Data Processing Addendum
Last updated 27 September 2026
This addendum forms part of the Terms of service between you (the controller) and Mahmoud Shayeb, operating Babara (the processor). It applies automatically when you use Babara and covers personal data you add or that Babara collects for you. It follows Article 28 of the GDPR and the UK GDPR. Need a signed copy? Email privacy@babara.app.
1. What we process, and why
- Purpose: sending payment reminders on your behalf, hosting each invoice’s pay page, recording your clients’ choices there, forwarding their replies to you, and showing you the history and statistics.
- Data subjects: the contacts at your clients (and anyone you copy on reminders).
- Personal data: names, email addresses, invoice details, pay-page choices (paid, promised date, question, “not me”), replies to reminders, and email delivery status.
- Duration: for as long as you use Babara, then deletion as described below.
2. Our commitments
- We process the data only on your documented instructions: these terms, your settings and the features you use. We’ll tell you if we think an instruction breaks data protection law.
- Anyone who can access the data is bound by confidentiality.
- We apply the security measures in section 4.
- We help you answer requests from data subjects and, where relevant, with impact assessments and consultations with authorities.
- We tell you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting your data.
- We make available the information needed to show compliance, and allow a reasonable audit on written request, at most once a year.
3. Subprocessors
You authorise the subprocessors on our subprocessor list. We’ll post changes there at least 14 days before a new subprocessor starts processing your data. If you object, you can close your account and fees for the unused period of a paid plan are refunded. We bind every subprocessor to data protection terms at least as protective as these.
4. Security measures
- Encryption in transit (HTTPS, HSTS) and at rest by our hosting provider.
- Every account’s data is separated; sessions and sign-in links are stored only as one-way hashes; no passwords exist to leak.
- Rate limits and sending caps against misuse, and automatic pauses after bounces, spam complaints or “not me” reports.
- Access to production data limited to the operator, for support and maintenance.
5. International transfers
Where personal data leaves the EEA or the UK to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2 for controller-to-processor and Module 3 for processor-to-processor transfers) are incorporated into this addendum by reference, together with the UK International Data Transfer Addendum for UK data. Annex I is section 1 of this page, Annex II is section 4 and Annex III is the subprocessor list.
6. Deletion
You can delete clients, invoices or your whole account at any time. Deleted data leaves our live database at once and our backups within 30 days, unless the law requires us to keep it.