Data processing agreement Jesdi
This is a translation of the Dutch original. In case of any difference in meaning, the Dutch version prevails.
This data processing agreement is concluded between:
- the Customer: the business that signs up for the Service of Jesdi and in doing so accepts this data processing agreement, hereinafter: the Controller; and
- Jesdi, established at Eksterstraat 139, 1742 ER Schagen, registered with the Netherlands Chamber of Commerce (Kamer van Koophandel, KvK) under number [KvK-nummer], hereinafter: the Processor.
The Controller and the Processor are together referred to as the Parties.
Recitals
- The Parties have concluded an agreement for the use of the online reservation system of Jesdi (the Main Agreement), to which the terms and conditions of Jesdi apply.
- In performing the Main Agreement, the Processor processes personal data on behalf of the Controller. The Controller determines the purposes and means of that processing.
- In this agreement the Parties record their arrangements, as required by Article 28 of the General Data Protection Regulation (GDPR; in Dutch: AVG).
- This agreement is concluded digitally: the Customer expressly accepts it by ticking a box when signing up or when logging in for the first time. The Processor records which version was accepted, at what time and by whom.
Article 1 – Definitions
Terms such as personal data, processing, data subject, personal data breach (data breach) and sub-processor have the meaning given to them by the GDPR.
Article 2 – Subject matter and instructions
- The Processor processes personal data exclusively on behalf of the Controller and only insofar as necessary to provide the Service, as described in Annex 1.
- The Processor processes personal data only on the basis of documented instructions from the Controller. The Main Agreement, this agreement and the way in which the Controller uses and configures the Service count as those instructions.
- The Processor does not process the personal data for its own purposes, does not sell them and does not use them for advertising or profiling.
- If the Processor is of the opinion that an instruction infringes the GDPR or other legislation, the Processor will inform the Controller of this immediately.
- If the Processor is required by law to process or disclose personal data (for example by order of a court), the Processor will inform the Controller of this in advance, unless the law prohibits this.
Article 3 – Obligations of the Controller
- The Controller warrants that the processing of personal data using the Service is lawful, that there is a valid legal basis and that data subjects (such as guests) are properly informed, for example in the Controller's own privacy statement.
- The Controller sends newsletters and monthly menus only to guests who have given their consent for this.
- The Controller does not record more data than necessary, in particular with regard to data concerning health such as allergies or dietary requirements in comments.
Article 4 – Confidentiality
- The Processor keeps the personal data confidential. Only persons who need them to provide, maintain or support the Service are given access, and only insofar as necessary.
- Everyone who has access to personal data on behalf of the Processor is bound by a duty of confidentiality.
- The Processor only views the Controller's back office if this is necessary for support or to resolve a fault, or at the request of the Controller.
Article 5 – Security
- The Processor takes appropriate technical and organisational measures to protect the personal data against loss and unlawful processing, taking into account the state of the art, the costs and the risks. These measures are set out in Annex 2.
- The Processor may adjust the measures, provided that the level of security is not reduced.
Article 6 – Sub-processors
- The Controller gives the Processor general authorisation to engage sub-processors. The sub-processors currently used are listed in Annex 3.
- The Processor will inform the Controller by e-mail at least one month in advance of the addition or replacement of a sub-processor. The Controller may object, stating reasons, within that period. If the Parties cannot reach agreement, the Controller may cancel the Main Agreement free of charge with effect from the date on which the change takes effect.
- The Processor imposes on sub-processors at least the same obligations as set out in this agreement and remains responsible towards the Controller for their compliance.
Article 7 – Transfers outside the European Economic Area
- The Processor stores the personal data within the European Economic Area (EEA).
- A transfer to a country outside the EEA takes place only if there is a valid basis for it under Chapter V of the GDPR, such as an adequacy decision (including the EU-U.S. Data Privacy Framework) or standard contractual clauses of the European Commission.
- For push notifications, encrypted messages pass through the notification services of the manufacturer of the phone or browser (see Annex 3). The content is end-to-end encrypted in accordance with the Web Push standard; these services cannot read the content.
Article 8 – Rights of data subjects
- The Service contains functions with which the Controller can itself handle requests from data subjects, such as exporting (access) and erasing (right to be forgotten) guest data and withdrawing marketing consent.
- Where that is not sufficient, the Processor will assist the Controller within a reasonable time in handling requests from data subjects.
- If the Processor itself receives a request from a data subject, the Processor will forward it to the Controller and will not handle it itself, unless the Controller instructs it to do so.
Article 9 – Data breaches
- The Processor will inform the Controller without undue delay, and where possible within 36 hours of the Processor becoming aware of it, of a data breach concerning the Controller's personal data.
- The notification contains, insofar as known: the nature of the breach, the categories of data and data subjects concerned, the approximate number, the likely consequences and the measures taken or to be taken. Information that is not yet known will be supplemented as soon as possible.
