Legal
Data processing agreement
How tischlein processes the data of your guests, team and applicants on your behalf. You conclude it when you book your subscription.
This is a convenience translation. Only the German version is legally binding: Vertrag zur Auftragsverarbeitung (German)
Version 2026-10-9c-5ce03680 · As of October 2026
Data processing agreement
As an annex to the general terms and conditions (terms of use) of tischlein and the products booked under them, dated the day of confirmation. Date, account and booked products are filled in when the agreement is concluded.
– hereinafter the “service agreement” –
between
the company named as invoice recipient when a tischlein subscription is booked; it is filled in with name, address and, where available, VAT ID when the agreement is concluded,
– hereinafter the “controller” –
and
OpsAgent UG (haftungsbeschränkt), operator of the tischlein platformClausewitzstr. 21
42389 Wuppertal
Germany
Amtsgericht Wuppertal, HRB 36493
represented by its managing director Pascal Kremp
E-mail: gdpr@tischlein.pro
– hereinafter the “processor” –
– both hereinafter jointly the “parties” –
conclude the following data processing agreement (“AVV”):
Preamble
With the service agreement the parties have entered into a processing relationship. To specify the resulting rights and obligations under the European General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC – GDPR) and the German Federal Data Protection Act (BDSG), the parties conclude the following agreement.
§ 1 Scope
(1) This agreement applies to the processing (Art. 4(2) GDPR) of all personal data (hereinafter: data) that are the subject of the service agreement or arise in its performance and are processed on the controller's instructions. Data of the processor's employees are outside its scope insofar as they concern only their employment with the processor.
(2) In all matters of data protection this agreement takes precedence over other agreements and arrangements between the parties, in particular the terms and conditions, unless the parties expressly agree otherwise.
(3) The controller may hold further companies and businesses in its tischlein account. It concludes this agreement for them as well, also gives the instructions for them and warrants that it is entitled to do so. Towards the processor it is responsible for the lawfulness of the processing of the data of all companies and businesses of its account. Where one of these companies is itself a controller, the processor's obligations under this agreement also apply towards it.
§ 2 Details of the processing
(1) The subject matter and duration of the processing and the extent, nature and purpose of the intended processing are determined by the service agreement, to which this agreement is attached as an annex. The subject matter is the provision of the tischlein platform as an online service, in particular websites, menus, guest inquiries, reservations and orders, forms, vouchers and tickets, newsletters, regular guests, job applications, staff scheduling and time tracking with payroll export, tasks, purchasing, the tischlein Chat and AI features such as image editing, in each case as far as the controller uses them. Processing comprises collecting data through the controller's websites and forms, storing, organising, displaying, retrieving, altering, transmitting (for example by e-mail), exporting, restricting and erasing data through the operations app, AI chat programs, the command line and the interface (API). This agreement applies for the term of the service agreement including a free trial, and beyond it for as long as the processor processes the controller's data (§ 7).
(2) The following types of personal data are processed by the processor, depending on the features used:
- guests and prospects: name, contact details (e-mail address, phone number, for deliveries the address), content of inquiries, reservations and orders (date, time, party size, occasion, ordered dishes, message), voluntary information such as allergies or intolerances, regular-guest data with consent;
- event participants and buyers of tickets and vouchers: name, e-mail address, order, chosen options, amount, payment and redemption status, admission (no card data);
- newsletter recipients: e-mail address, name where given, subscription and confirmation data (double opt-in), sending and delivery status, unsubscriptions;
- job applicants: name, contact details, application documents (such as CV, certificates and photos), details in the application form, messages, consent to the talent pool;
- the controller's employees: name, contact details, role, locations, working hours and breaks (time tracking), schedules and shifts, absences and their type, tasks and the details needed for the payroll export (such as personnel number, wage types and hours);
- users in the controller's team (operations app accounts): name, e-mail address, roles, login data and the change log;
- contact persons of suppliers (purchasing): name, contact details, orders;
- content in the tischlein Chat: messages, voice input, uploaded files and query results, which may contain data of the groups above;
- website visitors: technically required access data (server logs).
