Data Processing Agreement
Version October 9, 2026. Part of the Terms of Service.
This Data Processing Agreement (“this agreement”) is part of Schedulign's Terms of Service and applies to every business with a Schedulign account (“you”). It governs how Schedulign LLC (“Schedulign”) processes the personal information of your clients and of anyone else whose information you bring into Schedulign, and it is the written contract that privacy laws require between a business and its service provider. You accept it when you create your account, and again each time you keep using the service after it changes; Schedulign is bound by it as published. Where it differs from the Terms about client data, this agreement controls, except that the Terms' section “Consumer health data: Schedulign as your processor” controls for consumer health data wherever it is stricter.
Not legal advice. This agreement is written for how Schedulign works and for the laws it names, in English, which is the version that binds. Whether a law applies to your business, and what else it asks of you, is yours to decide, with your own advisor if you need one.
1. Definitions
- Client data: the personal information of your clients and of the other people you bring into Schedulign — the people who book, request, join a waitlist, ask to hear about openings or sign a document, the participants they name, and the people in your contact book and on your mailing list — including their names, contact details, booking details, the answers to your booking questions and intake forms (which can include health information), signed documents, your notes about them, payment status, and the identifiers Stripe gives a payment or a saved card. It does not include your own account information (your name, email address, sign-in details and plan), which Schedulign holds as the party responsible for it under the Privacy Policy.
- Processing: anything done with client data — collecting, storing, showing, sending, exporting, deleting.
- Privacy law: every law that applies to client data in your hands or in Schedulign's. By country: in the United States, Washington's My Health My Data Act, Nevada's and Connecticut's consumer health data laws, and the state privacy and breach-notice laws; in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector, Alberta's and British Columbia's Personal Information Protection Acts and Ontario's Personal Health Information Protection Act (PHIPA); in Australia, the Privacy Act 1988 and the state health records acts; in New Zealand, the Privacy Act 2020 and the Health Information Privacy Code 2020; and, once Schedulign opens there, the UK GDPR and the EU GDPR.
- Roles: you are the controller, regulated entity, APP entity, agency or custodian — the party that decides what client data is collected and why. Schedulign is your processor, service provider, agent or electronic service provider — the party that processes it for you. Each annex names the role its law uses.
- Subprocessor: a service provider Schedulign uses to process client data, listed in section 6.
- Security incident: a confirmed breach of Schedulign's security that leads to the accidental or unlawful destruction, loss or alteration of client data, or to its unauthorized disclosure or access.
2. What Schedulign processes, and why
Schedulign processes client data only to provide the service to you as you set it up: to show your booking pages and forms, take bookings and requests, run your waitlists and openings notifications, store the information and show it to you and to the people you allow, send the emails and calendar entries you set up and the ones your clients' own actions call for, take payments through your own Stripe account, export or delete the data when you ask, keep the service secure, and meet a legal obligation. The people and the data are those under “Client data”; the processing lasts as long as your account does, as section 9 describes.
3. Your instructions
Schedulign processes client data only on your documented instructions. Your instructions are: the Terms and this agreement; the settings you make in your dashboard — your events, questions, forms, documents, policies, team permissions and emails; the actions you and the people you allow take there, such as a booking made, moved, canceled, exported or deleted; and the written instructions you send to admin@schedulign.com. Schedulign tells you if an instruction appears to break a privacy law, and may decline it until you confirm it.
Schedulign never processes client data for its own purposes: it never sells it, shares it with a third party for that party's own use, uses it for advertising or to build profiles, uses it to train artificial intelligence or machine-learning models, combines it with another business's data, or uses it to contact your clients other than with the emails you set up and the ones their own actions call for.
4. Confidentiality
Schedulign limits access to client data to the personnel and subprocessors who need it to run the service, each bound to confidentiality by contract. Schedulign's staff console shows a workspace's recent bookings with client details masked, shows an address unmasked only when a support request names it, never shows intake form answers, and records every staff action. Inside your workspace, a team member sees a client's contact details, answers and intake forms only with a permission you or an admin grant, each off until you turn it on, and each opening of an intake form is recorded.
5. Security measures
Schedulign keeps administrative, technical and physical safeguards appropriate to the sensitivity of client data. Today they include:
- Encryption in transit: every connection uses TLS, and browsers are told to use only secure connections (HSTS).
- Encryption at rest: the database is encrypted at rest by the hosting provider; backups are encrypted separately with AES-256 before they leave the database host, kept 30 days, then deleted.
