BookBreathe Data Processing Agreement
Last updated: 5 September 2026
This Data Processing Agreement ("DPA") forms part of the BookBreathe Terms of Use between Flam Labs Ltd, trading as BookBreathe, a company registered in England and Wales under company number 17480585, whose registered office is at Primrose Cottage, Eversley Centre, Hook, Hampshire, RG27 0NF, United Kingdom ("BookBreathe", "we", "us" or "Processor"), and the business or organisation using the BookBreathe Service ("Customer", "you" or "Controller").
This DPA applies where BookBreathe processes Personal Data on behalf of the Customer in connection with the BookBreathe Service.
By agreeing to the BookBreathe Terms of Use and using the Service, the Customer also agrees to this DPA.
1. Definitions
For the purposes of this DPA:
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and other applicable UK data protection and privacy legislation, as amended or replaced from time to time.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given to them under Applicable Data Protection Law.
"Customer Data" means Personal Data processed by BookBreathe on behalf of the Customer through the Service.
"Service" means the BookBreathe websites, applications and services provided to the Customer.
"Sub-processor" means another processor engaged by BookBreathe to process Customer Data in connection with providing the Service.
2. Roles of the parties
The Customer is the Controller of Customer Data processed through BookBreathe.
BookBreathe acts as a Processor of that Customer Data on the Customer's behalf.
The Customer determines the purposes for which Customer Data is collected and processed.
The Customer is responsible for ensuring that its collection and use of Personal Data complies with Applicable Data Protection Law, including establishing an appropriate lawful basis and providing any necessary privacy information to Data Subjects.
BookBreathe will process Customer Data only as necessary to provide the Service and in accordance with the Customer's documented instructions, except where processing is required by applicable law.
The Customer's use and configuration of the Service, together with the Terms of Use and this DPA, constitute documented instructions to BookBreathe.
If BookBreathe is legally required to process Customer Data contrary to those instructions, BookBreathe will inform the Customer before carrying out that processing unless prohibited from doing so by law.
3. Details of the processing
Subject matter
BookBreathe processes Personal Data to provide software that enables service businesses to manage customer enquiries, communications, quotes, payments, bookings and related business activities.
Duration
Processing will continue for as long as the Customer uses the Service and for any limited retention period following termination or deletion that is reasonably necessary for backups, security, legal obligations or the orderly deletion of data.
Nature and purpose
Processing may include:
- collecting;
- receiving;
- storing;
- organising;
- retrieving;
- displaying;
- transmitting;
- updating;
- securing;
- backing up;
- deleting; and
- otherwise processing Personal Data as necessary to provide the Service.
The purpose of the processing is to enable the Customer to manage its customer relationships, enquiries, communications, quotes, payments and bookings using BookBreathe.
Categories of Data Subjects
Customer Data may relate to:
- prospective customers of the Customer;
- customers of the Customer;
- people making enquiries;
- people included within booking or event information;
- Customer employees;
- Customer contractors; and
- Customer team members.
Types of Personal Data
Depending on how the Customer configures and uses BookBreathe, Customer Data may include:
- names;
- email addresses;
- telephone numbers;
- postal addresses;
- enquiry information;
- event information;
- appointment or booking information;
- dates and locations;
- messages and communications;
- uploaded files;
- quote information;
- payment and transaction information;
- booking history;
- IP addresses and technical information; and
- other information submitted by Data Subjects or entered by the Customer into the Service.
The Customer controls the information it requests from its customers through configurable enquiry forms and other features.
4. Customer responsibilities
The Customer is responsible for ensuring that:
- it has a lawful basis for processing Customer Data;
- Data Subjects receive appropriate privacy information;
- information requested through enquiry forms is appropriate and necessary;
- Personal Data entered into BookBreathe has been collected lawfully;
- instructions given to BookBreathe comply with Applicable Data Protection Law; and
- its use of the Service complies with Applicable Data Protection Law.
The Customer must not instruct BookBreathe to process Personal Data unlawfully.
Unless expressly agreed otherwise, the Customer should not use BookBreathe to intentionally collect or store special category Personal Data where doing so is not reasonably necessary for its business.
