Data Processing Agreement
Version 1.0 · Annex 3 in version 1.0 · As of 20 September 2026
This agreement specifies the obligations under Article 28 GDPR for the services Servire GmbH, Spielwang 20, 83377 Vachendorf, Germany (the "processor") provides to the customer (the "controller"). It supplements the general terms and conditions and applies to the location for which it was accepted.
The controller determines the purposes and means of processing the data of its guests and staff. The processor processes this data exclusively on its behalf and on its instructions.
The agreement is concluded electronically, which Article 28(9) GDPR permits. The processor documents the version, the time and the accepting person and provides the controller with the full text as a PDF.
Section 1 — Subject matter, duration and termination
The subject matter is the processing of personal data arising from the use of the Servire point-of-sale system and its modules. The nature, scope and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1.
The agreement begins upon acceptance and continues for as long as the processor processes personal data on behalf of the controller. It ends with the underlying main contract, but not before the return or deletion under Section 9 has been completed.
Either party may terminate this agreement for good cause, in particular if the other party seriously breaches data protection law or material obligations under this agreement and fails to remedy the breach within a reasonable period despite being requested to do so. This agreement cannot be terminated without also terminating the main contract, because the services cannot be provided without processing on behalf of the controller.
Section 2 — Nature and purpose of processing, data and data subjects
The processor processes the data solely in order to provide the contractually agreed services. Processing for its own purposes does not take place under this agreement.
Where the processor processes data for its own purposes, for example to perform the contract with the controller, for billing or for a cross-location guest account, it acts as a controller in its own right. Such processing is not covered by this agreement and is identified separately in Annex 3.
Processing takes place in member states of the European Union or the European Economic Area. Processing in a third country only takes place where the requirements of Chapter V GDPR are met; Annex 3 identifies such cases together with their legal basis.
Section 3 — Instructions of the controller
The processor processes the data only on documented instructions from the controller. This agreement including its annexes, together with the settings the controller configures in the software, constitute its initial instructions.
Further instructions are issued by the controller in text form to datenschutz@servire.de. Instructions given orally are confirmed in text form without undue delay. The processor documents all instructions.
Where the processor is of the opinion that an instruction infringes data protection law, it informs the controller without undue delay and suspends execution. It does not carry out an instruction whose execution would infringe data protection law, even after the controller confirms it.
Where the processor is required by Union or member state law to carry out processing that goes beyond the instructions, it informs the controller before processing, unless that law prohibits such information on important grounds of public interest.
Section 4 — Confidentiality
The processor engages only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation continues after their engagement ends.
The processor familiarises the persons engaged with the applicable data protection provisions and with the obligation to follow instructions. They are granted access only to the extent their task requires.
Section 5 — Security of processing
The processor implements the technical and organisational measures required under Article 32 GDPR. They are described in Annex 2 and are binding for the term of this agreement.
The processor may develop the measures further as long as the level of protection is not reduced. It documents material changes and makes them available to the controller on request.
Section 6 — Sub-processors
The controller grants general authorisation under Article 28(2) GDPR for the engagement of sub-processors. The undertakings engaged at the time this agreement is concluded are listed in Annex 3 with their legal entity, service, types of data and place of processing.
Where the processor intends to add or replace a sub-processor, it informs the controller in text form, sent to the billing address on file, before the intended engagement. The information identifies the undertaking, its service, the types of data concerned and the place of processing.
The controller may object to the engagement on data protection grounds in text form within 30 days of receiving the information. The engagement starts at the earliest after that period has expired; until then the undertaking named does not process any of the controller's data. If it objects in time, the processor offers an alternative, continues to provide the service without the sub-processor concerned, or discontinues the affected part of the service, and the undertaking is not engaged for that location. If none of these options is reasonable, either party may terminate the agreement in respect of the affected service upon reasonable notice. If the controller does not object within the period, the engagement is deemed authorised.
The processor contractually imposes on every sub-processor the same obligations that apply to it under this agreement. It remains liable to the controller for the performance of those obligations.
Ancillary services that do not involve processing of the controller's personal data, such as pure telecommunications services or cleaning, do not constitute sub-processing. Where an ancillary service involves access to such data, in particular the destruction of data carriers, it constitutes sub-processing under this section. Otherwise the processor takes appropriate precautions to protect the data.
Section 7 — Rights of data subjects
If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not respond itself.
The processor assists the controller by appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction of processing, data portability and objection. The software provides export and deletion functions for this purpose; Annex 1 identifies them per module.
These functions remain available to the controller irrespective of whether this agreement is in force. A dispute about the agreement must not prevent the controller from fulfilling data subject rights.
Section 8 — Assistance and notification of breaches
The processor assists the controller in complying with the obligations under Articles 32 to 36 GDPR, in particular regarding security of processing, data protection impact assessments and prior consultation of the supervisory authority, taking into account the information available to it.
