This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Merchant (“Controller”) and Horecarte BV, trading as Deposiq (“Processor”), and applies where Deposiq processes personal data on the Merchant’s behalf under Article 28 GDPR.
The Merchant is the controller of guest personal data collected through Deposiq. Horecarte BV acts as processor, processing that data only to provide the Service.
The Processor shall process personal data only on the Controller’s documented instructions, including as set out in the Terms and this DPA, unless required otherwise by EU or Member State law (in which case it will inform the Controller, unless legally prohibited).
The Processor ensures that persons authorised to process the data are bound by confidentiality.
The Processor implements appropriate technical and organisational measures under Article 32 GDPR, as described on the Security page (Annex III).
The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex II. The Processor imposes equivalent data-protection obligations on each sub-processor and remains liable for their performance. We will give notice of intended changes and the Controller may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting & infrastructure | Germany / Finland (EU) |
| Stripe Payments Europe, Ltd. | Card payment processing (on the merchant’s own connected account) | Ireland (EU) |
| Mollie B.V. | Payment processing (on the merchant’s own connected account) | Netherlands (EU) |
| Brevo (Sendinblue SAS) | Transactional email delivery | France (EU) |
Taking into account the nature of the processing, the Processor assists the Controller with: responding to data-subject requests; and its obligations under Articles 32–36 (security, breach notification, impact assessments and prior consultation).
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and provides the information the Controller reasonably needs to meet its own notification duties.
The Processor processes personal data within the EU/EEA only. Any transfer outside the EU/EEA will be covered by an approved safeguard (e.g. Standard Contractual Clauses).
The Processor makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an appointed auditor, on reasonable notice and subject to confidentiality.
On termination of the Service, the Processor deletes or returns all personal data at the Controller’s choice, and deletes existing copies unless EU or Member State law requires storage.
Liability is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the Netherlands.
As listed in the table above.
As described on the Security page (EU hosting, encryption in transit and at rest, hashed passwords, admin 2FA, least-privilege access, rate limiting/firewall, SHA-256 evidence integrity, encrypted off-site backups).
Horecarte BV — privacy@deposiq.com.
Cookies. We’d like to use Google Analytics to understand how the site is used. Nothing runs unless you accept — and you can change your mind anytime. See our Privacy Policy.