Data Processing Agreement (DPA) pursuant to Art. 28 GDPR
Effective from: 22 September 2026
This document is a draft under legal review.
- 1.0
This Data Processing Agreement ("DPA") is concluded between the customer of the BookDinePlay platform as controller within the meaning of Art. 4 (7) GDPR ("Controller" or "Operator") and ThreeB IT GmbH, Bergstrang 105, 49479 Ibbenbüren, Germany, registered in the commercial register of the local court (Amtsgericht) Steinfurt under HRB 12324, VAT ID DE322793746, e-mail hello@bookdineplay.com, as processor within the meaning of Art. 4 (8) GDPR ("Processor" or "BookDinePlay"). It specifies the data protection obligations of the parties under the contract of use for BookDinePlay based on the Terms of Service ("Main Agreement") and, like the Main Agreement, is addressed exclusively to business customers (entrepreneurs, Unternehmer) who use BookDinePlay for their restaurant, bar or event business. The DPA is accepted at registration together with the Main Agreement and applies for the entire term of the Main Agreement.
§ 1 Subject Matter and Duration of the Processing
(1) The subject matter of this DPA is the processing of personal data by BookDinePlay on behalf of the Controller in the course of providing the BookDinePlay platform under the Main Agreement. This includes in particular the acceptance, storage, management and transmission of table reservations, bookings of game-related resources, orders, event registrations and tickets, the management of user accounts of the Controller's staff, the sending of confirmation, reminder and status messages to guests, and the provision of the operator console, the API, the widgets and the mobile applications.
(2) The processing takes place exclusively within the European Union or the European Economic Area. Processing in a third country takes place only under the conditions of § 7 (5).
(3) The duration of the processing corresponds to the term of the Main Agreement. The DPA ends with the Main Agreement without the need for separate termination; the obligations under § 9 (deletion and return) and § 5 (confidentiality) survive the end of the contract. Isolated termination of the DPA is excluded because the Main Agreement cannot be performed without processing on behalf; the right to terminate the Main Agreement for cause, in particular in the event of serious breaches of this DPA, remains unaffected.
(4) Insofar as BookDinePlay processes personal data of the Controller itself and of its contact persons (account data, billing data, communication, records of the acceptance of contract documents), it does so for the performance of the Main Agreement on its own responsibility, and such processing is not subject to this DPA; information on it is provided in the privacy policy at bookdineplay.com/privacy.
§ 2 Nature and Purpose of the Processing
(1) Nature of the processing: collection (through widgets, API, WordPress plugin, public booking pages and the operator console), recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission to the Controller and to recipients authorised by it (for example via the API to the Controller's website), alignment (for example to check availability and for admission control by QR code), restriction and erasure.
(2) Purpose of the processing: The processing serves exclusively to provide the services described in the Main Agreement to the Controller, namely the receipt and management of reservations, bookings, orders, registrations and ticket purchases by the Controller's guests, communication with guests in connection with these transactions, the representation of the payment status of guest payments, the management of staff accounts and permissions of the Controller, and ensuring the secure and fault-free operation of the platform (including logging and error monitoring).
(3) BookDinePlay does not process the data for its own purposes, in particular not for advertising, for profiling of guests or for disclosure to third parties outside the engagement. The creation of anonymised usage statistics that cannot be traced back to individual persons or individual controllers is permitted for the purpose of improving the platform.
(4) Guests' payment data (in particular card data) is not processed by BookDinePlay but directly by the payment service provider Stripe on the basis of a separate contractual relationship between the Controller and Stripe. In this respect BookDinePlay processes only the payment status, transaction identifiers and amounts.
§ 3 Categories of Data and Data Subjects
(1) Categories of data subjects: guests of the Controller (persons who make a reservation, booking, order or event registration or for whom a ticket is issued, as well as accompanying persons whose names are recorded for named tickets), staff and other users of the Controller's operator console, and other persons whose data the Controller records in messages or notes.
