Data Processing Agreement
Last updated: 17 July 2026
This Data Processing Agreement (DPA) forms part of the Terms of Use between the FormiBook user and the legal entity identified under “Processor details” (the Processor) and applies automatically where the Processor processes personal data on the user’s behalf.
The user is controller and the Processor is processor unless a particular processing activity is legally classified otherwise.
1. Subject and duration
The Processor processes data to provide, protect, support and terminate the service during the account term and the agreed return and deletion periods.
2. Processing
Operations include collection, storage, organisation, display, transmission on a lawful instruction, backup, export and deletion. The purpose is management of resources, services, availability, customers, bookings, messages, prices, statuses and related payment records.
Data subjects may include customers, guests, employees, representatives and other persons whose data the user lawfully enters. Data may include identity and contact information, booking and service details, messages, files, payment statuses and special categories where the user chooses to process them on a lawful basis.
3. User instructions
The Processor processes data only on the user’s documented lawful instructions, including these terms and actions in the system. If the Processor considers an instruction to infringe data-protection law, it will inform the user and may suspend the instruction pending clarification.
4. Confidentiality and security
Access is limited to persons who need it and are bound by confidentiality. The Processor applies proportionate security measures, including access management, protected transmission, logging, backup, vulnerability management and response procedures. Specific measures may evolve without reducing the overall level of protection.
5. Subprocessors
The user gives general authorisation to engage subprocessors. The current register, including purposes and processing locations, is available to an authorised user in the system or on request to info@expooffice.lt. The Processor imposes no less protective data obligations on subprocessors.
The Processor gives at least 15 days’ notice of an addition or replacement. The user may object during that period based on a specific, substantiated data-protection risk. The Processor will seek a commercially reasonable alternative; if none is available, either party may terminate the affected service. If termination occurs before the end of a paid period, the unused part is refunded.
6. International transfers
A transfer outside the EEA is permitted only under an applicable GDPR mechanism, including an adequacy decision or Standard Contractual Clauses and necessary supplementary measures. The user authorises the Processor to enter into relevant terms with subprocessors.
7. Data-subject requests and assistance
Taking account of the processing, the Processor reasonably assists the user with data-subject requests and duties relating to security, incident notifications, DPIAs and supervisory consultations. The user remains responsible for the decision and communication with the data subject.
8. Personal-data breach
After confirming a personal-data breach, the Processor notifies the user without undue delay and supplies available information needed to assess and meet the user’s obligations. A notification is not an admission of fault.
9. Return and deletion
An export is provided on separate request under the Terms of Use. After termination, the user has 30 days to receive it. Data is then deleted from the active system unless law requires retention; residual data is removed from isolated backups through rotation within 90 days.
10. Information and audits
The Processor supplies information reasonably necessary to demonstrate Article 28 GDPR compliance. A documentary or remote review is used first. An ordinary audit may occur no more than once a year on reasonable advance notice, during business hours and subject to confidentiality and other users’ security.
An additional review is allowed after a confirmed incident or where required by a supervisory authority. The user bears the cost unless the audit identifies a material breach by the Processor.
11. Liability and precedence
Liability is governed by the Terms of Use subject to mandatory GDPR rights. If there is a conflict on personal-data processing, this DPA prevails over the general Terms.
12. Law, languages and contact
Lithuanian law applies. If language versions differ, the Lithuanian version prevails unless mandatory law requires otherwise. DPA contact: info@expooffice.lt.