Where the processor becomes aware of a personal data breach, it notifies the controller without undue delay, as a rule within 24 hours of becoming aware. The 72-hour period applying to the controller under Article 33 GDPR is not a waiting period for the processor.
The initial notification describes the nature of the breach, where possible the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The processor provides missing information without undue delay as soon as it becomes available.
The security contact of the processor is datenschutz@servire.de. The controller keeps a contact address for such notifications up to date; absent a separate designation, the billing address on file applies.
Section 9 — Return and deletion
After the end of the processing, the processor deletes the personal data or returns it, at the choice of the controller. If the controller does not make a choice, the processor first makes the data available for retrieval and then deletes it in accordance with the periods set out in the general terms and conditions.
The processor provides a data export in a common machine-readable format, in particular in accordance with DSFinV-K for fiscally relevant data.
Data subject to a statutory retention obligation is exempt from deletion. This applies in particular to fiscal cash register records, which must be retained for ten years under Sections 147 and 146a of the German Fiscal Code, and to working time records. Such data is blocked for the duration of the retention obligation and processed solely for that purpose.
Backup copies are overwritten in the course of the usual retention cycles. Until then they remain protected against further processing. Both parties receive this agreement as a PDF upon conclusion; the controller can download it again at any time in the web desk. The processor keeps the record of acceptance for as long as the location exists and makes it available to the controller on request before deletion.
Section 10 — Evidence and audits
The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR.
The controller may carry out audits, including inspections, or have them carried out by an auditor it mandates. The processor contributes to such audits. Audits generally take place upon reasonable notice during normal business hours; in the event of a personal data breach or a specific suspicion of a serious infringement, they may also take place at short notice. The auditor is bound to confidentiality; where the auditor is a direct competitor, the processor may object on objective grounds and request a different auditor.
The processor may also provide evidence by means of current attestations, certificates or audit reports issued by independent bodies. Where this is not sufficient for the controller in an individual case, its right to carry out its own audit remains unaffected.
Section 11 — Obligations of the controller
The controller is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects. It informs its guests and staff about the processing and obtains any necessary consent itself, in particular for email marketing.
The controller collects only data it needs for its purposes and configures the software accordingly. It manages the accounts of its staff and revokes them without undue delay when they are no longer required.
The controller informs the processor without undue delay if, when reviewing the results, it identifies errors or irregularities regarding data protection provisions.
Section 12 — Liability and final provisions
Liability is governed by Article 82 GDPR and by the liability provisions of the general terms and conditions. Liability towards data subjects under Article 82 GDPR remains unaffected.
Amendments to this agreement require text form. In the event of contradictions between this agreement and the general terms and conditions, this agreement prevails in matters of data protection.
Should any provision be invalid, the remainder of the agreement remains effective. The invalid provision is replaced by the applicable statutory provisions.
Annex 1 — Subject matter of processing, types of data and data subjects
Which data arises depends on the modules the controller uses. The following overview describes the maximum scope per module.
| Module / processing | Data subjects | Types of data | Retention |
|---|---|---|---|
| Point-of-sale operation (core function) | Staff of the controller | Name of the operating person on receipts and in reports, user account, permissions, timestamps of transactions. For an invoice additionally the name and address of the recipient; technical data to protect the public entry points against abuse | Fiscal records for ten years under Section 147 of the German Fiscal Code |
| Guest management (CRM) | Guests of the controller | Salutation, first and last name, email, telephone, address, date of birth, language, company and VAT ID, invoice address, staff notes, customer number, card code, membership of guest groups and attributes such as regular-guest status or a block on online reservations, visit and revenue metrics. Information on allergies and intolerances constitutes health data within the meaning of Article 9 GDPR. Where newsletter consent is given, and when joining through the guest account, additionally the time, IP address and browser identifier as evidence, along with the link to the cross-location guest account | Until deleted by the controller; anonymisation replaces deletion where tax retention obligations prevent it |
| Reservations and waiting list | Guests of the controller | First and last name, email, telephone, party size, time, table, guest remarks, internal notes, information on allergies | Until deleted by the controller |
| Guest ordering, self-order terminal and order at the table | Guests of the controller | Name, email, telephone, order contents, pickup or delivery time, delivery address where applicable, payment reference, tip | The order itself is kept for a further 30 days after completion and then deleted automatically. The guest details are transferred into the business's order history and remain there until the controller has them deleted. The receipt is subject to fiscal retention |
| Voucher sales | Purchasers and recipients | Name and email of the purchaser, name of the recipient, any differing invoice details, voucher code and balance | Until the voucher expires plus retention periods |
| Loyalty card and guest account | Guests of the controller | Link to the guest profile, points and stamp balance, transaction history, card number for the wallet pass | Until the guest profile is deleted |
| Receipt delivery and receipt claim | Guests of the controller | Email address, name where applicable, link to the receipt | Access tokens expire automatically, as a rule after seven to thirty days |
| Working time recording | Staff of the controller | Name, personnel number, clock-in and clock-out times and breaks, hourly rate and wage amounts, surcharges, indications of breaches of the German Working Hours Act, IP address and device identifier when clocking, corrections with justification | Deletion after the end of the sixth calendar year following the record |
| Support chat and help | Staff of the controller | Content of enquiries, which may contain personal data, user account | Until the location is deleted |
Functions supporting data subject rights: guest management provides a complete data export and an anonymisation for every guest profile, covering linked reservations, orders and waiting list entries. Staff obtain access to their working time data through the time recording module. The controller may also request a complete data export of the location at any time.