(2) Categories of personal data: master and contact data (name, e-mail address, telephone number), reservation and booking data (date, time, duration, party size, chosen resource, occasion, special requests, status), order data (items ordered, amounts, table assignment), event and ticket data (registration, names per ticket, ticket code, admission status, cancellation and refund status), message content between guest and Controller, payment status and transaction identifiers (but not card data), account and permission data of staff (name, e-mail address, role, login identifier of the identity service), and log and usage data (IP address, timestamps, browser identifier). The data categories are listed in detail in Annex 1.
(3) Special categories of personal data under Art. 9 GDPR are not the subject of the commissioned processing. The Controller ensures that guests and staff are not asked to provide such data in free-text fields (such as special requests, messages, notes); insofar as guests nevertheless voluntarily provide information, for example on allergies or intolerances, BookDinePlay processes it exclusively as part of the reservation within the scope of this DPA.
(4) The Controller is responsible for collecting only the data required for the respective transaction and for using the platform accordingly.
§ 4 Instructions
(1) BookDinePlay processes the personal data exclusively within the scope of the agreements made and on documented instructions from the Controller, unless BookDinePlay is required to process by European Union or member state law; in that case BookDinePlay informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
(2) The Main Agreement, this DPA and the settings and actions performed by the Controller in the operator console, through the API and through the functions provided by BookDinePlay (such as creating, changing and cancelling reservations, bookings and registrations, maintaining events and messages, and setting up user accounts) are deemed instructions of the Controller. Instructions going beyond the functional scope of the platform must be given in text form to hello@bookdineplay.com; oral instructions must be confirmed in text form without undue delay. BookDinePlay documents such instructions.
(3) BookDinePlay may refuse instructions that exceed the functional scope of the platform or require a change to the agreed services, or make them subject to a separate agreement on effort and remuneration, unless they are necessary for the Controller to comply with statutory obligations.
(4) If BookDinePlay is of the opinion that an instruction infringes the GDPR or other Union or member state data protection provisions, BookDinePlay informs the Controller without undue delay. BookDinePlay is entitled to suspend the implementation of the instruction concerned until the Controller confirms or changes it.
(5) The persons entitled to issue instructions are those registered as operators in the Controller's operator console and the contact persons stored under the Main Agreement. The Controller ensures that changes to the persons entitled to issue instructions are reflected in the operator console promptly.
§ 5 Confidentiality
(1) BookDinePlay undertakes to treat the personal data processed on behalf of the Controller confidentially and to use it only within the scope of this DPA.
(2) BookDinePlay ensures that all persons involved in the processing have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality, that they are familiarised with the data protection provisions relevant to them before taking up their duties, and that the obligation of confidentiality continues after the end of their duties.
(3) Access to personal data is restricted to the persons who need it to perform their tasks (need-to-know principle). Access by BookDinePlay staff to tenant data in the course of support or fault resolution takes place only insofar as it is necessary to handle a specific request of the Controller or to maintain operations.
(4) BookDinePlay does not disclose personal data to third parties unless provided for in this DPA (in particular to sub-processors under § 7), instructed by the Controller or required by law. If BookDinePlay receives an official or judicial order to hand over data of the Controller, BookDinePlay informs the Controller without undue delay insofar as legally permissible and limits the disclosure to what is legally required.
§ 6 Technical and Organisational Measures
(1) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, BookDinePlay implements appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures implemented at the time the contract is concluded are described in Annex 2.
(2) The measures include in particular the ability to ensure the ongoing confidentiality, integrity, availability and resilience of the processing systems and services, the ability to restore the availability of and access to the data in a timely manner in the event of a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the measures.
(3) The technical and organisational measures are subject to technical progress and further development. BookDinePlay is entitled to replace individual measures with equivalent or better measures provided that the overall level of protection is not reduced. Material changes are documented; the current version of Annex 2 is available at bookdineplay.com/dpa.
(4) The Controller has taken note of the measures described in Annex 2 and considers them appropriate having regard to the categories of data it processes. The Controller is itself responsible for the security of the end devices, browsers, websites and credentials it uses and for configuring the platform in compliance with data protection law.
