FormiBook
Product Online booking Solutions Pricing Demo
Sign in Start free
Product Online booking Solutions Pricing Demo
Sign in Start free

Data Processing Agreement

Last updated: 17 July 2026

This Data Processing Agreement (DPA) forms part of the Terms of Use between the FormiBook user and the legal entity identified under “Processor details” (the Processor) and applies automatically where the Processor processes personal data on the user’s behalf.

The user is controller and the Processor is processor unless a particular processing activity is legally classified otherwise.

1. Subject and duration

The Processor processes data to provide, protect, support and terminate the service during the account term and the agreed return and deletion periods.

2. Processing

Operations include collection, storage, organisation, display, transmission on a lawful instruction, backup, export and deletion. The purpose is management of resources, services, availability, customers, bookings, messages, prices, statuses and related payment records.

Data subjects may include customers, guests, employees, representatives and other persons whose data the user lawfully enters. Data may include identity and contact information, booking and service details, messages, files, payment statuses and special categories where the user chooses to process them on a lawful basis.

3. User instructions

The Processor processes data only on the user’s documented lawful instructions, including these terms and actions in the system. If the Processor considers an instruction to infringe data-protection law, it will inform the user and may suspend the instruction pending clarification.

4. Confidentiality and security

Access is limited to persons who need it and are bound by confidentiality. The Processor applies proportionate security measures, including access management, protected transmission, logging, backup, vulnerability management and response procedures. Specific measures may evolve without reducing the overall level of protection.

5. Subprocessors

The user gives general authorisation to engage subprocessors. The current register, including purposes and processing locations, is available to an authorised user in the system or on request to info@expooffice.lt. The Processor imposes no less protective data obligations on subprocessors.

The Processor gives at least 15 days’ notice of an addition or replacement. The user may object during that period based on a specific, substantiated data-protection risk. The Processor will seek a commercially reasonable alternative; if none is available, either party may terminate the affected service. If termination occurs before the end of a paid period, the unused part is refunded.

6. International transfers

A transfer outside the EEA is permitted only under an applicable GDPR mechanism, including an adequacy decision or Standard Contractual Clauses and necessary supplementary measures. The user authorises the Processor to enter into relevant terms with subprocessors.

7. Data-subject requests and assistance

Taking account of the processing, the Processor reasonably assists the user with data-subject requests and duties relating to security, incident notifications, DPIAs and supervisory consultations. The user remains responsible for the decision and communication with the data subject.

8. Personal-data breach

After confirming a personal-data breach, the Processor notifies the user without undue delay and supplies available information needed to assess and meet the user’s obligations. A notification is not an admission of fault.

9. Return and deletion

An export is provided on separate request under the Terms of Use. After termination, the user has 30 days to receive it. Data is then deleted from the active system unless law requires retention; residual data is removed from isolated backups through rotation within 90 days.

10. Information and audits

The Processor supplies information reasonably necessary to demonstrate Article 28 GDPR compliance. A documentary or remote review is used first. An ordinary audit may occur no more than once a year on reasonable advance notice, during business hours and subject to confidentiality and other users’ security.

An additional review is allowed after a confirmed incident or where required by a supervisory authority. The user bears the cost unless the audit identifies a material breach by the Processor.

11. Liability and precedence

Liability is governed by the Terms of Use subject to mandatory GDPR rights. If there is a conflict on personal-data processing, this DPA prevails over the general Terms.

12. Law, languages and contact

Lithuanian law applies. If language versions differ, the Lithuanian version prevails unless mandatory law requires otherwise. DPA contact: info@expooffice.lt.

Processor details
Processor: MB “Expooffice” Email: info@expooffice.lt Address: Gojaus g. 8, Gojaus k., Trakų r. Phone: +370 693 31699

Back to home

FormiBook

Manage resources, availability and bookings from customer enquiry to confirmation.

Product

ProductOnline bookingPricingHelp Center

Contact

DemoVilnius, Lietuva+370 698 77 745+370 693 31699

Legal

Privacy PolicyTerms of UseCookie PolicyData ProcessingCookie settings