PRIVACY STATEMENT OF PROAGENDA

Last updated: Aug 1st 2026

This notice is for the businesses, organisations and venues who use ProAgenda to run their bookings and client records — coaching academies, sports clubs, studios, salons, practices, schools and similar. If you are an individual who books an appointment because a business you use runs on ProAgenda, please read our Privacy Notice for Clients instead.

ProAgenda is a registered trading name of Golf Financial Services B.V., registered with the Dutch Chamber of Commerce under number 34130467, at Jan van Krimpenweg 9e, 2031 CE Haarlem, the Netherlands. Where this notice says "ProAgenda", "we" or "us", it means that company.

We have customers in Europe, the United Kingdom, North America, Australia and elsewhere. This notice applies wherever you are, with region-specific rights set out under Your rights.


Our two roles

This distinction matters, so we set it out first.

We are the controller for your own account. When you subscribe, we decide how we handle your name, contact details, login and billing information, and we are responsible for that processing.

We are a processor for your clients' data. The records you create about the people you serve — bookings, notes, progress, video where you use it, payments — belong to you. You decide what to collect, why, and how long to keep it. We hold and process that data on your instructions and for no other purpose.

In the language of European and UK data protection law, you are the controller for your client records and we are your processor. If you are in a jurisdiction that uses different terms — "business" and "service provider" in California, for example — the same split applies: you determine the purposes, we act on your instructions.

Our data processing agreement forms part of our Terms and Conditions. If your organisation requires a separately signed version, ask us.


What we process, and why

Your account

Data Purpose Why we are allowed to (EEA/UK)
Name, email address, telephone number, address Creating and running your account, support, invoicing Performance of our contract with you
Username, password (stored hashed), role and permissions Authenticating you and controlling access Performance of our contract
Subscription and payment records Billing, accounting, tax Contract, and legal obligation for tax records
IP address, log and usage data Security, troubleshooting, preventing misuse Our legitimate interest in keeping the service secure

We rely on contract, not consent, for the data needed to run your account. Consent must be freely withdrawable, and you cannot withdraw consent to processing that is necessary for a service you have asked us to provide. Calling it consent would misrepresent your rights.

Marketing

If you have opted in, we may email you about new features and services. Every email has an unsubscribe link, and you can object at any time. Basis: consent, which you may withdraw freely.

Data you enter about your clients

Contact details, bookings and attendance, notes and progress records, packages, credits, vouchers and memberships, payments, and video where you use it. We process this on your instructions as your processor. You determine the purpose and the lawful basis, and you are responsible for telling your clients what you hold and why.


Notes, health information and video

Notes are free text, and that matters more than it might appear. Many of our customers record information that counts as health data under data protection law: an injury or physical limitation at a sports or fitness business, an allergy, a skin or scalp condition at a salon, a medical note relevant to a treatment. Health data receives heightened protection in most jurisdictions.

We apply the same access controls and audit logging to notes as to the rest of your records. But you should be deliberate about what you record, why, and whether you need it.

Video is an optional feature. Where you use it, files are uploaded to Bitmovin, which encodes them, stores them in Ireland and delivers them through a global content delivery network. Video links are shown only to logged-in users entitled to see them and contain long, effectively unguessable identifiers. However, the links are not access-controlled at the point of delivery: they carry no expiry and cannot be withdrawn, so anyone who obtains a link can view that video.

Deleting a record does not currently delete the video file. Our provider has confirmed that removal of stored video is handled as an account-level request rather than through their interface. If you need video permanently removed, contact us and we will arrange it. We are implementing automatic deletion during 2026, and separately evaluating a change to our own storage and delivery so that links can expire and be withdrawn.

Please treat video links as confidential and do not forward or publish them.


Who else processes data

We use the following sub-processors. We remain responsible for them and impose data protection obligations on each by contract.

Provider Location What they do
Hypersolid Netherlands (Equinix AM2 and AM7, Amsterdam) Hosts our server and manages backups
Bitmovin, Inc. United States. Video stored in Ireland, delivered via a global network Video encoding, storage and delivery
Twilio SendGrid United States Sends service emails (account, booking, notification)
Stripe Ireland, with onward transfer to the United States Processes payments

Amazon Web Services acts as Bitmovin's sub-processor. Stripe engages its own sub-processors, published on its website.

Our public website separately uses Google Analytics and Google Tag Manager, which process website visitor data only and have no access to platform data.

We give at least 30 days' notice before adding or replacing a sub-processor, so you have the opportunity to object.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your data or your clients' data to train machine learning models. We disclose data to others only where the law requires it — for example a valid order from a court or law enforcement.