(3) The data subjects affected (categories of data subjects) are: guests and prospects, event participants, buyers of tickets and vouchers, newsletter recipients, job applicants, the controller's employees, users in the controller's team, contact persons of suppliers and website visitors.
(4) As a rule, no special categories of data (Art. 9 GDPR) are processed. Health data are processed only in the following cases: information guests give voluntarily (such as allergies or intolerances in an inquiry or order), information applicants voluntarily include in their documents, and employees' absences due to illness (without diagnosis) that the controller enters in scheduling and time tracking and exports. The processor processes these data only as part of the respective records; the controller is responsible for the legal basis of their processing.
(5) The personal data processed have a normal protection requirement. The health data named in paragraph 4 may have a higher protection requirement; the measures of the annex “Technical and organisational measures (TOM)” apply to them equally.
§ 3 Obligations and authority to issue instructions
(1) The parties shall comply with the obligations imposed on them by data protection law (in particular the GDPR). The controller may at any time demand the surrender, rectification, adjustment, erasure and restriction of processing of the data; it can carry out most of these steps itself through the features of tischlein.
(2) To safeguard the rights of data subjects, the processor supports the controller appropriately, in particular by ensuring suitable technical and organisational measures. For this, tischlein provides features with which the controller can handle data subject requests under Chapter III GDPR (such as access, rectification, erasure, restriction, data portability or objection) and find, export, correct and erase data itself.
(3) Where a data subject turns directly to the processor to exercise a data subject right, the processor forwards the request to the controller without undue delay. It does not answer the request itself unless the controller instructs it to.
(4) The processor may process data only within the controller's instructions, unless it is required to process them otherwise by Union or Member State law to which it is subject (e.g. investigations by law enforcement or state security authorities). In such a case the processor informs the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3) sentence 2 point (a) GDPR). An instruction is the controller's order, in text form, given electronically through the features of tischlein or orally, directed at a specific handling of data by the processor. Orders shall be documented. The instructions are initially defined by the service agreement and this agreement. The controller gives further instructions by using and configuring tischlein (operations app, AI chat programs, command line, interface); the processor documents them in the change log with user, time and access channel. In addition, the controller may change, supplement or replace the instructions by individual instructions in text form, for example by e-mail to gdpr@tischlein.pro. The controller confirms oral instructions in text form without undue delay.
(5) The processor shall inform the controller without undue delay if it considers that an instruction infringes data protection law. The processor may suspend the execution of the instruction until the controller confirms or changes it. The persons entitled to give instructions on the controller's side, the persons entitled to receive instructions on the processor's side and the intended channels of communication are set out in the annex “Authority to issue instructions”.
(6) Changes to the subject matter of processing involving changes of procedure shall be agreed jointly and documented. Where the controller itself switches on a feature of tischlein, books an additional product or changes settings, this counts as agreed; the change log documents it. Changes to the service agreement and to this agreement are governed by § 11(1).
(7) The processor may give information to third parties or to the data subject only with the controller's prior express consent in text form, unless it is required to disclose by Union or Member State law. Messages the controller sends through tischlein to guests, applicants, employees or other recipients are instructions under paragraph 4 and not information within the meaning of this paragraph.
(8) The processor does not use the data for any other purposes and in particular may not pass them on to third parties, unless it is required to disclose by Union or Member State law; the use of subcontractors is governed by § 8. Copies and duplicates are not made without the controller's knowledge. Excepted are backup copies insofar as they are necessary to ensure proper data processing, and temporary copies needed to resolve a malfunction (annex “Technical and organisational measures (TOM)”).
(9) The controller keeps the record of processing activities within the meaning of Art. 30(1) GDPR. The processor provides the controller, on request, with information for inclusion in the record. The processor keeps a record of all categories of processing activities carried out on behalf of the controller in accordance with Art. 30(2) GDPR.
