To jest archiwalna wersja dokumentu. Nowe umowy zawiera się według wersji obowiązującej.

Zobacz wersję obowiązującą

Wersja 2026-07-31

Data processing agreement (DPA)

Opublikowano 31 lipca 2026 r.

To jest tłumaczenie pomocnicze. Wiążąca jest polska wersja dokumentu.

Wersja polska

This document sets out how AUTH LTD (“Tujemy”, “the Processor”) processes guests' personal data on behalf of a partner venue (“the Controller”) in connection with the use of the Tujemy platform, available at tujemy.com. Depending on the venue, reservations are handled directly by the Tujemy system or, for venues using that integration, passed through to the GetUp panel; the terms below apply in both cases. By registering a venue with Tujemy, you accept the terms of this agreement.

1. Parties and subject matter

The controller of the personal data of guests making reservations is the partner venue (a restaurant or a hotel). AUTH LTD (no. 17296846, Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE) acts as a data processor within the meaning of Article 28 GDPR, to the extent needed to handle reservations made by guests through Tujemy.

2. Nature and purpose of processing

Data is processed solely so that the venue can handle the reservation: confirming the time, contacting the guest and delivering the service booked.

3. Categories of data and of data subjects

  • the guest's first and last name,
  • email address and phone number,
  • reservation details: time, party size, special requests,
  • reservation history and reviews of the venue.

4. Tujemy's obligations as a processor

  • we process data only on the Controller's documented instructions and only as far as providing the reservation service requires,
  • we ensure that data is accessible only to people bound by a duty of confidentiality,
  • we apply the technical and organisational measures described in section 6,
  • we assist the Controller in handling the exercise of data subject rights and in meeting the obligations under Articles 32 to 36 GDPR,
  • once the cooperation ends we delete or return the data, unless the law requires us to keep it.

5. Subprocessors

We use the following subprocessors:

  • Google Cloud / Firebase (Google Ireland Limited): database hosting and authentication,
  • Stripe: payments and reservation deposits (applies to venues taking deposits through Tujemy),
  • Resend: transactional email delivery (confirmations, reservation requests),
  • GetUp: handling reservations and availability on the venue's behalf (applies to venues using that integration).

The list of subprocessors may change; we give partner venues advance notice of material changes.

6. Security measures

We use encrypted connections (TLS), role-based access control and authentication managed by Firebase Authentication. User passwords are never stored by Tujemy in plain text.

7. Transfers outside the EEA

AUTH LTD is a company registered in the United Kingdom. To the extent that processing involves transferring data outside the European Economic Area, we rely on the standard contractual clauses approved by the European Commission or on another appropriate mechanism under Chapter V GDPR.

8. Reporting breaches

We will inform the Controller of any personal data breach affecting data processed for its venue without undue delay, and no later than 72 hours after we become aware of the breach.

9. Term and contact

This agreement applies for as long as the venue works with Tujemy. For matters concerning data processing and this agreement, contact us at support@tujemy.com.

SHA-256 tekstu polskiego

384b303f210d2da5e0334eb0488b10c8b893207c2856efebdf34f250b78a3b45

Skrót pozwala sprawdzić, że ten tekst jest dokładnie tym, który zapisano przy akceptacji.