Where data is held, and international transfers

Our application and database are in Amsterdam, the Netherlands. This is true for all customers, wherever you are based.

If you are outside Europe, this means your data is transferred to and stored in the European Economic Area, and receives the protection of that framework regardless of where you are.

Some processing takes place outside the EEA:

  • Service emails through Twilio SendGrid in the United States, relying on Standard Contractual Clauses and, for UK-origin data, the UK International Data Transfer Agreement.
  • Payment data with Stripe's Irish entity, transferring onward to the United States under the EU–US Data Privacy Framework with Standard Contractual Clauses as fallback.
  • Video with Bitmovin, Inc., a US company. Files are stored in Ireland but delivered through a global network. We are documenting the transfer mechanism with the provider and will update this notice.

How long we keep data

Data Retention
Your account and its contents For as long as your account is open
Your account after it becomes inactive Retained 12 months to allow reactivation, then deleted. Sooner on written request
Invoices and tax records Seven years, as Dutch law requires
Support correspondence Until the matter is resolved
Change log entries Life of the account; not purged
Backups Seven days, rolling

Many of our customers operate seasonally and suspend and reactivate their accounts across a year, which is why we hold data for 12 months rather than deleting immediately. If you would rather we did not, tell us and we will delete within 30 days.

We do not operate different retention periods for different data types, and retention is not configurable per customer.

You can delete your own account, which permanently removes it from our database. Records deleted by other users in your organisation are removed from the platform but retained in our database until we permanently erase them; write to us and we will do so within five working days. Video files are the exception described above.


Your rights

Wherever you are, you can ask us to:

  • tell you what data we hold about you and why
  • give you a copy of it
  • correct anything inaccurate
  • delete it, where we have no continuing reason or legal duty to keep it
  • restrict or object to how we use it
  • transfer it to another provider in a machine-readable format
  • withdraw consent, where consent is the basis (for example marketing)

We will not discriminate against you for exercising any of these rights.

Email info@proagenda.com. We respond within one month; where a shorter period applies in your jurisdiction, we meet that instead. We may need to verify your identity first, so that we do not disclose or delete someone else's data by mistake.

For requests about your clients' data, the client should approach you as the controller, and we will help you respond.

If you are in the EEA, the UK or Switzerland

Your rights come from the EU GDPR, UK GDPR or the Swiss Federal Act on Data Protection. You may complain to a supervisory authority: the Autoriteit Persoonsgegevens in the Netherlands (autoriteitpersoonsgegevens.nl), the Information Commissioner's Office in the UK (ico.org.uk), the FDPIC in Switzerland, or the authority where you live or work.

If you are in California

Under the CCPA as amended by the CPRA you may request to know, delete, correct, and opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring an opt-out. You may designate an authorised agent. You will not receive different pricing or service for exercising your rights.

If you are elsewhere in the United States

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and others as they take effect — have rights to access, correct, delete and obtain a copy of their personal data, and to opt out of targeted advertising, sale and certain profiling. We do not engage in any of those three activities. Where an appeal right exists, you may appeal our decision by replying to our response; we will explain the outcome in writing.

If you are in Canada

You have rights of access and correction under PIPEDA and equivalent provincial laws. You may complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.

If you are in Australia

You have rights of access and correction under the Privacy Act 1988 and the Australian Privacy Principles. You may complain to the Office of the Australian Information Commissioner.

If you are in Brazil

You have rights under the LGPD including confirmation, access, correction, anonymisation, portability and deletion. You may complain to the ANPD.

Anywhere else

Local law may give you further or different rights. We will honour any right you have under the law that applies to you. Tell us what you are asking for and we will deal with it on that basis.


Our website

Our website uses Google Analytics and Google Tag Manager to understand how visitors use the site. These set cookies and share data with Google in the United States. You can decline analytics cookies through our cookie banner without losing access to the site. Our site also embeds social media buttons; those providers may collect data when the buttons load.


Security

Access to data is restricted by role: staff see their assigned clients, and organisation permissions govern what each user can do. All traffic runs over HTTPS. Changes to records are logged with the user and timestamp, and organisation administrators can view that log. Backups are encrypted. Multi-factor authentication is not currently available.

Our full security position, including controls not yet in place, is in our Data Protection Statement.


Changes

We will update this notice when our processing changes, and will change the date at the top. For significant changes we will tell you by email or in the platform rather than relying on you to check.


Contact

Golf Financial Services B.V., trading as ProAgenda Jan van Krimpenweg 9e, 2031 CE Haarlem, the Netherlands info@proagenda.com · KvK 34130467 EU +31 20 449 6099 · UK +44 1753 913045 · US +1 832 534 0478