(10) The data are processed on behalf of the controller within the territory of the European Union (EU) or the European Economic Area (EEA); the servers are located in Frankfurt am Main. Data are transferred to a third country or an international organisation only to the subcontractors named in the annex “Subcontractors” for the services named there, and only where the conditions of Chapter V GDPR are met, in particular on the basis of an adequacy decision (such as the EU-US Data Privacy Framework) or of EU standard contractual clauses; the annex names the respective basis. With this agreement the controller instructs the processor to carry out these transfers. Any further transfer to a third country takes place only on the basis of a documented instruction of the controller under paragraph 4, under § 8(1), or to comply with a specific provision of Union or Member State law to which the processor is subject, and must comply with Chapter V GDPR. The fundamental conditions for the lawfulness of the processing remain unaffected.
(11) The processor ensures that natural persons acting under its authority who have access to data process them only on the controller's instructions. The controller hereby generally approves processing of data outside the processor's premises (e.g. teleworking, working from home, mobile working), provided the measures set out in the annex “Technical and organisational measures (TOM)” are complied with; no consent in the individual case is required.
§ 4 Mandatory statutory obligations of the processor
(1) The processor ensures that the persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and demonstrates this to the controller on request. This includes instruction on the binding to instructions and purpose that applies in this processing relationship. Authorised persons receive access only insofar as they need it for their tasks.
(2) The parties support each other in demonstrating and documenting their accountability with regard to the principles of proper data processing, including the implementation of the necessary technical and organisational measures (Art. 5(2), Art. 24(1) GDPR). The processor provides the controller with the relevant information as needed.
(3) If the processor is legally required to appoint a data protection officer, the officer's contact details shall be communicated to the controller for direct contact. If the processor is not subject to this requirement, it communicates the contact details of a contact person for data protection. The processor is currently not required to appoint a data protection officer; the contact person for data protection is its managing director Pascal Kremp, reachable at gdpr@tischlein.pro.
(4) The processor informs the controller without undue delay of inspections and measures by supervisory authorities, or if a supervisory authority makes enquiries, investigates or otherwise gathers information at the processor within its competence, insofar as they concern the controller's data.
§ 5 Technical and organisational measures and their review
(1) The parties agree on the specific technical and organisational security measures set out in the annex “Technical and organisational measures (TOM)” to this agreement. The annex “Technical and organisational measures (TOM)” forms part of this agreement.
(2) If a review by the controller shows that the technical and organisational measures to be taken by the processor under Article 32 GDPR need to be adjusted, the processor shall implement the adjustments. As tischlein is a uniform service for all customers, the parties agree on the type and timing of implementation; measures required to comply with Art. 32 GDPR are implemented by the processor in any case.
(3) Technical and organisational measures are subject to technical progress. The processor may therefore implement alternative adequate measures. The security level of the measures set out in the annex “Technical and organisational measures (TOM)” must not be reduced. Material changes shall be documented; the processor adjusts the annex accordingly.
(4) The processor makes available to the controller all information necessary to demonstrate compliance with this agreement and with the statutory requirements. In particular it allows for and contributes to audits and inspections conducted by the controller or an auditor mandated by it. A mandated auditor must be bound to confidentiality and must not be a competitor of the processor.
(5) Reviews are carried out primarily on the basis of documents and evidence, in particular this agreement with its annexes, information from the processor in text form, current attestations presented, reports of sufficiently qualified and independent bodies (e.g. auditors, independent data protection auditors), adherence to approved codes of conduct under Art. 40 GDPR, a certification under Art. 42 GDPR or a suitable certification by IT security or data protection audit, where available also those of the subcontractors. The processor undertakes to inform the controller without undue delay of its exclusion from approved codes of conduct under Art. 41(4) GDPR, the withdrawal of a certification under Art. 42(7) GDPR and any other form of revocation or material change of the aforementioned evidence.
