Skip to content

Data Processing Agreement (DPA) – Plattio

This Data Processing Agreement (the "DPA") forms an integral part of the Terms of Service of Plattio (the "Terms") and is accepted together with them. It governs the processing of personal data that Plattio LLC ("Plattio") carries out on behalf of the customer (the "Customer") in providing the Service, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR"). In data protection matters, this DPA prevails over the Terms, and the Standard Contractual Clauses referred to in Clause 9 prevail over both.

1. Parties and roles

The Customer acts as the Controller and Plattio as the Processor. The terms "personal data," "processing," "data subject," "personal data breach," and similar terms have the meaning given to them by the GDPR.

2. Details of the processing

  • Subject matter and nature: hosting and management of reservations and waitlists, messaging (confirmations, reminders, and campaigns), CRM, analytics and reporting (including artificial intelligence features), and technical support.
  • Purpose: the provision of the Service in accordance with the Terms.
  • Duration: the term of the agreement, plus the deletion periods set out in Clause 10.
  • Categories of data subjects: the Customer's end customers (diners) and the Customer's staff.
  • Types of data: identification and contact data, reservation data, history and notes, preferences, and platform usage data.
  • The Customer undertakes not to enter special categories of data (Art. 9 GDPR) or data of minors below the applicable minimum age.

3. Instructions

Plattio will process personal data only in accordance with the Customer's documented instructions, which are set out in the Terms, in this DPA, and in the configuration of the Service made by the Customer. Plattio will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Staff confidentiality

Plattio ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access the data only to the extent necessary to provide the Service.

5. Security

Plattio applies appropriate technical and organizational measures (Art. 32 GDPR), including: TLS/AES encryption, role-based access control, multi-factor authentication for administrators, access and audit logs, encrypted backups with periodic testing, environment separation, security testing, and protection against DDoS attacks. These measures constitute Annex II for the purposes of the Standard Contractual Clauses referred to in Clause 9.

6. Sub-processors

The Customer provides general authorization for the engagement of sub-processors. The current list appears in the sub-processors section of the Privacy Policy and is available at [email protected]. Plattio will give at least 30 days' notice of additions or replacements (by email or a notice on the platform); the Customer may object on reasonable data protection grounds and, if no solution is reached, terminate the affected part of the Service. Plattio imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA and remains liable to the Customer for its sub-processors' compliance.

7. Assistance and breach notification

Taking into account the nature of the processing, Plattio will assist the Customer: (a) in handling data subjects' rights, forwarding to the Customer without delay any requests it receives and providing the tools of the Service; and (b) in complying with the obligations regarding security, breach notification, impact assessments, and prior consultations (Arts. 32 to 36 GDPR), with the information available to it. Plattio will notify the Customer of any personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it, with the available information under Art. 33(3) GDPR.

8. Audits

Plattio will make available to the Customer the information necessary to demonstrate compliance with this DPA, first through the documentation, certifications, and reports available to it. The Customer may conduct an audit (itself or through a non-competitor third party bound by confidentiality) at most once a year, with 30 days' notice, during business hours, without accessing other customers' data or compromising the security of the platform, and bearing its costs.

9. International transfers

Data is processed in the United States and other countries. For transfers from the EEA, by accepting this DPA the parties enter into the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), module two (controller to processor), which are incorporated by reference: Annex I is completed with the parties and processing details in Clauses 1 and 2 of this DPA; Annex II, with the measures in Clause 5; Clause 17 is governed by Spanish law and Clause 18 designates the Spanish courts. Sub-processors established in the United States cover their transfers under their EU–US Data Privacy Framework certifications or their own Standard Contractual Clauses.

10. Deletion and return

Upon termination of the Service, the Customer has 30 days to export its data in a commonly used, machine-readable format. After that period, Plattio will delete the personal data processed on behalf of the Customer, and backups will be permanently deleted within a maximum of 90 days, unless a legal obligation requires their retention.

11. Liability

Liability between the parties arising from this DPA is subject to the limits set out in the Terms, without prejudice to the rights of data subjects (who may invoke the Standard Contractual Clauses as third-party beneficiaries) or to the liability regime under Article 82 GDPR.

12. Term and contact

This DPA remains in force for as long as Plattio processes personal data on behalf of the Customer. For any matter relating to this DPA:

Plattio LLC

Email: [email protected]

Address: 8 The Green STE B, Dover, DE 19901, United States

Last updated: July 28, 2026