Legal

Data Processing Agreement

Last updated: 14 August 2026· v1.0

1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between SIR PATRYK PEAS, ul. Długa 57c/45, 53-633 Wrocław, Poland, NIP (VAT): PL8982147972, operating as EasyLounge ("EasyLounge" or the "Processor"), and the Lounge Operator identified by the corresponding Account (the "Lounge Operator" or the "Controller").

This DPA is incorporated into the Terms by reference and does not require a separate signature: by accepting the Terms, the Lounge Operator also enters into this DPA. It applies whenever EasyLounge processes personal data on behalf of the Lounge Operator in connection with the easylounge.io platform and related services (the "Services"), and it constitutes the parties' agreement pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). In the event of a conflict between this DPA and the Terms with respect to the processing of personal data on the Lounge Operator's behalf, this DPA prevails.

2. Definitions and Roles

Terms such as "personal data", "processing", "controller", "processor", "data subject", "special categories of personal data", and "personal data breach" have the meanings given to them in the GDPR. "Customer Data" has the meaning given in the Terms.

Consistent with Section 1 of our Privacy Policy, the parties allocate roles as follows:

  • The Lounge Operator is the controller of personal data contained in Customer Data — in particular data relating to its own staff (including, where the optional face check-in feature is enabled, biometric face descriptors) and its venue operations. EasyLounge is the processor of that data and processes it only on the Lounge Operator's documented instructions, as set out in this DPA.
  • EasyLounge is an independent controller of personal data it processes for its own purposes — account registration and administration, billing, security and fraud prevention, analytics and improvement of its own Services, and legal compliance. That processing is described in the Privacy Policy and is not governed by this DPA.

3. Subject Matter, Duration, Nature and Purpose

EasyLounge processes Customer Data for the purpose of providing, operating, maintaining, securing, and supporting the Services, as further described in Annex I (Description of Processing). Processing continues for the duration of the Lounge Operator's subscription (including any trial period) and a subsequent wind-down period, after which personal data is deleted as described in Section 10.

4. Documented Instructions

EasyLounge processes Customer Data only on the Lounge Operator's documented instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by European Union or Member State law to which EasyLounge is subject; in that case, EasyLounge informs the Lounge Operator of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

The Lounge Operator's use and configuration of the Services constitute its complete documented instructions: creating an Account, entering and managing Customer Data, enabling or disabling features (such as face check-in or a point-of-sale integration), adjusting settings, and using in-product controls each instruct EasyLounge to process the data involved in the way the feature or setting describes. Additional or different instructions require the parties' written agreement and may be declined where they exceed what the Services provide.

EasyLounge informs the Lounge Operator without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law. EasyLounge may suspend execution of the instruction until it is confirmed or modified.

5. Confidentiality

EasyLounge ensures that every person it authorises to process Customer Data (including its personnel and contractors) is bound by a contractual or statutory obligation of confidentiality and processes Customer Data only as needed to perform their role in providing the Services.

6. Security of Processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, EasyLounge implements and maintains the technical and organizational measures described in Annex II (Technical and Organizational Measures), in accordance with Article 32 GDPR. EasyLounge may update those measures from time to time, provided that updates do not materially reduce the overall level of protection during the subscription term.

7. Sub-Processing

The Lounge Operator grants EasyLounge a general written authorization to engage the sub-processors listed in Annex III (Sub-Processors). EasyLounge imposes on each sub-processor, by way of contract, data-protection obligations providing materially the same level of protection as this DPA, and remains fully liable to the Lounge Operator for the performance of each sub-processor's obligations.

EasyLounge announces any intended addition or replacement of a sub-processor at least fourteen (14) days in advance by email to account owners. The Lounge Operator may object to the change on reasonable data-protection grounds within that period. Where the parties cannot resolve the objection, the Lounge Operator's remedy is to stop using the feature that the new sub-processor supports or, where the sub-processor is essential to the Services as a whole, to terminate the subscription in accordance with the Terms; fees already paid are handled as the Terms provide.

8. Assistance to the Controller

Taking into account the nature of the processing, EasyLounge assists the Lounge Operator:

  • with appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Lounge Operator's obligation to respond to data subjects exercising their rights under Articles 12–23 GDPR (access, rectification, erasure, restriction, portability, objection). In most cases the Services provide the means directly — Customer Data can be viewed, corrected, exported, and deleted through the dashboards and in-product controls; where a request cannot be satisfied that way, EasyLounge provides reasonable assistance on request;
  • in ensuring compliance with the Lounge Operator's obligations under Articles 32–36 GDPR (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the information available to EasyLounge. This includes providing the information about the face check-in feature that a Lounge Operator reasonably needs to carry out a data-protection impact assessment covering biometric processing.

9. Personal Data Breach

EasyLounge notifies the Lounge Operator without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects, and is supplemented as further information becomes available. EasyLounge provides reasonable cooperation with the Lounge Operator's own notification obligations under Articles 33–34 GDPR. Notification of, or response to, a breach is not an acknowledgement of fault or liability.

10. Deletion and Return of Data

The Lounge Operator can export its order history at any time during the subscription: orders beyond the plan's live window are archived as CSV files available for download in the admin (Settings → Billing), and current data remains accessible through the dashboards until deletion.