- Field-level encryption: intake form answers, with the name and signature sent with them, are sealed with AES-256-GCM before they are stored, and so are calendar connection tokens. The key can be rotated and every sealed row re-sealed under the new key.
- Passwords and tokens: passwords are stored only as bcrypt hashes, and common passwords are refused; password-reset, email-verification and invitation tokens are stored only as one-way hashes; the links clients use to manage a booking are signed and expire.
- Access control: a team member's access to client details, answers and intake forms is governed by permissions that start off; the staff console has its own sign-in, a 12-hour session, a lockout after repeated failed attempts and a record of every action; access to production systems is limited to authorized personnel.
- Abuse protection: sign-in, sign-up, booking and every public form are rate-limited and carry a field that stops scripts; a suspicious request is refused and logged.
- Logs and error reports: server logs are written with passwords, tokens, secrets and email addresses removed; error reports carry no request bodies, cookies or IP addresses, so a report never carries what a form sent.
- No third-party scripts: the pages load no analytics, advertising, tracking or session-replay script, the site's content security policy stops a browser from loading scripts or fonts from anywhere but schedulign.com, and nothing collects precise location.
- Records: an activity log records the actions taken in a workspace with the account that took them; each opening of an intake form is recorded; the Privacy Policy's section on how long information is kept sets every retention period.
Schedulign may improve these measures and never lowers them without the notice section 13 describes. On request, Schedulign gives you the information you reasonably need to show a regulator or a client that these measures are in place.
6. Subprocessors
Schedulign uses these subprocessors, each under a written contract that limits it to providing its service to Schedulign and binds it to confidentiality and data protection obligations at least as protective as this agreement. Schedulign remains responsible to you for each of them.
- Railway, United States: application hosting, the database (every booking, contact, form answer and image), server logs and an encrypted copy of the backups.
- GitHub, United States: the scheduled jobs (reminders, retention clean-up) and encrypted nightly database backups, kept 30 days.
- Resend, United States: email delivery, carrying what each message is about: names, session times, locations, amounts and the links to manage a booking.
- Stripe, United States: payments and saved cards on the business's own Stripe account, and the business's Schedulign subscription. Receives a client's data only when the client pays online or saves a card, under the business's own agreement with Stripe.
- Sentry, United States: error monitoring, with no request bodies, cookies or IP addresses, and email addresses and tokens removed before a report leaves Schedulign's servers.
- Google, United States: calendar entries for bookings when the business connects Google Calendar, and Google Workspace, which hosts the support mailbox. Receives a client's data only when the business connects Google Calendar, under the business's own agreement with Google.
Before a new subprocessor receives client data, Schedulign names it here and in the Privacy Policy at least 30 days in advance and emails account owners. You may object in writing within those 30 days; if Schedulign cannot resolve your objection, you may delete your business, and Schedulign refunds the unused part of any plan period you paid for in advance.
7. Security incidents
If Schedulign discovers a security incident affecting client data, it tells you without undue delay and no later than 72 hours after confirming that your clients' data was affected — and, for consumer health data, immediately after discovering the breach, as the Terms promise — by email to the account owner. The notice says what happened, which data and roughly how many people are affected, what Schedulign has done and will do, and whom to contact; Schedulign updates it as it learns more, and keeps a record of the incident and its assessment for 5 years. You decide whether and how to notify your clients and a regulator, and Schedulign helps you with what it knows and with what the law asks of a service provider.
8. Help with requests, inquiries and assessments
Your clients' requests. The service gives you the tools to answer a request to access, correct, export or delete a client's data yourself: Settings → Danger zone → Your data exports everything; a booking, a contact page and an intake form show what you hold about a person; Delete client data on a past or canceled booking, or Delete this person on a contact page, removes a client's details, answers, intake forms and the record of who opened them while the booking's time and money stay as your records; and a client can withdraw their consent to an intake form from the form's own link, which deletes the answers sent through it and tells you. A request that reaches Schedulign about data you hold is passed to you within 5 business days, with help to answer it; Schedulign does not answer it for you.
Regulators and assessments. Schedulign answers your reasonable written questions about this agreement once a year, and at any time after a security incident or when a regulator asks you; gives you this agreement, the Privacy Policy and the security description above for your privacy impact assessment or your own privacy notice; and tells you, where the law allows, if a regulator or an authority asks it for your clients' data. Schedulign does not host on-site audits of its own or its subprocessors' facilities; where a law gives you or a regulator a right to one, Schedulign cooperates with the regulator and provides its subprocessors' own assurance reports where they exist.
