Wersja 2026-09-17

Data Processing Agreement

Opublikowano 17 września 2026 r. Wobec umów zawartych wcześniej obowiązuje od dnia wskazanego w powiadomieniu, nie wcześniej niż od 2 października 2026 r.

To jest tłumaczenie pomocnicze. Wiążąca jest polska wersja dokumentu.

Wersja polska

§ 1. Parties and conclusion of the Agreement

  1. 1.
    This agreement (the “Agreement”) is concluded between the business running a venue that has created a Venue account in the Tujemy service (the “Controller”) and AUTH LTD, a company incorporated under the law of England and Wales and registered at Companies House under number 17296846, with its registered office at Suite A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom (the “Processor”).
  2. 2.
    The Agreement is concluded when it is accepted on creating the Venue account or in the Panel, forms part of the services contract concluded under the Terms for Venues (the “Main Contract”), and implements the requirements of Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).
  3. 3.
    Capitalised terms not defined in the Agreement have the meanings given to them in the Terms for Venues. Breach means a personal data breach within the meaning of Article 4(12) GDPR, and Sub-processor means an entity to which the Processor sub-contracts the processing of the Data.
  4. 4.
    The Polish version of the Agreement is binding. The English version is a courtesy translation.

§ 2. Subject matter and scope

  1. 1.
    The Controller entrusts the Processor with processing the personal data that the Controller enters into the Panel or that is kept in the Panel for the Controller’s purposes (the “Data”), in particular:
    1. 1)entries in the booking book, including bookings taken outside the Service and walk-in guests;
    2. 2)notes and visit histories of guests kept in the Panel;
    3. 3)messages exchanged with guests through the Panel;
    4. 4)data about members of the Controller’s team, as regards their roles, permissions and activity log in the Panel.
  2. 2.
    The Agreement does not cover data that the Processor processes as an independent controller, in particular Guests’ account data, Booking data as regards receiving Bookings and passing them to the Controller, billing data and the data described in the Privacy Policy.
  3. 3.
    Nature of the processing: storing, organising, displaying, searching, sending notifications about and deleting the Data in a cloud-based IT system.
  4. 4.
    Purpose of the processing: providing the Panel services to the Controller under the Main Contract.
  5. 5.
    Types of Data: name, telephone number, email address, date, time and number of people, special requests, notes, visit history, content of messages and data about team members (name, email address, role and activity log). Special requests and notes may contain data concerning health, in particular information about food allergies, if entered.
  6. 6.
    Categories of data subjects: the Controller’s guests, people making bookings on their behalf and members of the Controller’s team.
  7. 7.
    Duration of the processing: the term of the Main Contract and, after it ends, the time needed to return or delete the Data in accordance with § 9.
  8. 8.
    The Controller declares that it has a legal basis for processing the Data and for entrusting its processing and, where it enters data concerning health into the Panel, a basis under Article 9(2) GDPR as well.

§ 3. Obligations of the Processor

  1. 1.
    The Processor:
    1. 1)processes the Data only on the documented instructions of the Controller, including with regard to transfers of Data to a third country; the instructions are the Agreement, the Main Contract and the Controller’s settings and actions in the Panel;
    2. 2)where Union or Member State law requires it to process the Data, informs the Controller of that requirement before processing, unless that law prohibits such information;
    3. 3)immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions;
    4. 4)ensures that persons authorised to process the Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
    5. 5)applies the security measures required under Article 32 GDPR, described in § 6;
    6. 6)complies with the conditions for engaging Sub-processors set out in § 4;
    7. 7)taking into account the nature of the processing, assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from data subjects exercising their rights;
    8. 8)forwards to the Controller without undue delay, and in any event within 5 business days, any requests from data subjects addressed directly to the Processor, and does not answer them itself unless the Controller authorises it to do so;
    9. 9)taking into account the nature of the processing and the information available to it, assists the Controller in complying with the obligations under Articles 32 to 36 GDPR;
    10. 10)deletes or returns the Data after the end of the services in accordance with § 9;
    11. 11)makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on the terms set out in § 7.

§ 4. Sub-processors

  1. 1.
    The Controller gives the Processor general authorisation to engage Sub-processors. On the date the Agreement is concluded, the Sub-processors are:
    1. 1)Google Ireland Limited (Ireland) and Google LLC (United States) – Firebase services: the Cloud Firestore database and file storage in data centres within the European Economic Area, and user authentication;
    2. 2)Vercel Inc. (United States) – hosting and running the application in the Frankfurt am Main region (Germany);
    3. 3)Resend (United States) – sending emails, including booking confirmations;
    4. 4)650 Industries, Inc. (Expo, United States) – delivering push notifications to the mobile application.
  2. 2.
    The Processor informs the Controller of any intended change concerning the addition or replacement of a Sub-processor by email to the address associated with the Venue account, at least 14 days before the change, identifying the Sub-processor, the activities entrusted to it and the place of processing.
  3. 3.
    Within the period referred to in paragraph 2, the Controller may object to the change on reasonable grounds relating to data protection. If the parties do not agree on a solution, the Controller may terminate the Main Contract with effect from the date of the change, in which case the fee for the unused part of the billing period is refunded.
  4. 4.
    The Processor imposes on each Sub-processor, by contract, the same data protection obligations as are set out in the Agreement, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that Sub-processor’s obligations.
  5. 5.
    Stripe provides payment services to the Controller under a separate agreement concluded directly between the Controller and Stripe and is not a Sub-processor.

