Personal Data Processing Terms

Data Processing Agreement (DPA) concluded pursuant to Art. 28 GDPR

Effective from July 16, 2026 | Platform Operator: Roman Khapenkov, Company ID (IČO) 06261035

1. Contracting Parties and Their Roles

Data Controller: The restaurant (a legal entity or natural person) registered on the Rezervato platform, which collects and determines the purposes of processing its guests’ personal data.

Data Processor: Roman Khapenkov, a self-employed natural person, Company ID (IČO): 06261035, registered at Poznaňská 434/35, Bohnice, 181 00 Prague 8 (“Rezervato”), who processes personal data on the controller’s instructions as part of operating the booking platform.

By entering into an agreement to use the Rezervato platform, the restaurant agrees to this Data Processing Agreement (hereinafter the “DPA”) as an integral part of the contractual relationship.

2. Subject Matter and Scope of Processing

On behalf of the restaurant (controller), Rezervato processes the following categories of guest personal data:

Data category Specific data Purpose
Identification first name, last name booking management
Contact email, phone confirmation, reminders
Booking date, time, party size, notes, status operation of the booking system
Historical number of visits, average spend, preferences restaurant CRM
Technical IP address, user agent (access log) security, abuse prevention

The Processor does not process special categories of personal data (health data, biometric or genetic data).

3. Duration of Processing and Retention

3.1 Personal data is processed for the duration of the agreement between the restaurant and the Rezervato platform.

3.2 After a restaurant’s account is cancelled, data is retained for a further 30 days (a recovery period) and then automatically and irreversibly deleted.

3.3 The customer (restaurant) may request early export and deletion of data at any time via the Settings section, or by sending a request to info@rezervato.cz. We will complete the export within 5 business days in CSV/JSON format.

4. Controller Instructions and Processing Directions

4.1 Rezervato processes personal data solely on the basis of the controller’s (restaurant’s) documented instructions, as set out in this DPA and in the platform’s terms of use.

4.2 If Rezervato is legally required to act beyond these instructions, it will notify the controller in advance (unless the law prohibits this).

4.3 The restaurant must not enter special categories of personal data within the meaning of Art. 9 GDPR into booking notes or free-text fields.

5. Security Measures

Rezervato implements and maintains the following technical and organizational measures (TOMs):

  • Data transfer encryption: TLS 1.2/1.3 for all communication
  • Password encryption: Argon2id (no readable password stored anywhere in the database)
  • Access rights: role-based access control, with data segregation between individual restaurants (multi-tenancy)
  • Database backups: daily backups retained for 14 days
  • Monitoring: logging of access and anomalies
  • Physical security: servers located in ISO 27001-certified data centers (Active24, a.s.)

6. Subcontractors (Sub-processors)

6.1 The controller hereby grants general authorization for the engagement of sub-processors. The current list is set out below:

Sub-processor Location Purpose
Active24, a.s. Czech Republic Hosting, database
Stripe Payments Europe, Ltd. Ireland Payment gateway (restaurant’s payment details, not guests’)
Websupport, s.r.o. Slovakia (EU servers) Sending transactional emails (SMTP)

6.2 We will notify the controller by email at least 14 days in advance of any intention to engage a new sub-processor. The controller may raise an objection; if Rezervato proceeds with the change regardless, the controller may terminate the agreement without penalty.

7. Cross-Border Data Transfers

7.1 Guest personal data is primarily processed and stored on servers in the Czech Republic (EU/EEA).

7.2 Email delivery is handled by Websupport, s.r.o. using servers within the EU. No transfer of personal data outside the EEA takes place; any future transfer would be carried out on the basis of Standard Contractual Clauses (SCCs) under Commission Decision 2021/914.

8. Rights of Data Subjects

8.1 The restaurant (controller) is responsible for fulfilling the rights of data subjects (guests) — the right of access, rectification, erasure, restriction of processing, and data portability.

8.2 Rezervato, as processor, will provide the restaurant with the technical tools needed to fulfill these obligations (data export, deletion of a guest record in the CRM).

8.3 If a guest contacts Rezervato directly to exercise their rights, Rezervato will promptly redirect them to the relevant restaurant (controller).

9. Reporting of Security Incidents

9.1 In the event of a security incident that could compromise personal data, Rezervato will notify the restaurant without undue delay, and no later than 72 hours after becoming aware of it.

9.2 The notification will include: the nature of the incident, the categories and approximate number of data subjects affected, the possible consequences, and the measures taken.

9.3 The obligation to report the incident to the relevant supervisory authority (the Office for Personal Data Protection, uoou.cz) rests with the controller (restaurant).

10. Audit and Compliance

10.1 Upon request, Rezervato will provide the controller with all information necessary to demonstrate compliance with the processor’s obligations under Art. 28 GDPR.

10.2 The controller may conduct, or have an accredited third party conduct, an audit, subject to at least 30 days’ prior notice and limited to the scope necessary to verify compliance. The cost of the audit is borne by the controller.

11. Obligations of the Controller (Restaurant)

The restaurant undertakes to:

  • have a valid legal basis for processing guests’ personal data (consent or legitimate interest)
  • inform guests about the processing of their data (privacy policy on the restaurant’s website)
  • not enter special categories of personal data into the platform
  • ensure that employees with access to the system are trained in data protection
  • promptly inform Rezervato of any security breach it becomes aware of

12. Contact for Data Protection Queries and Supervisory Authority

Contact Rezervato at: info@rezervato.cz

Supervisory authority: Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.cz