This Data Processing Agreement ("DPA") forms part of the Terms of Service between the venue ("Controller") and Kratisis ("Processor") and applies to any personal data processed by the Processor on behalf of the Controller through the Kratisis Service.
1. Subject-matter & duration
The Processor processes personal data provided by the Controller (e.g. guest names, phone numbers, reservation details, notes) for as long as the Controller uses the Service and for retention periods required to provide it.
2. Nature & purpose of processing
Storing, retrieving, organising, transmitting and deleting personal data solely to provide the Kratisis Service, including hosting, backups, generating and emailing weekly reports (when enabled by the venue) and on-demand CSV/Excel exports requested by the Controller's staff, sending authentication and password-reset emails, and technical support at the Controller's request.
3. Categories of data subjects & data
- Data subjects: Controller's staff users, Controller's guests.
- Data: contact details (name, phone, email), reservation and visit history, notes and tags entered by staff, deposit/charge indicators, and internal metadata such as timestamps and audit-log entries.
4. Processor obligations
- Process personal data only on documented instructions of the Controller (the Service configuration is such instruction).
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (TLS, encryption at rest for backups, RBAC, RLS, logging).
- Assist the Controller in fulfilling data-subject requests to the extent reasonably possible.
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- Delete or return personal data at the end of the Service, subject to legal retention.
- Make available information necessary to demonstrate compliance and allow audits on reasonable notice, subject to confidentiality.
5. Sub-processors
The Controller provides general authorisation for the use of sub-processors (infrastructure, database, email delivery). The Processor will inform the Controller of intended changes and give the Controller the opportunity to object.
6. International transfers
Any transfer outside the EEA/UK is protected by appropriate safeguards including the EU Standard Contractual Clauses where applicable.
7. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.
8. Governing law
Cyprus, consistent with the Terms of Service.
9. Contact
Data-protection contact: info@kratisis.com.