Skip to content
Servire: The POS system for your hospitality business
Get started

Data Processing Agreement

Version 1.0 · Annex 3 in version 1.0 · As of 20 September 2026

This agreement specifies the obligations under Article 28 GDPR for the services Servire GmbH, Spielwang 20, 83377 Vachendorf, Germany (the "processor") provides to the customer (the "controller"). It supplements the general terms and conditions and applies to the location for which it was accepted.

The controller determines the purposes and means of processing the data of its guests and staff. The processor processes this data exclusively on its behalf and on its instructions.

The agreement is concluded electronically, which Article 28(9) GDPR permits. The processor documents the version, the time and the accepting person and provides the controller with the full text as a PDF.

Section 1 — Subject matter, duration and termination

The subject matter is the processing of personal data arising from the use of the Servire point-of-sale system and its modules. The nature, scope and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1.

The agreement begins upon acceptance and continues for as long as the processor processes personal data on behalf of the controller. It ends with the underlying main contract, but not before the return or deletion under Section 9 has been completed.

Either party may terminate this agreement for good cause, in particular if the other party seriously breaches data protection law or material obligations under this agreement and fails to remedy the breach within a reasonable period despite being requested to do so. This agreement cannot be terminated without also terminating the main contract, because the services cannot be provided without processing on behalf of the controller.

Section 2 — Nature and purpose of processing, data and data subjects

The processor processes the data solely in order to provide the contractually agreed services. Processing for its own purposes does not take place under this agreement.

Where the processor processes data for its own purposes, for example to perform the contract with the controller, for billing or for a cross-location guest account, it acts as a controller in its own right. Such processing is not covered by this agreement and is identified separately in Annex 3.

Processing takes place in member states of the European Union or the European Economic Area. Processing in a third country only takes place where the requirements of Chapter V GDPR are met; Annex 3 identifies such cases together with their legal basis.

Section 3 — Instructions of the controller

The processor processes the data only on documented instructions from the controller. This agreement including its annexes, together with the settings the controller configures in the software, constitute its initial instructions.

Further instructions are issued by the controller in text form to datenschutz@servire.de. Instructions given orally are confirmed in text form without undue delay. The processor documents all instructions.

Where the processor is of the opinion that an instruction infringes data protection law, it informs the controller without undue delay and suspends execution. It does not carry out an instruction whose execution would infringe data protection law, even after the controller confirms it.

Where the processor is required by Union or member state law to carry out processing that goes beyond the instructions, it informs the controller before processing, unless that law prohibits such information on important grounds of public interest.

Section 4 — Confidentiality

The processor engages only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after their engagement ends.

The processor familiarises the persons engaged with the applicable data protection provisions and with the obligation to follow instructions. They are granted access only to the extent their task requires.

Section 5 — Security of processing

The processor implements the technical and organisational measures required under Article 32 GDPR. They are described in Annex 2 and are binding for the term of this agreement.

The processor may develop the measures further as long as the level of protection is not reduced. It documents material changes and makes them available to the controller on request.

Section 6 — Sub-processors

The controller grants general authorisation under Article 28(2) GDPR for the engagement of sub-processors. The undertakings engaged at the time this agreement is concluded are listed in Annex 3 with their legal entity, service, types of data and place of processing.

Where the processor intends to add or replace a sub-processor, it informs the controller in text form, sent to the billing address on file, before the intended engagement. The information identifies the undertaking, its service, the types of data concerned and the place of processing.

The controller may object to the engagement on data protection grounds in text form within 30 days of receiving the information. The engagement starts at the earliest after that period has expired; until then the undertaking named does not process any of the controller's data. If it objects in time, the processor offers an alternative, continues to provide the service without the sub-processor concerned, or discontinues the affected part of the service, and the undertaking is not engaged for that location. If none of these options is reasonable, either party may terminate the agreement in respect of the affected service upon reasonable notice. If the controller does not object within the period, the engagement is deemed authorised.

The processor contractually imposes on every sub-processor the same obligations that apply to it under this agreement. It remains liable to the controller for the performance of those obligations.

Ancillary services that do not involve processing of the controller's personal data, such as pure telecommunications services or cleaning, do not constitute sub-processing. Where an ancillary service involves access to such data, in particular the destruction of data carriers, it constitutes sub-processing under this section. Otherwise the processor takes appropriate precautions to protect the data.

Section 7 — Rights of data subjects

If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not respond itself.

The processor assists the controller by appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction of processing, data portability and objection. The software provides export and deletion functions for this purpose; Annex 1 identifies them per module.

These functions remain available to the controller irrespective of whether this agreement is in force. A dispute about the agreement must not prevent the controller from fulfilling data subject rights.

Section 8 — Assistance and notification of breaches

The processor assists the controller in complying with the obligations under Articles 32 to 36 GDPR, in particular regarding security of processing, data protection impact assessments and prior consultation of the supervisory authority, taking into account the information available to it.

