PrytanPrytan
All legal documents

Data-processing terms

Version 2026-10-02. A lawyer is reviewing this document; any change is posted here with its date before it applies.

These terms follow Article 28 of the GDPR. They are part of the terms for businesses and you accept them with those terms; the version and the date are recorded. You are the business. Prytan is [Company name, kennitala, registered address, Iceland]. Contact: support@prytan.ai.

1. Who is responsible for what

One booking passes through three hands. Each is responsible for its own part.

PartWho is responsibleUnder what
A person's own Prytan account, and collecting and sending the booking that person asked forPrytan, as a controller in its own rightthe privacy policy for people who book
The booking, from the moment your booking system receives it, and everything else in your booking systemYou, as a separate controlleryour own privacy policy
What Prytan keeps and shows for you: the booking record in your dashboard, notifications and alert emails, reading back the bookings Prytan made, and the known-customer checkYou are the controller; Prytan is your processorthese terms

These terms cover the third row only. Prytan and you are not joint controllers.

2. What is processed

Annex A lists whose data, which data, why, and for how long. Prytan does not receive or process any other customer of yours. It never reads your customer list or your calendar. It reads back only the bookings it made, each by its own id.

3. Your instructions

Prytan processes the data in Annex A only on your documented instructions. These are your instructions:

  1. Show and tell. Keep the record of each booking made at your business through Prytan, show it to the people in your organisation (the customer's name, never the phone number or email), and tell them when it is made, moved or cancelled.
  2. Read back. Ask your booking system about the bookings Prytan made, each by its own id, to learn when one was changed or cancelled.
  3. Send bookings to your booking system, wherever it is. You instruct Prytan to send each booking to the booking system you connected, in whatever country that system stores data. You confirm that you have a valid agreement with that system, including a valid tool for any transfer outside the European Economic Area.
  4. Existing customers only. Setting a staff member to take only existing customers in your booking system is your instruction to apply that rule as Annex A describes. The check is made only with a phone number Prytan verified by a text code, never with one a person merely saved. While texts are switched off it is not made at all.
  5. Your own AI. When someone in your organisation connects an AI and ticks "My business insights", that is your instruction to give that AI the figures your dashboard shows: look-ups, which agents, what they asked about, bookings made through Prytan with the customers' names, busiest times, and what needs attention. Phone numbers and emails are never included. Customers' names are never included for bookings of health services. The AI's provider is your provider, not Prytan's sub-processor. You are responsible for it, including any transfer of data abroad that it makes.
  6. Security. Keep the service secure and fair, for example with rate limits.

Anything else needs your written instruction. If we believe an instruction breaks the law, we will say so.

4. Confidentiality

Only people who need to can access the data, and they are bound to keep it confidential. Prytan is currently one person. This clause is written for the day that changes.

5. Security

Prytan protects the data with the measures in Annex B and keeps them at least as strong as they are today.

6. Sub-processors

You agree that Prytan uses the sub-processors on the sub-processor list. Each is bound by a written contract to the same data-protection duties as these terms place on Prytan, and Prytan stays responsible to you for what they do.

We tell you by email at least 30 days before we add, replace or switch on a sub-processor. You may object in writing. If we cannot resolve your objection, you may end the service before the change applies.

Your booking system is not Prytan's sub-processor. It is your own processor, and Prytan hands data to it on your instruction (clause 3).

7. Helping you

Taking account of what Prytan holds, we help you:

  • answer a person who uses their rights (access, correction, deletion, restriction, objection, a copy of their data);
  • with a data-protection impact assessment, or a consultation with a data-protection authority, if one is needed;
  • show that you meet your own duties about this processing.

There is no charge beyond reasonable effort.

8. Breaches

If we learn of a breach of security that affects your customers' data, we tell you without undue delay, and in any case within 48 hours of learning of it. We tell you what happened, which data and roughly how many people are affected, what we have done, and who to contact. We keep you informed as we learn more.

9. Transfers outside the European Economic Area

The database and the server are inside the EEA. Annex C lists every transfer outside it and the tool that covers it. Prytan makes no other transfer of your customers' data without telling you first under clause 6.

10. Return or deletion

When you remove a business, its bookings are deleted at once. When the agreement ends, you choose: Prytan gives you a copy of your customers' booking records in a common file format, or deletes them. If you do not choose within 30 days, Prytan deletes them. Either way the deletion is complete within 30 days of your choice, unless the law requires Prytan to keep something. Encrypted backups age out within a further 14 days.

