Skip to content
StudioBook
Back to home

Data Processing Agreement (DPA)

Last updated: March 2026

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service between the studio owner ("Controller") and StudioBook ("Processor") and governs the processing of personal data by the Processor on behalf of the Controller in accordance with Art. 28 GDPR.

1. Scope and Parties

This DPA applies between:
- Controller: The studio owner who uses StudioBook to manage their studio, classes, and member bookings.
- Processor: StudioBook, operated by Marcel Jurna, Am Glockenberg 52, 51515 Kürten, Germany. Contact: hello@studiobook.app, +49 1525 3619145.

The Controller determines the purposes and means of the processing of personal data. The Processor processes personal data only on behalf of the Controller and in accordance with the Controller's documented instructions.

2. Subject Matter and Duration

The Processor provides a cloud-based booking and studio management platform. In the course of providing this service, the Processor processes personal data on behalf of the Controller.

This DPA is effective for the entire duration of the service agreement between the Controller and the Processor. It terminates automatically when the service agreement ends and all personal data has been deleted or returned.

3. Types of Personal Data Processed

The following categories of personal data are processed:
- Member/client names
- Member/client email addresses
- Booking history (classes booked, cancellations, waitlist entries)
- Attendance records
- Credit pack and membership usage
- Payment references (Stripe customer/charge IDs — no card numbers or bank details)
- Account creation method (email, Google OAuth)

4. Categories of Data Subjects

  • Studio members and clients: individuals who book classes, purchase credits or memberships, or otherwise interact with the studio's booking page.
  • Studio staff and instructors: individuals assigned to classes by the Controller.

5. Processor Obligations

5.1 Processing on Instructions

The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 Confidentiality

The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3 Security Measures (Art. 32 GDPR)

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures are described in detail in the Annex (Technical and Organisational Measures) of this DPA.

5.4 Sub-Processors

The Controller grants the Processor general authorisation to engage sub-processors listed in Section 6 of this DPA. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes within 14 days. If the Controller objects on reasonable grounds, the parties shall negotiate in good faith to find a solution. If no solution is found, the Controller may terminate the service agreement.

The Processor shall impose the same data protection obligations as set out in this DPA on any sub-processor by way of a contract. The Processor remains fully liable to the Controller for the performance of the sub-processor's obligations.

5.5 Data Subject Rights

The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).

5.6 Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach. The notification shall include:
- A description of the nature of the personal data breach
- The categories and approximate number of data subjects and records concerned
- The likely consequences of the breach
- The measures taken or proposed to address the breach

5.7 Data Protection Impact Assessment

The Processor shall assist the Controller with data protection impact assessments and prior consultations with supervisory authorities (Art. 35–36 GDPR), taking into account the nature of processing and the information available to the Processor.

5.8 Deletion or Return of Data

Upon termination of the service agreement, the Processor shall, at the choice of the Controller, delete or return all personal data and delete existing copies unless Union or Member State law requires storage of the personal data. When the Controller deletes their account, all personal data is immediately and permanently removed.

Retention periods are detailed in our Privacy Policy.

5.9 Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

6. Sub-Processors

The Processor uses the following sub-processors:

Sub-ProcessorPurposeLocation
SupabaseDatabase hosting, authentication, edge functionsEU (Frankfurt, Germany)
StripePayment processing (SaaS subscriptions, Stripe Connect for member payments)EU (Ireland) / US
ResendTransactional email delivery (booking confirmations, reminders)US
GoogleOAuth authentication (sign-in with Google)EU / US
VercelApplication hosting and deploymentEU / US

7. Data Breach Notification

In the event of a personal data breach, the Processor shall:
- Notify the Controller within 24 hours of becoming aware of the breach
- Provide all information required under Art. 33(3) GDPR
- Cooperate with the Controller in investigating and remedying the breach
- Assist the Controller in fulfilling their notification obligations to supervisory authorities and data subjects

8. International Data Transfers

Where personal data is transferred to sub-processors outside the European Economic Area (EEA):
- EU Standard Contractual Clauses (SCCs): are in place with all non-EU sub-processors
- EU-US Data Privacy Framework: applicable sub-processors (Stripe, Resend, Google) are certified under the EU-US Data Privacy Framework
- The Processor ensures that any transfer complies with Chapter V GDPR

9. Technical and Organisational Measures (Annex)

The Processor implements the following measures pursuant to Art. 32 GDPR:

9.1 Access Control

  • Row Level Security (RLS) policies on all database tables
  • Multi-tenant isolation by studio_id — each studio can only access its own data
  • Role-based access control (studio owner, instructor, member)
  • JWT-based authentication tokens with expiration

9.2 Encryption

  • In transit: All data transmitted via TLS 1.2+ (HTTPS only)
  • At rest: AES-256 encryption via Supabase/AWS infrastructure
  • No unencrypted data storage or transmission

9.3 Authentication

  • Bcrypt password hashing with salting
  • OAuth 2.0 via Google
  • JWT tokens for session management
  • Secure password reset flows via email verification

9.4 Availability and Resilience

  • Managed database backups via Supabase
  • Point-in-time recovery capability
  • Hosted on AWS EU infrastructure with redundancy

9.5 Data Separation

  • Logical multi-tenant architecture with strict studio_id scoping
  • Each studio's data is logically isolated from other studios
  • No cross-studio data access possible through the application layer

9.6 Input Control

  • Audit logging via notification_logs table
  • All booking, cancellation, and payment events are logged with timestamps
  • Transactional email delivery logs

9.7 Transfer Control

  • HTTPS-only communication (no HTTP fallback)
  • CORS restrictions limiting API access to authorised origins
  • API authentication required for all data endpoints

10. Liability

The Processor shall be liable for damages caused by processing that does not comply with this DPA or with the obligations of the GDPR specifically directed to processors. The Processor remains liable if a sub-processor fails to fulfil its data protection obligations.

11. Term and Termination

This DPA is effective for the entire duration of the service agreement between the Controller and the Processor. It cannot be terminated separately from the service agreement. Upon termination, the obligations regarding data deletion/return (Section 5.8) and confidentiality (Section 5.2) survive.

12. Governing Law and Jurisdiction

This DPA is governed by the laws of the Federal Republic of Germany. For merchants (Kaufleute), the exclusive place of jurisdiction is Cologne, Germany. For consumers, the statutory rules on jurisdiction apply.

13. Contact

For questions regarding this DPA or data protection matters:

Marcel Jurna
Am Glockenberg 52, 51515 Kürten, Germany
E-Mail: hello@studiobook.app
Phone: +49 1525 3619145