Data Processing Addendum

Last updated: June 2026

This addendum explains how Mawedly processes data on your behalf and each party's obligations.

Parties

You (the user) are the data Controller. Mawedly is the data Processor, processing data on your behalf and per your instructions.

Nature of processing

Mawedly is a technical scheduling tool. You control: what data you enter (your customers' names and appointments), its purpose (scheduling), and who accesses it. We process this data only to provide the scheduling service — nothing more.

Mawedly's obligations

We process data only per your instructions; we do not sell it or use it for advertising; we notify you promptly if we discover a security breach affecting your data; we help you fulfil data-subject rights (access/correction/deletion); and we delete your data within 30 days of account deletion.

Your obligations

You are responsible for the accuracy and lawfulness of the data you enter, obtaining your customers' consent before collecting their data, and complying with data-protection laws in your country (PDPL, GDPR, CCPA, etc.). If your profession requires a license, you are responsible for its validity.

Sub-processors

We use the following sub-processors. We may update the list and will notify you of material changes.

ProcessorPurposeLocation
SupabaseDatabase & storageSupabase Cloud
ResendEmail notificationsUnited States
WhatsApp / MetaWhatsApp notificationsUnited States
Lemon SqueezyPaid plan subscription processingUnited States

Cross-border data transfer

Data is stored on Supabase Cloud servers and may be transferred across borders for operational purposes, with appropriate safeguards (encryption and data-processing agreements).

Security

Encryption in transit (TLS/SSL), tenant isolation via row-level security (RLS), and secure, time-limited file links.

Contact

For data requests or breach reports: hello@mawedly.com.