5. BookBreathe's obligations
BookBreathe will:
- process Customer Data only on documented instructions from the Customer;
- comply with applicable obligations imposed directly upon processors by Applicable Data Protection Law;
- ensure that people authorised to process Customer Data are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures;
- reasonably assist the Customer with Data Subject requests;
- reasonably assist the Customer with its applicable data protection obligations;
- notify the Customer of qualifying Personal Data Breaches as described below;
- maintain appropriate records where required by law; and
- make information reasonably necessary to demonstrate compliance with this DPA available to the Customer.
6. Confidentiality
BookBreathe will ensure that employees, contractors and other people authorised to process Customer Data are subject to appropriate confidentiality obligations.
Access to Customer Data will be limited to people who reasonably require access for purposes including operating, maintaining, securing or supporting the Service.
7. Security
BookBreathe will implement appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the nature of the processing, these measures may include:
- encryption of data in transit;
- secure password hashing;
- authentication and access controls;
- tenant isolation;
- private storage for customer files;
- database security;
- backups;
- logging and monitoring;
- software patching and dependency updates;
- access restrictions;
- secure hosting infrastructure; and
- appropriate procedures for responding to security incidents.
Security measures may evolve as BookBreathe and the technologies used to provide the Service develop.
No method of electronic storage or transmission can guarantee absolute security.
8. Personal Data Breaches
If BookBreathe becomes aware of a Personal Data Breach affecting Customer Data, BookBreathe will notify the affected Customer without undue delay where required by Applicable Data Protection Law.
Where reasonably available, the notification will provide information concerning:
- the nature of the breach;
- the categories of information affected;
- the categories of Data Subjects affected;
- the likely consequences of the breach; and
- measures taken or proposed to address or mitigate the breach.
Where all information is not immediately available, BookBreathe may provide information in stages.
BookBreathe will take reasonable steps to investigate, contain and mitigate Personal Data Breaches affecting Customer Data.
The Customer remains responsible for determining whether it is required to notify the Information Commissioner's Office, affected Data Subjects or another authority.
9. Data Subject requests
Taking into account the nature of the processing, BookBreathe will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
These may include requests for:
- access;
- rectification;
- erasure;
- restriction;
- portability; or
- objection to processing.
Where BookBreathe receives a request directly from a Data Subject relating to Customer Data, BookBreathe may direct that person to the relevant Customer unless BookBreathe is legally required to respond directly.
The Customer remains responsible for responding to Data Subject requests.
10. Sub-processors
The Customer provides BookBreathe with general authorisation to engage Sub-processors where reasonably necessary to provide the Service.
Sub-processors may provide services including:
- cloud hosting;
- database infrastructure;
- file storage;
- email delivery;
- payment processing;
- security;
- monitoring and error reporting; and
- other infrastructure necessary to operate BookBreathe.
BookBreathe will ensure that Sub-processors processing Customer Data are subject to written contractual obligations providing an appropriate level of data protection consistent with the requirements applicable to BookBreathe under this DPA.
BookBreathe remains responsible for its Sub-processors to the extent required by Applicable Data Protection Law.
Where required, BookBreathe will make information about its material Sub-processors available to Customers.
Where BookBreathe intends to add or replace a Sub-processor that materially affects the processing of Customer Data, BookBreathe will provide reasonable notice where required, allowing the Customer an opportunity to raise reasonable data protection objections.
11. International transfers
BookBreathe will not transfer Customer Data outside the United Kingdom unless the transfer complies with Applicable Data Protection Law.
Where a Sub-processor processes Customer Data outside the United Kingdom, BookBreathe will ensure that an appropriate transfer mechanism is used where required.
This may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses; or
- another lawful transfer mechanism.
12. Assistance with compliance
Taking into account the nature of the processing and information available to BookBreathe, BookBreathe will provide reasonable assistance to the Customer in meeting applicable obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- Data Protection Impact Assessments; and
- consultation with supervisory authorities where required.
13. Data Protection Impact Assessments
Where the Customer reasonably determines that its use of BookBreathe requires a Data Protection Impact Assessment, BookBreathe will provide information reasonably available to it that is necessary to assist the Customer in completing that assessment.
The Customer remains responsible for determining whether a DPIA is required and for conducting it.
14. Deletion and return of Customer Data
During the term of the Service, the Customer may access and manage Customer Data through the functionality made available by BookBreathe.
Following termination of the Customer's account, BookBreathe will delete or return Customer Data in accordance with the Customer's instructions where reasonably practicable and as required by Applicable Data Protection Law.