§ 7 Sub-processors
(1) The Controller grants BookDinePlay general authorisation to engage the sub-processors listed in Annex 3 for the performance of the contractual services. Sub-processors are service providers that process personal data of the Controller in direct connection with the provision of the main service. Ancillary services that BookDinePlay uses in support of the performance of the Main Agreement (such as telecommunications services, maintenance and user service without data access, cleaning, auditors) are not sub-processing; BookDinePlay nevertheless ensures the protection of the data through appropriate agreements in that respect as well.
(2) BookDinePlay has concluded a contract with each sub-processor imposing on the sub-processor essentially the same data protection obligations as those imposed on BookDinePlay under this DPA, in particular providing sufficient guarantees that the appropriate technical and organisational measures are implemented in such a manner that the processing meets the requirements of the GDPR. BookDinePlay reviews sub-processors before engaging them and regularly thereafter, in particular on the basis of certifications, audit reports and contractual assurances.
(3) BookDinePlay informs the Controller of any intended engagement of a new sub-processor or replacement of an existing sub-processor at least 30 days before the intended engagement by e-mail to the e-mail address stored in the account; the current list is available at bookdineplay.com/dpa. The Controller may object to the change in text form within 30 days of receipt of the information on important grounds relating to data protection. If the Controller does not object, the change is deemed approved. In the event of an objection, the parties endeavour to find an amicable solution; if this fails and BookDinePlay cannot reasonably provide the service without the new sub-processor, either party is entitled to terminate the Main Agreement with 30 days' notice.
(4) If a sub-processor fails to fulfil its data protection obligations, BookDinePlay is liable to the Controller for the performance of that sub-processor's obligations as for its own fault.
(5) Processing of personal data in a country outside the European Union or the European Economic Area, or access from such a country, takes place only if the special requirements of Art. 44 et seq. GDPR are met, in particular if an adequacy decision of the European Commission exists (for example for companies certified under the EU-US Data Privacy Framework) or appropriate safeguards such as the standard contractual clauses of the European Commission have been agreed. The sub-processors engaged by BookDinePlay operate the data processing for BookDinePlay in data centres within the European Union; individual sub-processors established outside the EU are listed in Annex 3 together with the respective transfer basis.
§ 8 Assistance to the Controller
(1) BookDinePlay assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR (access, rectification, erasure, restriction of processing, data portability, objection). BookDinePlay assists the Controller with data subjects' requests for access, rectification and erasure; requests from the Controller are received at hello@bookdineplay.com and handled within the statutory time limits. Insofar as the operator console allows individual transactions to be viewed, corrected or cancelled, the Controller may use those functions itself.
(2) If a data subject contacts BookDinePlay directly, BookDinePlay forwards the request to the Controller without undue delay and does not answer it itself unless the Controller has instructed BookDinePlay to do so. BookDinePlay refers the data subject to the Controller as the contact, insofar as the Controller is known to BookDinePlay.
(3) Taking into account the nature of the processing and the information available to BookDinePlay, BookDinePlay assists the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR, in particular regarding the security of processing, the notification of personal data breaches to the supervisory authority and the communication to data subjects, data protection impact assessments and prior consultations of the supervisory authority.
(4) Personal data breaches. If BookDinePlay becomes aware of a personal data breach concerning the Controller's data, BookDinePlay notifies the Controller without undue delay, and at the latest within 48 hours of becoming aware, in text form to the e-mail address stored in the account. The notification contains, as far as known, a description of the nature of the breach including the categories and approximate number of data subjects and records concerned, the contact details of a contact point at BookDinePlay, a description of the likely consequences and of the measures taken or proposed to address and mitigate the breach. Information not yet available at the time of notification is provided without undue further delay. BookDinePlay takes the necessary measures to secure the data and mitigate adverse effects without undue delay and documents the incident.
(5) BookDinePlay assists the Controller with enquiries and inspections by the supervisory authority insofar as they concern the processing under this DPA, and provides the Controller with the information required for that purpose.