Annex 2 — Technical and organisational measures
The measures under Article 32 GDPR take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risk to data subjects.
| Area | Measures |
|---|---|
| Encryption | Transmission exclusively over TLS. Data at rest is encrypted at storage level using AES-256. Credentials are stored only as hashes, access tokens exclusively as hashes with automatic expiry. |
| Physical access control | Processing takes place in the data centres of the providers engaged, subject to their physical access concepts including separation, video surveillance and logging. The processor does not operate its own server rooms for customer data. |
| System access control | Authentication exclusively through a central identity system. Administrative access is limited to a named group of persons and additionally secured. Point-of-sale devices additionally identify themselves through a device attestation. |
| Data access control | Access to data is verified server-side for every individual query. The default is denial; access must be explicitly permitted. Within a business, the controller manages the permissions of its staff per function. Particularly sensitive areas such as payroll and working time data are further restricted and accessible only through verified server interfaces. |
| Separation control | The data of each business resides in its own data container. The access check binds every query to membership of that specific business. Production and test operations run in separate projects with separate access and separate data. |
| Transfer control | Transfers to sub-processors take place exclusively in encrypted form and on the basis of the agreements under Section 6. Exports for the controller are provided through time-limited links that cannot be guessed. |
| Input control | Fiscally relevant transactions are logged immutably and signed by a technical security device. Changes to master data and to working time records are recorded with time, acting person and previous state. |
| Availability and resilience | The data resides in a managed database service with automatic backup and point-in-time recovery within the window provided by the vendor. The point-of-sale system continues to operate offline during network outages and synchronises afterwards. Systems are monitored. |
| Recoverability | Defined procedures with named responsibilities exist for incidents and security events. Restorations are tested as the occasion requires. |
| Procedures for review and evaluation | Changes to security-relevant code are reviewed before adoption. Access rules are covered by automated tests. Errors and anomalies in operation are recorded and evaluated centrally, without transmitting personal content. |
| Data protection by design | Data required only temporarily is stored with automatic expiry and deleted without intervention. Transaction data is stripped of personal details after completion. Default settings are chosen to minimise data. |
| Sub-processor control | Sub-processors are assessed for suitability before engagement and contractually bound to the same obligations. Their performance is monitored on an ongoing basis. |
Annex 3 — Sub-processors
The following undertakings process personal data on behalf of the controller, through the processor. Changes are governed by the procedure under Section 6.
| Undertaking | Service | Types of data | Place of processing |
|---|---|---|---|
| Google Cloud EMEA Limited, Ireland (Google Cloud and Firebase) | Operation of the database, file storage, user management and server-side processing | All data listed in Annex 1 | European Union, Frankfurt am Main region |
| Sendinblue GmbH (Brevo), Germany | Sending of emails: receipts, reservation and order confirmations, messages to staff, newsletters of the controller | Name, email address, content of the respective message including receipt or reservation data | European Union |
| fiskaly GmbH, Austria | Technical security device under Section 146a of the German Fiscal Code and creation of fiscal export files | Name of the operating person, transaction data, and for invoices the invoice address of the guest | European Union |
| Functional Software, Inc. (Sentry), United States, with processing via Sentry GmbH, Germany | Collection of technical error reports for fault resolution | Technical information about the error and the user account; personal content is not transmitted | European Union, Frankfurt am Main data centre |
| Google Cloud EMEA Limited, Ireland (Vertex AI) | Assistance with importing menus and with the help chat | Content of submitted documents and enquiries, to the extent the controller transmits it | European Union |
The following recipients are not processors but controllers in their own right. The controller decides whether to use them and concludes the necessary agreements directly with them: payment service providers (Stripe, SumUp, Zettle, PayPal, Payone), delivery platforms (Wolt, Uber Eats and platforms connected through the intermediary Flyt), reservation referral through Google, accounting and tax services (DATEV, sevDesk) and the tax adviser designated by the controller.
Own processing by the processor: Servire GmbH acts as a controller in its own right for the performance of the contractual relationship with the controller and for a cross-location guest account that guests create themselves. This processing is not covered by this agreement; the privacy policy at servire.de provides information about it.
The German version of this agreement prevails. This English translation is provided for readability only.