What Surf Booking will do, will never do, and the precise legal architecture behind it. Six explicit promises plus the operational and legal fine print every controller has the right to see.
Surf Booking is B2B SaaS. Schools are our customers; students are the schools' customers. Under GDPR Art. 4(7)–(8), the school is the data controller and Surf Booking is the data processor for student data. One school never sees another school's students, contacts, bookings or operational history. Each school operates in an isolated data silo. The only cross-school surface carrying identifiable data is the optional Instructor Marketplace, which an instructor opts into themselves and which only exposes the employment history they choose to publish (anonymous aggregated statistics — the rankings category — identify no one; see promises 2 and 3). When an end-user creates a Surf Booking account directly (independent of any school), Surf Booking is the controller for that account layer — see the joint-controllership note below.
We do not sell, rent, swap or transfer personal or identifiable student or school data to advertisers, social networks, data brokers or any commercial entity. Period. The only third parties that ever touch personal data are the technical sub-processors listed below — each receives only the strict minimum needed to operate the service and is bound by a Data Processing Agreement compliant with GDPR Art. 28. Distinct from this: anonymous, zone-aggregated statistics (k≥3, never linked to any individual student or school — the same category we already publish in the rankings) may power partner and brand APIs; anonymous aggregate data is not personal data under GDPR and no student is identifiable from it. The single non-commercial exception is a binding M&A scenario (sale, merger, asset transfer): we would transfer data under the same obligations and notify schools at least 30 days in advance.
Public comparisons (Surf Today rankings, awards, country/zone stats, peak hours, seasonal trends) are aggregated and de-identified — never linked to individual student identities outside their own school. These same de-identified, zone-level aggregates (k≥3) are what we may make available to brand and hardware partners via API — because they are anonymous, they are not personal data, and no student or school is identifiable from them. Inside a school's own Control Center, that school sees its own students' booking history; that is the school's data, processed on the school's documented instructions.
User passwords are stored with bcrypt (cost factor 12). Surf Booking cannot read or recover them, even with direct database access. Forgotten passwords are reset by the user via email-link self-service.
We only release student data outside the school silo in two cases: (a) a binding judicial order under Portuguese or EU law (warrant, summons, official letter from a competent authority); or (b) a binding legal obligation directed at Surf Booking as a company (regulator request). Tax: for our own corporate income tax, we declare to the Portuguese Tax Authority (AT) only our own revenue — the platform commission charged to schools. Invoices to students are issued by the school as the controller. We do not pass student names, NIFs or booking details to AT for our corporate tax obligations. Separately, where Surf Booking qualifies as a Reporting Platform Operator under DAC7 (EU Directive 2021/514, transposed in Portugal by Decreto-Lei 73/2023), we report aggregate seller (school) information — NIF, IBAN, quarterly transaction totals — never individual student data. Where legally allowed, we notify the affected school.
Access, rectification, erasure, portability, objection and withdrawal of consent — written request to [email protected]. Target response: 48h. Statutory limit under RGPD Art. 12.º(3): one month, extensible +2 months for complex or numerous requests; we always inform you within 30 days if we need the extension. You also have the right to lodge a complaint directly with the Comissão Nacional de Proteção de Dados (CNPD) at www.cnpd.pt.
Every external service that ever sees personal data, what it sees, where it sits, and the legal mechanism for the transfer. If a service is not on this list, your personal data has not reached it. (Anonymous zone-aggregated statistics — the rankings category — are not personal data and are covered under promises 2 and 3 above.)
The clauses every B2B-DPA needs in plain language: retention, transfers, breach SLA, sub-processor changes, end-of-contract, audit, children, joint controllership, legal bases.
Active accounts: data kept while the account is active. After a school cancels: 30 days for export, then deletion or anonymisation — except where statute requires longer retention (e.g. Portuguese accounting law: 10 years on tax-relevant records; insurance waiver signatures: 7 years; error logs: 90 days; encrypted backups rotate every 14 days).
Some sub-processors are based in the United States (Stripe Inc., OpenAI, xAI, Groq, Expo, WhatsApp/Meta). Transfers rely on the EU–US Data Privacy Framework adequacy decision (10 Jul 2023) where applicable, plus EU Standard Contractual Clauses (Module 3, processor-to-sub-processor) executed with each provider. EU-resident sub-processors (Stripe Payments Europe, Cloudflare R2 Frankfurt, Sentry EU, Railway EU) keep data in the EU.
If a data breach affects a school's data, Surf Booking notifies the school controller within 24 hours of detection — buying the school the time it needs to meet its own 72-hour CNPD obligation. The notice contains scope, affected data categories, mitigation taken and our 24/7 contact.
We notify schools at least 30 days before adding or replacing any sub-processor that touches student data. Schools may object; if the objection is reasonable and we cannot provide an equivalent alternative, the school may terminate without penalty.
When a school terminates: full data export available for 30 days, then deletion. Encrypted backups expire on the regular 14-day rotation. We confirm completion in writing.
Schools have audit rights under the DPA. Practically, we satisfy them via: (a) this public commitment; (b) a signed DPA with Annex II security measures; (c) on-request security reports. Roadmap: ISO 27001 / SOC2 Type II certification by 2027.
Portugal has lowered the digital consent age to 13 under Lei 58/2019 Art. 16(1). Children under 13 cannot create their own Surf Booking account. Lessons booked for minors require a guardian-signed waiver via the school. We do not run marketing profiles on minors and do not engage in automated decision-making affecting them.
When a user creates a Surf Booking account directly (not through a school), Surf Booking is the controller of that account-layer data (profile, preferences, app history). Once that user books with a school, the booking-layer data is jointly governed: the school becomes controller for the booking, Surf Booking is processor for that booking. The two layers are kept distinct in the database; access is gated accordingly.
We process personal data on the following bases: (a) performance of contract — schools' SaaS contract and students' booking contract; (b) compliance with legal obligations — tax, accounting, DAC7; (c) legitimate interest — platform security, anti-fraud, aggregated analytics; (d) consent — non-essential cookies, marketing communications, push notifications. Consent can be withdrawn at any time per Art. 7(3) without affecting prior lawful processing.
Schools that need a Data Processing Agreement can request one. We respond within one business day with the standard EU template, ready to sign, including the school-specific Annex I (parties), Annex II (technical/organisational measures) and Annex III (sub-processors).
Request DPA