Skip to content

Data Processing Agreement (DPA)

Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28(3) GDPR between the business using gastronomx (hereinafter “Controller” or “Customer”) and Jonas Reuber, gastronomx, Mozartring 32, 88436 Eberhardzell, Germany (hereinafter “Processor” or “Provider”). This agreement is concluded by accepting the terms and conditions upon registration and forms part of the usage contract.

Last updated: September 2026

Note: The German version of this page is legally binding. This translation is provided for information only.

§ 1 Parties and conclusion

(1) The Controller is the Customer – the business that processes personal data of its guests, employees and contacts via its gastronomx account. The Processor is Jonas Reuber, gastronomx, Mozartring 32, 88436 Eberhardzell, Germany, email: service@agentur-reuber.com. (2) This data processing agreement (DPA) is concluded by accepting the General Terms and Conditions when registering a gastronomx account; the text form requirement is thereby satisfied (Art. 28(9) GDPR). On request, the Provider will make a signed version available to the Customer. (3) In the event of conflicts between this DPA and the GTC, the provisions of this DPA prevail for the processing of personal data on behalf of the Controller.

§ 2 Subject matter and duration

(1) The subject matter of the engagement is the provision of the gastronomx platform (menu, website, reservations, reviews, online ordering and vouchers, newsletter, CRM, loyalty programme, analytics, multi-location management) including hosting, storage, display, transmission and deletion of the personal data arising in the process. (2) The duration corresponds to the term of the usage contract. The DPA ends upon its termination; § 8 (deletion and return) continues to apply.

§ 3 Nature and purpose of processing

Processing comprises the collection, storage, organisation, display, transmission (e.g. confirmation emails to guests), evaluation (e.g. utilisation and review statistics for the Customer) and deletion of personal data. The purpose is exclusively the provision of the functions booked by the Customer: receiving and managing reservations, orders and vouchers, collecting and displaying guest reviews, sending newsletters with double opt-in, managing regular guests and loyalty programmes, and evaluating these processes for the Customer.

§ 4 Categories of data subjects and data

(1) Data subjects: guests and customers of the business (including persons making reservations, ordering, buying vouchers, reviewing, newsletter subscribers, participants in loyalty programmes), employees and other users of the business with access to the dashboard, and contact persons of suppliers or partners insofar as the Customer records them. (2) Categories of data: master data (name, salutation), contact data (email address, phone number, delivery address), reservation data (date, time, number of persons, table, notes, status), order and voucher data (basket, amounts, payment status, pick-up or delivery time; payment data itself is processed exclusively at Stripe), review data (review text, stars, proof of visit, reports), newsletter data (email address, proof of consent with timestamp and IP address, language), CRM and loyalty data (visit frequency, points, segments, notes of the Customer), user data of employees (email address, role, sign-in logs) and technical data (timestamps, IP address, browser identifier). (3) Special categories of personal data (Art. 9 GDPR) are not the subject of the engagement. The Customer may only collect information on allergies or intolerances that guests voluntarily leave in note fields insofar as this is permissible, and must delete it once dealt with.

§ 5 Obligations of the Processor

(1) Processing on instructions: The Provider processes personal data exclusively within the framework of the agreements made and according to the documented instructions of the Customer. The Customer generally issues instructions by configuring and using the platform in the dashboard; further instructions must be issued in text form (email). If the Provider considers an instruction to be unlawful, it will inform the Customer immediately and may suspend execution until confirmation. No processing for the Provider's own purposes takes place. If the Provider is required to process data by Union or Member State law, it will inform the Customer of that legal requirement before processing, unless that law prohibits such information. (2) Confidentiality: The Provider ensures that all persons involved in the processing are bound to confidentiality and process the data only on instruction. (3) Security: The Provider implements the technical and organisational measures described in § 11 pursuant to Art. 32 GDPR and develops them in line with the state of the art without lowering the level of protection. (4) Assistance: The Provider assists the Customer by appropriate means in fulfilling the rights of data subjects (access, rectification, erasure, data portability, etc.), in the security of processing, in notifying personal data breaches, in data protection impact assessments and in consulting the supervisory authority (Art. 28(3)(e) and (f) GDPR). If a data subject contacts the Provider directly, the Provider forwards the request to the Customer without delay. (5) Evidence: The Provider makes available to the Customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for audits in accordance with § 9. (6) The Provider's contact person for data protection: Jonas Reuber, service@agentur-reuber.com.

§ 6 Obligations of the Controller

(1) The Customer is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. In particular, the Customer ensures that legal bases exist for the processing (e.g. contract for reservations and orders, consent for the newsletter) and that the information obligations under Art. 13 and 14 GDPR towards guests are fulfilled; for this purpose the Customer maintains the legal notice and privacy policy of their public pages. (2) The Customer issues instructions and requests to the Provider in text form and designates the persons authorised to issue instructions (usually the account holders with the “Owner” role). (3) The Customer informs the Provider immediately if they detect errors or irregularities in the processing.