(6) Assistance going beyond the functions provided in the platform and the cooperation owed by law, or occasioned by misconduct of the Controller, may be charged by BookDinePlay on a time-and-materials basis at its applicable hourly rates after prior notice.
§ 9 Deletion and Return
(1) During the term of the contract the Controller may at any time instruct in text form to hello@bookdineplay.com the deletion of individual personal data or records. BookDinePlay removes the data from the production systems without undue delay and at the latest within 30 days of receipt of the instruction; in backups it is overwritten in the course of the regular backup cycle. Deleted data in backups is accessed until it is overwritten only to restore the service in the event of a fault.
(2) Reservation, booking and registration data is stored for the term of the Main Agreement unless the Controller instructs its deletion under paragraph 1, and is returned or deleted after the end of the contract in accordance with paragraph 3.
(3) After termination of the Main Agreement, BookDinePlay makes all personal data processed on behalf of the Controller available for return in a common, machine-readable format within 30 days on request in text form. After 30 days from the end of the contract BookDinePlay, at the Controller's choice, either deletes the data completely or deletes it after prior return; if the Controller does not express a choice, the data is deleted. Deletion is confirmed to the Controller in text form on request.
(4) Excluded from deletion is data that BookDinePlay must continue to store on the basis of statutory retention obligations (such as billing and accounting records) and log data required for evidence and security. Such data is blocked until the respective period expires, processed exclusively for the purpose underlying its retention, and then deleted.
(5) BookDinePlay retains documentation serving as evidence of proper data processing beyond the end of the contract in accordance with the respective retention periods.
§ 10 Evidence and Audits
(1) BookDinePlay makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR. To this end BookDinePlay provides on request in particular the current description of the technical and organisational measures, the list of sub-processors, the certifications and audit reports published by the infrastructure providers used, and information on security incidents.
(2) BookDinePlay allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller and bound to confidentiality. The Controller announces audits at least 30 days in advance in text form, conducts them at most once per calendar year and additionally for a specific reason (in particular after a personal data breach or at the request of a supervisory authority), and limits them to what is necessary to verify compliance with this DPA. Audits are conducted during normal business hours and must not unreasonably impair BookDinePlay's business operations or the security of other customers.
(3) Since BookDinePlay operates the processing in data centres of infrastructure providers, an inspection of those data centres is not possible; in that respect evidence is provided by the independent audit reports and certifications published by the providers, to which BookDinePlay refers the Controller on request.
(4) The Controller bears the costs of its audits. BookDinePlay may charge, after prior notice and on a time-and-materials basis, for its expenses in supporting audits that exceed one audit per calendar year and are not occasioned by a reason for which BookDinePlay is responsible.
(5) BookDinePlay informs the Controller without undue delay if a supervisory authority initiates an investigation or measure with regard to the processing under this DPA, insofar as such information is legally permissible. Both parties support each other in responding to enquiries from the supervisory authority concerning the processing on behalf.
(6) The contact for data protection questions of the Controller is hello@bookdineplay.com. Should BookDinePlay appoint a data protection officer, the contact details will be published at bookdineplay.com/privacy.
§ 11 Liability
(1) The liability of the parties is governed by Art. 82 GDPR and the liability provisions of the Main Agreement. The limitations of liability agreed in the Main Agreement also apply to claims arising out of or in connection with this DPA, unless mandatory law, in particular Art. 82 GDPR, provides otherwise.
(2) In relation to BookDinePlay, the Controller is responsible for the lawfulness of the processing, the safeguarding of the rights of the data subjects, the lawfulness of the data collection through the platform and the lawfulness of the instructions it issues. It indemnifies BookDinePlay against third-party claims based on a breach of these obligations, insofar as BookDinePlay is not responsible for the breach.
(3) BookDinePlay is liable to the Controller for damage caused by processing where BookDinePlay has not complied with the obligations of the GDPR specifically directed to processors or has acted outside or contrary to the lawful instructions of the Controller.
