Data processing agreement
Last updated 27 August 2026 · BespokeWorks, London, United Kingdom
Why this exists
When your clients’ details go into TallyUp, you decide what happens to them and we carry it out. UK GDPR calls you the controller and us the processor, and Article 28 requires that to be written down before we start. This is that document. It applies automatically to every business using TallyUp; you do not need to sign anything, though we will sign a copy if your insurer or your own client asks for one.
What we process, and why
Subject matter and duration. We process personal data so that TallyUp can run your bookings, for as long as you have an account with us, and for the short wind-down period described under “When you leave” below.
Nature and purpose. Storing, organising, retrieving, displaying to you and your staff, sending on your behalf (confirmations, reminders, the messages you write), and deleting. We do not do anything else with it.
Types of personal data.Names, email addresses, phone numbers, postal addresses, dates of birth, emergency contacts, booking and attendance history, payment records (we never hold card numbers; see “Payments”), the notes your staff write, and anything your clients enter into forms you build, which for a class or clinic business will often include health information: injuries, pregnancy, medication, conditions. Health data is a special category under Article 9 and is treated accordingly.
Categories of data subject. Your clients, the people they book on behalf of, and your own staff.
Our obligations to you
These are the Article 28(3) commitments, in the order the law sets them out.
- We act only on your instructions. Using TallyUpis the instruction. We do not process your clients’ data for our own purposes, we do not sell it, and we never market to your client list, whether for ourselves or for another business on TallyUp. If the law ever forced us to act otherwise, we would tell you first unless we were legally barred from doing so.
- Everyone with access is under a duty of confidence. Access to production data is limited to those who need it to run or support the service.
- We keep it secure.Encrypted in transit and at rest, passwords hashed with bcrypt and never recoverable, tenant isolation enforced on every query so one business cannot read another’s data, automated daily backups with point-in-time recovery, and access to the platform back office restricted to a named list rather than to any role that could be self-granted.
- We tell you before we add a sub-processor. The current list is on the sub-processors page. We give notice before adding one, and each is bound by terms no weaker than these.
- We help you answer your clients. If someone asks you for a copy of their data, or asks you to correct or erase it, the console lets you do it yourself. Where it does not, we will help, at no charge.
- We help you meet Articles 32 to 36. Security, breach notification and impact assessments, given what we know about how the service is built.
- We tell you about a breach without undue delay. If personal data you control is breached, we contact you with what we know, what we are doing and what we advise, so that you can meet your own 72-hour duty to the ICO. We will not sit on it.
- You get it back, or we delete it.See “When you leave”.
- You can audit us. Ask, and we will answer questions about how the service handles data, in writing.
Payments
Card details never reach TallyUp. Payments are taken by Stripe, who are a separate controller for the payment itself and hold the card data under their own terms and PCI certification. We see the amount, the outcome and a reference, never a card number.
Where your data lives
In the United Kingdom and the European Economic Area. Our database and application run on Google Cloud in Europe. Some sub-processors are US companies operating under the UK extension to the EU-US Data Privacy Framework or standard contractual clauses; each is named on the sub-processors page with the safeguard that applies.
When you leave
Your data remains available to export for 30 days after your account closes, so that nothing is lost in the gap between leaving us and arriving somewhere else. After that we delete it, and it falls out of encrypted backups within a further 35 days. Tell us at any point in that window and we will delete it sooner. We keep only what we must for our own accounting and tax records, which is the fact of the transaction rather than your clients’ details.
Getting in touch
Data protection questions, requests and breach reports: privacy@bespokeworks.ai. We answer within five working days, and immediately for anything involving a breach.
Changes
We will tell you before these terms change in any way that matters, and the date at the top always shows when they last did. Previous versions are available on request.
This agreement sits alongside our terms of service and privacy notice. Where this document and the terms of service disagree about personal data, this document wins.