Back to home

GDPR Article 28

Data Processing Agreement Template

Controller-to-processor terms for venues that use PROMTIS to process staff, guest, order, delivery, feedback, and operational data.

Last updated: August 28, 2026

Document status

This is the current PROMTIS Data Processing Agreement template. It is intended to form part of a customer agreement only when the parties identify the Customer and PROMTIS legal entities and accept it through an order form, signed agreement, or another recorded acceptance mechanism.

The PROMTIS operator is TECHBRAIN d.o.o., Slovenia. Its complete registered details and the governing-law fields must be confirmed before execution. Publishing this template does not itself create a signed agreement with a visitor.

1. Roles and scope

For personal data that a venue submits to or collects through PROMTIS for its restaurant operations, the venue is the controller and PROMTIS acts as processor. PROMTIS may act as an independent controller for its own account administration, billing, security, legal compliance, and direct support records as described in the Privacy Notice.

This DPA applies only to processing performed by PROMTIS on behalf of the Customer under the applicable service agreement.

2. Processing instructions

PROMTIS will process Customer Personal Data only on documented instructions from the Customer, including instructions expressed through product configuration and ordinary use of the service, unless Union or Member State law requires otherwise.

If PROMTIS believes an instruction infringes applicable data-protection law, it will inform the Customer unless prohibited by law.

3. Confidentiality and security

PROMTIS will ensure that persons authorised to process Customer Personal Data are bound by confidentiality and will maintain technical and organisational measures appropriate to the risk. Measures include role-based access, authentication controls, transport security, restricted production access, logging and diagnostics, backup and recovery practices, and vulnerability and dependency maintenance appropriate to the service.

Customer remains responsible for configuring roles, limiting staff access, protecting credentials, and using the service lawfully.

4. Subprocessors

The Customer grants general written authorisation for PROMTIS to use subprocessors needed to operate the service. PROMTIS will impose data-protection obligations that are materially equivalent to those in this DPA and remains responsible for its subprocessors as required by Article 28 GDPR.

The providers confirmed by the operator are Railway for application hosting and Stripe for subscription and payment processing where enabled. User-requested AI features may involve the provider configured for that feature. Before this template is executed, PROMTIS must identify all subprocessors, their purposes, processing locations, and transfer safeguards in an up-to-date list.

PROMTIS must maintain an up-to-date subprocessor list with provider identity, purpose, processing location, and transfer safeguard. Customers must receive reasonable advance notice of material additions and a meaningful opportunity to object on data-protection grounds.

5. International transfers

PROMTIS will not transfer Customer Personal Data outside the EEA without a lawful transfer mechanism. Where required, the parties will rely on an adequacy decision, approved Standard Contractual Clauses, or another mechanism recognised by Chapter V GDPR, together with supplementary measures where appropriate.

6. Assistance to the Customer

Taking into account the nature of processing and the information available, PROMTIS will reasonably assist the Customer with data-subject requests, security obligations, personal-data breach notifications, data-protection impact assessments, and consultations with supervisory authorities.

PROMTIS will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information needed for the Customer's assessment and notification duties.

7. Deletion and return

At the end of the service, PROMTIS will delete or return Customer Personal Data at the Customer's choice, unless applicable law requires retention. Deletion from active systems and backups may follow documented operational retention cycles.

8. Audit information

PROMTIS will make information reasonably necessary to demonstrate compliance with Article 28 available to the Customer. Audits should first use current security documentation, questionnaires, and independent evidence where available. On-site or bespoke audits require reasonable notice, confidentiality, proportional scope, and allocation of exceptional costs unless a confirmed breach requires otherwise.

Annex A: processing details

Subject matter and duration: operation of the subscribed PROMTIS services for the term of the customer agreement and applicable deletion period.

Nature and purpose: hosting venue content, managing users and roles, receiving and routing orders, kitchen and warehouse operations, reports, feedback, support, and customer-requested translation or generation.

Data subjects: customer owners and staff, venue guests and order recipients, support contacts, suppliers and other individuals whose details the Customer enters into the service.

Personal data: names, contact details, account identifiers, roles, order and table details, guest feedback, delivery information, staff activity, supplier contacts, device and security logs, and content submitted for support or AI-assisted features. Customers must not submit special-category data unless expressly agreed and lawfully supported.

Annex B: fields required before execution

PROMTIS legal entity, registered address, registration and tax numbers, signatory, governing law, competent courts, primary hosting and database regions, definitive subprocessor list, retention schedule, breach contact, and the applicable Standard Contractual Clause modules must be completed and approved before this template is executed.