(4) If a claim is made against one party by a data subject or a supervisory authority, it informs the other party without undue delay; the parties support each other in defending unfounded claims. If a party pays full compensation to a data subject, it is entitled to claim back from the other party that part of the compensation corresponding to the other party's share of responsibility for the damage.
(5) Amendments and additions to this DPA must be made in text form; § 11 of the Main Agreement (changes to the Terms) applies accordingly to changes of this DPA. Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected. In all other respects the final provisions of the Main Agreement apply, in particular regarding governing law, place of jurisdiction and language version: this DPA is provided in German and English; the German version is authoritative. Annexes 1 to 3 form part of this DPA.
Annex 1 – Data Categories and Data Subjects
The following overview describes the categories of data subjects and the associated data categories that BookDinePlay processes on behalf of the Controller. Which fields are actually collected depends on how the Controller configures the platform.
| Data subjects | Data categories | Source | Purpose |
|---|---|---|---|
| Guests (reservation and booking) | Name, e-mail address, telephone number; date, time, duration, party size, chosen resource (table, billiard table, dart board, shuffleboard, event area), occasion, special requests; status (requested, confirmed, cancelled, completed, no-show); confirmation and cancellation identifiers | Entered by the guest via widget, public booking page, WordPress plugin or API; entered by the Controller in the operator console | Handling of the reservation or booking, communication, capacity planning |
| Guests (orders) | Items ordered, quantities, amounts, table assignment, time; for QR orders the table identifier | Entered by the guest or staff | Handling of the order |
| Guests (events and tickets) | Name and e-mail address of the registrant; names of ticket holders; ticket code; admission status and admission time; cancellation identifier; payment status, amount, transaction and refund identifiers of the payment service provider | Entered by the guest; status messages from the payment service provider | Registration, ticket issuance, admission control, refunds |
| Guests (communication) | Content and time of messages between guest and Controller | Entered by guest or staff | Communication in connection with reservations, bookings and registrations |
| Guests (technical data) | IP address, browser identifier, timestamp, origin of the request | Automatically when the public interfaces are used | Security, error analysis |
| Staff and users of the Controller | Name, e-mail address, role and permissions, login identifier of the identity service; technical usage logs; time, language, IP address and browser identifier at the acceptance of contract documents | Entered by the Controller; identity service; automatically on use | Access management, traceability, security |
Not processed: card data, account numbers and other payment instruments of guests (these are held exclusively by the payment service provider), identity document data, and special categories of personal data unless voluntarily provided by guests in free-text fields.
Annex 2 – Technical and Organisational Measures
The platform is operated on Microsoft Azure in the Germany West Central region (Frankfurt am Main). The following measures describe the state at the time the contract is concluded and are continuously developed.
1. Confidentiality
- Physical access control: The infrastructure provider's data centres are certified under ISO/IEC 27001 and further standards and protected by multi-level physical access controls, video surveillance and security staff. BookDinePlay operates no server rooms of its own.
- System access control: Administrative access to cloud resources takes place through personally assigned accounts with role-based permissions (Azure RBAC). Services authenticate to each other through managed identities without passwords stored in configuration files. Secrets (connection strings, API keys, signing keys) are kept in Azure Key Vault and not stored in source code.
- Data access control: Role-based access control (RBAC) both for the infrastructure and within the platform. Operators, staff and platform administrators receive only the rights required for their role. Every record is assigned to a tenant; every query is restricted server-side to the tenant of the requesting account. Public interfaces require an API key bound to a venue; publishable keys are additionally bound to a list of permitted origin domains, and secret keys are stored only as a hash.
- Separation control: Multi-tenant architecture with logical separation of data per tenant; separate development and production environments; no use of production personal data in development.
- Pseudonymisation and data minimisation: Application logs (OpenTelemetry) contain identifiers instead of clear names; error reports to the error monitoring system (Sentry) are scrubbed of secrets and credentials before transmission; payment instruments are held exclusively by the payment service provider; cancellation identifiers, ticket codes and QR tokens are randomly generated, unguessable values.