9. Deletion and return when you leave
You can export client data at any time and delete it at any time, as section 8 describes. When you delete your business (Settings → Danger zone), your pages, sign-in and booking links go offline at once; 30 days later everything is permanently erased, and it leaves the encrypted backups within 30 days after that. The 30-day window exists only so that an accidental deletion can be reversed by contacting admin@schedulign.com. After that, Schedulign keeps nothing of your clients' data except the activity log with every personal detail removed, and what a law requires it to keep; the one-way hashes of the addresses that unsubscribed from your promotional emails are deleted with your business. A booking you archive is not deleted: it stays in your records and exports until you delete the client's details or your business.
10. Processing in the United States
Schedulign processes client data in the United States, on the systems and with the subprocessors in section 6, and nowhere else. By using the service you authorize that transfer, and this agreement is the written contract the laws in the annexes ask for before one. While in the United States the data is subject to US law, and US courts and authorities can require Schedulign to disclose it under a valid legal process — a subpoena under federal or state law, a court order, or an order under the Stored Communications Act, and in principle orders under the CLOUD Act and surveillance laws such as section 702 of the Foreign Intelligence Surveillance Act, which can reach the data of people outside the United States held by US providers. Schedulign discloses only what the process requires, asks that an overbroad request be narrowed where it can, tells you before, or as soon afterwards as the law allows, and has no arrangement giving any authority standing access to its systems. This section, with sections 5 and 6, is the description of the legal regime and the safeguards that a privacy impact assessment under the laws in the annexes needs.
11. Your responsibilities
- You have a lawful basis — a consent, a contract with your client, or another basis your law allows — for every item of client data you collect and bring into Schedulign, and you tell your clients how you use it in your own privacy notice, naming Schedulign as a service provider in the United States where your law asks for that.
- You collect health information only on an intake form, where the client's express consent is asked, and you handle it under your own law: HIPAA, under which Schedulign signs no business associate agreement; Washington's and other states' consumer health data laws; Quebec's and Australia's rules for sensitive information; PHIPA; the Health Information Privacy Code.
- You have the consent your law requires before Schedulign sends a promotional email for you — Canada's Anti-Spam Legislation, Australia's Spam Act 2003, New Zealand's Unsolicited Electronic Messages Act 2007, the CAN-SPAM Act — you keep a record of it, and you keep your mailing address in Settings → Profile current.
- You give your team members access only as they need it, keep your sign-in safe, and answer your clients' requests within the time your law allows.
- Your instructions comply with your law, and you tell Schedulign of a request or complaint that concerns Schedulign's processing.
12. Liability
The Terms' “Warranties and liability” applies to this agreement, including its carve-outs for what the law does not let a contract limit. Each side is liable to the people whose data is involved as the applicable privacy law provides.
13. Changes and term
This agreement lasts as long as your account does, and sections 7, 9 and 10 outlast it for as long as Schedulign holds any client data. Schedulign changes this agreement as the Terms' “Changes” section describes: a change that reduces a protection comes with 30 days' notice to the account owner and the right to leave with a refund of the unused part of a plan period paid for in advance; a change that adds a protection, a subprocessor change under section 6, or a change required by law may take effect sooner, with notice.
14. Annex A: Canada
Roles. You are the organization accountable for your clients' personal information under PIPEDA (principle 4.1) and the provincial Acts; Schedulign is your service provider, processing it on your behalf and for your purposes only. Under principle 4.1.3 you use this agreement to provide a comparable level of protection while the information is processed by Schedulign in the United States.
What Schedulign commits to: everything above, and in particular use and disclosure only for the purposes you set and to meet a legal obligation; the security measures in section 5; the notice of a security incident in section 7, in time for your assessment of a real risk of significant harm, your report to the Privacy Commissioner of Canada and your notice to the people affected under PIPEDA section 10.1 (and the records you keep for 24 months), your report to the Information and Privacy Commissioner of Alberta under PIPA section 34.1, and your report to the Commission d'accès à l'information under Quebec's law; and the deletion in section 9.
Alberta. Section 13.1 of Alberta's Personal Information Protection Act asks you to notify the people concerned that a service provider outside Canada holds their information; the Privacy Policy's Canada section gives you wording to reuse.
