Data Processing Addendum
Last updated: August 1, 2026
This Data Processing Addendum ("Addendum") forms part of the Terms of Service between Bizsys Consulting LLC ("Bizsys Consulting LLC", "we") and the business that uses Tableside ("Business", "you"). It governs our processing of personal information about your customers — the people who book appointments with you. It applies automatically when you accept the Terms; no signature is required.
Where this Addendum and the Terms conflict on the handling of customer personal information, this Addendum controls.
1. Definitions
"Customer Personal Information" means personal information about your customers that we process on your behalf through Tableside — booking details, contact details, notes, messaging consent, and related records.
"State Privacy Laws" means the California Consumer Privacy Act as amended by the CPRA, and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other US states, in each case as applicable and as amended, together with Washington's My Health My Data Act and Nevada SB 370.
"Business", "Service Provider", "Controller", "Processor", "Sell", "Share", and "Consumer Health Data" have the meanings given in the applicable State Privacy Laws.
2. Roles of the parties
With respect to Customer Personal Information, you are the Business and Controller and Bizsys Consulting LLC is your Service Provider and Processor. You determine why and how your customers' information is collected and used; we process it only to provide Tableside to you.
We act as a Controller only for information about your own account — your user records, subscription, billing, support history, and how you use the platform — which is governed by our Privacy Policy rather than this Addendum.
3. Scope and instructions
We process Customer Personal Information only on your documented instructions. Your instructions consist of the Terms, this Addendum, the configuration choices you make in the product, and any further lawful written instruction you give us. We will tell you if we believe an instruction violates applicable law, and may pause the affected processing until it is resolved.
The subject matter is the provision of appointment booking software; the duration is the term of your subscription plus the retention periods described in Section 11; the nature and purpose are described in our Privacy Policy; the categories of data subjects are your customers and your staff; and the categories of data are identifiers, contact details, appointment records, communications metadata, and any consumer health data described in Section 10.
4. Our service provider commitments
Bizsys Consulting LLC shall not:
- Sell or Share Customer Personal Information, as those terms are defined under State Privacy Laws;
- retain, use, or disclose it for any purpose other than performing the services specified in the Terms, including any commercial purpose of our own;
- retain, use, or disclose it outside the direct business relationship between you and us;
- combine it with personal information we receive from, or on behalf of, another business, or collect from our own interactions with consumers, except as permitted to perform a business purpose or detect security incidents; or
- use it to build or improve profiles, train general-purpose models, or otherwise create products for parties other than you.
We certify that we understand these restrictions and will comply with them. We may process de-identified or aggregated data that cannot reasonably be linked to any consumer or device, and will not attempt to re-identify it.
5. Your responsibilities
You are responsible for having a lawful basis to collect your customers' information and for giving them the notices your jurisdiction requires. You are also responsible for anything you configure that sends data elsewhere — most notably analytics or advertising tags you add to your booking page, for which you are the Controller, and Google Calendar, if you connect it. Connecting Calendar is a documented instruction to send Customer Personal Information (name, contact details, service, time, staff, extras, and notes) to Google on the calendar you choose. You are responsible for that calendar's sharing and for having a lawful basis to put customer details there. See Section 10 before enabling advertising tags or Calendar sync on a wellness booking page.
You agree not to upload special categories of data that Tableside is not built to hold, including payment card numbers, government identifiers, or clinical records.
6. Subprocessors
You give us general authorization to engage subprocessors to deliver the service. Our current subprocessors are listed at tableside/subprocessors. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain responsible to you for their performance.
We will give you at least 30 days' notice before adding or replacing a subprocessor that processes Customer Personal Information, by email to your account's notification address and by updating that page. If you reasonably object on data protection grounds within that period, we will work with you in good faith; if we cannot resolve it, you may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid fees.
7. Security
We maintain administrative, technical, and organizational measures appropriate to the risk, including: encryption of data in transit; hashing of account credentials; role-based access control with per-business isolation; least-privilege access for personnel, granted only as needed to operate and support the service; protection of forms against cross-site request forgery; rate limiting on public endpoints; automated removal of personal details from records past their retention window; and reliance on established infrastructure and payment providers. Card data is handled entirely by Stripe and never reaches our systems. When you connect a Stripe account to collect booking payments, Stripe processes those charges as your payment processor.
Personnel with access to Customer Personal Information are bound by confidentiality obligations that survive their engagement.
8. Security incidents
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Information. Our notice will describe what we know about the nature of the incident, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed.
We will provide reasonable assistance so that you can meet your own notification obligations to consumers and regulators. As Controller, you are responsible for deciding whether and how to notify your customers.
9. Assistance with consumer rights
Tableside includes tools that let you answer your customers' access, portability, and deletion requests yourself, from the Privacy requests page in your dashboard. Using them is the fastest route and keeps you in control of your own records.
If a consumer contacts us directly about information we process for you, we will not respond substantively on your behalf; we will refer them to you and tell you about the request. Where you cannot fulfil a request through the product, we will provide reasonable assistance at no additional charge.
10. Consumer health data
Washington's My Health My Data Act and Nevada SB 370 can treat the fact that a consumer sought or received a wellness service as regulated consumer health data. Because Tableside serves massage, spa, and similar businesses, we treat appointment records as consumer health data by default. Our handling is described in our Consumer Health Data Privacy Policy.
Bizsys Consulting LLC does not sell consumer health data and does not disclose the service booked to any advertising or analytics provider. If you enable Calendar sync, we copy the service name and notes onto your Google Calendar. That is not advertising, but it is a disclosure you are instructing. You agree not to use Tableside to sell consumer health data, and acknowledge that enabling third-party advertising or remarketing tags on your booking page may constitute such a sale — which under Washington law requires a signed authorization from each consumer, and carries a private right of action. We disable third-party tags on booking pages for businesses located in Washington and Nevada.
11. Deletion and return
You can export your data at any time while your subscription is active. Closing your account from your dashboard settings permanently deletes your business record and everything scoped to it, including all Customer Personal Information, and we direct our subprocessors to do the same. While a Google Calendar connection is active, a deletion request or our retention sweep also attempts to delete the matching events from that calendar. If you have disconnected, or Google has revoked the grant, we cannot reach those events; they remain on your calendar.
Two categories are retained after deletion because other law requires it: records evidencing a consumer's consent to receive text messages, retained without other identifying details for the period of the federal Telephone Consumer Protection Act's statute of limitations; and billing and tax records. Backups are overwritten on a rolling basis and are not restored except to recover from an incident.
Personal details on individual bookings are removed automatically once an appointment passes the platform's retention window, whether or not anyone requests it.
12. Audits and assessments
On reasonable written request, no more than once in any twelve-month period, we will provide the information reasonably necessary for you to verify our compliance with this Addendum, including responses to a security questionnaire and a written description of our controls. Where a State Privacy Law grants you a right to take reasonable and appropriate steps to stop and remediate unauthorized processing, we will cooperate with those steps.
13. Changes
We may update this Addendum to reflect changes in law or in the service. We will not make a change that materially reduces the protections it provides without giving you at least 30 days' notice and the opportunity to terminate the affected subscription without penalty.
Contact
Questions about this Addendum? Email support@booktableside.com.
Bizsys Consulting LLC, 7901 4th St N # 20814, St. Petersburg, FL 33702
