Log in

Data processing agreement

Processing your bookers' data

When people book your rooms and desks, you decide what happens with their details; we store and handle them for you, only as needed to run Booking. This agreement (GDPR Article 28) is part of our terms of service.

Last updated 6 October 2026

Parties

The agreement applies for as long as we process personal data for you, and ends when that data has been deleted or returned.

What is processed

No special categories of personal data are needed. Please don't ask people to write such data (for example about health) in the purpose or note fields.

Our commitments

Security

Subprocessors

You allow us to use these providers. We bind each of them to data protection obligations at least as strict as ours, and stay responsible for them.

We'll tell you at least 30 days before adding or replacing a subprocessor. If you object for a good reason and we can't find a solution, you may end the service and get back fees paid in advance for the remaining time.

Transfers outside the EU

Where a subprocessor handles data outside the EU/EEA, the transfer is protected with the safeguards the GDPR requires – the EU–US Data Privacy Framework where the provider is certified, otherwise the European Commission's standard contractual clauses.

Helping you

Personal data breaches

If we become aware of a breach affecting your data, we tell you without undue delay and within 48 hours, with what we know: what happened, which data and people are likely affected, the likely consequences, and what we're doing about it. We help you with notifying the authority and the people concerned.

At the end

When you stop using FloorKite, you can download your bookings for 30 days. After that we delete the personal data we hold for you, including copies, within 90 days from backups – unless the law requires us to keep something, in which case we keep it safe and only for that.