Last updated: 2026-09-14
Data processing agreement
This data processing agreement is made between the business using BKG.dk (the "controller") and LynBro ApS, CVR 46321499 (the "processor"). It forms part of the terms of service and applies for as long as the customer has an account with us. The Danish version is the authoritative one.
1. What this covers
When a salon uses BKG.dk it enters data about its own customers. The salon decides about that data; we hold and process it solely on the salon's behalf, on its instructions, and for the purposes the service exists for: bookings, reminders, payments, client history and reporting.
2. Nature of the processing
| Categories of data subjects | The salon's customers and staff |
|---|---|
| Categories of data | Name, email, phone number, appointment times, services, notes written by the salon, payment status and Stripe references |
| Special categories | Not covered. The service is not intended for health data, and a notes field is not a medical record |
| Duration | While the account is active, plus 90 days |
3. Our obligations
- We process the data only on your documented instructions — using the service is the instruction, and anything beyond it is agreed in writing.
- Our people are bound by confidentiality, and access is limited to those who need it.
- We apply appropriate technical and organisational measures under Art. 32 — see clause 6.
- We assist you with data subject requests, with security, with breach notification and with impact assessments.
- On termination we delete the data unless the law requires otherwise (accounting records are kept for 5 years).
4. Sub-processors
You give general authorisation for our use of sub-processors. They are:
| Provider | Purpose | Location |
|---|---|---|
| Contabo GmbH | Servers and operations | EU (France/Germany) |
| Stripe Payments Europe, Ltd. | Card payments, if you enable them | EU (Ireland), group in the US |
| Twilio Ireland Ltd. | SMS, if you enable it | EU (Ireland), group in the US |
| Google Ireland Ltd. | Calendar sync, if a staff member connects a calendar | EU (Ireland), group in the US |
Email is sent from our own server in the EU. If the list changes we give 30 days' notice and you may object; if you do, you may terminate the affected part of the service at no cost.
5. Transfers outside the EU/EEA
Data is stored in the EU. Some providers have group companies in the US where support or security functions may access it. Such transfers rely on the European Commission's Standard Contractual Clauses and the provider's supplementary measures.
6. Security
- Passwords are stored hashed. All traffic uses TLS.
- Session cookies are HttpOnly and Secure, set by the server and never by a script.
- Each customer's data is logically separated from every other's, enforced in the data access layer.
- Administrative actions are written to an audit log.
- Two-factor authentication is available.
- Daily, verified backups; restores are rehearsed.
- Card numbers never reach our servers — Stripe handles them.
7. Personal data breaches
We notify you without undue delay and within 24 hours of becoming aware of a breach, with what you need in order to notify the Danish Data Protection Agency within 72 hours.
8. Audit
We make available the information needed to demonstrate compliance and allow for audits, including inspections, by you or an auditor you appoint, on reasonable notice and at most once a year unless a supervisory authority requires otherwise.
9. Liability and termination
This agreement ends with the subscription. You can export your data while the account is active and for 90 days after. Then it is deleted. Liability follows the terms of service.
10. Contact
LynBro ApS, CVR 46321499 · hello@lynbro.dk
If you need this as a signed document, we will sign it on request.