Data Processing Agreement
Last updated: July 24, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Tommachi AS, org. no. 914 824 680 MVA, Waldemars hage 6, 0175 Oslo, Norway (the “Processor”) and the business that uses MyWaitlist.app (the “Controller”, “you”). It is entered into automatically when you accept the Terms, and it governs our processing of personal data about your clients on your behalf under Article 28 of the GDPR. Where this DPA conflicts with the Terms on data protection, this DPA prevails.
1. Roles and scope
For the client data you enter into the service, you are the controller and we are your processor. For your own account data, we are the controller — that is governed by our Privacy Policy, not this DPA. Terms not defined here have the meaning given in the GDPR.
2. Subject matter, nature and duration
We process personal data only to provide the MyWaitlist service — storing your waitlist, sending the offers and invitations you trigger, and the related features you use. Processing lasts for as long as your account is active, and ends as set out in section 9. The categories of data and data subjects are described in Annex 1.
3. Our obligations as processor
We will:
- process client data only on your documented instructions — which include the Terms, this DPA, and your configuration and use of the service — unless required to act by EU or Norwegian law, in which case we will inform you first unless that law prohibits it;
- ensure that everyone authorised to process the data is bound by an obligation of confidentiality;
- implement appropriate technical and organisational security measures under Article 32 (see Annex 2);
- assist you, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights;
- assist you in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation (Articles 32–36);
- notify you without undue delay after becoming aware of a personal-data breach affecting your data;
- make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits as set out in section 8;
- inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.
4. Your obligations as controller
- You must have a valid legal basis to collect the client data and to have us process it, and to send offers and invitations to those clients.
- Your instructions must comply with data-protection law, and you are responsible for the accuracy and lawfulness of the data you enter.
- You must not use the service to process special categories of data (such as health data) unless you have a valid basis and appropriate safeguards.
5. Sub-processors
You give us general authorisationto engage the sub-processors listed in Annex 3 to help deliver the service. We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and we remain responsible for their performance. If we add or replace a sub-processor, we will notify you in advance (in the app or by email, normally at least 30 days beforehand). If you have a reasonable objection, you may raise it within that period; if we can't resolve it, you may terminate the affected service.
6. International transfers
Client data is stored in the EU. Where a sub-processor processes data outside the EEA, we ensure a valid transfer mechanism is in place — the European Commission's Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework — together with any additional safeguards required.
7. Security
We maintain the technical and organisational measures described in Annex 2, appropriate to the risk. We regularly review them and may update them, provided the level of protection is not reduced.
8. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Audits are conducted during business hours, subject to confidentiality, and in a way that does not disrupt our operations or other customers.
9. Deletion and return of data
You can delete client data at any time from within the app. When your account ends, we delete or return the client data as you choose, and remove it from our live systems within 30 days and from encrypted backups on our normal rotation shortly after — unless EU or Norwegian law requires us to keep it longer.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by applicable data-protection law.
11. Governing law
This DPA is governed by Norwegian law, with Oslo District Court as the agreed legal venue, consistent with the Terms.
Annex 1 — Details of processing
Categories of data subjects
The clients and prospective clients that you add to your waitlist or who join it through your public page.
Categories of personal data
- Name
- Contact details (email address and/or phone number)
- Client photo, if you add one
- Service preferences, appointment and availability preferences
- Notes you record, and waitlist and offer history
Nature and purpose
Storage, organisation and communication to operate a waitlist and booking-request workflow on your behalf.
Annex 2 — Security measures
- Encryption of data in transit (TLS) and at rest.
- Strict data isolation between businesses using database row-level security, so one account can never see another's data.
- Authentication with hashed passwords and support for Google sign-in; bot protection on sign-up and login.
- Access controls limiting administrative access to what is strictly necessary.
- Regular, encrypted backups.
- Use of reputable, security-certified infrastructure providers.
- Breach detection and notification processes.
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication and image storage | EU (AWS, Ireland) |
| Vercel, Inc. | Application hosting and cookieless analytics | USA / EEA |
| Stripe Payments Europe, Ltd. | Subscription billing and card processing | EU / USA |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | USA |
| Cloudflare, Inc. | Bot protection (Turnstile) on sign-up and login | USA / global |
| Google Ireland Ltd. | Optional Google sign-in | EU / USA |
Questions about this DPA? Contact support@mywaitlist.app.