Where the processor becomes aware of a personal data breach, it notifies the controller without undue delay, as a rule within 24 hours of becoming aware. The 72-hour period applying to the controller under Article 33 GDPR is not a waiting period for the processor.

The initial notification describes the nature of the breach, where possible the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The processor provides missing information without undue delay as soon as it becomes available.

The security contact of the processor is datenschutz@servire.de. The controller keeps a contact address for such notifications up to date; absent a separate designation, the billing address on file applies.

Section 9 — Return and deletion

After the end of the processing, the processor deletes the personal data or returns it, at the choice of the controller. If the controller does not make a choice, the processor first makes the data available for retrieval and then deletes it in accordance with the periods set out in the general terms and conditions.

The processor provides a data export in a common machine-readable format, in particular in accordance with DSFinV-K for fiscally relevant data.

Data subject to a statutory retention obligation is exempt from deletion. This applies in particular to fiscal cash register records, which must be retained for ten years under Sections 147 and 146a of the German Fiscal Code, and to working time records. Such data is blocked for the duration of the retention obligation and processed solely for that purpose.

Backup copies are overwritten in the course of the usual retention cycles. Until then they remain protected against further processing. Both parties receive this agreement as a PDF upon conclusion; the controller can download it again at any time in the web desk. The processor keeps the record of acceptance for as long as the location exists and makes it available to the controller on request before deletion.

Section 10 — Evidence and audits

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR.

The controller may carry out audits, including inspections, or have them carried out by an auditor it mandates. The processor contributes to such audits. Audits generally take place upon reasonable notice during normal business hours; in the event of a personal data breach or a specific suspicion of a serious infringement, they may also take place at short notice. The auditor is bound to confidentiality; where the auditor is a direct competitor, the processor may object on objective grounds and request a different auditor.

The processor may also provide evidence by means of current attestations, certificates or audit reports issued by independent bodies. Where this is not sufficient for the controller in an individual case, its right to carry out its own audit remains unaffected.

Section 11 — Obligations of the controller

The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It informs its guests and staff about the processing and obtains any necessary consent itself, in particular for email marketing.

The controller collects only data it needs for its purposes and configures the software accordingly. It manages the accounts of its staff and revokes them without undue delay when they are no longer required.

The controller informs the processor without undue delay if, when reviewing the results, it identifies errors or irregularities regarding data protection provisions.

Section 12 — Liability and final provisions

Liability is governed by Article 82 GDPR and by the liability provisions of the general terms and conditions. Liability towards data subjects under Article 82 GDPR remains unaffected.

Amendments to this agreement require text form. In the event of contradictions between this agreement and the general terms and conditions, this agreement prevails in matters of data protection.

Should any provision be invalid, the remainder of the agreement remains effective. The invalid provision is replaced by the applicable statutory provisions.

Annex 1 — Subject matter of processing, types of data and data subjects

Which data arises depends on the modules the controller uses. The following overview describes the maximum scope per module.

Module / processingData subjectsTypes of dataRetention
Point-of-sale operation (core function)Staff of the controllerName of the operating person on receipts and in reports, user account, permissions, timestamps of transactions. For an invoice additionally the name and address of the recipient; technical data to protect the public entry points against abuseFiscal records for ten years under Section 147 of the German Fiscal Code
Guest management (CRM)Guests of the controllerSalutation, first and last name, email, telephone, address, date of birth, language, company and VAT ID, invoice address, staff notes, customer number, card code, membership of guest groups and attributes such as regular-guest status or a block on online reservations, visit and revenue metrics. Information on allergies and intolerances constitutes health data within the meaning of Article 9 GDPR. Where newsletter consent is given, and when joining through the guest account, additionally the time, IP address and browser identifier as evidence, along with the link to the cross-location guest accountUntil deleted by the controller; anonymisation replaces deletion where tax retention obligations prevent it
Reservations and waiting listGuests of the controllerFirst and last name, email, telephone, party size, time, table, guest remarks, internal notes, information on allergiesUntil deleted by the controller
Guest ordering, self-order terminal and order at the tableGuests of the controllerName, email, telephone, order contents, pickup or delivery time, delivery address where applicable, payment reference, tipThe order itself is kept for a further 30 days after completion and then deleted automatically. The guest details are transferred into the business's order history and remain there until the controller has them deleted. The receipt is subject to fiscal retention
Voucher salesPurchasers and recipientsName and email of the purchaser, name of the recipient, any differing invoice details, voucher code and balanceUntil the voucher expires plus retention periods
Loyalty card and guest accountGuests of the controllerLink to the guest profile, points and stamp balance, transaction history, card number for the wallet passUntil the guest profile is deleted
Receipt delivery and receipt claimGuests of the controllerEmail address, name where applicable, link to the receiptAccess tokens expire automatically, as a rule after seven to thirty days
Working time recordingStaff of the controllerName, personnel number, clock-in and clock-out times and breaks, hourly rate and wage amounts, surcharges, indications of breaches of the German Working Hours Act, IP address and device identifier when clocking, corrections with justificationDeletion after the end of the sixth calendar year following the record
Support chat and helpStaff of the controllerContent of enquiries, which may contain personal data, user accountUntil the location is deleted

