Data Processing Agreement

Effective April 27, 2026 · Last updated April 20, 2026

This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Terms of Service (“Terms”) between Freebo Software Solutions LLC (“Freebo” or “Processor”) and the Operator (“Controller”) who subscribes to the Freebo platform.

This DPA applies to the extent that Freebo processes Personal Data on behalf of the Controller in connection with providing the Service, and such processing is subject to applicable Data Protection Laws.

1. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person that is processed by Freebo on behalf of the Controller through the Service.
  • “Data Protection Laws” means all applicable laws relating to the processing of Personal Data, including the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA/CPRA, and any other applicable privacy or data protection legislation.
  • “Data Subject” means the individual to whom Personal Data relates.
  • “Sub-processor” means a third party engaged by Freebo to process Personal Data on behalf of the Controller.
  • “Security Incident” means any confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed under this DPA.

Terms not defined here have the meanings given in the Terms of Service or applicable Data Protection Laws.

2. Roles & Scope

  • Controller: The Operator (you). You determine the purposes and means of processing your customers' Personal Data.
  • Processor: Freebo. We process Personal Data on your behalf and in accordance with your documented instructions.

Under the CCPA/CPRA, Freebo acts as a “Service Provider” with respect to Personal Data received from or on behalf of the Controller.

The Controller is solely responsible for: (a) ensuring a lawful basis for the collection and processing of Personal Data; (b) providing required privacy notices to Data Subjects; (c) obtaining any necessary consents; (d) ensuring the accuracy of Personal Data; and (e) responding to Data Subject requests.

3. Processing Details

Subject Matter Provision of the Freebo booking and reservation management platform
Nature of Processing Collecting and transmitting guest/customer data from the online booking system for activity reservations; monitoring Data Subject usage of the Service; conducting analytics; processing communications
Purpose Providing and improving the Service; enabling Data Subjects to enter into Activity Contracts with the Controller; analyzing usage and statistics; product and service development
Duration As determined by the Controller (duration of subscription plus applicable retention periods)
Categories of Data Subjects Controller's customers/guests (persons making bookings); Controller's employees and authorized users; website visitors
Types of Personal Data Full name, email address, phone number, payment transaction metadata (card details processed by Stripe, not stored by Freebo), booking details, online activity data, information collected via cookies/similar technologies, and any additional data the Controller configures for collection

Freebo may process Personal Data for irreversible anonymization and/or aggregation to use for research, analysis, improvement, and development purposes. Such anonymized data is no longer considered Personal Data under this DPA.

4. Processor Obligations

Freebo shall:

  • Process Personal Data only on documented instructions from the Controller (which include the instructions set forth in the Terms and this DPA), unless required by applicable law.
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see Section 5).
  • Assist the Controller, taking into account the nature of processing, in responding to Data Subject requests, to the extent commercially reasonable.
  • Assist the Controller in ensuring compliance with obligations regarding security, breach notification, and data protection impact assessments, taking into account the nature of processing and information available to Freebo.
  • At the Controller's choice, delete or return Personal Data upon termination of the Service (subject to Section 10).
  • Make available information necessary to demonstrate compliance with this DPA and allow for audits (subject to Section 9).
  • Inform the Controller if, in Freebo's opinion, an instruction infringes Data Protection Laws (without obligation to actively monitor compliance of instructions).

5. Technical & Organizational Measures

Both parties shall implement and maintain appropriate measures including:

  • Event logging and monitoring
  • User identification and authorization controls
  • Encryption of Personal Data in transit and at rest
  • Ability to restore availability and access after incidents
  • Ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Regular testing and evaluation of security measures

Freebo may update its security measures from time to time, provided that updates do not materially decrease the overall level of protection.

6. Sub-processors

The Controller provides general written authorization for Freebo to engage Sub-processors. Current Sub-processors:

Sub-processor Purpose Location
Stripe, Inc. Payment processing United States
Supabase, Inc. Database hosting & authentication United States
Railway Corp. Application hosting United States
Resend, Inc. Transactional email delivery United States
Twilio Inc. Transactional SMS delivery — engaged only where the customer opts in to text messages at checkout United States
Railway Corp. (Redis) Redis (job queue processing) United States
Cloudflare, Inc. DNS, CDN, WAF, and edge TLS termination United States
Google LLC Google Calendar integration — engaged only where the Controller opts in and authorizes the connection United States
Zoho Corporation Business email hosting (mail to and from @freebo.ai addresses, including legal/privacy/support inboxes) United States

Changes: Freebo will notify the Controller by email of any intended addition or replacement of Sub-processors, giving the Controller an opportunity to object. If the Controller does not object in writing within 15 days of notification, consent is deemed given. If the Controller objects on reasonable data protection grounds, and Freebo cannot reasonably accommodate the objection, the Controller may terminate the affected Service by providing written notice within 30 days.

Freebo shall impose on Sub-processors data protection obligations no less protective than those in this DPA. Freebo remains liable for the acts and omissions of its Sub-processors to the same extent Freebo would be liable if performing the processing directly, subject to the limitations set forth in the Terms.

