Data Processing Agreement
This document is provided in English. If you need it in another language, contact us at hi@rizzrv.com and we will arrange a translation. If a translated version ever conflicts with the English version, the English version prevails.
1. Scope and parties
This Data Processing Agreement (“DPA”) is part of the Terms & Conditions between Rizzrv (“we”, the “Processor”) and the business holding a Rizzrv account (“you”, the “Controller”). It applies automatically from the moment you create an account — no signature is needed — and governs all personal data we process on your behalf under Article 28 GDPR.
2. Roles
For the personal data your guests and staff members submit through the platform, you are the controller and we are the processor. For the data we hold about you as our customer (your account, billing and support correspondence) we are an independent controller; that processing is described in our Privacy Policy and is not covered by this DPA.
3. Details of the processing
- Subject matter and nature: hosting your booking page, storing and managing bookings, showing them in your dashboard and calendar, computing booking analytics for you, and sending booking-related emails (confirmations, reminders, a “starting soon” notice and cancellation messages) to your guests.
- Duration: the life of your account, plus the deletion period in section 11.
- Purpose: providing the Service described in the Terms — nothing else.
- Categories of data subjects: your guests (the people who book with you) and the staff members you add to your account.
- Categories of personal data: guest name, email address and optional phone number; booking date, time, service, party size and language preference; free-text notes; where you enable it, allergen information; staff member names and working hours.
- Special categories: allergen information provided by a guest may reveal health information. It is collected only where you enable the field, submitted only after the guest ticks an explicit consent box on the booking form (the time of consent is recorded with the booking, Art. 9(2)(a) GDPR), used solely to fulfil the booking, and never used for any other purpose. No other special-category data is intended to be processed.
4. Instructions
We process personal data only on your documented instructions. The Terms, this DPA and the configuration you set in the dashboard (services, notification timing, integrations) are your instructions. We will inform you if we believe an instruction infringes the GDPR, and we will not process the data for our own purposes.
5. Confidentiality
Everyone we authorise to process personal data is bound by confidentiality obligations and processes data only as needed to operate and support the Service.
6. Security (Article 32 GDPR)
Taking into account the state of the art and the nature of the data, we implement:
- encryption of all data in transit (TLS);
- hosting of the application and database in ISO 27001-certified data centres in Nuremberg and Falkenstein, Germany;
- strict per-account (tenant) isolation of data in the application and database;
- credentials stored only as cryptographic hashes; access on a need-to-know basis;
- regular backups stored within the EU;
- capability-scoped links for guest self-service (a guest can only manage their own booking).
7. Subprocessors
You authorise us to use the following subprocessors. We remain fully responsible for their performance:
| Subprocessor | Processing activity | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting: application servers and the database where all booking data is stored | Nuremberg & Falkenstein, Germany (EU) |
| Cloudflare, Inc. | Delivery of static website assets (marketing site, dashboard and booking-page front-ends); no booking data is stored with Cloudflare | Global edge network (US company) |
| Resend | Transactional email delivery: recipient address and the content of booking emails | United States |
| Stripe Payments Europe, Ltd. | Payment processing for your subscription (your billing data only — guest data is never shared with Stripe) | Dublin, Ireland (EU) |
| Google Ireland Limited | Reserve with Google — only if you enable the integration. Attribution is per business via a referral token kept for at most 30 days; conversion reports contain no guest personal data | Ireland (EU) / global |
We will announce the addition or replacement of subprocessors at least 30 days in advance by email or by updating this page. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected part of the Service.
8. International transfers
Personal data is stored in Germany. Where a subprocessor processes data outside the European Economic Area (Cloudflare, Resend), the transfer is safeguarded by the EU Standard Contractual Clauses or an EU adequacy decision such as the EU–US Data Privacy Framework.
9. Assistance
Taking the nature of the processing into account, we assist you with your GDPR obligations: we forward without undue delay any data subject request we receive that concerns your guests, and provide reasonable assistance with security, breach notification and data protection impact assessments (Articles 32–36 GDPR).
The dashboard’s Privacy & data page contains built-in tooling for data subject requests: search a guest’s email address to see everything stored about them (Art. 15), download it as a portable machine-readable file (Art. 20), and erase their personal data (Art. 17). Guests can also serve themselves through the secure link in their booking emails — download at any time, erasure once the booking is over or cancelled. Every export and erasure is recorded in a per-account privacy log so you can demonstrate compliance (Art. 5(2)).
10. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you need for your own notification duties as it becomes available.
11. Deletion and return
During the agreement you can delete guest personal data through the dashboard — per guest on the Privacy & data page, or automatically by setting a retention period after which booking personal data is erased (your documented retention instruction) — or by instructing us at hi@rizzrv.com. Erasure anonymizes the booking irreversibly: personal fields are removed while the anonymous booking record remains for your statistics.
You can export all data we process for you — profile, configuration, staff and every booking — as a machine-readable JSON file from the dashboard at any time. Closing the account (also available in the dashboard) deletes your booking page, all bookings and guest data, staff logins and your account immediately, and in any case within 90 days, unless EU or member-state law requires longer storage.
12. Audits
We make available the information reasonably necessary to demonstrate compliance with this DPA. You may audit compliance — through documentation requests or, where required, an on-site inspection by an independent auditor bound to confidentiality — at most once per year, with 30 days’ notice, during business hours and at your own cost, unless a supervisory authority or a confirmed breach requires otherwise.
13. Precedence and governing law
If this DPA conflicts with the Terms on a data protection matter, the DPA prevails. The governing law and jurisdiction clauses of the Terms apply.
14. Contact
Data protection questions and requests: hi@rizzrv.com.