This document sets out how AUTH LTD (“Tujemy”, “the Processor”) processes guests' personal data on behalf of a partner venue (“the Controller”) in connection with the use of the Tujemy platform, available at tujemy.com. Depending on the venue, reservations are handled directly by the Tujemy system or, for venues using that integration, passed through to the GetUp panel; the terms below apply in both cases. By registering a venue with Tujemy, you accept the terms of this agreement.
1. Parties and subject matter
The controller of the personal data of guests making reservations is the partner venue (a restaurant or a hotel). AUTH LTD (no. 17296846, Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE) acts as a data processor within the meaning of Article 28 GDPR, to the extent needed to handle reservations made by guests through Tujemy.
2. Nature and purpose of processing
Data is processed solely so that the venue can handle the reservation: confirming the time, contacting the guest and delivering the service booked.
3. Categories of data and of data subjects
- the guest's first and last name,
- email address and phone number,
- reservation details: time, party size, special requests,
- reservation history and reviews of the venue.
4. Tujemy's obligations as a processor
- we process data only on the Controller's documented instructions and only as far as providing the reservation service requires,
- we ensure that data is accessible only to people bound by a duty of confidentiality,
- we apply the technical and organisational measures described in section 6,
- we assist the Controller in handling the exercise of data subject rights and in meeting the obligations under Articles 32 to 36 GDPR,
- once the cooperation ends we delete or return the data, unless the law requires us to keep it.
5. Subprocessors
We use the following subprocessors:
- Google Cloud / Firebase (Google Ireland Limited): database hosting and authentication,
- Stripe: payments and reservation deposits (applies to venues taking deposits through Tujemy),
- Resend: transactional email delivery (confirmations, reservation requests),
- GetUp: handling reservations and availability on the venue's behalf (applies to venues using that integration).
The list of subprocessors may change; we give partner venues advance notice of material changes.
6. Security measures
We use encrypted connections (TLS), role-based access control and authentication managed by Firebase Authentication. User passwords are never stored by Tujemy in plain text.
7. Transfers outside the EEA
AUTH LTD is a company registered in the United Kingdom. To the extent that processing involves transferring data outside the European Economic Area, we rely on the standard contractual clauses approved by the European Commission or on another appropriate mechanism under Chapter V GDPR.
8. Reporting breaches
We will inform the Controller of any personal data breach affecting data processed for its venue without undue delay, and no later than 72 hours after we become aware of the breach.
9. Term and contact
This agreement applies for as long as the venue works with Tujemy. For matters concerning data processing and this agreement, contact us at support@tujemy.com.