7. Data Subject Requests

  • The Controller is responsible for handling all Data Subject requests (access, rectification, erasure, restriction, portability, objection).
  • If Freebo receives a request directly from a Data Subject, Freebo will promptly redirect the Data Subject to the Controller and notify the Controller of the request.
  • Freebo will provide reasonable technical assistance to help the Controller fulfill Data Subject requests, upon the Controller's written request.
  • The Controller is solely responsible for assessing the legality and legitimacy of Data Subject requests before instructing Freebo to act.

8. Security Incident Notification

Upon becoming aware of a confirmed Security Incident, Freebo will:

  • Notify the Controller without undue delay (and in any event within 72 hours of confirmation).
  • Provide the following information (to the extent reasonably available at the time):
    • Description and presumed cause of the incident
    • Categories and approximate number of Data Subjects affected
    • Categories of Personal Data records affected
    • Likely consequences of the incident
    • Measures taken or proposed to mitigate the incident
  • Take reasonable steps to contain, investigate, and remediate the incident.
  • Reasonably cooperate with the Controller in the Controller's communications with supervisory authorities and Data Subjects.
  • Maintain a record of Security Incidents, including facts, effects, and remedial actions.

The Controller determines whether notification to supervisory authorities and/or Data Subjects is required. The Controller shall consult with Freebo regarding the timing, content, and manner of any public notification and shall take into account Freebo's reasonable requests. The Controller shall not reference Freebo by name in any public statement or notification to Data Subjects regarding a Security Incident without Freebo's prior written authorization, unless required by law.

9. Audits

Freebo will make available information reasonably necessary to demonstrate compliance with this DPA, subject to the following:

  • The Controller shall first request compliance information in writing. Freebo will respond within 30 days.
  • If reasonable doubts remain after receiving information, the Controller may conduct or commission an audit, subject to: (a) minimum 60 days written notice; (b) business hours only; (c) maximum duration of 2 business days; (d) no more than once per 12 months; and (e) conducted in a manner that does not disrupt Freebo's business operations.
  • All audit costs (including Freebo's reasonable costs for cooperation) are borne by the Controller.
  • All information obtained during an audit is Confidential Information of Freebo.
  • The Controller shall use an independent, qualified third-party auditor bound by confidentiality obligations acceptable to Freebo.

10. Data Retention & Deletion

  • Upon termination of the Controller's subscription, the Controller may request return (via data export) or deletion of Personal Data within 30 days.
  • If no request is received within 30 days of termination, Freebo may delete or anonymize the Personal Data at its discretion.
  • After 12 months following termination, Freebo has no obligation to maintain, export, or return any Personal Data.
  • Freebo may retain Personal Data where required by applicable law (including tax, financial reporting, and legal hold obligations) or where reasonably necessary for the establishment, exercise, or defense of legal claims.
  • Anonymized or aggregated data derived from Personal Data may be retained indefinitely and is not subject to deletion obligations.
  • The Controller may reactivate the Service and instruct Freebo to retain data rather than delete, provided the request is made within the 30-day window.

11. International Data Transfers

Freebo's Service is based in the United States and primarily directed to US-based Operators. Personal Data is processed and stored in the United States.

Where the Controller is subject to GDPR, UK GDPR, or similar extraterritorial data protection laws and transfers Personal Data to Freebo, the parties will rely on Standard Contractual Clauses (SCCs) or other applicable transfer mechanisms as required by law. Copies of executed SCCs are available upon reasonable written request at [email protected].

12. CCPA/CPRA Provisions

To the extent the CCPA/CPRA applies to Personal Data processed under this DPA:

  • Freebo is a “Service Provider” as defined under the CCPA/CPRA.
  • Freebo shall not sell or share (as defined by CCPA/CPRA) Personal Data received from the Controller.
  • Freebo shall not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Terms, including for a commercial purpose other than providing the Service.
  • Freebo shall not combine Personal Data received from the Controller with Personal Data collected from other sources, except as permitted under the CCPA/CPRA for Service Provider activities.
  • Freebo certifies that it understands and will comply with these CCPA/CPRA restrictions.
  • Freebo will notify the Controller if it determines it can no longer meet its obligations under the CCPA/CPRA.

13. Liability

  • Each party's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Service.
  • The Controller may not recover from Freebo any fines, penalties, or administrative sanctions imposed by supervisory authorities, except to the extent directly and solely caused by Freebo's material breach of its obligations under this DPA (in which case liability remains subject to the caps in the Terms).
  • For the avoidance of doubt, any liability arising under this DPA (including under the SCCs) counts toward and is not in addition to the liability caps in the Terms.
  • Neither party excludes liability for fraud, willful misconduct, or death/personal injury caused by negligence.

14. Term & Amendments

This DPA commences on the effective date of the Terms and continues until all Personal Data has been deleted or returned in accordance with this DPA.

Freebo may update this DPA from time to time to reflect changes in Data Protection Laws, regulatory guidance, or processing practices. Material changes will be communicated with at least 30 days notice. Continued use of the Service after the effective date of changes constitutes acceptance of the updated DPA.

15. Governing Law

This DPA shall be governed by the same law governing the Terms of Service (laws of the State of Texas), except where Data Protection Laws mandate otherwise (in which case the mandatory provisions of the applicable Data Protection Law shall prevail).

16. Contact

For questions or requests related to this DPA:

Freebo Software Solutions LLC
Austin, Texas, United States
Email: [email protected]