11. Audit

  • Information. At any time, on request, we give you in writing the information you need to see that Prytan meets these terms.
  • Audit. Once a year, on 30 days' written notice, you or an independent auditor you appoint may audit how Prytan meets these terms. The audit takes place in working hours, under a duty of confidentiality, without access to other businesses' data, and at your cost.
  • If an audit finds that Prytan does not meet these terms, Prytan puts it right without delay.

12. Liability

The liability rules in the terms for businesses apply to these terms too. Nothing in them limits what an individual may claim under data-protection law.

13. Which document wins, and changes

On personal data, these terms win over the terms for businesses. They change in the same way as those terms: 30 days' notice, the right to leave, and a new recorded acceptance.

Annex A: the processing

Whose dataWhich dataWhyFor how long
Your customers who book through an AI agentname, phone number, email address where your booking system needs it, service, time, staff where chosen, the name the agent gave itself, its network address, the outcome, the booking's id in your booking systemto show you the booking (the name only), to tell you when it is made, moved or cancelled, and to read it back by its id24 months after the appointment, or at once when you remove the business
Your customers in your booking system, for staff you set to take only existing customersone question per check: has this phone number, verified by Prytan with a text code, booked with this staff member? The answer is yes or no. Not made while texts are switched off, which is the case today. Never made at a health businessto apply your own "existing customers only" rulethe answer is not stored; it is held in memory for ten minutes
Your customers, in the figures your own AI readsthe customers' names in bookings made through Prytan, never for bookings of health servicesto answer your questions about your own businessnot stored again: read from the booking records above

Nature of the processing: storing, showing, reading back, sending notices. Categories of people: your customers who book through Prytan. Sensitive data: a booking of a health service is health data. Prytan makes such a booking only for a person who gave Prytan their explicit consent, and never includes names of those bookings in the figures your AI reads.

Annex B: security measures

  • Encryption. Access tokens and keys for your booking system are encrypted at rest with a key held outside the database. All traffic uses HTTPS. Database backups are encrypted.
  • Access. Every request in the app is limited to your own organisation, and every personal request to the person's own account. Automated tests check both on every release. The admin area is limited to named operator accounts.
  • Sign-in. One-time codes and links. Codes and passes are stored only as hashes. An AI's access pass lasts 60 minutes and can be revoked at once.
  • The database. The provider's public data interface is locked: it gives nothing without Prytan's own credentials, which only Prytan's server holds.
  • The server. A firewall that allows only web traffic and key-based administration; automatic security updates.
  • Logs. Cleaned of email addresses and phone numbers as they are written.
  • Limits. Rate limits per caller, a daily limit per business, and limits per person.
  • Deletion. A nightly job enforces the periods in Annex A.
  • Software. Fixed, tested versions of every package; known weaknesses checked before each release.
  • Incidents. The notice in clause 8.

Annex C: transfers

Prytan's own sub-processors. See the sub-processor list. In short: the database (Frankfurt) and the server (Amsterdam) are in the EEA, under contracts with companies in Singapore and the USA. Email is sent from Ireland and stored in the USA for 30 days. Each is covered by the European Commission's standard contractual clauses, the EU-US Data Privacy Framework, or both.

Your booking system. Prytan sends each booking to the system you connected, on your instruction (clause 3). Where that system stores data:

Booking systemCompany and where data is stored
Noonaan Icelandic company; data in Amsterdam, Netherlands
Cal.comUSA
Clinikoan Australian company; data in the region you chose: Australia, the United Kingdom, Canada or Ireland
SimplyBook.mea Cypriot company; data in Canada, France and Singapore
Squarefor European businesses Squareup International Ltd, Ireland; data in the USA, the EU and elsewhere
Acuityfor businesses outside the USA Squarespace Ireland Limited; data in the USA

Canada and the United Kingdom are covered by adequacy decisions. For the USA, Australia and Singapore you confirm that your agreement with the system includes a valid transfer tool.

Country addenda

Each addendum applies only when Prytan is offered in that country, and only to a business there.

United Kingdom

When Prytan is offered there. Where UK data-protection law applies to your customers' data, these terms apply with "UK GDPR" read in place of "GDPR". For any transfer from the UK to a country without UK adequacy, the UK's International Data Transfer Addendum to the standard contractual clauses applies between us.

United States

When Prytan is offered there. Prytan acts as your service provider. Prytan uses your customers' data only to provide the service to you. Prytan does not sell it, does not share it for advertising, and does not combine it with data from other sources except as these terms allow. Prytan tells you if it can no longer meet these duties.

Health businesses in the United States are not offered through Prytan. For that reason no HIPAA business-associate contract is part of these terms.

Questions: support@prytan.ai. Report a bug.