Skip to document content

Legal

Data Processing Addendum

Effective
Effective date: 2 August 2026
Updated
Last updated: 2 August 2026
Version
Version 1.0

Service provider: ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ, a sole proprietorship established in Greece, trading as “DineSlate”. Registered address: 151 Makrygianni Street, Moschato 18346, Greece. VAT number: 079009366, ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ. Legal and data-protection contact: reservations@dineslate.com.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service and governs the personal data DineSlate processes on the restaurant’s behalf.

1. Parties and roles

Controller: the restaurant using the platform.

Processor: DineSlate.

This DPA does not cover processing for which DineSlate acts as an independent controller (accounts, authentication, device licensing, billing, security, support, legal compliance).

2. Subject matter, duration, nature and purpose

2. Subject matter, duration, nature and purpose
ItemDescription
Subject matterProvision of the reservation platform and its related features
DurationFor as long as the agreement between the restaurant and DineSlate is in force
Nature and purposeReceiving and managing reservations, waitlist, CRM, operational emails, evaluations, operational analytics
Data categoriesIdentity and contact data, reservation data, preferences and notes, allergy/dietary information as entered, evaluations, recorded visit bill
Data subjectsGuests of the restaurant and the restaurant’s contact persons

3. Documented instructions

DineSlate processes the data only on the restaurant’s documented instructions, as expressed in the Terms of Service, the platform configuration and the restaurant’s use of the features.

If DineSlate considers an instruction to infringe data-protection law, it will inform the restaurant.

4. Controller obligations

  • to have a lawful basis for every processing operation it instructs
  • to secure an Article 9 condition where health data such as allergies is recorded
  • to provide the required information notices to data subjects
  • not to record irrelevant or excessive sensitive data in free-text notes
  • to manage its own staff accounts and remove access promptly

5. Confidentiality

Every person authorised by DineSlate to process the data is bound by a duty of confidentiality.

6. Security measures (Article 32)

  • encryption in transit
  • role-based access control and per-restaurant data isolation
  • database-level access restrictions
  • device installation licensing and control
  • action logging and audit records
  • private storage for internal files
  • managed backups provided by the infrastructure provider

7. Subprocessors

The restaurant grants general authorisation for the use of subprocessors.

DineSlate uses third-party technology providers, including Supabase for database, authentication, storage and related cloud functionality, and Resend for operational email delivery. Processing locations, authorised subprocessors and international-transfer mechanisms are described in the providers’ current official legal and technical documentation and, where required, in the contractual safeguards applicable to DineSlate’s use of their services.

The current list is published at /en/subprocessors. Before a subprocessor is added or replaced, that page is updated so the restaurant can object on reasonable data-protection grounds.

DineSlate imposes on its subprocessors data-protection obligations materially equivalent to these, and remains responsible for their acts to the extent provided by Article 28 GDPR.

8. International transfers

  • Personal data may be processed inside the European Economic Area (EEA) and in third countries.
  • DineSlate does not guarantee EEA-only processing unless this has been verified for the relevant service.
  • The applicable transfer safeguards depend on the provider, the processing context and the current contractual documentation, such as Standard Contractual Clauses or another Chapter V GDPR mechanism.
  • Provider subprocessor lists and processing locations may change.
  • DineSlate updates its Subprocessor List when a material change affects its own processing.

9. Assistance to the controller

  • assistance in responding to data-subject requests through the platform’s features
  • assistance with security of processing, breach notification and impact assessments, taking into account the nature of processing and the information available

10. Personal data breaches

DineSlate notifies the restaurant without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, and provides the information reasonably available to it.

Notification to the supervisory authority and, where required, to data subjects remains the restaurant’s responsibility as controller.

11. Return and deletion

On termination, DineSlate deletes or returns the data at the restaurant’s choice, unless retention is required by law.

The restaurant can export its operational data before termination using the platform’s export tools.

Data remaining in backups is deleted as the corresponding backup cycle expires.

12. Audit and evidence of compliance

DineSlate makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including subprocessor documentation.

Audits take place on reasonable written notice, during business hours, without access to other customers’ data, and in a manner that does not disrupt the security or operation of the platform.

13. Liability

To the maximum extent permitted by applicable law, DineSlate’s total aggregate liability for all claims arising from or relating to a specific Affected Service will not exceed the greater of: (a) five hundred euros (€500); and (b) the total amounts paid or payable by the Restaurant for that specific Affected Service during the twelve (12) months preceding the event giving rise to the claim.

The limitation does not apply in the following cases:

  • fraud or fraudulent misrepresentation;
  • wilful misconduct or intent;
  • gross negligence, where limitation in advance is prohibited;
  • death or personal injury, where liability cannot lawfully be limited;
  • mandatory liability under data-protection law;
  • any other liability that applicable law does not permit the parties to exclude or limit.

Administrative fines and third-party claims are allocated in accordance with the roles and responsibilities set out in the GDPR.

14. Governing law

Governing law: the laws of Greece. Competent courts: the competent courts of Athens, Greece.

Legal name
ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ
Legal form
sole proprietorship established in Greece
Trading name
DineSlate
VAT number
079009366
Tax office
ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ
Registered address
151 Makrygianni Street, Moschato 18346, Greece
Governing law
the laws of Greece
Courts
the competent courts of Athens, Greece

Contact: reservations@dineslate.com