Legal

Data Processing Agreement

This Data Processing Agreement (DPA) applies when Petra Nova Holdings, trading as Its My Site, processes Customer Personal Data on behalf of the Customer in connection with the Services. It forms part of the Terms of Service (or other written agreement governing use of the Services), is accepted electronically through signup or use of the Service, and is intended to satisfy Article 28 of the UK GDPR / EU GDPR and similar applicable data processing requirements. A signed version may be provided on request.

Effective date: 3 August 2026

Processor identity

Related: Terms of Service · Privacy Policy · Subprocessors.

1. Definitions and scope

In this DPA:

  • Customer means the practitioner, business, or other person that has an account for the Services and determines (alone or jointly) the purposes and means of processing Customer Personal Data.
  • Customer Personal Data means personal data that the Customer (or its end users) submits to, or generates in, the Services for processing on the Customer’s behalf (for example client booking details, CRM records, form answers, and site content containing personal data).
  • Controller and Processor have the meanings given in Data Protection Laws.
  • Services means the Its My Site platform and related features described in the Terms of Service, including hosting of the Customer’s public site, bookings, CRM-style client records, forms, contracts, calendar integrations, and platform support.
  • Subprocessor means a third party engaged by us to process Customer Personal Data in connection with the Services.
  • Data Protection Laws means the UK GDPR, the EU GDPR (where applicable), and other data protection laws that apply to the processing under this DPA.

For Customer Personal Data processed through the Services on the Customer’s behalf, the Customer acts as Controller (or as a processor toward its own clients, as applicable), and Petra Nova Holdings / Its My Site acts as Processor.

This DPA does not govern processing where Its My Site acts as an independent controller for its own purposes — for example the marketing website, account authentication, platform billing, security and fraud prevention, product analytics and advertising measurement on platform hosts, support operations, or legal compliance. Those activities are described in our Privacy Policy and other applicable terms.

2. Subject matter, duration, nature, and purpose

  • Subject matter: provision of the Its My Site Services to the Customer.
  • Duration: for as long as the Customer uses the Services, plus any limited period needed after termination for deletion or return and for lawful retention described in Section 9.
  • Nature: hosting, storage, organisation, retrieval, transmission, support, booking workflows, form handling, CRM-style records, optional calendar integration, contract and e-signature workflows, and related processing needed to provide the Services.
  • Purpose: to provide, secure, maintain, and support the Services as instructed by the Customer (including through the Customer’s use and configuration of the product).

Further detail is set out in Annex 1.

3. Types of data and data subjects

Depending on how the Customer uses the Services, Customer Personal Data may include:

  • Identity and contact details (for example name and email)
  • Account and profile information the Customer enters about their practice
  • Practitioner customer / CRM records (leads, contacts, notes, status fields)
  • Booking and appointment data
  • Form responses and similar intake content
  • Contract / agreement content, signatures, and related metadata
  • Communications content sent through or generated by the Services (for example enquiry messages)
  • Payment-related identifiers and transaction references (card data is handled by Stripe; we do not store full card numbers)
  • Technical and usage data needed to deliver and secure the Services (for example path-level visit counts on the Customer’s published site; IP or user-agent where collected for form or e-sign audit trails)

Data subjects may include:

  • Customer account users
  • Customer staff or team members (if any are given access)
  • The Customer’s leads, contacts, prospects, and clients
  • Other individuals whose personal data the Customer chooses to submit through the Services

4. Customer instructions and responsibilities

We process Customer Personal Data only on documented instructions from the Customer, including instructions given through the Customer’s use and configuration of the Services, unless we are required to process data by applicable law. If a legal requirement prevents us from following an instruction, we will inform the Customer unless the law prohibits that notice.

The Customer is responsible for:

  • the lawfulness of Customer Personal Data it submits or collects through the Services
  • providing required privacy notices to data subjects
  • obtaining consents or establishing another lawful basis where required
  • deciding whether special-category data is entered into the Services
  • configuring and using the Services in a way that is appropriate for its practice and obligations

5. Confidentiality and security

We ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

We implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, taking into account the nature of the Services and the state of the art. A summary of those measures is in Annex 2.

We will provide the Customer with reasonable assistance, as appropriate to our role as Processor, in relation to security incidents affecting Customer Personal Data and related compliance obligations described in Section 8.

6. Special-category data

The Services are not designed or marketed as a special-category (sensitive data) processing service. We do not systematically collect special-category data for our own independent purposes.

Special-category data is not prohibited by default. The Customer may choose to submit such data through free-text fields, forms, notes, bookings, contracts, or similar content areas. The Customer remains responsible for having a lawful basis under Article 6 and, where applicable, Article 9 of the UK GDPR / EU GDPR, and for providing any necessary notices and safeguards. The Customer should only submit special-category data where it is necessary and lawful for their use of the Services.

7. Subprocessors

The Customer provides general written authorisation for us to use the subprocessors listed on our Subprocessors page. That page forms part of this DPA (see Annex 3).

We will impose data protection obligations on subprocessors that are no less protective, in substance, than those in this DPA, to the extent applicable to the services they provide.

