Legal

Data Processing Agreement

Last updated 16 July 2026 · Article 28 GDPR

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Merchant (“Controller”) and Horecarte BV, trading as Deposiq (“Processor”), and applies where Deposiq processes personal data on the Merchant’s behalf under Article 28 GDPR.

Template to be reviewed by legal counsel before it is relied upon.

1. Roles

The Merchant is the controller of guest personal data collected through Deposiq. Horecarte BV acts as processor, processing that data only to provide the Service.

2. Scope & instructions

The Processor shall process personal data only on the Controller’s documented instructions, including as set out in the Terms and this DPA, unless required otherwise by EU or Member State law (in which case it will inform the Controller, unless legally prohibited).

3. Confidentiality

The Processor ensures that persons authorised to process the data are bound by confidentiality.

4. Security

The Processor implements appropriate technical and organisational measures under Article 32 GDPR, as described on the Security page (Annex III).

5. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex II. The Processor imposes equivalent data-protection obligations on each sub-processor and remains liable for their performance. We will give notice of intended changes and the Controller may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
Hetzner Online GmbHCloud hosting & infrastructureGermany / Finland (EU)
Stripe Payments Europe, Ltd.Card payment processing (on the merchant’s own connected account)Ireland (EU)
Mollie B.V.Payment processing (on the merchant’s own connected account)Netherlands (EU)
Brevo (Sendinblue SAS)Transactional email deliveryFrance (EU)

6. Assisting the Controller

Taking into account the nature of the processing, the Processor assists the Controller with: responding to data-subject requests; and its obligations under Articles 32–36 (security, breach notification, impact assessments and prior consultation).

7. Personal data breach

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and provides the information the Controller reasonably needs to meet its own notification duties.

8. International transfers

The Processor processes personal data within the EU/EEA only. Any transfer outside the EU/EEA will be covered by an approved safeguard (e.g. Standard Contractual Clauses).

9. Audit

The Processor makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an appointed auditor, on reasonable notice and subject to confidentiality.

10. Deletion or return

On termination of the Service, the Processor deletes or returns all personal data at the Controller’s choice, and deletes existing copies unless EU or Member State law requires storage.

11. Liability & governing law

Liability is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the Netherlands.

Annex I — Details of processing

  • Subject matter: provision of the Deposiq security-deposit management Service.
  • Duration: for the term of the Service.
  • Nature & purpose: requesting, recording, tracking, evidencing and resolving security deposits.
  • Data subjects: the Merchant’s guests / customers.
  • Categories of data: name, email, phone; deposit amount, method, status and timeline; evidence documents and photos uploaded by the Merchant; IP address and timestamps of guest actions.
  • Special categories: none required by the Service. The Merchant should not upload special-category data.

Annex II — Sub-processors

As listed in the table above.

Annex III — Technical & organisational measures

As described on the Security page (EU hosting, encryption in transit and at rest, hashed passwords, admin 2FA, least-privilege access, rate limiting/firewall, SHA-256 evidence integrity, encrypted off-site backups).

Contact

Horecarte BV — privacy@deposiq.com.