Data processing agreement

Agreement on processing on instruction under Art. 28 GDPR between the customer (controller) and novitune Ltd (processor). It forms part of the contract on the use of Nuvical and applies where the provider processes personal data on behalf of the customer.

1. Parties and subject matter

The processor is novitune Ltd, Ioanni Pasaporti 30, 8543 Koili, Paphos, Cyprus (registration number HE 476271), represented by the Director Sascha Growe. The controller is the respective customer using Nuvical to manage its appointments and client data. Contact for data protection matters: sascha@novitune.com.

The subject matter is the processing of personal data by the processor exclusively on documented instruction from the controller in the course of using the Nuvical platform.

2. Duration

Processing takes place for the term of the underlying usage contract. It ends when that contract ends; the rules on deletion and return then apply (point 11).

3. Nature, scope and purpose of processing

The processor processes data for the purpose of providing the agreed functions, in particular appointment booking and management, client management, sending appointment and service messages, payment and deposit handling as well as the modules activated by the controller (for example patient records, photo documentation).

4. Type of data and categories of data subjects

Processing covers in particular master data (name, contact details), appointment and booking data, communication data and payment-related data. If the controller activates the corresponding modules, special categories of personal data within the meaning of Art. 9 GDPR may also be processed (for example health data in patient records). In that case the controller ensures the necessary legal basis and consents.

Data subjects are the controller's clients and prospects as well as its staff, where their data is processed in the platform.

5. Obligations of the processor

The processor undertakes in particular:

  • to process data only on documented instruction from the controller;
  • to bind the persons authorised to process the data to confidentiality;
  • to implement appropriate technical and organisational measures under Art. 32 GDPR (point 6);
  • to support the controller in fulfilling data subject rights and notification duties (points 9 and 10);
  • to inform the controller without undue delay if an instruction infringes data protection law.

6. Technical and organisational measures

The processor takes in particular the following measures:

  • Encryption of sensitive data fields in the database (AES-256-GCM).
  • Transport encryption of all communication via HTTPS/TLS.
  • Tenant separation at database level (row-level security), so that every business can only access its own data.
  • Role-based access control and the option of two-factor authentication.
  • Regular, encrypted backups stored on separate infrastructure.
  • Virus scanning of uploaded files.
  • Logging of security-relevant access and events (audit log).
  • Credentials for external services stored by the controller (for example for its payment account) are kept encrypted, are not displayed again after saving and are used only for their specific purpose.
  • No processing of complete card or account details: they are entered exclusively on pages or in components of the payment service provider.

The measures are adapted to the state of the art; the level of protection is not lowered as a result.

7. Support access to the controller's data

In order to provide support, the processor may in individual cases access the data stored in the controller's account and operate the platform with the rights of one of the controller's users ("support session"). This serves exclusively to analyse errors, resolve faults and help with using the platform, and counts as a documented instruction under point 5.

In doing so the processor ensures that:

  • every support session is logged with start, end, the person acting and the reason, and is visible to the controller in its administration; this also applies to rejected access attempts. If a session ends by timeout, the log entry shows the latest possible end time.
  • the controller is informed by email when a support session begins.
  • the session is time-limited and ends automatically, at the latest after 60 minutes.
  • actions within the session are attributed in the log to the acting person at the processor, not to the controller's account.
  • only data needed for the respective purpose is accessed.

The controller can restrict support access to case-by-case approval at any time in its administration, or switch it off entirely. Switching it off may mean that support can only be provided to a limited extent, or not at all.

8. Professional secrecy (Section 203 German Criminal Code)

If the controller belongs to a profession subject to a statutory duty of confidentiality (Section 203(1) of the German Criminal Code, in particular doctors, dentists, psychotherapists and members of state-regulated health professions), the processor acts as another contributing person within the meaning of Section 203(3) sentence 2.

The processor undertakes to bind all persons employed by it or acting on its behalf who may gain access to the controller's data to confidentiality in writing before they start, and to point out that a breach is punishable under Section 203(4). The obligation continues beyond the end of their work and is evidenced on request.

Secrets are only disclosed where this is necessary in order to provide the service.

9. Data subject rights

The processor supports the controller with appropriate technical and organisational measures in fulfilling requests from data subjects for access, rectification, erasure, restriction, data portability and objection. If a data subject contacts the processor directly, the processor forwards the matter to the controller without undue delay.

10. Notification of personal data breaches

The processor notifies the controller of personal data breaches without undue delay after becoming aware of them and supports the controller in fulfilling its notification duties under Art. 33 and 34 GDPR.

11. Deletion and return after the contract ends

After the contract ends, the processor deletes the processed data or returns it, at the controller's choice, unless a statutory retention obligation prevents this. Before deletion, the processor provides the controller with export options for a reasonable period.

12. Sub-processors

The controller consents to the use of the sub-processors listed below. The processor informs the controller in text form in good time about intended changes (adding or replacing a sub-processor); the controller may object for important data protection reasons.

ProviderPurposeLocationThird country
Hetzner Online GmbHServer hosting (data centre in Germany)Germanynone
Meta Platforms Ireland Ltd.WhatsApp delivery (Business Cloud API)IrelandUSA (SCC / DPF)
Twilio Inc.SMS deliveryUSA / IrelandUSA (SCC / DPF)
Sendinblue SAS (Brevo)Email deliveryFrancenone (EU)

13. The controller's payment service providers

If the controller connects an account with a payment service provider in Nuvical (currently Stripe or Viva.com), the processor transmits the data required for the respective payment to that provider on the controller's instructions, in particular the amount, a description of the service, the reference to the booking and, where applicable, the payer's email address, and receives payment status and transaction identifiers from it.

The controller engages the payment service provider itself and on its own account. The payment service provider is not a sub-processor of the processor and is therefore not listed in point 12. The contractual relationship and the data protection role of the payment service provider are governed by the agreement between the controller and the payment service provider.

The processor never receives complete card or account details of payers, including for in-person card payments (Tap to Pay). Stored credentials of the payment account are protected in accordance with point 6 and are used solely to process payments, cancellations and refunds triggered through Nuvical.

14. Evidence and audits

The processor provides the controller with the information needed to demonstrate compliance with these obligations and allows for reasonable audits. Audits are carried out in a way that does not disproportionately disrupt operations.

15. Liability and final provisions

Liability is governed by the GDPR and by the liability rules of the underlying usage contract. The law of the Republic of Cyprus applies. In the event of contradictions between this agreement and the usage contract, this agreement prevails in data protection matters.

Last updated: September 2026. This English version is provided for convenience. In case of differences, the German version prevails.