§ 5. Transfers of Data to third countries

  1. 1.
    The Processor is established in the United Kingdom. Access to the Data from the United Kingdom takes place on the basis of the European Commission’s decision finding an adequate level of protection of personal data in the United Kingdom.
  2. 2.
    Transfers of Data to Sub-processors in the United States take place on the basis of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework where the Sub-processor participates in that framework, and otherwise on the basis of standard contractual clauses adopted by the European Commission.
  3. 3.
    The Controller instructs the Processor to transfer the Data to the extent described in this section.

§ 6. Security measures

  1. 1.
    The Processor applies, in particular, the following measures:
    1. 1)encryption of connections using TLS;
    2. 2)encryption of the Data at rest by the infrastructure provider;
    3. 3)no direct access to the database from browsers or applications, and access to the Data only through the application server, which checks permissions on every request;
    4. 4)access control in the Panel based on roles and permissions set by the Controller, mandatory two-factor authentication for team members invited to the Panel by the Controller, and the option for the person who created the Venue account to turn it on;
    5. 5)access by the Processor’s staff only through the administration panel, with mandatory two-factor authentication, restriction to trusted devices or networks, permissions granted according to job responsibilities and logging of actions;
    6. 6)passwords managed by the Firebase Authentication service and never stored in plain text;
    7. 7)limits on the number of sign-in and other attempts;
    8. 8)storage of the database and files in data centres within the European Economic Area.
  2. 2.
    The Processor regularly assesses the effectiveness of the measures and may change them, provided that a change does not lower the level of protection of the Data.

§ 7. Information and audit

  1. 1.
    At the Controller’s request, the Processor makes available the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, in particular a description of the measures applied, the current list of Sub-processors and answers to the Controller’s reasonable questions.
  2. 2.
    The Controller, or an auditor mandated by the Controller and bound by confidentiality, may carry out an audit, including an inspection, after giving the Processor at least 14 days’ notice. An audit is carried out on business days, in a way that does not disrupt the Processor’s business or endanger the security of other customers’ data, and no more than once a year, unless there is a reasonable suspicion of a breach of the Agreement or a supervisory authority requires the audit.
  3. 3.
    The Controller bears the costs of an audit, unless the audit reveals a material breach of the Agreement by the Processor.

§ 8. Personal data breaches

  1. 1.
    After becoming aware of a Breach affecting the Data, the Processor notifies the Controller without undue delay, and in any event within 36 hours, by email to the address associated with the Venue account.
  2. 2.
    The notification contains at least the information referred to in Article 33(3) GDPR, to the extent available. Information that cannot be provided at once is provided in phases without undue delay.
  3. 3.
    The Processor promptly takes action to mitigate the effects of the Breach, documents it and cooperates with the Controller in investigating the Breach and notifying it to the supervisory authority.

§ 9. End of processing

  1. 1.
    After the Main Contract ends, the Processor, as the Controller decides within 30 days, returns the Data in electronic form or deletes it. If the Controller does not communicate a decision within that period, the Processor deletes the Data within a further 60 days.
  2. 2.
    The obligation to delete does not apply to Data whose further storage is required by Union or Member State law, or to data that the Processor processes as an independent controller in accordance with § 2(2).
  3. 3.
    At the Controller’s request, the Processor confirms that the Data has been deleted.

§ 10. Final provisions

  1. 1.
    The parties’ liability to data subjects is governed by Article 82 GDPR. The parties’ liability to each other is governed by the Terms for Venues, to the extent permitted by law.
  2. 2.
    In matters of personal data protection, the provisions of the Agreement take precedence over those of the Main Contract.
  3. 3.
    The Agreement remains in force for the term of the Main Contract and until the obligations in § 9 have been performed.
  4. 4.
    The Agreement is amended in the manner provided for amendments to the Terms for Venues.
  5. 5.
    The Agreement is governed by Polish law.
  6. 6.
    Matters concerning the Agreement should be addressed to privacy@tujemy.com.
  7. 7.
    This version of the Agreement applies from 17 September 2026 to Controllers who create a Venue account from that day, and to other Controllers from the day stated in the notice of change, but no earlier than 15 days after that notice was received.

SHA-256 tekstu polskiego

92be3568609d6aaaaf7f3760f8501785ad4beb1f904da9a62f79579eea20b6c5

Skrót pozwala sprawdzić, że ten tekst jest dokładnie tym, który zapisano przy akceptacji.