(6) Where the evidence under paragraph 5 is insufficient in the individual case, the review may also take place as an on-site inspection. For this purpose, after timely prior notice (as a rule at least 30 days), the controller may satisfy itself at the processor's premises during normal business hours, without disrupting operations, of the adequacy of the measures to comply with the statutory requirements or with the technical and organisational requirements needed to perform this agreement. Inspections take place at most once per calendar year unless a specific occasion such as a personal data breach justifies another. For the data centres of the subcontractors, their audit reports and certificates serve as evidence. The controller bears the costs of a review unless it reveals a material breach of this agreement by the processor.
(7) In addition, the processor provides the controller with all information it needs for the reviews under paragraph 4 and for an assessment of the impact of the envisaged processing operations on the protection of the data (data protection impact assessment within the meaning of Art. 35 GDPR) and any prior consultation of the supervisory authority (Art. 36 GDPR).
(8) In consultation with the controller, the processor shall take all measures necessary to secure the data and the security of processing, in particular also taking into account the state of the art, and to mitigate possible adverse effects for data subjects.
(9) For support beyond the features of tischlein and the processor's statutory obligations, the processor may charge a reasonable fee, unless a breach by the processor made it necessary.
§ 6 Notification of breaches by the processor
The processor notifies the controller without undue delay, where possible within 48 hours of becoming aware, by e-mail to the owners of the account, of serious disruptions of its operations, suspected breaches of this agreement or of statutory data protection provisions, breaches of such provisions or other irregularities in the processing of the controller's data. This applies in particular with regard to the notification obligation under Art. 33(2) GDPR and the corresponding obligations of the controller under Art. 33 and Art. 34 GDPR. The notification contains, as far as known, the information under Art. 33(3) GDPR; the processor provides missing information as soon as it is available. The processor undertakes to support the controller appropriately where necessary in its obligations under Art. 33 and 34 GDPR. The processor may make notifications under Art. 33 or 34 GDPR on behalf of the controller only after prior instruction under § 3 of this agreement.
§ 7 Erasure and return of data
(1) Data carriers and data sets provided remain the property of the controller; as between the parties, the data processed on its behalf belong solely to the controller.
(2) During the term of the service agreement the controller can at any time export its data in a common, machine-readable format through AI chat programs, the command line or the interface (API) and erase them itself.
(3) After completion of the contractually agreed services, or earlier at the controller's request, the processor shall return to the controller all personal data processed on its behalf or, with the controller's prior consent, erase them in compliance with data protection law. After the end of the service agreement the processor keeps the data for at least 90 days (§ 8(3) of the terms and conditions) so that the controller can export them (return) or resume tischlein; when this period expires, consent to erasure is deemed given and the processor erases the data unless the controller has requested their return before. At the controller's request it erases them earlier. This covers in particular data provided to the processor, processing and usage results created and data sets (including copies or reproductions made of them) connected with the processing relationship. Copies in backups are erased when their retention period expires, at the latest 30 days after erasure in the live system. Further storage is permitted only where Union or Member State law requires it. The processor confirms the erasure to the controller in text form on request.
(4) The processor may keep documentation serving as evidence of processing in accordance with the order and with proper practice (such as this agreement and the confirmation of its conclusion) in line with the respective retention periods beyond the end of the contract until those periods end. Alternatively, it may hand it over to the controller at the end of the contract to discharge itself. For the data kept under sentence 1, the obligations under paragraph 3 apply once the retention period has ended.
§ 8 Subcontractors
(1) The processor has the controller's general authorisation to engage the subcontractors (further processors) listed in the agreed list in the annex “Subcontractors”. The processor informs the controller expressly in text form (by e-mail to the owners of the account) at least 30 days in advance of any intended changes to this list by adding or replacing subcontractors or by using a subcontractor for a new service, thereby giving the controller sufficient time to object to such changes before the subcontractor is engaged. The processor provides the controller with the information needed to exercise its right to object; the current list is available at https://tischlein.pro/en/dpa. The controller may object to the change within 30 days of being informed, for an important reason relating to data protection, in text form, for example by replying to the e-mail. The parties then seek an amicable solution. If none is found, the controller may terminate the service agreement with effect from the date the change takes effect; fees paid in advance for the period after that are refunded pro rata. If the controller does not object in time, the change is deemed approved.
