Skip to content
Servire: The POS system for your hospitality business
Get started

Data Processing Agreement

Version 1.3 · Annex 3 in version 1.2 · As of 10 October 2026

This agreement specifies the obligations under Article 28 GDPR for the services Servire GmbH, Spielwang 20, 83377 Vachendorf, Germany (the "processor") provides to the customer (the "controller"). It supplements the general terms and conditions and applies to the location for which it was accepted.

The controller determines the purposes and means of processing the data of its guests and staff. The processor processes this data exclusively on its behalf and on its instructions.

The agreement is concluded electronically, which Article 28(9) GDPR permits. The processor documents the version, the time and the accepting person and provides the controller with the full text as a PDF.

Section 1 — Subject matter, duration and termination

The subject matter is the processing of personal data arising from the use of the Servire point-of-sale system and its modules. The nature, scope and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1.

The agreement begins upon acceptance and continues for as long as the processor processes personal data on behalf of the controller. It ends with the underlying main contract, but not before the return or deletion under Section 9 has been completed.

Either party may terminate this agreement for good cause, in particular if the other party seriously breaches data protection law or material obligations under this agreement and fails to remedy the breach within a reasonable period despite being requested to do so. This agreement cannot be terminated without also terminating the main contract, because the services cannot be provided without processing on behalf of the controller.

Section 2 — Nature and purpose of processing, data and data subjects

The processor processes the data solely in order to provide the contractually agreed services. Processing for its own purposes does not take place under this agreement.

Where the processor processes data for its own purposes, for example to perform the contract with the controller, for billing or for a cross-location guest account, it acts as a controller in its own right. Such processing is not covered by this agreement and is identified separately in Annex 3.

Processing takes place in member states of the European Union or the European Economic Area. Processing in a third country only takes place where the requirements of Chapter V GDPR are met; Annex 3 identifies such cases together with their legal basis.

Section 3 — Instructions of the controller

The processor processes the data only on documented instructions from the controller. This agreement including its annexes, together with the settings the controller configures in the software, constitute its initial instructions.

Further instructions are issued by the controller in text form to datenschutz@servire.de. Instructions given orally are confirmed in text form without undue delay. The processor documents all instructions.

Where the processor is of the opinion that an instruction infringes data protection law, it informs the controller without undue delay and suspends execution. It does not carry out an instruction whose execution would infringe data protection law, even after the controller confirms it.

Where the processor is required by Union or member state law to carry out processing that goes beyond the instructions, it informs the controller before processing, unless that law prohibits such information on important grounds of public interest.

Section 4 — Confidentiality

The processor engages only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after their engagement ends.

The processor familiarises the persons engaged with the applicable data protection provisions and with the obligation to follow instructions. They are granted access only to the extent their task requires.

Section 5 — Security of processing

The processor implements the technical and organisational measures required under Article 32 GDPR. They are described in Annex 2 and are binding for the term of this agreement.

The processor may develop the measures further as long as the level of protection is not reduced. It documents material changes and makes them available to the controller on request.

Section 6 — Sub-processors

The controller grants general authorisation under Article 28(2) GDPR for the engagement of sub-processors. The undertakings engaged at the time this agreement is concluded are listed in Annex 3 with their legal entity, service, types of data and place of processing.

Where the processor intends to add or replace a sub-processor, it informs the controller in text form, sent to the billing address on file, before the intended engagement. The information identifies the undertaking, its service, the types of data concerned and the place of processing.

The controller may object to the engagement on data protection grounds in text form within 30 days of receiving the information. The engagement starts at the earliest after that period has expired; until then the undertaking named does not process any of the controller's data. If it objects in time, the processor offers an alternative, continues to provide the service without the sub-processor concerned, or discontinues the affected part of the service, and the undertaking is not engaged for that location. If none of these options is reasonable, either party may terminate the agreement in respect of the affected service upon reasonable notice. If the controller does not object within the period, the engagement is deemed authorised.

The processor contractually imposes on every sub-processor the same obligations that apply to it under this agreement. It remains liable to the controller for the performance of those obligations.

Ancillary services that do not involve processing of the controller's personal data, such as pure telecommunications services or cleaning, do not constitute sub-processing. Where an ancillary service involves access to such data, in particular the destruction of data carriers, it constitutes sub-processing under this section. Otherwise the processor takes appropriate precautions to protect the data.

Section 7 — Rights of data subjects

If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not respond itself.

