data. When the Controller deletes their account, all personal data is immediately and permanently removed.

Retention periods are detailed in our Privacy Policy.

5.9 Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

6. Sub-Processors

The Processor uses the following sub-processors:

Sub-ProcessorPurposeLocation
SupabaseDatabase hosting, authentication, edge functionsEU (Frankfurt, Germany)
StripePayment processing (SaaS subscriptions, Stripe Connect for member payments)EU (Ireland) / US
ResendTransactional email delivery (booking confirmations, reminders)US
GoogleOAuth authentication (sign-in with Google)EU / US
VercelApplication hosting and deploymentEU / US
Urban Sports GmbH (Urban Sports Club) — *only where the Controller has switched the Urban Sports Club integration on*Publishing the Controller's class schedule to the Urban Sports Club app and receiving the resulting bookings and check-insGermany (Berlin)

7. Data Breach Notification

In the event of a personal data breach, the Processor shall:
- Notify the Controller within 24 hours of becoming aware of the breach
- Provide all information required under Art. 33(3) GDPR
- Cooperate with the Controller in investigating and remedying the breach
- Assist the Controller in fulfilling their notification obligations to supervisory authorities and data subjects

8. International Data Transfers

Where personal data is transferred to sub-processors outside the European Economic Area (EEA):
- EU Standard Contractual Clauses (SCCs): are in place with all non-EU sub-processors
- EU-US Data Privacy Framework: applicable sub-processors (Stripe, Resend, Google) are certified under the EU-US Data Privacy Framework
- The Processor ensures that any transfer complies with Chapter V GDPR

9. Technical and Organisational Measures (Annex)

The Processor implements the following measures pursuant to Art. 32 GDPR:

9.1 Access Control

  • Row Level Security (RLS) policies on all database tables
  • Multi-tenant isolation by studio_id — each studio can only access its own data
  • Role-based access control (studio owner, instructor, member)
  • JWT-based authentication tokens with expiration

9.2 Encryption

  • In transit: All data transmitted via TLS 1.2+ (HTTPS only)
  • At rest: AES-256 encryption via Supabase/AWS infrastructure
  • No unencrypted data storage or transmission

9.3 Authentication

  • Bcrypt password hashing with salting
  • OAuth 2.0 via Google
  • JWT tokens for session management
  • Secure password reset flows via email verification

9.4 Availability and Resilience

  • Managed database backups via Supabase
  • Point-in-time recovery capability
  • Hosted on AWS EU infrastructure with redundancy

9.5 Data Separation

  • Logical multi-tenant architecture with strict studio_id scoping
  • Each studio's data is logically isolated from other studios
  • No cross-studio data access possible through the application layer

9.6 Input Control

  • Audit logging via notification_logs table
  • All booking, cancellation, and payment events are logged with timestamps
  • Transactional email delivery logs

9.7 Transfer Control

  • HTTPS-only communication (no HTTP fallback)
  • CORS restrictions limiting API access to authorised origins
  • API authentication required for all data endpoints

10. Liability

The Processor shall be liable for damages caused by processing that does not comply with this DPA or with the obligations of the GDPR specifically directed to processors. The Processor remains liable if a sub-processor fails to fulfil its data protection obligations.

11. Term and Termination

This DPA is effective for the entire duration of the service agreement between the Controller and the Processor. It cannot be terminated separately from the service agreement. Upon termination, the obligations regarding data deletion/return (Section 5.8) and confidentiality (Section 5.2) survive.

12. Governing Law and Jurisdiction

This DPA is governed by the laws of the Federal Republic of Germany. For merchants (Kaufleute), the exclusive place of jurisdiction is Cologne, Germany. For consumers, the statutory rules on jurisdiction apply.

13. Contact

For questions regarding this DPA or data protection matters:

Marcel Jurna
Am Glockenberg 52, 51515 Kürten, Germany
E-Mail: hello@studiobook.app
Phone: +49 1525 3619145