Functions supporting data subject rights: guest management provides a complete data export and an anonymisation for every guest profile, covering linked reservations, orders and waiting list entries. Staff obtain access to their working time data through the time recording module. The controller may also request a complete data export of the location at any time.

Annex 2 — Technical and organisational measures

The measures under Article 32 GDPR take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risk to data subjects.

AreaMeasures
EncryptionTransmission exclusively over TLS. Data at rest is encrypted at storage level using AES-256. Credentials are stored only as hashes, access tokens exclusively as hashes with automatic expiry.
Physical access controlProcessing takes place in the data centres of the providers engaged, subject to their physical access concepts including separation, video surveillance and logging. The processor does not operate its own server rooms for customer data.
System access controlAuthentication exclusively through a central identity system. Administrative access is limited to a named group of persons and additionally secured. Point-of-sale devices additionally identify themselves through a device attestation.
Data access controlAccess to data is verified server-side for every individual query. The default is denial; access must be explicitly permitted. Within a business, the controller manages the permissions of its staff per function. Particularly sensitive areas such as payroll and working time data are further restricted and accessible only through verified server interfaces.
Separation controlThe data of each business resides in its own data container. The access check binds every query to membership of that specific business. Production and test operations run in separate projects with separate access and separate data.
Transfer controlTransfers to sub-processors take place exclusively in encrypted form and on the basis of the agreements under Section 6. Exports for the controller are provided through time-limited links that cannot be guessed.
Input controlFiscally relevant transactions are logged immutably and signed by a technical security device. Changes to master data and to working time records are recorded with time, acting person and previous state.
Availability and resilienceThe data resides in a managed database service with automatic backup and point-in-time recovery within the window provided by the vendor. The point-of-sale system continues to operate offline during network outages and synchronises afterwards. Systems are monitored.
RecoverabilityDefined procedures with named responsibilities exist for incidents and security events. Restorations are tested as the occasion requires.
Procedures for review and evaluationChanges to security-relevant code are reviewed before adoption. Access rules are covered by automated tests. Errors and anomalies in operation are recorded and evaluated centrally, without transmitting personal content.
Data protection by designData required only temporarily is stored with automatic expiry and deleted without intervention. Transaction data is stripped of personal details after completion. Default settings are chosen to minimise data.
Sub-processor controlSub-processors are assessed for suitability before engagement and contractually bound to the same obligations. Their performance is monitored on an ongoing basis.

Annex 3 — Sub-processors

The following undertakings process personal data on behalf of the controller, through the processor. Changes are governed by the procedure under Section 6.

UndertakingServiceTypes of dataPlace of processing
Google Cloud EMEA Limited, Ireland (Google Cloud and Firebase)Operation of the database, file storage, user management and server-side processingAll data listed in Annex 1European Union, Frankfurt am Main region
Sendinblue GmbH (Brevo), GermanySending of emails: receipts, reservation and order confirmations, messages to staff, newsletters of the controllerName, email address, content of the respective message including receipt or reservation dataEuropean Union
fiskaly GmbH, AustriaTechnical security device under Section 146a of the German Fiscal Code and creation of fiscal export filesName of the operating person, transaction data, and for invoices the invoice address of the guestEuropean Union
Functional Software, Inc. (Sentry), United States, with processing via Sentry GmbH, GermanyCollection of technical error reports for fault resolutionTechnical information about the error and the user account; personal content is not transmittedEuropean Union, Frankfurt am Main data centre
Google Cloud EMEA Limited, Ireland (Vertex AI)Assistance with importing menus and with the help chatContent of submitted documents and enquiries, to the extent the controller transmits itEuropean Union

The following recipients are not processors but controllers in their own right. The controller decides whether to use them and concludes the necessary agreements directly with them: payment service providers (Stripe, SumUp, Zettle, PayPal, Payone), delivery platforms (Wolt, Uber Eats and platforms connected through the intermediary Flyt), reservation referral through Google, accounting and tax services (DATEV, sevDesk) and the tax adviser designated by the controller.

Own processing by the processor: Servire GmbH acts as a controller in its own right for the performance of the contractual relationship with the controller and for a cross-location guest account that guests create themselves. This processing is not covered by this agreement; the privacy policy at servire.de provides information about it.

The German version of this agreement prevails. This English translation is provided for readability only.