- The Controller decides whether the breach is notified to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and/or to data subjects. The Processor assists with this and itself takes all reasonable measures to limit the breach and prevent recurrence.
- The Processor keeps a record of all data breaches.
Article 10 – Assistance and audits
- The Processor assists the Controller where reasonable in complying with the obligations under Articles 32 to 36 inclusive of the GDPR, such as a data protection impact assessment (DPIA) or a prior consultation.
- The Processor makes available all information necessary to demonstrate compliance with this agreement.
- The Controller may have compliance audited by an independent expert bound by confidentiality, no more than once a year and with at least four weeks' prior notice, unless there is a specific indication of a serious failure. The costs are borne by the Controller, unless the audit shows that the Processor fails to comply with this agreement in material respects.
- The Processor may charge a reasonable rate, notified in advance, for assistance that goes beyond what the Service itself makes possible, except where the need arises from a failure on the part of the Processor.
Article 11 – Liability
The liability of the Parties is governed by what has been agreed on this in the terms and conditions of Jesdi, on the understanding that liability towards data subjects and supervisory authorities is governed by Articles 82 and 83 of the GDPR.
Article 12 – Term and termination
- This agreement applies for as long as the Main Agreement is in force and thereafter for as long as the Processor still processes personal data of the Controller.
- Until the end date of the Main Agreement, the Controller can export the data itself. Until 30 days after the end, the Processor will make an export available on request. No later than 90 days after the end, the Processor will delete all personal data, unless a statutory retention obligation applies. Data disappear from back-ups no later than when those back-ups are overwritten, subject to a maximum of 90 days.
- On request, the Processor will confirm in writing that the data have been deleted.
Article 13 – Final provisions
- The Processor may amend this agreement in the manner set out in the terms and conditions. Amendments that reduce the protection of personal data will not take effect unless the Controller is able to cancel the Main Agreement free of charge.
- This agreement is governed by Dutch law. Disputes will be submitted to the court designated in the terms and conditions of Jesdi.
Annex 1 – Specification of the processing
| Purpose of the processing | Providing the online reservation system: receiving and managing reservations, recognising guests and counting their visits, sending confirmation and cancellation e-mails, sending notifications to the restaurant, sending newsletters (monthly menu) to guests who have given their consent for this, and handling privacy requests. |
|---|---|
| Categories of data subjects | Guests of the Controller who make a reservation or for whom a reservation is recorded; employees and other users of the Controller who have access to the back office or the app. |
| Categories of personal data – guests | Name, e-mail address, telephone number; date, time, number of persons, table and status of reservations; number of visits and no-shows; comments on a reservation and the restaurant's internal notes; whether and when consent for newsletters was given or withdrawn, with the text by which consent was given and an irreversibly encrypted (hashed) representation of the IP address as proof. |
| Special categories of personal data | Not intended to be processed. However, guests or the restaurant may record health information in comments, such as allergies or dietary requirements. This is used only for the visit and is erased along with the other data in the event of an erasure request or anonymisation. |
| Categories of personal data – users | Name, e-mail address, encrypted password, last login time, session data, and for push notifications a technical address of the device with a device description (such as "iPhone"). |
| Retention periods | For as long as the Main Agreement is in force, in accordance with the Controller's settings. By default, guests without consent for newsletters and without a reservation in the past 24 months are automatically anonymised; the Controller can adjust this period. After termination: see Article 12. |
| Place of processing | Within the EEA, with the exception of encrypted push notifications (see Article 7.3). |
Annex 2 – Security measures
- All connections to the Service are encrypted via HTTPS (TLS).
- Passwords are stored only as a strong, salted hash (scrypt); login is temporarily blocked after repeated failed attempts.
- Session cookies are HttpOnly and Secure; only a hash of session keys is stored.
- Each restaurant sees only its own data; every database query is scoped per restaurant.
- New users receive a personal invitation link that is valid for a limited time; no passwords are sent by e-mail.
- IP addresses in the consent log are stored only in hashed form.
- Protection against misuse of the reservation form (limit on the number of attempts, spam filter).
- Push notifications are end-to-end encrypted (Web Push, aes128gcm with VAPID).
- Daily back-ups, stored within the EEA and protected against unauthorised access.
- Administrative access to servers and the platform is restricted to the Processor and secured with strong passwords or keys.
- Software and operating systems are regularly updated with security updates.
- Automatic anonymisation of old guest data in accordance with the configured retention period.
Annex 3 – Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| STRATO AG | Hosting of the servers, database and back-ups | Germany, EU |
| STRATO AG | Sending e-mails (confirmations, notifications, newsletters) | Germany, EU |
| Google (Firebase Cloud Messaging), Apple (Apple Push Notification service), Mozilla (Autopush), Microsoft (Windows Push Notification Services) | Relaying encrypted push notifications to the phone or browser of users who have enabled notifications. The content cannot be read by these parties. | Worldwide; transfer on the basis of the EU-U.S. Data Privacy Framework or standard contractual clauses |