B2B Privacy Commitment

Your data. Your students. Yours alone.

What Surf Booking will do, will never do, and the precise legal architecture behind it. Six explicit promises plus the operational and legal fine print every controller has the right to see.

Six explicit promises

Your students are yours, not ours

Surf Booking is B2B SaaS. Schools are our customers; students are the schools' customers. Under GDPR Art. 4(7)–(8), the school is the data controller and Surf Booking is the data processor for student data. One school never sees another school's students, contacts, bookings or operational history. Each school operates in an isolated data silo. The only cross-school surface carrying identifiable data is the optional Instructor Marketplace, which an instructor opts into themselves and which only exposes the employment history they choose to publish (anonymous aggregated statistics — the rankings category — identify no one; see promises 2 and 3). When an end-user creates a Surf Booking account directly (independent of any school), Surf Booking is the controller for that account layer — see the joint-controllership note below.

We never sell or trade data

We do not sell, rent, swap or transfer personal or identifiable student or school data to advertisers, social networks, data brokers or any commercial entity. Period. The only third parties that ever touch personal data are the technical sub-processors listed below — each receives only the strict minimum needed to operate the service and is bound by a Data Processing Agreement compliant with GDPR Art. 28. Distinct from this: anonymous, zone-aggregated statistics (k≥3, never linked to any individual student or school — the same category we already publish in the rankings) may power partner and brand APIs; anonymous aggregate data is not personal data under GDPR and no student is identifiable from it. The single non-commercial exception is a binding M&A scenario (sale, merger, asset transfer): we would transfer data under the same obligations and notify schools at least 30 days in advance.

Cross-school analytics are aggregated and de-identified

Public comparisons (Surf Today rankings, awards, country/zone stats, peak hours, seasonal trends) are aggregated and de-identified — never linked to individual student identities outside their own school. These same de-identified, zone-level aggregates (k≥3) are what we may make available to brand and hardware partners via API — because they are anonymous, they are not personal data, and no student or school is identifiable from them. Inside a school's own Control Center, that school sees its own students' booking history; that is the school's data, processed on the school's documented instructions.

We cannot read your passwords

User passwords are stored with bcrypt (cost factor 12). Surf Booking cannot read or recover them, even with direct database access. Forgotten passwords are reset by the user via email-link self-service.

Legal exceptions, narrowly defined

We only release student data outside the school silo in two cases: (a) a binding judicial order under Portuguese or EU law (warrant, summons, official letter from a competent authority); or (b) a binding legal obligation directed at Surf Booking as a company (regulator request). Tax: for our own corporate income tax, we declare to the Portuguese Tax Authority (AT) only our own revenue — the platform commission charged to schools. Invoices to students are issued by the school as the controller. We do not pass student names, NIFs or booking details to AT for our corporate tax obligations. Separately, where Surf Booking qualifies as a Reporting Platform Operator under DAC7 (EU Directive 2021/514, transposed in Portugal by Decreto-Lei 73/2023), we report aggregate seller (school) information — NIF, IBAN, quarterly transaction totals — never individual student data. Where legally allowed, we notify the affected school.

Full GDPR rights, well-defined

Access, rectification, erasure, portability, objection and withdrawal of consent — written request to [email protected]. Target response: 48h. Statutory limit under RGPD Art. 12.º(3): one month, extensible +2 months for complex or numerous requests; we always inform you within 30 days if we need the extension. You also have the right to lodge a complaint directly with the Comissão Nacional de Proteção de Dados (CNPD) at www.cnpd.pt.

Sub-processors — who touches what

Every external service that ever sees personal data, what it sees, where it sits, and the legal mechanism for the transfer. If a service is not on this list, your personal data has not reached it. (Anonymous zone-aggregated statistics — the rankings category — are not personal data and are covered under promises 2 and 3 above.)

