Sub-processor List
Effective date: 5 July 2026 · Last updated: 13 August 2026
This page lists the sub-processors that Xaiotech Pty Ltd ABN 63 821 547 002 trading as Bookaiq (“Bookaiq”) engages to process personal data on behalf of Workspace Owners. This list is maintained in accordance with the Data Processing Addendum, Section 6.
Workspace Owners are notified of changes to this list at least 14 days in advance, per the DPA.
Infrastructure Sub-processors (by category)
As a security measure, Bookaiq does not publicly name its underlying infrastructure providers — publishing the exact vendor list aids supply-chain reconnaissance against the platform. Infrastructure sub-processors are therefore listed here by category, with the data processed and hosting region for each. The current named list — legal entities and provider privacy policies included — is available to any Workspace Owner or prospective customer on written request (see Requesting the named list below), and named-list recipients receive the same 14-day change notice.
| Sub-processor | Legal entity | Purpose | Personal data processed | Primary hosting region | Provider privacy policy |
|---|---|---|---|---|---|
| Database & authentication infrastructure | Named on written request | Managed database hosting, authentication, and row-level access control | All Service data: account records, booking records, customer data, staff data, intake-form responses, organisation settings | Sydney, Australia | Provided with the named list |
| Application hosting & content delivery | Named on written request | Application hosting, serverless compute, content delivery network (CDN) | HTTP request data (IP, headers, path), server-rendered page content, static assets | Sydney, Australia (compute); global (CDN edge) | Provided with the named list |
| SMS & messaging delivery | Named on written request | SMS delivery (booking reminders and confirmations); WhatsApp message delivery where enabled. A primary provider plus a contingency fallback route. | Recipient phone numbers, message content, delivery metadata | EU / global carrier network | Provided with the named list |
| Transactional email delivery | Named on written request | Email delivery (booking confirmations, reminders, system notifications). A primary provider plus a fallback route. | Recipient email addresses, email subject and body content, sender display names | EU / United States | Provided with the named list |
Customer-visible Service Providers
These providers are visible in the product itself — you (or your clients) interact with them directly at checkout, sign-in, or through an integration the Workspace Owner connects — so they are named here.
| Sub-processor | Legal entity | Purpose | Personal data processed | Primary hosting region | Provider privacy policy |
|---|---|---|---|---|---|
| Stripe | Stripe, Inc. | Subscription billing for Australian customers; Stripe payments for client payment collection (deposits, upfront payment, payment links, refunds, receipts) | Payment card details (tokenised), billing name and address, transaction amounts, subscription status, connected-account data | United States / global | stripe.com/privacy |
| Lemon Squeezy | Lemon Squeezy, LLC | Merchant-of-record subscription billing for non-Australian customers (calculates and remits local taxes, issues tax invoices) | Payment card details, billing name and address, email, tax jurisdiction, transaction amounts, subscription status | United States | lemonsqueezy.com/privacy |
| Google LLC | Google sign-in (OAuth 2.0 / OIDC); Google Calendar two-way sync; Google Meet links for online-video bookings; Google Places API and static maps (business address search and display); push notifications to the Bookaiq Android app | Calendar event data (titles, times, free/busy status); authentication tokens and profile info (name, email, photo); meeting join links; location search queries and place details; device push tokens and notification content | United States / global | policies.google.com/privacy | |
| Microsoft | Microsoft Corporation | Microsoft sign-in (OAuth 2.0 / OIDC); Outlook/Microsoft 365 calendar two-way sync; Microsoft Teams meeting links for online-video bookings | Calendar event data (titles, times, free/busy status); authentication tokens and profile info (name, email, photo); meeting join links | United States / global | privacy.microsoft.com |
| Zoom | Zoom Communications, Inc. | Zoom meeting creation for online-video bookings — engaged only when a Workspace Owner connects their Zoom account | Meeting topic and times (may include the service name and Booking Client name), join links, staff OAuth tokens | United States / global | zoom.us/privacy |
| Xero | Xero Limited | Invoice creation in the Workspace Owner's own Xero organisation — engaged only when a Workspace Owner connects Xero | Booking Client name and email, invoice line items and amounts, staff OAuth tokens | United States / global | xero.com/legal/privacy |
| Meta | Meta Platforms, Inc. | Facebook / Instagram Page connection (where available) — engaged only when a Workspace Owner connects their Meta account | Workspace Owner's Page identifiers and access tokens, Page metadata | United States / global | facebook.com/privacy/policy |
Requesting the Named List
Workspace Owners and prospective customers with a diligence or compliance need can request the current named infrastructure sub-processor list by emailing support@bookaiq.com with the subject line “Named sub-processor list.” Requests are answered within 5 business days. The named list carries the same information as this page — legal entity, purpose, data processed, region, and provider privacy policy — for each category above.
