LEGAL
Data processing agreement
The controller and processor responsibilities between a business and Bexus Systems, in the form UK GDPR Article 28 requires.

1. Who is who
For everything a business’s customers do through Bexus Booking, the business is the controller and Carl Guinney, trading as Bexus Systems, is the processor. The business decides what to collect and why; we hold and handle it on the business’s instructions and for no purpose of our own.
For the business’s own account, and for anybody who applies for a founding place, we are the controller — that part is covered by the privacy notice rather than by this agreement.
2. What is processed
- Subject matter and duration
- Providing the booking and diary service, for as long as the business uses Bexus Booking.
- Nature and purpose
- Storing appointments and customer records; computing availability; sending transactional booking messages; keeping an audit record of changes.
- Categories of data subject
- The business’s customers, and the people the business gives access to its diary.
- Categories of personal data
- Name, email address, telephone number where given, appointment history, and any note the business chooses to keep about a customer.
- Special category data
- None is required and none is asked for. A business should not record health information in a customer note; if it does, it does so as controller and on its own basis.
3. Our obligations as processor
- Only on instructions. We process personal data only on the business’s documented instructions, which include using the service as it is described. If the law requires us to do otherwise we will tell the business first, unless the law forbids that.
- Confidentiality. Anybody we authorise to handle the data is bound to keep it confidential.
- Security. Appropriate technical and organisational measures — see section 5.
- Sub-processors. Only with the business’s general authorisation, and we will give notice of any change so the business can object. The current list is in section 6.
- Data subject requests. We assist the business in responding to requests for access, correction, erasure, restriction, portability and objection.
- Breaches. We notify the business without undue delay after becoming aware of a personal data breach, and in any case within 24 hours, with what we know at the time.
- Assistance. We assist with data protection impact assessments and with prior consultation, to the extent the information is ours to give.
- Return and deletion. At the end of the service we return the business’s data in a readable form and then delete it, except where the law requires us to keep it. A business can download its customers, its round and its bookings itself at any time, including while an account is suspended or closed — so return does not depend on us answering a request. Suspension and closure delete nothing; deletion is a separate step agreed with the business.
- Information and audit. We make available what is needed to show compliance with this agreement, and we submit to audit as described in section 7.
4. The business’s obligations
- To have a lawful basis for what it collects, and to give its customers the information the law requires — including its own privacy notice.
- To keep its own access under control, and to remove people who no longer need it.
- Where it imports customer information it already holds — to have the authority and the lawful basis to do so, and to have given those customers the information the law requires. We ask the business to confirm this before an import runs and record which wording was confirmed, which is a record of the instruction and not a transfer of the responsibility.
- Not to upload special-category information. The import is intended for ordinary customer, property and service information; special-category details — health, ethnicity, religion, political opinions, sexual orientation — are outside what it is for. An access note is for what the job needs — a gate, a dog, a key safe — rather than a fact about the person.
- To decide for itself whether it may market to imported customers. Putting somebody into Bexus Booking is an instruction to do the work they expect, and nothing more.
- Not to instruct us to do anything that would put either of us in breach of data protection law.
5. Security measures
These are the measures actually in place, not a list of intentions.
- Separation enforced by the database. Every business’s data is protected by PostgreSQL row-level security, forced on, so a query without a business’s context returns no rows at all rather than relying on application code to filter. The application connects as a role that cannot bypass it.
- Least privilege. The serving process holds no migration or superuser credential. It cannot delete audit records, cannot create its own invitations, and cannot read the founding-application table it writes to.
- Passwords. Stored only as a one-way hash, never in a form we can reverse.
- Transport. HTTPS everywhere, with session cookies marked HttpOnly, SameSite and Secure.
- Data minimisation by design. The message queue stores no recipient address and no message body; the audit trail stores the name of a changed field and never its old value; booking-management links are stored only as a one-way digest.
- Backups. Taken before every schema change, with the change refused unless evidence of a backup is present, and kept outside the application’s reach.
6. Sub-processors
- Hetzner Online GmbH (Germany)
- Hosting for the application and the database.
- A transactional email provider
- For booking confirmations and account recovery. None is engaged at the date of this agreement and no message has been sent to anybody. One will be named here, with notice, before it processes anything.
There are no analytics, advertising or profiling sub-processors, because the product uses none.
7. Audit
We will answer reasonable written questions about how the data is handled, and provide the documentation we hold. Given the size of the supplier, an on-site audit is by agreement rather than on demand, at the business’s cost, no more than once a year unless a breach or a regulator makes it necessary.
8. International transfers
Processing takes place in the United Kingdom and the European Economic Area. There is no transfer outside them at the date of this agreement. If engaging an email provider changes that, the safeguard will be named here before the transfer begins.
9. This is a draft
This document is offered for review and is not executed. A business that needs a signed agreement should ask, and should have it reviewed on its own behalf. Get in touch through support.
Who we are
- Trading name
- Bexus Systems, a UK sole trader established in England and Wales.
- Trader
- Carl Guinney
- Contact
- hello@bexusbooking.com
- Trading address
- 30 The Perrings, Bristol, BS48 4YL