Keepslot

Data processing agreement (DPA) for trainers

Version of 2026-08-25

This agreement says how Keepslot processes your clients' data on your behalf. It is the contract the GDPR (art. 28) requires between the person responsible for the data (you) and the one processing it for them (us). It is part of the Terms of use.

Contents

  1. Who signs and how
  2. What we process, why and for how long
  3. Your instructions
  4. Confidentiality
  5. Security measures
  6. Sub-processors
  7. How we help you
  8. End of service: return or delete
  9. Information and audit
  10. Liability
  11. Law and changes

1. Who signs and how

You accept this agreement when you reply «Yes» to the sign-up message in WhatsApp or press the accept button on the number connection page. We store the date and time of that acceptance in your account and you can ask for it at any time. Without acceptance, Keepslot does not message your clients.

2. What we process, why and for how long

Swipe sideways to see more →

Subject matterManaging bookings, reminders, rescheduling, waiting list, package balances and debts of your clients, through your WhatsApp Business number.
DurationAs long as your account is active, plus the 30-day deletion period after you cancel.
NatureStoring, organising, sending and receiving messages via approved templates, counting balances, logging actions. No automated decisions with legal effects.
PurposeOnly providing the Keepslot service to you. Never our own marketing, never selling data, never training models on your clients' data.
Data subjectsYour clients and, where they are minors, the parents or guardians who act as contact.
Types of dataName, phone, language, bookings, package balances, debts (amounts), consents, messages exchanged through Keepslot, copy of your manual messages (only for the 24-hour window), notes «what we did / what to do next». Health data and other special categories are forbidden — do not enter them.

3. Your instructions

We process data only on your instructions: this agreement, the Terms, your account settings (working hours, cancellation rules, approved templates) and the commands you give us. If an instruction seems to us to break the law, we tell you before following it.

You warrant that you have a legal basis for the data you give us: that your clients know you use Keepslot, that they agreed to reminders and that, for minors, you have the responsible adult's permission.

4. Confidentiality

Everyone on our side who can touch the data is bound to confidentiality by contract. Internal access is limited to the minimum needed to run the service and fix problems, and is logged.

5. Security measures

We review these measures at least once a year and whenever something relevant changes.

6. Sub-processors

You authorise us to use the providers listed in the Privacy policy (Supabase, Vercel, YCloud, Meta, Stripe, Google when you connect the calendar, Anthropic for your commands, Plausible). Each has a contract with us with obligations equivalent to this one.

If we want to add or replace a provider that touches your clients' data, we notify you 30 days in advance by message or email. If you disagree, you can cancel the account within that period at no cost. We remain responsible to you for what our providers do.

Transfers outside the EU (USA) only under the European Commission's standard contractual clauses or EU-US Data Privacy Framework certification.

7. How we help you

8. End of service: return or delete

When the account ends, you can ask within the following 30 days for an export of your clients, balances and bookings as a file (CSV). After 30 days we permanently erase active data, except what the law obliges us to keep (invoices). If production backups exist, their applicable retention and deletion cycle is published in the Privacy Policy.

You can also delete clients one by one at any time («delete X»): they become invisible immediately and are erased after 30 days.

9. Information and audit

On request, we give you the information needed to show you comply with the GDPR: this page, the list of providers, the security measures and your clients' consent records.

If you need an audit, it can take place once a year, with 30 days' notice, during working hours, remotely first (documents and questions). Costs are yours, unless the audit finds a serious failure on our side.

10. Liability

Each party is liable for the damage it causes by breaching the GDPR in its role. Our liability to you follows the limits in the Terms of use, except where the law does not allow a limit.

11. Law and changes

Portuguese law and the GDPR apply (and the UK GDPR for clients in the United Kingdom). If we change this agreement, we give 30 days' notice and publish the new version with its date; the version you accepted stays recorded in your account.