Stripe
FlowCard payments + payouts
LocationEU (Stripe Payments Europe, Ireland) + US transfer
MechanismEU–US Data Privacy Framework + Standard Contractual Clauses
Railway / Cloudflare
FlowApplication hosting + DNS + WAF
LocationEU regions
MechanismDPA + EU-resident infrastructure
Cloudflare R2
FlowImage and document object storage
LocationEU (Frankfurt)
MechanismDPA + EU region pinned
Resend
FlowTransactional email delivery
LocationEU + US
MechanismEU–US DPF + SCCs
Expo
FlowPush notifications (titles + bodies, no PII payload)
LocationUS
MechanismEU–US DPF + SCCs
Sentry
FlowError and crash reports (PII redacted before send)
LocationEU region
MechanismDPA + EU-resident processing
InvoiceExpress
FlowIssuing Surf Booking's commission invoices to schools (school name, NIF, commission amounts)
LocationPortugal
MechanismDPA + AT-certified
OpenAI / xAI
FlowText translation + admin-side description generation. PII regex-redacted (email/phone/NIF/IBAN/ID) before any free-form text leaves Surf Booking
LocationUS
MechanismEU–US DPF + SCCs + data minimisation
Groq
FlowVoice note transcription (audio) and message safety classification. Text goes through PII redaction before send
LocationUS
MechanismEU–US Data Privacy Framework + SCCs
WhatsApp Business / Meta
FlowOutbound transactional notifications (schools opt-in only). Phone number is the identifier; no message body containing personal student data
LocationUS (with EU regional servers)
MechanismEU–US DPF + SCCs

Operational and legal detail

The clauses every B2B-DPA needs in plain language: retention, transfers, breach SLA, sub-processor changes, end-of-contract, audit, children, joint controllership, legal bases.

Retention

Active accounts: data kept while the account is active. After a school cancels: 30 days for export, then deletion or anonymisation — except where statute requires longer retention (e.g. Portuguese accounting law: 10 years on tax-relevant records; insurance waiver signatures: 7 years; error logs: 90 days; encrypted backups rotate every 14 days).

International transfers (Art. 13(1)(f))

Some sub-processors are based in the United States (Stripe Inc., OpenAI, xAI, Groq, Expo, WhatsApp/Meta). Transfers rely on the EU–US Data Privacy Framework adequacy decision (10 Jul 2023) where applicable, plus EU Standard Contractual Clauses (Module 3, processor-to-sub-processor) executed with each provider. EU-resident sub-processors (Stripe Payments Europe, Cloudflare R2 Frankfurt, Sentry EU, Railway EU) keep data in the EU.

Breach notification (Art. 33)

If a data breach affects a school's data, Surf Booking notifies the school controller within 24 hours of detection — buying the school the time it needs to meet its own 72-hour CNPD obligation. The notice contains scope, affected data categories, mitigation taken and our 24/7 contact.

Sub-processor changes (Art. 28(2))

We notify schools at least 30 days before adding or replacing any sub-processor that touches student data. Schools may object; if the objection is reasonable and we cannot provide an equivalent alternative, the school may terminate without penalty.

End of contract (Art. 28(3)(g))

When a school terminates: full data export available for 30 days, then deletion. Encrypted backups expire on the regular 14-day rotation. We confirm completion in writing.

Audit rights (Art. 28(3)(h))

Schools have audit rights under the DPA. Practically, we satisfy them via: (a) this public commitment; (b) a signed DPA with Annex II security measures; (c) on-request security reports. Roadmap: ISO 27001 / SOC2 Type II certification by 2027.

Children (Art. 8 GDPR + Lei 58/2019 Art. 16)

Portugal has lowered the digital consent age to 13 under Lei 58/2019 Art. 16(1). Children under 13 cannot create their own Surf Booking account. Lessons booked for minors require a guardian-signed waiver via the school. We do not run marketing profiles on minors and do not engage in automated decision-making affecting them.

Joint controllership for direct accounts (Art. 26)

When a user creates a Surf Booking account directly (not through a school), Surf Booking is the controller of that account-layer data (profile, preferences, app history). Once that user books with a school, the booking-layer data is jointly governed: the school becomes controller for the booking, Surf Booking is processor for that booking. The two layers are kept distinct in the database; access is gated accordingly.

Legal basis for processing (Art. 6)

We process personal data on the following bases: (a) performance of contract — schools' SaaS contract and students' booking contract; (b) compliance with legal obligations — tax, accounting, DAC7; (c) legitimate interest — platform security, anti-fraud, aggregated analytics; (d) consent — non-essential cookies, marketing communications, push notifications. Consent can be withdrawn at any time per Art. 7(3) without affecting prior lawful processing.

Supervisory authority: Right to lodge a complaint with the supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt · [email protected]

Need a signed DPA?

Schools that need a Data Processing Agreement can request one. We respond within one business day with the standard EU template, ready to sign, including the school-specific Annex I (parties), Annex II (technical/organisational measures) and Annex III (sub-processors).

Request DPA
Last updated: 2026-05-07 Full privacy policy · Terms