Skip to main content

Legal

Overview

This Data Protection Addendum (“DPA”) describes how Kavelle processes personal data on behalf of the businesses that use Kavelle to run their operations (each a “Partner”). It supplements the agreement between the Partner and Kavelle and applies where Kavelle acts as a processor of the Partner’s client and staff data.

Roles

The Partner is the controller of its clients’ and staff’s personal data, and Kavelle is the processor of that data. Each party is responsible for complying with applicable data protection laws. The Partner is responsible for the accuracy and lawful basis of the data it uploads to or collects through Kavelle.

Scope of Processing

Kavelle processes personal data only to:

  • provide the Kavelle Services to the Partner;
  • follow the Partner’s documented instructions; and
  • comply with applicable law.

Data processed may include client contact details and booking data, and Partner staff contact and role information. Partners must not upload payment card data outside the designated payment functionality or special-category data except where lawfully permitted.

Security

Kavelle implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or disclosure, including encryption in transit, access controls, and monitoring. Access to personal data is limited to authorized personnel under confidentiality obligations.

Sub-Processors

The Partner authorizes Kavelle to engage sub-processors (such as cloud hosting, database, email, and SMS delivery providers) to support the Kavelle Services. Kavelle imposes data protection obligations on its sub-processors no less protective than those in this DPA and remains responsible for their performance.

Data Subject Requests and Breaches

Kavelle will assist the Partner in responding to requests from individuals to exercise their data rights, to the extent the Partner cannot do so directly through the Kavelle Services. Kavelle will notify the Partner without undue delay after becoming aware of a personal-data breach affecting the Partner’s data.

Retention and Deletion

Following termination of the agreement, the Partner may export its data through the Kavelle Services for a limited period, after which Kavelle may delete it, except where retention is required by law.

Contact

Questions about data protection? Email support@kavellebooking.com. See also our Privacy Policy.

Last updated: July 29, 2026