§ 7 Sub-processors

(1) The Customer grants the Provider general authorisation to engage the following sub-processors: • Vercel Inc., Covina, California, USA – hosting, content delivery network and server functions; execution of the server functions in Frankfurt am Main; EU standard contractual clauses. • Supabase, Inc., Singapore – database, authentication and file storage; operated in the AWS region eu-central-1 (Frankfurt am Main) at Amazon Web Services EMEA SARL, Luxembourg; EU standard contractual clauses for any support access. • Stripe Payments Europe, Ltd., Dublin, Ireland – payment processing for orders and vouchers (Stripe Connect); for payment processing Stripe is partly an independent controller; the Customer has its own contractual relationship with Stripe via the Connected Account Agreement. • Resend Inc., San Francisco, California, USA – sending of transactional emails (confirmations, double opt-in, notifications); processing in the EU region (Ireland); EU standard contractual clauses. (2) The Provider has concluded contracts with the sub-processors that impose on them essentially the same data protection obligations as this DPA. The Provider remains responsible to the Customer for the fulfilment of the sub-processors' obligations. (3) The Provider informs the Customer of intended changes (addition or replacement of sub-processors) at least four weeks in advance by email. The Customer may object to the change in text form within four weeks of receipt of the notification for an important data protection reason. If no amicable solution is reached, either party may terminate the usage contract extraordinarily with effect from the date the change takes effect. (4) The current list of sub-processors is available at www.gastronomx.com/en/dpa.

§ 8 Deletion and return after the end of the contract

(1) After termination of the usage contract, the Provider will, on request, make an export of the data processed on behalf of the Customer available within 30 days in a common, machine-readable format (e.g. CSV or JSON). (2) 30 days after the end of the contract, the Provider deletes all personal data processed on behalf of the Customer including copies, unless statutory retention obligations prevent this; backups are overwritten in the regular cycle. On request, the Provider confirms the deletion in text form. (3) Data that must be retained for longer due to statutory obligations (e.g. accounting records relating to payments) is blocked for the retention period and deleted thereafter.

§ 9 Audit rights of the Controller

(1) The Customer is entitled to verify compliance with this DPA and the technical and organisational measures. The Provider primarily satisfies audit requests by providing evidence (self-disclosures, description of the measures, and certificates and audit reports of the sub-processors, e.g. SOC 2 or ISO 27001 attestations of Vercel, Supabase/AWS and Stripe). (2) If this evidence is insufficient in an individual case, the Customer may, after giving notice of at least 14 days, carry out an audit during normal business hours or have it carried out by a third party bound to confidentiality – without a specific reason at most once a year. The Provider may demand reasonable remuneration for the effort incurred. (3) The Provider informs the Customer of audit activities and measures of the supervisory authority insofar as they concern the processing on behalf of the Customer.

§ 10 Notification of personal data breaches

(1) The Provider notifies the Customer without undue delay, and at the latest within 48 hours of becoming aware, of any personal data breach affecting data processed on behalf of the Customer. The notification contains, as far as known, the nature and extent of the breach, the categories of data and data subjects concerned, the likely consequences and the measures taken and proposed; information that becomes known later is provided without delay. (2) The Provider assists the Customer in fulfilling their notification and communication obligations under Art. 33 and 34 GDPR and documents personal data breaches including the remedial measures taken.

§ 11 Annex: Technical and organisational measures (Art. 32 GDPR)

1. Physical and system access control: operation exclusively in certified data centres of the sub-processors (AWS Frankfurt am Main, Vercel) with physical access controls; no own server operation. Access to production systems only for named administrators with personal accounts, strong passwords and two-factor authentication (2FA); access to database and hosting consoles is kept to a minimum. 2. Data access control and tenant isolation: role-based authorisation concept in the platform (Owner, Manager, Staff). Strict separation of the data of different businesses at database level through Row Level Security (RLS): every query is bound to the business stored in the signed access token; cross-business access is technically excluded. Privileged server access (service role) is possible exclusively server-side and is logged. 3. Encryption: all connections are encrypted via TLS 1.2 or higher (HTTPS); certificates are managed automatically. Database, backups and file storage are encrypted at rest (AES-256). Passwords are stored exclusively as salted hashes. Payment data is not stored on the Provider's systems (PCI-DSS-compliant processing at Stripe). 4. Input and transfer control: logging of security-relevant events (sign-ins, administrative changes, privileged access) with timestamps; transmission to sub-processors exclusively via encrypted interfaces; signed webhooks (e.g. Stripe) with idempotency checks. 5. Availability and resilience: regular automated database backups with a defined retention period, redundant data centre infrastructure, content delivery network with DDoS protection, system monitoring and defined recovery procedures. 6. Separation and data minimisation: separation of development and production environments; processing only of the data required for the respective function; deletion concept under § 8 and automatic deletion of expired processes (e.g. unsubstantiated review reports). 7. Organisational measures: obligation of all persons involved in the processing to maintain confidentiality; regular review of the measures and of the sub-processors; procedure for reporting security incidents (§ 10); secure software development with automated tests, version control and review of changes before deployment. The measures are continuously adapted to the state of the art; changes may not fall below the level of protection.

§ 12 Liability and final provisions

(1) Art. 82 GDPR applies to the liability of the parties. Internally, each party is liable for damage caused by a breach of this DPA or the GDPR attributable to it; the liability provisions of the GTC (§ 10) apply in addition insofar as they are compatible with Art. 82 GDPR. (2) German law applies; the place of jurisdiction is, where permissible, the Provider's registered seat. (3) Amendments to this DPA must be made in text form. The Provider may adapt this DPA if this becomes necessary due to changes in the legal situation, case law or the sub-processors used; § 12 of the GTC applies accordingly. (4) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected. The German version is legally binding. Last updated: September 2026