Before adding or replacing a subprocessor that materially affects the processing of Customer Personal Data, we will give at least 30 days’ prior notice (for example by updating the Subprocessors page and/or email notice). The Customer may object on reasonable data protection grounds within that notice period. If the parties cannot reasonably resolve the objection, the Customer may stop using the affected feature or terminate the affected Services, as appropriate under the Terms of Service.

8. Assistance with rights, incidents, and compliance

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to help the Customer:

  • respond to data subject requests relating to Customer Personal Data
  • address personal data breaches affecting Customer Personal Data, including providing information we reasonably hold so the Customer can meet its notification obligations
  • support data protection impact assessments and prior consultation with a supervisory authority, where applicable

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us about the nature of the breach and measures taken or proposed.

9. Deletion or return

At the end of the provision of Services relating to processing (including when the Customer deletes their account or the agreement ends), we will, at the Customer’s choice, return Customer Personal Data or delete it, unless applicable law requires storage.

In practice, when an account is terminated or deleted, we erase associated production Customer Personal Data without undue delay and in any event within 30 days, except for limited records we may retain longer where required for billing, security, fraud prevention, dispute resolution, legal obligations, or legal claims (for example Stripe billing metadata). Residual copies may remain temporarily in secure backups until overwritten in the ordinary backup cycle.

Unfinished setups that are started but never published may be erased earlier under our abandoned-onboarding retention practice described in the Privacy Policy (currently after 30 days of inactivity).

10. Audit and information rights

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Audit and information requests must be reasonable and proportionate, and scheduled to avoid unreasonable disruption to the Services.

Where suitable, remote or document-based review (for example security summaries, this DPA, the Subprocessors page, and relevant policy pages) is the default. On-site audits, if reasonably necessary, are subject to confidentiality, security, and operational safeguards, and to advance notice.

11. International transfers

Customer Personal Data may be processed in countries other than the Customer’s own country through our hosting providers and approved subprocessors. Where required by Data Protection Laws, we rely on appropriate transfer safeguards offered by those providers (or other lawful transfer mechanisms).

More detail may be available on the Subprocessors page, in applicable vendor terms, or on request to legal@its-my-site.com.

12. Order of precedence

If there is a conflict between this DPA and the Terms of Service solely with respect to the processing of Customer Personal Data, this DPA controls to that extent. For governing law and jurisdiction, the Terms of Service apply unless a separate written agreement between the parties says otherwise.

13. Contact

Questions about this DPA: legal@its-my-site.com

Effective date: 3 August 2026. We may update this DPA from time to time; the effective date above will be revised when we do. Material changes may also be communicated by email or in-product notice where appropriate.

Annex 1 — Description of processing

  • Subject matter: Hosting and operation of the Its My Site Services for the Customer.
  • Duration: Term of the Customer’s use of the Services, plus post-termination deletion / limited lawful retention (Section 9).
  • Nature and purpose: Processing necessary to provide, secure, maintain, and support the Services as instructed by the Customer, including public site hosting, bookings, CRM-style records, forms, contracts, optional calendar sync, and related communications.
  • Categories of personal data: As listed in Section 3 (identity/contact, profile/site content, CRM, bookings, forms, contracts, communications, payment references, and technical/security data associated with service delivery).
  • Categories of data subjects: As listed in Section 3 (Customer users, optional staff, and the Customer’s leads/clients/contacts and other individuals whose data the Customer submits).

Annex 2 — Technical and organisational measures

Measures we use are designed to be appropriate for a small multi-tenant SaaS product. They include, among other things:

  • Access controls: authenticated access to the practitioner dashboard; tenant-scoped data access enforced in the application and database (row-level security patterns); service-role / privileged credentials restricted to server-side operations.
  • Authentication: passwordless email one-time codes for sign-in; session controls including idle timeout on the dashboard; step-up email verification for certain sensitive account actions (for example account deletion and billing portal access).
  • Encryption in transit: HTTPS / TLS for the production Service.
  • Encryption of certain secrets at rest: calendar OAuth refresh tokens stored encrypted (application-level encryption) when calendar sync is connected.
  • Least privilege and secrets handling: separation of client-safe configuration from server-only secrets; no storage of full payment card numbers on our servers (handled by Stripe).
  • Service provider management: use of vetted infrastructure and subprocessors listed on the Subprocessors page, under their respective terms.
  • Deletion workflows: in-product account deletion that erases associated production tenant data, with abandoned never-published setups purged after a defined inactivity period (see Privacy Policy and Section 9).
  • Logging and abuse controls: operational and security logging as needed to run and protect the Service; request integrity protections on server functions; verification of payment webhooks and authenticated cron jobs where used.
  • Backup and recovery: reliance on infrastructure provider backup and recovery capabilities for the hosted database and application platform.
  • Incident support: processes to investigate and notify Customers of personal data breaches affecting Customer Personal Data as described in Section 8.

These measures are not a guarantee against all security risks. We do not claim specific third-party certifications in this DPA unless separately confirmed in writing.

Annex 3 — Approved subprocessors

Current approved subprocessors are listed on our Subprocessors page. That page forms part of this DPA and may be updated from time to time subject to the notice process in Section 7.