Data Processing Agreement

Last updated: May 2026

Parties

This Data Processing Agreement ("DPA") is entered into between:

  • [Platform Operator Name]("Processor") — the company that operates this booking platform.
  • The restaurant, salon, or other business that has subscribed to the platform ("Controller") — the entity that determines the purposes and means of processing guest booking data.

This DPA is incorporated into the Terms of Service between the Processor and each Controller and applies to all personal data processed by the Processor on behalf of the Controller.

Subject matter

The Processor provides a SaaS booking platform that allows the Controller to accept and manage guest reservations. In doing so, the Processor processes personal data on behalf of the Controller.

Categories of data processed

The following categories of personal data are processed under this DPA:

  • Guest name
  • Guest email address
  • Guest phone number
  • Special requests (e.g. dietary needs, accessibility)
  • Preference notes recorded by venue staff about a guest

The data subjects are the guests who make bookings with the Controller's venues.

Purpose of processing

The Processor processes guest data solely to provide the booking platform service to the Controller, including accepting reservations, sending confirmation messages, and enabling the Controller to manage its bookings. The Processor will not process personal data for any other purpose without the Controller's written instruction.

Sub-processors

The Controller authorises the Processor to engage the following sub-processors. The Processor will inform the Controller of any intended changes and give the Controller the opportunity to object.

  • Supabase, Inc.— managed database and authentication infrastructure. Guest booking data is stored in Supabase's Postgres database hosted in the EU region.
  • Stripe, Inc. — payment processing. Card data is processed by Stripe and is not stored by the Processor.

Each sub-processor is bound by data processing terms at least as protective as this DPA.

Retention and deletion at contract end

Upon termination or expiry of the Controller's subscription, the Processor will, within 30 days, delete or anonymise all personal data associated with the Controller's account, unless applicable law requires longer retention.

During the term, personal data is retained in accordance with the platform's standard retention schedule (see the Privacy Policy). The Controller may request early deletion at any time by contacting [Platform Operator contact].

Self-service erasure assistance

The platform provides guests with a self-service data erasure feature accessible from their booking confirmation page. When a guest requests erasure, the Processor will immediately anonymise the guest's personal details on that booking and delete any associated preference notes. Booking records are retained in anonymised form.

If the Controller receives a data subject erasure request outside the self-service flow, the Processor will assist the Controller in fulfilling it within the timeframes required by GDPR.

Security measures

The Processor implements appropriate technical and organisational measures to protect personal data, including:

  • Row-level security (RLS) enforcing tenant isolation at the database layer
  • Encryption in transit (TLS) and at rest
  • Access controls limiting staff access to their own organisation's data
  • Regular automated retention enforcement to delete or anonymise stale data

Breach notification

In the event of a personal data breach affecting the Controller's guest data, the Processor will notify the Controller without undue delay and, where feasible, within 36 hours of becoming aware of the breach. The notification will include all information reasonably available to assist the Controller in meeting its own 72-hour notification obligation to the supervisory authority under GDPR Article 33.

Governing law

This DPA is governed by the laws of Sweden. Disputes shall be resolved in the courts of Sweden. Nothing in this clause limits either party's rights under GDPR.