The processor assists the controller by appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction of processing, data portability and objection. The software provides export and deletion functions for this purpose; Annex 1 identifies them per module.

These functions remain available to the controller irrespective of whether this agreement is in force. A dispute about the agreement must not prevent the controller from fulfilling data subject rights.

Section 8 — Assistance and notification of breaches

The processor assists the controller in complying with the obligations under Articles 32 to 36 GDPR, in particular regarding security of processing, data protection impact assessments and prior consultation of the supervisory authority, taking into account the information available to it.

Where the processor becomes aware of a personal data breach, it notifies the controller without undue delay, as a rule within 24 hours of becoming aware. The 72-hour period applying to the controller under Article 33 GDPR is not a waiting period for the processor.

The initial notification describes the nature of the breach, where possible the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The processor provides missing information without undue delay as soon as it becomes available.

The security contact of the processor is datenschutz@servire.de. The controller keeps a contact address for such notifications up to date; absent a separate designation, the billing address on file applies.

Section 9 — Return and deletion

After the end of the processing, the processor deletes the personal data or returns it, at the choice of the controller. If the controller does not make a choice, the processor first makes the data available for retrieval and then deletes it in accordance with the periods set out in the general terms and conditions.

The processor provides a data export in a common machine-readable format, in particular in accordance with DSFinV-K for fiscally relevant data.

Data subject to a statutory retention obligation is exempt from deletion. This applies in particular to fiscal cash register records, which must be retained for ten years under Sections 147 and 146a of the German Fiscal Code, and to working time records. Such data is blocked for the duration of the retention obligation and processed solely for that purpose.

Backup copies are overwritten in the course of the usual retention cycles. Until then they remain protected against further processing. Both parties receive this agreement as a PDF upon conclusion; the controller can download it again at any time in the web desk. The processor keeps the record of acceptance for as long as the location exists and makes it available to the controller on request before deletion.

Section 10 — Evidence and audits

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR.

The controller may carry out audits, including inspections, or have them carried out by an auditor it mandates. The processor contributes to such audits. Audits generally take place upon reasonable notice during normal business hours; in the event of a personal data breach or a specific suspicion of a serious infringement, they may also take place at short notice. The auditor is bound to confidentiality; where the auditor is a direct competitor, the processor may object on objective grounds and request a different auditor.

The processor may also provide evidence by means of current attestations, certificates or audit reports issued by independent bodies. Where this is not sufficient for the controller in an individual case, its right to carry out its own audit remains unaffected.

Section 11 — Obligations of the controller

The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It informs its guests and staff about the processing and obtains any necessary consent itself, in particular for email marketing.

The controller collects only data it needs for its purposes and configures the software accordingly. It manages the accounts of its staff and revokes them without undue delay when they are no longer required.

The controller informs the processor without undue delay if, when reviewing the results, it identifies errors or irregularities regarding data protection provisions.

Section 12 — Liability and final provisions

Liability is governed by Article 82 GDPR and by the liability provisions of the general terms and conditions. Liability towards data subjects under Article 82 GDPR remains unaffected.

Amendments to this agreement require text form. In the event of contradictions between this agreement and the general terms and conditions, this agreement prevails in matters of data protection.

Should any provision be invalid, the remainder of the agreement remains effective. The invalid provision is replaced by the applicable statutory provisions.

Annex 1 — Subject matter of processing, types of data and data subjects

Which data arises depends on the modules the controller uses. The following overview describes the maximum scope per module.

