1. Controller & Operating Entity
Dynamotics provides software services to businesses worldwide. Where applicable, we comply with the data protection laws of the jurisdictions in which we operate, including the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA) and other applicable privacy laws.
Operator: Dynamotics
Service Availability: Worldwide
Privacy Contact: support@dynamotics.com
This policy applies across all software properties within the Dynamotics platform:
- Public Pages:
dynamotics.com - Merchant Management Portal:
dashboard.dynamotics.com - Merchant Booking Portals: Client booking subdomains (e.g.,
[merchant].dynamotics.com), embedded widgets, or custom domains powered by Dynamotics.
2. Controller vs. Processor Roles & DPA
In accordance with Article 4 of the GDPR, responsibilities are partitioned based on our relationship with the data subject:
We act as a Data Controller for personal data collected directly from Merchants, account owners, and staff members creating accounts on dashboard.dynamotics.com, as well as general website visitors on dynamotics.com.
When end-customers book appointments through a Merchant's website powered by Dynamotics, the Merchant acts as the Data Controller for that customer data. Dynamotics acts strictly as a Data Processor handling data on the Merchant's instructions.
Where Dynamotics processes personal data on behalf of Merchants, such processing is subject to our Data Processing Agreement where required by applicable law. Merchants may request a copy by contacting support@dynamotics.com.
3. Merchant & User Responsibilities
Businesses ("Merchants") using the Dynamotics platform to collect end-customer bookings act as independent Data Controllers and are responsible for ensuring their own legal compliance, including:
- Providing their own clear privacy notice to end-customers detailing how customer data is processed.
- Ensuring a valid lawful basis under GDPR exists for any customer data collected via custom booking form fields.
- Responding directly to end-customer requests regarding data access, corrections, or deletions.
- Ensuring that information provided to Dynamotics (including business contact details and staff rosters) is accurate and kept up to date.
4. Purposes & Categories of Processing
Purposes of Processing
We process personal information for the following core operational purposes:
- Create and manage merchant accounts and staff credentials.
- Provide online scheduling and client booking functionality.
- Send transactional booking confirmations, updates, and reminders.
- Maintain platform security, prevent abuse, and enforce rate limits.
- Improve service reliability, infrastructure stability, and performance.
- Provide customer support and respond to technical inquiries.
- Manage subscriptions, payments, invoices, receipts, billing history, and customer support.
Categories of Data Processed
A. Merchant Account & Staff Data
Authentication identifiers managed through Supabase Auth. Dynamotics does not store plaintext passwords.
B. Subscription & Billing Information
When merchants subscribe to paid Dynamotics services, billing information is processed through Stripe, our payment service provider. This may include customer name, email address, subscription status, invoice information, payment history, and transaction identifiers. Dynamotics does not store full payment card numbers or payment authentication data. Payment card details are collected and processed directly by Stripe under Stripe's own privacy terms.
C. End-Customer Booking Information
Full name, email address, contact phone number, appointment date/time requested during checkout, and optional comments entered into booking fields.
D. Technical and Security Information
IP addresses, browser user-agent strings, request timestamps, and diagnostic error logs required to protect platform stability and security.