Quebec (Law 25). Schedulign does not yet accept businesses established in Quebec (the Terms, “Canada”). For when it does, and for a business elsewhere in Canada whose clients are in Quebec: this agreement is the written agreement sections 17 and 18.3 of Quebec's Act require before personal information is communicated outside Quebec or entrusted to a service provider. It sets out the measures taken to protect the information (section 5), that the information is used only for the mandate (section 3), that it is kept confidential (section 4), that Schedulign notifies you without delay of a confidentiality incident and lets you verify compliance (sections 7 and 8), and that it is destroyed at the end (section 9). For your privacy impact assessment under section 17, section 10 describes the legal regime of the United States and sections 5 and 6 the safeguards and the subprocessors. Schedulign's person in charge of the protection of personal information is its Privacy Officer, named in the Privacy Policy.
Ontario health information custodians (PHIPA). Where you are a health information custodian, Schedulign provides its service to you as an electronic service provider under section 10(4) of the Act and section 6 of Ontario Regulation 329/04, and accordingly: it does not use the personal health information you entrust to it except as necessary to provide the service; it does not disclose it except as required by law; it does not permit its personnel or subprocessors to access it except as necessary to provide the service; it keeps it secure as section 5 describes; and you remain the custodian who decides about it. Schedulign is not a health information network provider: the service does not enable one custodian to disclose personal health information to another, and a team of several custodians sharing one workspace is your own arrangement, on which you should take advice.
15. Annex B: Australia
Roles. You are the APP entity — or, where the Privacy Act does not bind you, the business accountable to your clients — that discloses personal information to Schedulign, an overseas recipient in the United States, under Australian Privacy Principle 8.1. Where you provide a health service, the Act binds you whatever your turnover (section 6FB), and the information you hold about your clients' health is sensitive information.
What Schedulign commits to, so that you can take the reasonable steps APP 8.1 requires and remain accountable under section 16C: to collect, hold, use and disclose the personal information you disclose to it only as this agreement and your instructions allow, and in a way consistent with the Australian Privacy Principles — in particular APP 6 (use and disclosure), APP 11 (security, and destruction or de-identification when no longer needed, as section 9 describes), APPs 12 and 13 (helping you give access and make corrections) and APP 8 (no further overseas disclosure beyond the United States subprocessors named here); and to tell you of an eligible data breach as section 7 provides, within 72 hours of confirming it, so that you can assess it within 30 days and notify the Office of the Australian Information Commissioner and the people affected under the Notifiable Data Breaches scheme, with Schedulign's help in that assessment and those notices.
State health records acts. Where Victoria's Health Records Act 2001, New South Wales's Health Records and Information Privacy Act 2002 or the ACT's Health Records (Privacy and Access) Act 1997 applies to you, this agreement is the contract those Acts expect for a transfer of health information outside the state, and Schedulign commits to handle that information consistently with their privacy principles.
Whether the Privacy Act binds Schedulign itself turns on its turnover, and Schedulign has not opted in under section 6EA; whatever the answer, these commitments bind it to you by contract.
16. Annex C: New Zealand
Roles. Under section 11 of the Privacy Act 2020, Schedulign holds your clients' personal information as your agent, for the sole purpose of storing and processing it for you: the information is treated as held by you, the agency, and your giving it to Schedulign is not a disclosure under information privacy principle 11 or a disclosure to an overseas person under principle 12. Schedulign uses it only for your purposes and never for its own; section 3 of this agreement is the term that keeps the relationship within section 11.
What Schedulign commits to: the security principle 5 requires, as section 5 describes; help with access and correction requests under principles 6 and 7, within the 20 working days the Act allows you, as section 8 describes; notice of a notifiable privacy breach as section 7 provides, so that you can notify the Privacy Commissioner and the people affected as soon as practicable under section 114; and deletion under section 9.
Health Information Privacy Code 2020. Where you are a health agency, the Code's rules apply to the health information you hold about your clients, and Schedulign handles that information as your agent consistently with them, including rule 5 (security) and rule 12 (no disclosure outside New Zealand other than to Schedulign and its subprocessors, as your agent).
17. Contact
Questions about this agreement, a request, a complaint or a notice: admin@schedulign.com, or by mail to Schedulign LLC, 23312 77th Ave SE, Woodinville, WA 98072, United States, attention Privacy Officer.
See also the Terms of Service, the Privacy Policy and the Consumer Health Data Privacy Policy.