Data Processing Addendum
Last updated: June 2026
This addendum explains how Mawedly processes data on your behalf and each party's obligations.
Parties
You (the user) are the data Controller. Mawedly is the data Processor, processing data on your behalf and per your instructions.
Nature of processing
Mawedly is a technical scheduling tool. You control: what data you enter (your customers' names and appointments), its purpose (scheduling), and who accesses it. We process this data only to provide the scheduling service — nothing more.
Mawedly's obligations
We process data only per your instructions; we do not sell it or use it for advertising; we notify you promptly if we discover a security breach affecting your data; we help you fulfil data-subject rights (access/correction/deletion); and we delete your data within 30 days of account deletion.
Your obligations
You are responsible for the accuracy and lawfulness of the data you enter, obtaining your customers' consent before collecting their data, and complying with data-protection laws in your country (PDPL, GDPR, CCPA, etc.). If your profession requires a license, you are responsible for its validity.
Sub-processors
We use the following sub-processors. We may update the list and will notify you of material changes.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database & storage | Supabase Cloud |
| Resend | Email notifications | United States |
| WhatsApp / Meta | WhatsApp notifications | United States |
| Lemon Squeezy | Paid plan subscription processing | United States |
Cross-border data transfer
Data is stored on Supabase Cloud servers and may be transferred across borders for operational purposes, with appropriate safeguards (encryption and data-processing agreements).
Security
Encryption in transit (TLS/SSL), tenant isolation via row-level security (RLS), and secure, time-limited file links.
Contact
For data requests or breach reports: hello@mawedly.com.