Module / processingData subjectsTypes of dataRetention
Point-of-sale operation (core function)Staff of the controllerName of the operating person on receipts and in reports, user account, permissions, timestamps of transactions. For an invoice additionally the name and address of the recipient; technical data to protect the public entry points against abuseFiscal records for ten years under Section 147 of the German Fiscal Code
Guest management (CRM)Guests of the controllerSalutation, first and last name, email, telephone, address, date of birth, language, company and VAT ID, invoice address, staff notes, customer number, card code, membership of guest groups and attributes such as regular-guest status or a block on online reservations, visit and revenue metrics. Information on allergies and intolerances constitutes health data within the meaning of Article 9 GDPR. Where newsletter consent is given, and when joining through the guest account, additionally the time, IP address and browser identifier as evidence, along with the link to the cross-location guest accountUntil deleted by the controller; anonymisation replaces deletion where tax retention obligations prevent it
Reservations and waiting listGuests of the controllerFirst and last name, email, telephone, party size, time, table, guest remarks, internal notes, information on allergiesUntil deleted by the controller
Guest ordering, self-order terminal and order at the tableGuests of the controllerName, email, telephone, order contents, pickup or delivery time, delivery address where applicable, payment reference, tipThe order itself is kept for a further 30 days after completion and then deleted automatically. The guest details are transferred into the business's order history and remain there until the controller has them deleted. The receipt is subject to fiscal retention
Voucher salesPurchasers and recipientsName and email of the purchaser, name of the recipient, any differing invoice details, voucher code and balanceUntil the voucher expires plus retention periods
Loyalty card and guest accountGuests of the controllerLink to the guest profile, points and stamp balance, transaction history, card number for the wallet passUntil the guest profile is deleted
Receipt delivery and receipt claimGuests of the controllerEmail address, name where applicable, link to the receiptAccess tokens expire automatically, as a rule after seven to thirty days
Working time recordingStaff of the controllerName, personnel number, clock-in and clock-out times and breaks, hourly rate and wage amounts, surcharges, indications of breaches of the German Working Hours Act, IP address and device identifier when clocking, corrections with justification; approved leave and sickness days from shift planning as hours in the working time account, timesheet and payroll exportDeletion after the end of the sixth calendar year following the record
Shift planning: planning and announcing shifts, managing absences and leave, notifying staffStaff of the controllerShifts with date, start, end, break, position and note; positions, shift templates and daily notes; availability stated by the employee (times they cannot work and preferred days off) and fixed days off; requests to swap, hand over or take over shifts with message and decision; absences with type, period, half days, note and decision. For sickness only the fact of incapacity for work and its period are processed, no diagnosis; this is health data within the meaning of Article 9 GDPR. The type of an absence is visible only to the employee concerned, to persons with the right to manage the roster and, in the payroll export, to persons with the right to manage time recording; other staff only see that someone is absent. Annual leave entitlement and carry-over per calendar year; date of birth to check youth employment protection; indicators for marginal employment and on-call work; labour costs and planned-versus-actual comparisons derived from hourly rate and working time records. For notifications email address, delivery status and time of reminders sent, endpoint and keys of the push subscription with browser identifier; for the calendar subscription only a hash of the access token with the time of the last retrieval. Log of every publication with the full content of the published shifts, time and acting personAbsences: deletion after the end of the sixth calendar year following the end of the absence. Shifts, weekly rosters with daily notes, publication logs and requests: deletion two years after the date of the shift. Availability, push subscriptions and calendar subscription: until changed by the employee or until their account is deleted; subscriptions reported as invalid by the push service are deleted immediately. Other personal details: until deleted by the controller
Support chat and helpStaff of the controllerContent of enquiries, which may contain personal data, user accountUntil the location is deleted

Functions supporting data subject rights: guest management provides a complete data export and an anonymisation for every guest profile, covering linked reservations, orders and waiting list entries. Staff obtain access to their working time data through the time recording module and, where the controller enables the team area for them, to their shifts, requests, absences and leave account through the team area of the roster. The controller may also request a complete data export of the location at any time.

Annex 2 — Technical and organisational measures

The measures under Article 32 GDPR take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risk to data subjects.