Services the processor uses from third parties as ancillary services supporting the performance of the contract, for example telecommunication services, are not services of subcontractors within the meaning of this provision. The processor is nevertheless obliged to make appropriate and lawful contractual arrangements and to take control measures to ensure the protection and security of the controller's data also for outsourced ancillary services. Services the controller engages itself and connects to tischlein are not subcontractors either, for example its own AI chat program (e.g. Claude or ChatGPT), its own Stripe account for selling vouchers and tickets or its own Google or Instagram account; the controller itself is responsible for these services.
(2) Where the processor engages subcontractors, it shall ensure that its contractual arrangements with the subcontractor provide at least the level of data protection of the agreement between the controller and the processor and that all contractual and statutory requirements are met (Art. 28(4) GDPR); this applies in particular to the use of suitable technical and organisational measures ensuring an appropriate level of security of processing.
(3) The controller shall be granted control and audit rights corresponding to this agreement in the contractual arrangement with the subcontractor; for subcontractors that offer their services only on uniform terms, these rights are exercised primarily through their audit reports and certificates. The controller is likewise entitled, on request in text form, to receive information from the processor on the content of the contract concluded with the subcontractor and on how the subcontractor's data protection obligations are implemented in it.
(4) If the subcontractor fails to fulfil its data protection obligations, the processor is liable to the controller for the performance of the subcontractor's obligations. In this case, at the controller's request, the processor shall end the subcontractor's engagement in whole or in part or terminate the contractual relationship with the subcontractor, if and to the extent this is not disproportionate.
§ 9 Data protection review
The processor undertakes to grant the controller's data protection officer access for the performance of the officer's statutory tasks in connection with this processing, after prior notice, during normal business hours and primarily through documents, information and evidence; on-site inspections are governed by § 5(6). It will instruct its staff to cooperate with the data protection officer, in particular to answer the officer's questions truthfully and completely. Statutory duties of confidentiality and rights to refuse testimony of the persons named, and the confidentiality of other customers' data, remain unaffected.
§ 10 Liability and damages
With regard to liability and the right to compensation, reference is made to Article 82 GDPR. As between the parties, § 14 of the terms and conditions applies otherwise, insofar as Art. 82 GDPR does not mandatorily provide otherwise.
§ 11 Final provisions
(1) Amendments and additions to this agreement and all its components – including any assurances of the processor – require an agreement in text form and an express reference to the fact that it is an amendment or addition to these terms. This also applies to any waiver of this form requirement. The processor may amend this agreement by the procedure of § 15 of the terms and conditions (notice in text form at least six weeks before the change takes effect, right of the controller to object); changes to the list of subcontractors are governed by § 8(1).
(2) Should individual provisions of this agreement be invalid or unenforceable, the validity of the remaining provisions is not affected. The invalid or unenforceable provision is replaced by the valid and enforceable provision whose effects come closest to the objective the parties pursued with the invalid or unenforceable provision. The above applies accordingly if the agreement proves to be incomplete.
(3) The law of the Federal Republic of Germany applies. Jurisdiction is governed by § 17(2) of the terms and conditions. The German version is binding; translations are for information only.
Conclusion by electronic confirmation (Art. 28(9) GDPR)
This agreement is concluded in electronic form: the controller expressly confirms it when booking a subscription; the processor accepts it by providing this version for confirmation. Date, time, account and the confirming person are filled in on conclusion, and the accepted version is stored in the controller's account under “Documents”. No signature is required.
