hora data processing agreement
Last updated 9 October 2026
1. Parties and scope
This agreement is between the Business (the "controller") and Nima Project Ltd (the "processor"), and applies to personal data the processor handles for the Business through hora. It forms part of the hora terms and meets Article 28 of the GDPR.
2. What is processed
Subject matter and purpose: taking, managing and reminding about bookings and activity enrolments, waitlists, and related messages, for as long as the Business uses hora.
Data subjects: the Business's customers, and participants they book for (who may be children).
Data: names, email addresses, phone numbers, booking details and history, participant names, ages and notes entered by the customer or the Business, and no-show counts.
The Business should not enter special category data (for example health details) unless it has a lawful basis for doing so and has assessed it.
3. Processor obligations
The processor processes the data only on the Business's documented instructions (using hora as designed is such an instruction), ensures everyone with access is bound by confidentiality, and does not use the data for its own purposes.
Security measures include encryption in transit (HTTPS) and at rest for stored credentials, access limited by role and by business, separation of each Business's data, database-level safeguards against double bookings, monitoring, and backups.
4. Helping the Business
hora lets the Business export a customer's data and erase it from the dashboard, to answer access and erasure requests. The processor assists with other requests, with security, with data protection impact assessments and with consultations with authorities, where reasonable.
5. Breaches
The processor informs the Business without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting its data, with the information available to help the Business meet its own obligations.
6. Sub-processors
The Business gives general authorisation for the sub-processors listed below. The processor will give at least 30 days' notice of any addition or replacement, during which the Business may object; it imposes the same data protection obligations on each sub-processor and remains responsible for them. Transfers outside the EU rely on an adequacy decision or the EU Standard Contractual Clauses.
7. Retention, deletion and audits
Abandoned booking attempts, expired holds and old waitlist entries are deleted automatically. When the Business closes its account, all of its data is deleted within 30 days, except where the law requires otherwise; the Business may export its data beforehand.
The processor makes available the information needed to show compliance with this agreement, and allows reasonable audits, with reasonable notice and at the Business's cost.
Sub-processors
| Company | What for | Where |
|---|---|---|
| DigitalOcean, LLC | Hosting, database and file storage | EU (Frankfurt) region |
| ActiveCampaign, LLC (Postmark) | Sending booking emails | United States (Standard Contractual Clauses) |
| SendPulse [legal entity — from their DPA] | Sending text messages, only if SMS is switched on for the business | [Data location and transfer basis — from their DPA] |
| Google LLC | Calendar sync, only if the business connects Google Calendar | United States (EU–US Data Privacy Framework) |
| Functional Software, Inc. (Sentry) | Error monitoring; reports contain no customer personal data | United States (Standard Contractual Clauses) |
How to reach us
Email: [email protected]. A person will answer.
Nima Project Ltd
Company number 13152926, registered in England and Wales
3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom
The hora app is at hora.thenimaproject.com; the product page is at thenimaproject.com/products/hora.