Skip to main content

List of Matrix Booking system's sub-processors

These are the sub-processors for the Matrix Booking system (the application or product):

Name

Location

Activity

Data processed

Details

How long is the data kept for?

Amazon Web Services

EU

Hosting of Matrix Booking system.

Core service including database and application servers. Data includes:

  • full name

  • email address

  • telephone number (if provided)

  • resources booked (including the date, time, attendees and title of the booking)

  • IP address

https://aws.amazon.com/compliance/gdpr-center/

Data is kept for the duration of the customers contract. Data can be anonymised after X period, which is controlled by the customer administrators themselves.

Mailchimp

USA

Back up email service and for customers set up prior to 2023 that have not requested an EU mail delivery provider.

User booking notifications. Data includes:

  • full name

  • email address

  • resources booked (including the date, time, attendees and title of the booking)

https://mailchimp.com/legal/data-processing-addendum/

Data is held with the mail provider for a 30-day period to allow any diagnosis of recent email issues.

Sendgrid

USA

Operational email delivery (back up service).

User booking notifications. Data includes:

  • full name

  • email address

  • resources booked (including the date, time, attendees and title of the booking)

https://www.twilio.com/gdpr

https://www.twilio.com/legal/data-protection-addendum

Data is held with the mail provider for a 37-day period to allow any diagnosis of recent email issues. After this period, it is pseudonymised.

Mailgun

EU

Default operational email delivery.

User booking notifications. Data includes:

  • full name

  • email address

  • resources booked (including the date, time, attendees and title of the booking)

https://www.mailgun.com/gdpr/

Data is held with the mail provider for a 30-day period to allow any diagnosis of recent email issues.

Atlassian

EU

Hosting of web service desk for support activities.

Data includes:

  • inbound issues logged by customer administrators. Data includes:

  • username

  • email address

  • organisation name

  • ticket details

https://www.atlassian.com/trust/privacy/gdpr

 

Only customers that are set up to use the Matrix Booking support portal can raise support issues will have a log in to this application. For example, your organisation has 10,000 staff using Matrix Booking, but you may have only three that have access to the support portal. The data is maintained for the lifespan of the contract.

Datadog

EU

System log files used for support and maintenance.

Line entries made when an activity is performed, such as an availability search or a booking made. Data recorded is:

  • email address

  • resources booked (including the date, time, attendees and title of the booking, browser type and version)

https://www.datadoghq.com/legal/privacy/

Datadog stores data for a period of one month. After this period, they are stored in an Amazon AWS repository for one year.

Sentry

EU

Mobile application system crash log on errors to aid troubleshooting. 

When a non functional error occurs in the mobile app Sentry captures:

  • User id

  • email address

  • organisation name

As standard, Sentry also captures application, OS and device model information, and an IP address (per ISP).

https://sentry.io/security/#data-security-and-privacy

Data is retained for 90 days and then deleted.

Zoho

EU

Used for tracking the progress of customers as they progress through the purchase process and with generating the data needed for invoicing.

Prospect and customer sales, which includes:

  • names

  • addresses

  • email addresses

  • phone numbers

  • sales and contact notes

https://www.zoho.com/gdpr.html

 

The invoice data is kept in Zoho for the lifespan of the customer contract. After the contract expired, they are retained for a seven-year period for accounting records and audit history.

Quickbooks (Intuit Ltd.)

USA

Used for generating billing and invoices.

Data of named finance contacts includes:

  • name

  • email address

http://quickbooks.co.uk

The invoice data is kept in Quickbooks for the lifespan of the customer contract. After the contract expired, they are retained for a seven-year period for accounting records and audit history.

http://Fixed.net

EU

Marketing website form for contact us / book a demo / free trial

Basic information captured for prospects (not customers) to allow us to respond to sales enquiries:

  • name

  • email

  • company name

https://fixed.net/knowledge-base/article/privacy-policy

We hold this data for no longer than 30 days.

Chargebee Inc.

EU and USA

Provision of billing services

Chargebee Inc. will process the details of subscription and number of resources used. In terms of personal or personal-orientated data, Chargebee Inc. will process:

  • Email address provided for billing

  • Company name

  • Company address

https://www.chargebee.com/privacy/dpa/

 

The invoice data kept in Quickbooks for the lifespan of the customer contract. After the contract has expired, they are retained for a 7-year period for accounting records and audit history.

Salesloft

EU and USA

Not used for existing customers. Only used to record and track prospective sales. Once a prospect becomes a client, the data is deleted from this system.

Basic information are stored along with related correspondence (email) regarding potential interest in our products:

  • prospect name

  • email address

  • postal address

  • telephone number

https://www.salesloft.com/security-compliance

 

If the prospect becomes a customer, the data is deleted at this point. Otherwise the data is stored for up to five years.

Matomo

EU

Used to improve customer experience by monitoring key journeys and feature usage

Basic anonymised information is stored to understand how people use our applications and which features and functions are more popular and therefore how we can make those journeys more efficient. No individual information or organisation information is stored.

https://matomo.org/privacy/

As the data is fully anonymised, we keep the journey data for 5 years, or until the journey is no longer live and the related activity data is no longer required.

Changes in this version:

  • Confirmation that all data transfers are bound by the EU-US Data Privacy Framework (DPF) / Data Bridge and the UK Extension to the EU-US Data Privacy Framework” (UK Extension) under Article 45 of the UK General Data Protection Regulation (GDPR).

  • Addition of Matomo as a tool to analyse usage of our websites and applications

  • Addition of Sentry to provide application crash reporting

  • Removal of Logentries as no longer used

As the page is updated, previous versions can be made available for reference. If you have provided us with contact information for your DPO, they will notified of any significant changes to this page. If you haven’t provided us with this information, these changes will be provided to your administrators using the normal operational / service email distribution process.

Updated: 12/02/2025

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.