5. Legal Bases for Processing
Processing operations conducted by Dynamotics are grounded in legal bases defined under GDPR Article 6(1):
| Processing Purpose | GDPR Article 6 Basis | Data Involved |
|---|---|---|
| Dashboard Account Management | Art. 6(1)(b) - Contract Performance | Merchant user credentials |
| Processing Customer Bookings | Art. 6(1)(b) - Contract / Processor Terms | Customer appointment details |
| Sending Transactional Email Notifications | Art. 6(1)(b) - Contract Performance | Customer email, booking timestamp |
| Platform Security & Rate Limiting | Art. 6(1)(f) - Legitimate Interests | IP addresses, server logs |
| Subscription Billing & Payment Processing | Art. 6(1)(b) - Contract Performance | Billing details, subscription information, invoice records |
6. Sub-Processors & Infrastructure
To provide software infrastructure, Dynamotics engages third-party sub-processors bound by data protection contracts:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Supabase | Database hosting, authentication, storage, and backend infrastructure. | Depends on selected project region (e.g. EU) |
| Vercel Inc. | Web hosting, serverless edge routing, and application delivery. | Global edge infrastructure |
| Resend | Delivery of transactional emails such as account verification, password resets, booking confirmations, reminders, and service notifications. | US / EU infrastructure with appropriate safeguards |
| Cloudflare | DNS, network security, caching, content delivery, and protection against malicious traffic. | Global network |
| Stripe | Payment processing, subscription management, billing operations, invoices, receipts, and payment-related customer information. | European and global infrastructure depending on payment routing, with applicable safeguards for international transfers. |
Dynamotics uses Stripe to process subscription payments and manage billing operations. When a merchant purchases a paid subscription, payment details are submitted directly to Stripe. Dynamotics does not receive or store full payment card numbers. Stripe processes payment information as an independent payment service provider according to its own privacy policy and security practices.
7. International Data Transfers
Personal information may be processed in countries other than the country where it was collected. This may include payment-related processing performed by Stripe and its affiliated entities. Where required by applicable law, Dynamotics uses appropriate safeguards, including Standard Contractual Clauses or other approved transfer mechanisms, to protect international data transfers.
- Standard Contractual Clauses (SCCs): European Commission approved clauses incorporated into agreements with infrastructure vendors.
- EU-U.S. Data Privacy Framework (DPF): Transatlantic transfers conducted with certified US vendors where applicable.
8. Account Deletion & Data Retention
We retain personal information only for as long as necessary for the operational purposes described in this policy, including statutory legal, tax, or accounting requirements:
- Merchant Accounts: Retained while the platform account remains active. Deleted within a reasonable period after a verified deletion request unless legal obligations require longer retention.
- Booking Customer Data: Stored on behalf of Merchants according to their instructions or until deleted by the Merchant or customer request.
- Server Logs: Security logs are rotated and purged periodically.
Merchant account holders may request account closure and database deletion by contacting support@dynamotics.com. Please note that certain information may be retained where required by law, statutory accounting obligations, security requirements, or dispute resolution.
9. Data Subject Rights under GDPR
Under Articles 15-22 of the EU GDPR, individuals residing in the EU/EEA possess legal rights regarding their personal data:
Notice for Booking Customers: If you scheduled an appointment with a business using Dynamotics, please direct your request to that business directly, as they act as the Data Controller governing your booking details.
10. Technical Security & Breach Response
Pursuant to GDPR Article 32, technical and administrative safeguards are employed to secure processing activities:
- Transport Security: Network traffic with Dynamotics services is protected using HTTPS encryption and modern transport security protocols.
- Database Isolation: Row-Level Security (RLS) rules prevent multi-tenant data access between independent merchant accounts.
- Account Credentials: Users are responsible for maintaining the confidentiality of their account credentials and notifying Dynamotics of suspected unauthorized access.
If you are located in the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection authority. For users in Sweden, this authority is:
12. Acceptance of this Privacy Policy
By accessing or using the Dynamotics Platform, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law for specific processing activities, such consent will be requested separately and may be withdrawn at any time.
13. Children, Contact & Supervisory Authority
Protection of Minors
Dynamotics is intended for businesses and their customers. We do not knowingly provide services directly to children or intentionally collect children's personal data.
Merchants are responsible for determining whether their booking services are suitable for minors and for obtaining any legally required parental permissions.
Policy Updates
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the Effective Date shown at the top of this page.
Complaints and Contact Requests
If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please contact:
Email: support@dynamotics.com
We aim to respond to privacy-related requests within the timeframes required under applicable data protection laws.
Supervisory Authority Contact
The competent supervisory authority for data protection in Sweden is:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden | Email: imy@imy.se