Annex “Authority to issue instructions” to § 3
to the data processing agreement of the day of confirmation
between the controller
and OpsAgent UG (haftungsbeschränkt)
The processor shall inform the controller without undue delay if it considers that an instruction infringes data protection law. The processor may suspend the execution of the instruction until the controller confirms or changes it. The persons entitled to give instructions on the controller's side, the persons entitled to receive instructions on the processor's side and the intended channels of communication are set out below.
Persons entitled to give instructions on the controller's side:
- the owners of the tischlein account (role “owner”), who represent one another; the persons registered at conclusion are filled in by name
- within their roles and location rights, the further users to whom the controller gives access to the account, for instructions through the features of tischlein (§ 3(4))
Persons entitled to receive instructions on the processor's side:
- Pascal Kremp (managing director, all areas)
- data protection mailbox gdpr@tischlein.pro (all areas, deputy)
Intended channels of communication if, in the processor's opinion, an instruction infringes data protection law:
- ☒ in writing and/or
- ☒ electronically (e-mail in text form to the owners of the account or to gdpr@tischlein.pro) and/or
- ☐ orally
Instructions (including oral instructions) shall be documented by the parties. Changes to the persons entitled to give instructions, the persons entitled to receive them and the intended channels shall be notified to the other party without undue delay. On the controller's side the persons entitled to give instructions follow from the members and roles of its account; a change there counts as notified.
Annex “Technical and organisational measures (TOM)”
to the data processing agreement of the day of confirmation
between the controller
and OpsAgent UG (haftungsbeschränkt)
§ 5 of the data processing agreement refers to this annex for the details of the technical and organisational measures.
§ 1 Technical and organisational security measures
The parties shall implement suitable technical and organisational measures so that the processing of the data complies with the statutory requirements and the protection of the rights of the data subject is ensured appropriately.
§ 2 Internal organisation of the processor
The processor shall organise its internal operations so that they meet the particular requirements of data protection. In particular, it shall take measures suited to the type of data or data categories to be protected.
§ 3 Specific measures
(1) In detail, the following measures serving the implementation of Art. 32 GDPR are specified:
| No. | Measure | Implementation |
|---|---|---|
| 1. | Pseudonymisation and encryption of personal data | All connections to the platform, the operations app, the interface and the websites are encrypted with TLS (HTTPS). The servers' disks are encrypted; files and backups in Amazon S3 are encrypted server-side. Access keys to connected services (such as Google) are stored encrypted. The website visitor statistics work without cookies and without storing IP addresses, using a key that changes daily. The content data themselves are not pseudonymised because the controller uses them in clear text; guest inquiries and applications are anonymised once their retention period has passed (no. 15). |
| 2. | Ongoing confidentiality, integrity, availability and resilience of processing systems and services | Every record belongs to exactly one account; the application reads and writes data only in the context of that account (logical tenant separation), which automated tests check with every software change. Roles, permissions and location rights limit access within the team (no. 5). Changes are logged; pages, menus, events and designs are edited as drafts and published with versions. The server is protected against accidental stopping and deletion; new software versions are deployed without downtime. Resource-intensive tasks (such as PDF generation and image editing) run in separate queues. |
| 3. | Ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident | The database is backed up continuously (archiving of the database's change logs and daily backups) and can be restored to any point in time of the last days; in addition it is backed up every night to separate, encrypted storage in Frankfurt. Nightly backups are deleted after 30 days. An automatic check reports daily if a backup is missing; restoring is tested regularly in a separate test environment. Amazon S3 stores files redundantly in several data centres of the region; overwritten or deleted files remain recoverable for 30 days. |
| 4. | Process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures for ensuring the security of the processing | Every software change passes an automated test suite before deployment, which also checks the separation of accounts and the protection of the template sandbox. Infrastructure changes are documented in an inventory with a change log. The measures of this annex are reviewed at least once a year and on material changes of the platform (paragraph 2). |
| 5. | Identification and authorisation of users | Users sign in without a password through a link or code sent by e-mail, in the operations app also with passkeys or, on shared devices, with a PIN. AI chat programs, the command line and the interface get access through a sign-in procedure (OAuth) or API tokens; both can be revoked at any time. Roles and permissions (such as owner, editor, manager, service, HR, marketing, employee) and location rights limit who in the team sees and changes what. Only administrators with a personal SSH key can access the servers; in the AWS account, the application, e-mail sending and backups each have their own credentials with the permissions their purpose requires. |
