Data Processing Addendum
Version and effective date: 2026-09-29
This Data Processing Addendum (the "DPA") is part of the Terms of Service between the Operator and each provider who uses Bouncing Bison for their business ("you"). It covers the personal data we process on your behalf, as Article 28 of the GDPR requires.
Who is responsible for which data
- We are the controller for the account data of all users, customers and providers alike, and for running the marketplace: search, bookings, reviews, membership billing, security and our own legal obligations. Our Privacy Policy covers that processing.
- When a customer books you, you receive their name, the booking details and their messages. You are an independent controller for that data when you use it to deliver your service, invoice the customer or meet your own legal obligations, and for any copy you keep outside Bouncing Bison.
- We act as your processor where we store and handle personal data for your business on your instructions: your booking records with the customer details in them, your conversations with customers, your schedule and the notes in it, and the customer contacts you import with the invite feature. This DPA governs that processing.
1. Subject matter and duration
We host and handle the data described in section 3 so that you can manage bookings, messages, your schedule and customer invitations through Bouncing Bison. The processing lasts as long as you use provider features and ends when your account is deleted, as set out in section 5.
2. Nature and purpose
Storing, displaying, organising, transmitting (in the app and by email) and deleting data, only to provide the booking, messaging, scheduling and invite features of the Service to you.
3. Personal data and data subjects
The data subjects are your customers, people who ask to book you and people you invite. The data is their names and email addresses, booking dates, times, prices and notes, message content, reviews on your listings and anything you write in schedule notes. The Service does not ask for special categories of data (Article 9 GDPR). Do not put such data in notes or messages unless your service requires it and you have a legal basis.
4. Your responsibilities and rights
You are responsible for having a legal basis for the processing, for informing your customers as Articles 13 and 14 GDPR require, and for the instructions you give us. The way you use the Service's features, together with the Terms and this DPA, forms your documented instructions. You can give further instructions by email to the contact in section 9. If an instruction goes beyond what the Service can do, we may decline it, and you can then end your membership.
5. Our obligations
- We process the data only on your documented instructions, unless EU or member state law requires otherwise. In that case we tell you before we process it, unless that law forbids it. We tell you promptly if we think an instruction infringes data protection law.
- Everyone we allow to process the data is bound by confidentiality.
- We apply the technical and organisational measures in the annex below (Article 32 GDPR). We may change them as long as the level of protection does not fall.
- You give us general authorisation to use the sub-processors listed on our sub-processor page. We announce any addition or replacement there at least 30 days in advance. You can object on reasonable data protection grounds within that period; if we cannot resolve your objection, you can end your membership before the change takes effect. We bind each sub-processor to data protection obligations equivalent to this DPA and remain responsible to you for its work.
- We help you answer requests from data subjects under Chapter III GDPR, mainly through the Service's own features. If a data subject asks us directly about data we process for you, we refer them to you, unless the request concerns data we control ourselves.
- We help you meet your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to us.
- We notify you without undue delay after we become aware of a personal data breach affecting data we process for you. We include the information listed in Article 33(3) GDPR as far as we have it, and send the rest as we learn it.
- When your account is deleted, we delete the data we process for you, unless EU or member state law requires us to keep it or we hold the same data as controller (for example, a booking record your customer still needs). Before you delete your account you can download your data from the Privacy page of your account.
- We make available the information needed to show that we meet Article 28 GDPR, and we allow and contribute to audits, including inspections, by you or an auditor you appoint. Audits need reasonable notice, take place during business hours and must not disrupt the Service or expose other users' data. Each side bears its own costs.
6. International transfers
Our application servers, database and file storage are set up in the European Union. Where a sub-processor processes the data outside the European Economic Area, the transfer relies on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses, as offered by that sub-processor. The sub-processor page shows where each one processes data.
7. Liability and order of precedence
Liability under this DPA follows the Terms of Service, except where the GDPR does not allow liability to be limited. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
8. Acceptance and changes
You accept this DPA when you start a membership, or by clicking Accept on this page. We record which version you accepted and when. We announce material changes on this page before they take effect and ask you to accept the new version.
9. Contact
For anything about this DPA, including instructions and audit requests, contact the Operator:
The company that will operate Bouncing Bison is being set up. Its legal name, registration details, address and representative will be published here before commercial launch.
- Company
- Not yet published
- Registered office
- Not yet published
- Represented by
- Not yet published
- Trade register number
- Not yet published
- Not yet published
Annex: technical and organisational measures
These are the measures the Service applies today.
- Encryption in transit: the site is served only over HTTPS. Our host terminates TLS and redirects plain HTTP to HTTPS, and browsers are told to keep using HTTPS (HSTS).
- Hosting: the application and its PostgreSQL database run on Fly.io in Frankfurt. The application reaches the database over Fly.io's private network, not over the public internet.
- Passwords are stored only as argon2id hashes. A failed login takes as long for an unknown email address as for a wrong password, so response times do not reveal which accounts exist.
- Sessions use random tokens in cookies marked HttpOnly and SameSite=Lax, and Secure in production. A session expires after 30 days, and a password reset ends all other sessions.
- Access control: each booking, message, schedule entry and account page is checked against the signed-in user before it is shown or changed. Someone who is not a party to a booking gets the same answer as for a booking that does not exist. Admin pages are limited to designated administrator accounts.
- Request protection: the server rejects state-changing requests that come from other websites (an Origin and Referer check on top of SameSite cookies). A Content Security Policy limits the scripts, frames and connections a page may use. Sign-in, sign-up, password reset and account deletion are rate limited per IP address, and so are other write actions and data exports.
- Files: uploaded photos are kept in private Cloudflare R2 buckets and served only through the application. Uploads must be images, and images with oversized dimensions are refused before they are decoded.
- Payments: card details are entered on Stripe's hosted pages and never reach our servers. Stripe webhooks are accepted only with a valid signature.
- Proof of acceptance: each acceptance is written to the database and copied to a separate private storage bucket.
- Logging: our request logs record the method, path, status and duration of each request. They do not contain IP addresses or cookie values.
- Backups: database backups are those provided by Fly.io's Managed Postgres service.
- Retention: expired sessions and password reset links, old webhook records and old read notifications are deleted automatically on the schedule in our Privacy Policy.
- Data subject rights: every user can download their data and delete their account from their account settings.
Draft for review: placeholder text to be finalised with legal counsel before launch. · Sub-processors