AreaMeasures
EncryptionTransmission exclusively over TLS. Data at rest is encrypted at storage level using AES-256. Credentials are stored only as hashes, access tokens exclusively as hashes that either expire automatically or, like the link of a calendar subscription, can be revoked at any time.
Physical access controlProcessing takes place in the data centres of the providers engaged, subject to their physical access concepts including separation, video surveillance and logging. The processor does not operate its own server rooms for customer data.
System access controlAuthentication exclusively through a central identity system. Administrative access is limited to a named group of persons and additionally secured. Point-of-sale devices additionally identify themselves through a device attestation.
Data access controlAccess to data is verified server-side for every individual query. The default is denial; access must be explicitly permitted. Within a business, the controller manages the permissions of its staff per function. Particularly sensitive areas such as payroll, working time, roster and absence data are further restricted and accessible only through verified server interfaces. The type of an absence is shown only to the employee concerned and to authorised persons; other staff only see that someone is absent.
Separation controlThe data of each business resides in its own data container. The access check binds every query to membership of that specific business. Production and test operations run in separate projects with separate access and separate data.
Transfer controlTransfers to sub-processors take place exclusively in encrypted form and on the basis of the agreements under Section 6. Exports for the controller are provided through time-limited links that cannot be guessed. Push notifications to devices on which staff have enabled them themselves are delivered by the push service of the respective browser vendor. Their content is end-to-end encrypted beforehand in accordance with RFC 8291; the push service only receives a random subscription identifier and the encrypted content. Notifications are sent exclusively to the push services of Apple, Google, Microsoft and Mozilla.
Input controlFiscally relevant transactions are logged immutably and signed by a technical security device. Changes to master data and to working time records are recorded with time, acting person and previous state. Every publication of a roster is logged immutably with its full content, time and acting person.
Availability and resilienceThe data resides in a managed database service with automatic backup and point-in-time recovery within the window provided by the vendor. The point-of-sale system continues to operate offline during network outages and synchronises afterwards. Systems are monitored.
RecoverabilityDefined procedures with named responsibilities exist for incidents and security events. Restorations are tested as the occasion requires.
Procedures for review and evaluationChanges to security-relevant code are reviewed before adoption. Access rules are covered by automated tests. Errors and anomalies in operation are recorded and evaluated centrally, without transmitting personal content.
Data protection by designData required only temporarily is stored with automatic expiry and deleted without intervention. Transaction data is stripped of personal details after completion. Default settings are chosen to minimise data. Notifications state the type of an absence only to the employee concerned and to the roster managers, sickness entries trigger no notification, and the roster shows a date of birth only for minors.
Sub-processor controlSub-processors are assessed for suitability before engagement and contractually bound to the same obligations. Their performance is monitored on an ongoing basis.

Annex 3 — Sub-processors

The following undertakings process personal data on behalf of the controller, through the processor. Changes are governed by the procedure under Section 6.

UndertakingServiceTypes of dataPlace of processing
Google Cloud EMEA Limited, Ireland (Google Cloud and Firebase)Operation of the database, file storage and server-side processingAll data listed in Annex 1European Union
Google Cloud EMEA Limited, Ireland (Firebase Authentication)User management: sign-in of owners and employees to the Servire applicationsUser account: name, email address, password stored only as a hash; when signing in, technical data such as the IP addressUnited States; transfer on the basis of the EU-U.S. Data Privacy Framework, under which Google LLC is certified, or alternatively the EU standard contractual clauses
Hetzner Online GmbH, GermanyOperation of the servers for the API (backend), the Web desk, the Servire Hub and the guest appAll data listed in Annex 1 to the extent it is processed via the API; when the interfaces are accessed, technical connection data such as the IP addressGermany, Nuremberg data centre
Sendinblue GmbH (Brevo), GermanySending of emails: receipts, reservation and order confirmations, messages to staff, newsletters of the controllerName, email address, content of the respective message including receipt or reservation dataEuropean Union
fiskaly GmbH, AustriaTechnical security device under Section 146a of the German Fiscal Code and creation of fiscal export filesName of the operating person, transaction data, and for invoices the invoice address of the guestEuropean Union
Functional Software, Inc. (Sentry), United States, with processing via Sentry GmbH, GermanyCollection of technical error reports for fault resolutionTechnical information about the error and the user account; personal content is not transmittedEuropean Union, Frankfurt am Main data centre
Google Cloud EMEA Limited, Ireland (Vertex AI)Assistance with importing menus, with the help chat and in the statistics (statistics assistant, overview summary)Content of submitted documents and enquiries, to the extent the controller transmits it; in the statistics, aggregated figures of the business, for analyses by staff including the names of employeesEuropean Union
Google Cloud EMEA Limited, Ireland (Google Cloud Translation)Machine translation of the texts of the controller's website into EnglishEditorial texts of the website; personal data only to the extent the controller includes it in these textsUnited States; transfer on the basis of the EU-U.S. Data Privacy Framework, under which Google LLC is certified, or alternatively the EU standard contractual clauses

The following recipients are not processors but controllers in their own right. The controller decides whether to use them and concludes the necessary agreements directly with them: payment service providers (Stripe, SumUp, Zettle, PayPal, Payone), delivery platforms (Wolt, Uber Eats and platforms connected through the intermediary Flyt), reservation referral through Google, accounting and tax services (DATEV, sevDesk) and the tax adviser designated by the controller.

Own processing by the processor: Servire GmbH acts as a controller in its own right for the performance of the contractual relationship with the controller and for a cross-location guest account that guests create themselves. This processing is not covered by this agreement; the privacy policy at servire.de provides information about it.

The German version of this agreement prevails. This English translation is provided for readability only.