| 6. | Protection of data during transmission | Transfers are always encrypted: HTTPS (TLS) for websites, app, interface and the connection to the subcontractors, SSH for server administration; e-mails are handed to the sending service encrypted. Confidential files (such as application documents, chat files, exports and contract documents) can be retrieved only after sign-in or through short-lived signed links. Photos are sent to AI services without metadata (such as GPS data). |
| 7. | Protection of data during storage | Encrypted server disks and server-side encryption in Amazon S3 (no. 1). Confidential files are kept in non-public storage. Database and cache cannot be reached from the internet. Access keys to connected services are stored encrypted. |
| 8. | Physical security of locations at which personal data are processed | The servers are located in Amazon Web Services data centres in Frankfurt am Main (region eu-central-1). AWS controls physical access; its data centres are certified, among others, under ISO/IEC 27001. The processor runs no servers of its own in office premises. When working remotely (§ 3(11)), access takes place only through the encrypted connections under no. 6 with personal credentials; copies of production data are made on work devices only with the managing director's approval and only temporarily to resolve a malfunction, are not added to version control and are deleted afterwards. |
| 9. | Event logging | Changes to data are recorded in the change log with user, time and access channel (app, AI chat program, command line, interface). Web server logs (access and error logs with IP address) are rotated daily and deleted automatically after 60 days at the latest; the platform's application logs are written to a separate file each day and deleted automatically after 30 days at the latest. Missing backups are reported automatically (no. 3). |
| 10. | System configuration, including default configuration | Servers are set up and updated through a management tool (Laravel Forge); system-level changes are made through documented scripts, software deployment through a versioned script. A firewall (AWS security group and a firewall on the server) admits only web traffic (HTTP/HTTPS) and SSH. The PDF renderer runs in an isolated environment (sandbox with an AppArmor profile). The businesses' websites are preset to work without cookies and without third-party content; templates (themes) run in a secured sandbox. |
| 11. | Internal IT and IT security governance and management | The managing director is responsible for data protection and IT security. The platform runs in a separate AWS account used only for tischlein. Infrastructure, service providers and their settings are documented in an inventory with a change log. Access is granted on the principle of least privilege; persons authorised to process data are bound to confidentiality (§ 4(1)). Subcontractors are engaged only under contracts pursuant to Art. 28(4) GDPR (annex “Subcontractors”). |
| 12. | Certification/assurance of processes and products | The processor is not certified. Software quality is ensured by automated tests and a release check before every deployment (static code analysis, full test suite, build). For the subcontractors' data centres and services, their own certifications apply (paragraph 3). |
| 13. | Data minimisation | Forms collect only the information intended for the respective process; additional fields (such as in the application form) are switched on or off by the controller. The visitor statistics work without cookies and without IP addresses; photos are sent to AI services without metadata. tischlein stores no card data for payments. Regular-guest data are stored permanently only with the guest's consent. |
| 14. | Data quality | Input is validated on entry (such as required fields, format of e-mail addresses and phone numbers); newsletter subscriptions are confirmed by double opt-in. The controller can correct data at any time; changes are traceable through the change log and versions. |
| 15. | Limited data retention | Guest inquiries without regular-guest consent are anonymised automatically after twelve months by default, applications without talent-pool consent after six months by default; the controller can adjust the periods. Web server logs are deleted after 60 days at the latest, application logs after 30 days at the latest and nightly backups after 30 days, unless a specific security incident requires longer retention to investigate it. After the end of the service agreement § 7 applies. |
| 16. | Accountability | Change log with user, time and access channel (no. 9). The accepted version of this agreement is stored with version, checksum (SHA-256), confirming person and time in the controller's account. Notifications of new subcontractors are recorded per account. The processor keeps a record under Art. 30(2) GDPR (§ 3(9)). |
| 17. | Data portability and erasure | The controller can export its data in machine-readable form at any time through AI chat programs, the command line or the interface and erase them itself. After the end of the service agreement the data are erased under § 7(3), copies in backups at the latest 30 days later; the erasure is confirmed in text form on request. |
| 18. | Specific technical and organisational measures the processor takes to assist the controller | Features to find, export, correct and erase data for data subject requests (§ 3(2)); double opt-in, an unsubscribe link in every message and a suppression list for newsletters; templates for the websites' privacy policies naming the recipients actually used; forwarding of data subject requests (§ 3(3)); notification of breaches and support under Art. 33 and 34 GDPR (§ 6). |
(2) A procedure shall be established that allows the parties to regularly test, assess and evaluate the effectiveness of the technical and organisational measures in use. The processor reviews the measures of this annex at least once a year and on material changes of the platform, the infrastructure or the subcontractors, adjusts the annex where needed (§ 5(3)) and provides the result to the controller on request. The controller may review the measures under § 5(4) to (6).
