Data Processing Agreement (DPA)
Data processing agreement under GDPR Art. 28
Last updated: July 30, 2026
1. The parties
This DPA applies between Meetrana (data processor) and the connected business (data controller) that collects personal data from end customers via Meetrana's platform. This agreement is an integral part of the Business Terms.
2. Subject matter and duration
Meetrana processes personal data on behalf of the connected business for as long as the business has an active subscription. After termination, data is deleted per section 12.
3. Nature and purpose of the processing
Facilitating bookings between the business and end customers, handling payments (via Stripe Connect), sending booking confirmations by email, providing POS/checkout functionality, managing employee schedules.
4. Types of personal data
legal.dpa.section4.intro
- Name, email, phone number
- Booking history (when, what, with whom)
- Payment status (Meetrana sees the transaction amount, not card numbers or account data)
- Reviews and comments
- IP address and browser data (for security)
5. Categories of data subjects
legal.dpa.section5.intro
- End customers who book services from the connected business
- The business's employees whose schedules are managed in the system
6. Meetrana's obligations as data processor
legal.dpa.section6.intro
- Processes personal data only according to documented instructions from the business
- Ensures that personnel with access are subject to confidentiality obligations
- Implements appropriate technical and organizational security measures (see section 10)
- Engages subprocessors only with the business's consent (see section 8)
- Assists the business in fulfilling data subjects' rights (access, rectification, erasure, data portability)
- Assists with personal data breaches and regulatory notifications
- Deletes or returns all data at the end of the agreement (see section 12)
7. The business's obligations as data controller
legal.dpa.section7.intro
- Ensures a lawful basis for all processing of personal data
- Informs its customers about the processing under GDPR Art. 13
- Is responsible for responding to data subjects' requests within statutory deadlines
- Appoints a data protection officer where required
8. Subprocessors
Meetrana engages the following subprocessors to deliver the service: Supabase Inc. (database hosting, EU region Frankfurt) — supabase.com/legal/dpa Stripe Payments Europe Ltd. (payment processing, Ireland) — stripe.com/legal/dpa Vercel Inc. (web hosting, EU regions) — vercel.com/legal/dpa Resend Inc. (email delivery, EU region) — resend.com/legal/dpa New subprocessors are announced with 30 days' notice by email. The business has the right to object to new subprocessors and may terminate the agreement in that case.
9. Transfers to third countries
No personal data is currently transferred outside the EU/EEA. If this changes in the future, it will be done with appropriate safeguards under GDPR Chapter V (e.g. the EU's Standard Contractual Clauses).
10. Security measures
legal.dpa.section10.intro
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Row Level Security (RLS) in the database — data isolated per business
- Regular automatic backups
- Access control based on the principle of least privilege
- Logging of critical events
- Multi-factor authentication (MFA) for admin access
- Incident response plan and regular security review
11. Personal data breaches
Meetrana notifies the business without undue delay, no later than 24 hours after discovery, of a personal data breach affecting the business's data. The notification includes: the nature of the incident, categories and approximate number of affected data subjects, likely consequences, and measures taken. The business is responsible for notifying the supervisory authority (IMY) within 72 hours if the breach is likely to result in a risk to data subjects.
12. Deletion at the end of the agreement
When the business's subscription ends, all personal data is deleted or returned within 30 days. Exceptions: transaction data required under Swedish bookkeeping law (7 years) and data required to fulfill reporting obligations under the DAC7 directive.
Contact DPO
meetrana.support@gmail.com