Customer Data may remain temporarily within backups or archives after deletion from active systems.
Where immediate deletion from backups is not technically practical, the data will remain protected and will be deleted through BookBreathe's normal backup retention cycle.
BookBreathe may retain information where required by applicable law or where BookBreathe acts as an independent Controller for that information, such as certain financial, security or legal records.
15. Audits and compliance information
BookBreathe will make available information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR and this DPA.
Where that information is insufficient to reasonably demonstrate compliance, the Customer may request an audit relating specifically to BookBreathe's processing of Customer Data.
Audits must:
- be requested on reasonable notice;
- occur no more than once in any 12-month period unless a Personal Data Breach, regulatory requirement or reasonable evidence of material non-compliance justifies an additional audit;
- take place during normal business hours;
- avoid unreasonable disruption to BookBreathe or other customers;
- comply with reasonable security and confidentiality requirements; and
- be limited to information relevant to the Customer's Personal Data and BookBreathe's obligations under this DPA.
Where appropriate, BookBreathe may satisfy an audit request by providing relevant independent certifications, security documentation, questionnaires or audit reports instead of permitting direct access to systems containing other customers' information.
The Customer is responsible for its reasonable audit costs unless the audit identifies a material breach of this DPA by BookBreathe.
16. Customer instructions
The Customer instructs BookBreathe to process Customer Data as reasonably necessary to:
- provide the Service;
- operate features selected or configured by the Customer;
- communicate with Data Subjects on the Customer's behalf;
- facilitate payments and bookings;
- maintain and secure the Service;
- prevent fraud and abuse;
- provide technical support;
- maintain backups; and
- comply with other documented instructions provided through the Customer's use of the Service.
If BookBreathe believes that an instruction infringes Applicable Data Protection Law, BookBreathe will inform the Customer where required and may suspend the relevant processing until the matter is resolved.
17. Liability
The liability of each party arising from or relating to this DPA is subject to the limitations and exclusions of liability contained in the BookBreathe Terms of Use, except to the extent that such liability cannot lawfully be limited or excluded.
Nothing in this DPA limits any responsibility or liability imposed directly upon either party by Applicable Data Protection Law where that responsibility or liability cannot legally be excluded.
18. Relationship with the Terms of Use
This DPA forms part of the BookBreathe Terms of Use.
If there is a conflict between this DPA and the Terms of Use concerning the processing of Customer Data, this DPA will take precedence to the extent of that conflict.
The Privacy Policy explains how BookBreathe processes Personal Data where BookBreathe acts as a Controller in its own right.
19. Changes to this DPA
BookBreathe may update this DPA where reasonably necessary to:
- reflect changes to the Service;
- comply with changes in Applicable Data Protection Law;
- reflect changes to Sub-processors or infrastructure; or
- improve data protection arrangements.
Where a change materially affects the Customer's rights or BookBreathe's data protection obligations, BookBreathe will provide reasonable notice where appropriate.
20. Governing law
This DPA is governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction over disputes relating to this DPA, subject to any rights or jurisdiction that cannot lawfully be excluded.
21. Contact
Questions relating to this DPA or BookBreathe's processing of Personal Data can be sent to:
Flam Labs LtdPrimrose Cottage, Eversley Centre, Hook, Hampshire, RG27 0NF, United Kingdom
privacy@flamlabs.com
Schedule 1 — Processing details
Controller: The business or organisation holding the BookBreathe account.
Processor: Flam Labs Ltd / BookBreathe.
Subject matter: Provision of the BookBreathe enquiry, communication, quoting, payment and booking management Service.
Duration: For the duration of the Customer's use of BookBreathe, plus applicable deletion, backup and legal retention periods.
Purpose: To process Customer Data on behalf of the Customer in order to provide BookBreathe.
Data Subjects: Customers, prospective customers, enquiry submitters, booking participants where applicable, and members of the Customer's organisation.
Personal Data: Contact information, enquiry responses, communications, booking or event information, quotes, payment records, uploaded files, technical information and other information submitted to the Service by or on behalf of the Customer.
Special category data: Not intentionally required by BookBreathe as part of its standard Service. Customers should not request or store special category data unless they have determined that doing so is necessary and lawful.
Frequency: Continuous or as initiated by the Customer and its customers through use of the Service.