- Encryption: All connections to the services are encrypted with TLS (version 1.2 or higher); certificates are managed at the network edge (Azure Front Door). Databases, storage accounts and backups are encrypted at rest (Azure SQL Transparent Data Encryption and Storage Service Encryption respectively).
2. Integrity
- Transfer control: Data transfers take place exclusively over encrypted connections; data is made available only to authenticated and authorised users; e-mails are sent through an authenticated sending service (Azure Communication Services).
- Input control: Input is validated server-side; uploaded images are checked for format, size and structure before storage; application logs record when which transactions were processed.
- Protection against manipulation: Notifications from the payment service provider are checked for their signature before processing; content entered by operators is protected against script injection before delivery to browsers (escaping, nosniff).
3. Availability and Resilience
- Availability control: Operation as container applications (Azure Container Apps) with automatic restart on failure; connection through Azure Front Door; monitoring of errors and performance through OpenTelemetry and Sentry.
- Backup and recovery: Automated database backups with point-in-time restore (Azure SQL); object storage is kept redundantly by the infrastructure provider.
- Emergency management: Procedure for handling faults and security incidents with notification of the Controller in accordance with § 8 (4).
4. Procedures for Regular Testing, Assessment and Evaluation
- Data protection management: Named responsibilities for data protection and information security; record of processing activities; regular review of these measures and of the sub-processors engaged.
- Secure development: Source control with a protected main branch and changes exclusively through reviewed pull requests, automated tests and code scanning in the continuous integration pipeline, prompt installation of security updates.
- Sub-processor control: Careful selection of sub-processors, conclusion of data processing agreements, regular review on the basis of certifications and audit reports.
- Incident management: Central error monitoring (Sentry) with scrubbed reports, reporting of security incidents to hello@bookdineplay.com, follow-up with root cause analysis.
Annex 3 – Sub-processors
At the time the contract is concluded, BookDinePlay engages the following sub-processors. The current list is available at bookdineplay.com/dpa; changes are communicated in accordance with § 7 (3).
| Sub-processor | Registered office | Service | Location of processing | Transfer basis |
|---|---|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft Azure) | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland | Hosting of the platform: container applications, Azure SQL database, blob storage for media and backups, Key Vault, Front Door, monitoring and logging | European Union, Germany West Central region (Frankfurt am Main) | Processing in the EU; Microsoft Products and Services Data Protection Addendum including EU standard contractual clauses for any support access |
| Microsoft Ireland Operations Limited (Azure Communication Services) | as above | Sending of transactional e-mails to guests and users (confirmations, reminders, tickets, status messages) | European Union | Processing in the EU; Microsoft Products and Services Data Protection Addendum |
| Stripe Payments Europe, Limited | 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland | Payment processing for ticket sales and guest deposits and for the Controller's subscription billing; transmission of the payment status to the platform | European Union; for individual processing steps transfer to Stripe, Inc. (USA) | Stripe Data Processing Agreement with EU standard contractual clauses; Stripe, Inc. is certified under the EU-US Data Privacy Framework |
| Okta, Inc. (Auth0) | 100 First Street, San Francisco, CA 94105, USA | Authentication and management of the login accounts of operators, staff and platform administrators | European Union (Auth0 tenant in the EU region) | Okta Data Processing Addendum with EU standard contractual clauses; Okta, Inc. is certified under the EU-US Data Privacy Framework |
| Functional Software, Inc. (Sentry) | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Error monitoring and performance analysis of the platform; error reports are scrubbed of personal data before transmission | European Union (Sentry organisation with EU data residency, de.sentry.io, Frankfurt am Main) | Sentry Data Processing Addendum with EU standard contractual clauses; Functional Software, Inc. is certified under the EU-US Data Privacy Framework |
The Controller acknowledges that the contractual relationship regarding the connected Stripe account for guest payments (§ 6 of the Main Agreement) exists directly between the Controller and Stripe and that Stripe acts in that respect as an independent controller or as a processor of the Controller; in this context BookDinePlay processes only payment status, amounts and transaction identifiers.