Legal
Data Processing Addendum
- Effective
- Effective date: 2 August 2026
- Updated
- Last updated: 2 August 2026
- Version
- Version 1.0
Service provider: ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ, a sole proprietorship established in Greece, trading as “DineSlate”. Registered address: 151 Makrygianni Street, Moschato 18346, Greece. VAT number: 079009366, ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ. Legal and data-protection contact: reservations@dineslate.com.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and governs the personal data DineSlate processes on the restaurant’s behalf.
1. Parties and roles
Controller: the restaurant using the platform.
Processor: DineSlate.
This DPA does not cover processing for which DineSlate acts as an independent controller (accounts, authentication, device licensing, billing, security, support, legal compliance).
2. Subject matter, duration, nature and purpose
| Item | Description |
|---|---|
| Subject matter | Provision of the reservation platform and its related features |
| Duration | For as long as the agreement between the restaurant and DineSlate is in force |
| Nature and purpose | Receiving and managing reservations, waitlist, CRM, operational emails, evaluations, operational analytics |
| Data categories | Identity and contact data, reservation data, preferences and notes, allergy/dietary information as entered, evaluations, recorded visit bill |
| Data subjects | Guests of the restaurant and the restaurant’s contact persons |
3. Documented instructions
DineSlate processes the data only on the restaurant’s documented instructions, as expressed in the Terms of Service, the platform configuration and the restaurant’s use of the features.
If DineSlate considers an instruction to infringe data-protection law, it will inform the restaurant.
4. Controller obligations
- to have a lawful basis for every processing operation it instructs
- to secure an Article 9 condition where health data such as allergies is recorded
- to provide the required information notices to data subjects
- not to record irrelevant or excessive sensitive data in free-text notes
- to manage its own staff accounts and remove access promptly
5. Confidentiality
Every person authorised by DineSlate to process the data is bound by a duty of confidentiality.
6. Security measures (Article 32)
- encryption in transit
- role-based access control and per-restaurant data isolation
- database-level access restrictions
- device installation licensing and control
- action logging and audit records
- private storage for internal files
- managed backups provided by the infrastructure provider
7. Subprocessors
The restaurant grants general authorisation for the use of subprocessors.
DineSlate uses third-party technology providers, including Supabase for database, authentication, storage and related cloud functionality, and Resend for operational email delivery. Processing locations, authorised subprocessors and international-transfer mechanisms are described in the providers’ current official legal and technical documentation and, where required, in the contractual safeguards applicable to DineSlate’s use of their services.
The current list is published at /en/subprocessors. Before a subprocessor is added or replaced, that page is updated so the restaurant can object on reasonable data-protection grounds.
DineSlate imposes on its subprocessors data-protection obligations materially equivalent to these, and remains responsible for their acts to the extent provided by Article 28 GDPR.
8. International transfers
- Personal data may be processed inside the European Economic Area (EEA) and in third countries.
- DineSlate does not guarantee EEA-only processing unless this has been verified for the relevant service.
- The applicable transfer safeguards depend on the provider, the processing context and the current contractual documentation, such as Standard Contractual Clauses or another Chapter V GDPR mechanism.
- Provider subprocessor lists and processing locations may change.
- DineSlate updates its Subprocessor List when a material change affects its own processing.
9. Assistance to the controller
- assistance in responding to data-subject requests through the platform’s features
- assistance with security of processing, breach notification and impact assessments, taking into account the nature of processing and the information available
10. Personal data breaches
DineSlate notifies the restaurant without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, and provides the information reasonably available to it.
Notification to the supervisory authority and, where required, to data subjects remains the restaurant’s responsibility as controller.
11. Return and deletion
On termination, DineSlate deletes or returns the data at the restaurant’s choice, unless retention is required by law.
The restaurant can export its operational data before termination using the platform’s export tools.
Data remaining in backups is deleted as the corresponding backup cycle expires.
12. Audit and evidence of compliance
DineSlate makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including subprocessor documentation.
Audits take place on reasonable written notice, during business hours, without access to other customers’ data, and in a manner that does not disrupt the security or operation of the platform.
13. Liability
To the maximum extent permitted by applicable law, DineSlate’s total aggregate liability for all claims arising from or relating to a specific Affected Service will not exceed the greater of: (a) five hundred euros (€500); and (b) the total amounts paid or payable by the Restaurant for that specific Affected Service during the twelve (12) months preceding the event giving rise to the claim.
The limitation does not apply in the following cases:
- fraud or fraudulent misrepresentation;
- wilful misconduct or intent;
- gross negligence, where limitation in advance is prohibited;
- death or personal injury, where liability cannot lawfully be limited;
- mandatory liability under data-protection law;
- any other liability that applicable law does not permit the parties to exclude or limit.
Administrative fines and third-party claims are allocated in accordance with the roles and responsibilities set out in the GDPR.
14. Governing law
Governing law: the laws of Greece. Competent courts: the competent courts of Athens, Greece.
Provider details
- Legal name
- ΔΗΜΗΤΡΙΟΣ ΦΑΡΣΕΔΑΚΗΣ
- Legal form
- sole proprietorship established in Greece
- Trading name
- DineSlate
- VAT number
- 079009366
- Tax office
- ΚΕΦΟΔΕ ΑΤΤΙΚΗΣ
- Registered address
- 151 Makrygianni Street, Moschato 18346, Greece
- Governing law
- the laws of Greece
- Courts
- the competent courts of Athens, Greece
Contact: reservations@dineslate.com