(3) Where available, the following evidence is attached to this agreement:
- ☐ adherence to codes of conduct under Article 40 GDPR
- ☐ certification under Article 42 GDPR
- ☐ audit reports, attestations etc. of independent auditors, e.g. chartered accountants, auditors, data protection officers
- ☐ suitable certification through an audit process
The processor currently has no such evidence of its own. The data centres and services of Amazon Web Services are independently audited (among others ISO/IEC 27001 and SOC 2); this evidence belongs to the subcontractor, concerns its services and is named to the controller on request.
Annex “Subcontractors” to § 8
Under § 8(1) of the agreement, the subcontractors already engaged for the performance of this contract are to be named. Under § 8(1) of the agreement, the controller consents to their engagement. List as of version 2026-10-9c-5ce03680; the processor announces changes under § 8(1).
| Subcontractor (name, address or registered office) | Date the data processing agreement was concluded | (Partial) service within the processing | Place of processing and basis for transfers to third countries |
|---|---|---|---|
| Amazon Web Services EMEA SARL 38 Avenue John F. Kennedy, L-1855 Luxembourg |
6 October 2026: AWS GDPR Data Processing Addendum, part of the AWS Service Terms, in force since the tischlein AWS account was opened | hosting of the platform, database and websites (Amazon EC2), storage of files and backups (Amazon S3); sending e-mails (Amazon Simple Email Service); delivery of images through Amazon CloudFront, also from locations outside the EU | data centres in Frankfurt am Main (region eu-central-1); EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR) |
| Laravel Holdings Inc. USA |
Data Processing Addendum, part of the Laravel Forge terms of service, in force since the account was opened | server management (Laravel Forge): setup, updates and software deployment | USA (remote access to the servers in Frankfurt); EU standard contractual clauses (Art. 46(2)(c) GDPR) |
| Stripe Payments Europe, Limited 1 Grand Canal Street Lower, Dublin 2, Ireland |
Data Processing Agreement, part of the Stripe Services Agreement, in force since the account was opened | payments and invoices of the tischlein subscription (the customer's invoice address, payment method and invoices) | Ireland; processing also in the USA; EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR) |
| Anthropic Ireland, Limited 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland |
Data Processing Addendum, part of Anthropic's Commercial Terms of Service, in force since the account was opened | AI assistant in the tischlein Chat of the operations app: messages, files and the data the chat retrieves for a task | Ireland; processing also possible in the USA; EU standard contractual clauses (Art. 46(2)(c) GDPR) |
| OpenAI Ireland Ltd. 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland |
Data Processing Addendum, part of the OpenAI Services Agreement, in force since the account was opened | image editing: enhancing and editing photos and creating images with AI (photos without metadata); voice input in the chat (speech to text) | Ireland; processing also in the USA; EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR) |