Data processing agreement (DPA) for trainers
Version of 2026-08-25
This agreement says how Keepslot processes your clients' data on your behalf. It is the contract the GDPR (art. 28) requires between the person responsible for the data (you) and the one processing it for them (us). It is part of the Terms of use.
Contents
1. Who signs and how
- Controller: you, the trainer, holder of the Keepslot account.
- Processor: PAVEL BELOV, a sole trader registered in Portugal, tax number (NIF) 324091443, RUA MONSENHOR FERREIRA NÚMERO 299/305 1 DRT, 4710-407 BRAGA, PORTUGAL — info@keepslot.app.
You accept this agreement when you reply «Yes» to the sign-up message in WhatsApp or press the accept button on the number connection page. We store the date and time of that acceptance in your account and you can ask for it at any time. Without acceptance, Keepslot does not message your clients.
2. What we process, why and for how long
Swipe sideways to see more →
| Subject matter | Managing bookings, reminders, rescheduling, waiting list, package balances and debts of your clients, through your WhatsApp Business number. |
| Duration | As long as your account is active, plus the 30-day deletion period after you cancel. |
| Nature | Storing, organising, sending and receiving messages via approved templates, counting balances, logging actions. No automated decisions with legal effects. |
| Purpose | Only providing the Keepslot service to you. Never our own marketing, never selling data, never training models on your clients' data. |
| Data subjects | Your clients and, where they are minors, the parents or guardians who act as contact. |
| Types of data | Name, phone, language, bookings, package balances, debts (amounts), consents, messages exchanged through Keepslot, copy of your manual messages (only for the 24-hour window), notes «what we did / what to do next». Health data and other special categories are forbidden — do not enter them. |
3. Your instructions
We process data only on your instructions: this agreement, the Terms, your account settings (working hours, cancellation rules, approved templates) and the commands you give us. If an instruction seems to us to break the law, we tell you before following it.
You warrant that you have a legal basis for the data you give us: that your clients know you use Keepslot, that they agreed to reminders and that, for minors, you have the responsible adult's permission.
4. Confidentiality
Everyone on our side who can touch the data is bound to confidentiality by contract. Internal access is limited to the minimum needed to run the service and fix problems, and is logged.
5. Security measures
- Encryption in transit (TLS) and at rest in the database.
- Database in the European Union (Frankfurt). Production backup and restore must be configured and tested before live data is accepted.
- Trainer access through a private link with a unique token; keys and secrets kept outside the code.
- Data separated per trainer: your account never sees another's data.
- Every action logged with «undo».
- Technical logs deleted after 90 days.
- Regular security updates from providers.
We review these measures at least once a year and whenever something relevant changes.
6. Sub-processors
You authorise us to use the providers listed in the Privacy policy (Supabase, Vercel, YCloud, Meta, Stripe, Google when you connect the calendar, Anthropic for your commands, Plausible). Each has a contract with us with obligations equivalent to this one.
If we want to add or replace a provider that touches your clients' data, we notify you 30 days in advance by message or email. If you disagree, you can cancel the account within that period at no cost. We remain responsible to you for what our providers do.
Transfers outside the EU (USA) only under the European Commission's standard contractual clauses or EU-US Data Privacy Framework certification.
7. How we help you
- Requests from your clients (access, correction, erasure, portability, objection): if they reach us directly, we forward them to you within 3 working days and give you the data to answer. «STOP» and «delete» are executed immediately by the system.
- Data breaches: if we learn of an incident affecting your clients' data, we notify you within 48 hours at most with what we know (what happened, which data, which people, what we have already done) and keep you updated. We help you notify the authority and the people, if needed.
- Impact assessments and consultations with the authority: we give you the information you need about how we process the data.
8. End of service: return or delete
When the account ends, you can ask within the following 30 days for an export of your clients, balances and bookings as a file (CSV). After 30 days we permanently erase active data, except what the law obliges us to keep (invoices). If production backups exist, their applicable retention and deletion cycle is published in the Privacy Policy.
You can also delete clients one by one at any time («delete X»): they become invisible immediately and are erased after 30 days.
9. Information and audit
On request, we give you the information needed to show you comply with the GDPR: this page, the list of providers, the security measures and your clients' consent records.
If you need an audit, it can take place once a year, with 30 days' notice, during working hours, remotely first (documents and questions). Costs are yours, unless the audit finds a serious failure on our side.
10. Liability
Each party is liable for the damage it causes by breaching the GDPR in its role. Our liability to you follows the limits in the Terms of use, except where the law does not allow a limit.
11. Law and changes
Portuguese law and the GDPR apply (and the UK GDPR for clients in the United Kingdom). If we change this agreement, we give 30 days' notice and publish the new version with its date; the version you accepted stays recorded in your account.