Skip to content
OpenReserve

Data Processing Addendum

Effective 2026-10-07 · Last updated 2026-10-08

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between MemoryMaps, LLC d/b/a OpenReserve ("OpenReserve," "we," "us") and the business that uses OpenReserve (the "Business," "you"). It applies whenever we process personal data on your behalf. If this DPA conflicts with the Agreement, this DPA controls for the processing of personal data.

In plain English: Your business's data, including your clients' personal information, is yours. We process it only to provide OpenReserve to you, under your instructions, with the protections data-protection laws require.

1. Definitions

  • "Business Personal Data" means personal data in the information you, your staff or your clients submit to your OpenReserve account, which we process on your behalf.
  • "Data Protection Laws" means the privacy and data-protection laws that apply to that processing, including, where applicable, the California Consumer Privacy Act as amended (the "CCPA"), and other US state privacy laws.
  • "Subprocessor" means a service provider we engage that processes Business Personal Data.
  • "Controller," "processor," "business," "service provider," "data subject," "personal data" and "processing" have the meanings given in the Data Protection Laws.

2. Roles

You are the controller (and, under the CCPA, the business) for Business Personal Data. We are your processor (and service provider). You are responsible for having a lawful basis for the processing, for giving your clients the notices the law requires, and for the accuracy of the instructions you give us. We are a controller only for the account and usage information described in our Privacy Policy that we need to run and secure the Service.

3. Processing on your instructions

We process Business Personal Data only on your documented instructions. The Agreement, this DPA, your configuration of the Service and the requests you or your staff make through it are your complete instructions. If we believe an instruction breaks Data Protection Laws, we will tell you. If the law requires us to process Business Personal Data in another way, we will tell you before doing so, unless the law forbids it.

4. Details of the processing

  • Subject matter and duration: providing OpenReserve to you, for the term of the Agreement and until the data is deleted as described below.
  • Nature and purposes: hosting, storing, organizing, displaying, transmitting and deleting data, to provide the Service's features to you and your clients and processing payments through your Stripe account, and to secure and support the Service.
  • Data subjects: your staff, and your clients and prospective clients.
  • Categories of personal data:
    • Information about a business's clients: When you book with or buy from a business: your name, email address and phone number, your appointments and purchases, your preferences, and notes the business keeps about your visits.
    • Contact details and roles of your staff.
  • Special categories and sensitive data: none intended. Do not submit special categories of personal data unless a feature is designed for it.

5. Confidentiality

Everyone at OpenReserve who can access Business Personal Data is bound by confidentiality obligations and accesses it only as needed to provide, secure or support the Service, or as the law requires.

6. Security

We implement and maintain appropriate technical and organizational measures to protect Business Personal Data, including those described on our Security page: encryption in transit and at rest, separation of each business's data enforced in the database, least-privilege and logged access, short-lived credentials, and audit logging. Database recovery history is configured for six hours. Tenant media storage does not keep object versions. This recovery-history setting does not specify when every backup copy held by a provider is physically erased. We may update these measures as long as the overall level of protection is not reduced.

7. Subprocessors

You give us general authorization to engage Subprocessors. Our current Subprocessors are listed on our Subprocessors page. We will give you at least 30 days' notice before adding a new Subprocessor, and you may object on reasonable data-protection grounds as described on that page. We impose data-protection obligations on each Subprocessor that are at least as protective as this DPA, and we remain responsible for their performance.

8. Helping you meet your obligations

  • Requests from individuals. If we receive a request from one of your clients or staff to exercise their rights, we will forward it to you and not respond ourselves, except to tell them we have done so. The Service lets you access, correct, export and delete Business Personal Data; where it does not, we will help you respond, taking into account the nature of the processing.
  • Assessments. We will give you reasonable information and help you need for data-protection impact assessments, risk assessments, cybersecurity audits and consultations with regulators about the Service.

9. Personal data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Business Personal Data, we will notify you without undue delay, and in any case within 72 hours after confirming it. We will give you the information you reasonably need to meet your own notification obligations, update you as we learn more, and take reasonable steps to contain and remedy the breach.

10. Return and deletion

A business can export its data during the 30-day period after it closes its workspace. After that closure grace period, tenant-owned data is deleted once unresolved payment or refund obligations are resolved and the purge can complete. A scrubbed workspace record and a minimal purge audit record remain. This local deletion does not delete records held separately by Stripe or close the business's Stripe account. Database recovery history is configured for six hours. Tenant media storage does not keep object versions. This recovery-history setting does not specify when every backup copy held by a provider is physically erased. On request, we will confirm deletion in writing.

11. Audits

We will make available the information reasonably necessary to demonstrate our compliance with this DPA. Once every 12 months, or after a breach affecting your data, you may audit our compliance on at least 30 days' written notice, during business hours, at your expense, under confidentiality obligations, and without access to other customers' data. Where possible, we will first answer your questions in writing and share any relevant reports, which may satisfy the audit request.

12. CCPA service provider terms

When we process Business Personal Data that is personal information under the CCPA:

  1. We process it only for these specific business purposes:
    • hosting and storing it;
    • providing the features you use, such as scheduling, booking, client records;
    • sending the emails, push notifications you configure;
    • enabling payments through your Stripe account;
    • customer support;
    • security, fraud prevention and debugging; and
    • complying with the law.
  2. We do not sell or share it (as "share" is defined in the CCPA).
  3. We do not retain, use or disclose it for any purpose other than those business purposes, including any commercial purpose, or outside our direct business relationship with you, except as the CCPA regulations permit service providers (for example, to build or improve the quality of the Service without using it to serve another customer).
  4. We do not combine it with personal information we receive from or on behalf of another person, or collect from our own interactions with individuals, except as the CCPA permits.
  5. We comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses, including reasonable security.
  6. You may take reasonable and appropriate steps to ensure we use it consistently with your CCPA obligations, including the reviews and audits described above, and, on notice, to stop and remedy any unauthorized use.
  7. We will notify you if we determine we can no longer meet our obligations under the CCPA.
  8. We will help you respond to consumer requests, and you will tell us about any request we must comply with and give us the information we need to do so.
  9. We engage Subprocessors only under written contracts with terms at least as protective as these, and we notify you as described above.
  10. We will cooperate with your cybersecurity audits and risk assessments, and will not misrepresent any fact relevant to them.

13. Liability and term

Each party's liability under this DPA is subject to the limitations in the Agreement, to the extent the Data Protection Laws allow. This DPA lasts as long as we process Business Personal Data and ends when it has been deleted or returned.

14. Contact