Notes
- Stripe client payments: when a Workspace Owner enables Stripe to collect payments from Booking Clients, the payment data flows directly between the Booking Client and Stripe. Bookaiq receives only transaction status and a tokenised reference. Bookaiq does not hold, escrow, or intermediate client funds.
- Lemon Squeezy (merchant of record): for customers outside Australia, Lemon Squeezy acts as the merchant of record — it is the seller of record, collects payment, calculates local taxes, and issues the invoice. Bookaiq receives subscription status but not full payment details for these transactions.
- Google Places API: when a Workspace Owner searches for a business address in the location editor, the query is sent to Google’s Places API. The query may contain the business name or partial address but generally does not contain personal data of Booking Clients.
- Calendar sync data: calendar event data accessed through Google Calendar or Microsoft Outlook integrations is used solely to check availability (free/busy status) and prevent double-bookings. Bookaiq does not store the full content of external calendar events beyond what is necessary for the sync.
- Workspace-Owner-connected integrations: Google Calendar, Microsoft 365, Zoom, Xero, and Meta are engaged for a workspace only when the Workspace Owner (or an individual staff member) connects their own account with that provider. Data then flows to the Workspace Owner’s own account with the provider, under the provider’s own terms and privacy policy. Disconnecting the integration in Settings stops future data flows.
- Bring-your-own messaging accounts: a Workspace Owner may connect their own SMS provider account (e.g. Twilio or Bird) or their own email sending domain. Messages then go through the Workspace Owner’s own provider account under that provider’s terms — in that configuration the provider acts for the Workspace Owner directly, not as a Bookaiq sub-processor.
- Apple Calendar subscriptions: Bookaiq can publish a read-only iCal feed of a workspace’s bookings at a private URL, which the Workspace Owner can subscribe to from Apple Calendar (or any iCal-compatible calendar app). The feed is served by Bookaiq; Apple is not engaged as a sub-processor, and data reaches Apple only within the Workspace Owner’s own calendar app or iCloud account.
- Workspace analytics tags: a Workspace Owner may add their own Google Analytics 4 measurement ID and/or Meta Pixel ID to their public booking page. Those tags send page-visit and booking-funnel events directly from the visitor’s browser to Google or Meta under the Workspace Owner’s own account and terms. Bookaiq itself does not use any third-party analytics service on the application.
- Push notifications: push notifications to the Bookaiq Android app are delivered via the platform push service operated by Google (see the Google entry above). Browser (web push) notifications are delivered through the push service operated by the user’s own browser vendor. iOS native push is not currently enabled.
- No error-monitoring or support-desk sub-processors are currently engaged. If Bookaiq adds such services, they will be added here with 14 days’ notice.
Changes
| Date | Change | Notice given |
|---|---|---|
| 11 June 2026 | Initial list published | N/A (initial publication) |
| 5 July 2026 | Expanded the list: added messaging/email delivery providers, Zoom, Xero, Meta, and Android push delivery; expanded Google and Microsoft entries (Meet / Teams meeting links, static maps); added provider privacy-policy links; added notes on Workspace-Owner-connected integrations, Apple calendar feeds, analytics tags, and push notifications | None — list corrected to reflect providers already in service |
| 13 August 2026 | Infrastructure sub-processors are now published by category, with the named list available on written request. No providers were added or removed — this is a presentation change only; the engaged sub-processors are unchanged. | None — no change to the engaged sub-processors |
Subscribe to Updates
To receive email notifications when this list changes, contact support@bookaiq.com with the subject line “Sub-processor updates.”