Upon termination or deletion of the account, EasyLounge deletes the Customer Data associated with the venue: the tenant's database records are removed (deletion cascades across all venue data, including staff records and face descriptors), stored files — including order archives and uploaded images — are purged from storage, and any point-of-sale credentials held in the encrypted secrets vault are deleted. EasyLounge may retain data only where and for as long as European Union or Member State law requires storage, and deletes it once that requirement lapses.

11. Audit and Information Rights

EasyLounge makes available to the Lounge Operator the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR. Audit and information requests are satisfied primarily through documentation: this DPA and its annexes, the Privacy Policy, the sub-processor list at /subprocessors, and the security documentation and certifications that our infrastructure providers publish on their own sites.

Where an audit beyond documentation is required by applicable data-protection law or by a competent supervisory authority, EasyLounge allows for and contributes to an audit or inspection conducted by the Lounge Operator or an independent auditor mandated by it, subject to reasonable prior written notice, at the Lounge Operator's cost, during normal business hours, no more than once per year (unless a supervisory authority requires otherwise), and under confidentiality obligations protecting EasyLounge's and other customers' information.

12. Special Category Data — Biometric Face Check-In

Where the Lounge Operator enables the optional face check-in feature, the Services process biometric face descriptors of the staff members the Lounge Operator enrols — special category data under Article 9 GDPR. For this processing:

  • The Lounge Operator is solely responsible for establishing a lawful basis — the enrolled person's explicit consent (Art. 9(2)(a)) or another valid Article 9 condition available under the law of its Member State. Some jurisdictions restrict or prohibit the processing of employee biometric data even with consent; the Lounge Operator must verify what its local law (including employment law) permits before enrolling anyone.
  • EasyLounge processes descriptors only to provide the feature — recognising enrolled staff when they clock in and out at the venue kiosk — and for no other purpose. The camera image is processed on the device and is not retained; only the numerical descriptor is stored.
  • Deletion controls are built in: the team admin includes a "Delete face data" action that removes a person's enrolled descriptors, descriptors are removed when the staff member is removed, and disabling the feature stops face matching. Enrolment is never the only way to record attendance — a manager can clock staff in and out manually.

13. International Transfers

EasyLounge's primary database and hosting are located in Switzerland, which benefits from a European Commission adequacy decision, so that transfer requires no additional safeguards. Certain sub-processors listed in Annex III may process limited personal data outside the EEA; where they do, the transfer is protected by an adequacy decision or by Standard Contractual Clauses approved by the European Commission, supplemented by additional measures where necessary, as reflected in Annex III and in Section 6 of the Privacy Policy.

14. Point-of-Sale Providers

A point-of-sale provider that the Lounge Operator connects to the Services is not a sub-processor of EasyLounge. The Lounge Operator engages that provider under its own agreement, and the provider processes order data (including any staff name or label the Lounge Operator's configuration attributes to orders) as the Lounge Operator's own processor or as an independent controller, as that agreement provides. EasyLounge transmits data to the provider solely on the Lounge Operator's documented instruction — connecting and enabling the integration is that instruction — as described in Section 5.5 of the Privacy Policy.

15. Liability

Each party is liable for damage caused by processing as allocated by Article 82 GDPR. The aggregate liability of each party under or in connection with this DPA is subject to the exclusions and the cap set out in Section 14 of the Terms, except to the extent that liability cannot lawfully be limited.

16. Governing Law and Venue

This DPA is governed by the laws of the Republic of Poland, together with directly applicable European Union law, and any dispute arising out of or in connection with it is subject to the dispute-resolution provisions of the Terms, including the exclusive jurisdiction of the competent courts of Wrocław, Poland.

Annex I — Description of Processing

Categories of data subjects

  • The Lounge Operator's staff: owners, managers, and kiosk-only staff members;
  • Individuals appearing incidentally in Customer Data the Lounge Operator chooses to enter.

Venue guests are not data subjects of this processing. Orders placed through the Services carry no guest names, contact details, or other guest personal data, and none are collected by the guest-facing wizard.

Categories of personal data

  • Staff identification and role data: names, display labels, roles, job-role labels;
  • Staff working-time data: clock-in and clock-out events, shifts, hours worked;
  • Where the Lounge Operator enables face check-in: biometric face descriptors of enrolled staff (special category data — Article 9 GDPR);
  • Where the Lounge Operator connects a point-of-sale integration and attributes orders to staff: the staff name or label transmitted with orders;
  • Venue operational data entered by or on behalf of the Lounge Operator (inventory, blends, orders, tables, device labels), to the extent it contains personal data.

Nature and purpose of processing

Hosting, storage, transmission, display, synchronization across the venue's devices, analytics presented back to the Lounge Operator, archival, and deletion — each as needed to provide, operate, secure, and support the Services.

Duration

The subscription term (including any trial) plus a wind-down period, followed by deletion as described in Section 10.

Annex II — Technical and Organizational Measures

  • Encryption in transit — connections to the Services are encrypted using TLS;
  • Encryption at rest — provided by our hosting provider for the database and stored files;
  • Secrets protection — point-of-sale credentials are stored encrypted in a dedicated secrets vault, accessible only to server-side service roles, and are redacted from logs and activity records;
  • Tenant isolation — per-tenant row-level security enforced in the database, so one venue's data is not readable from another venue's account or devices;
  • Access control — role-based access (owner / manager / staff) within each venue, and least-privilege service credentials on the server side;
  • Device controls — kiosk sessions are bound to approved devices; a blocked device loses access immediately;
  • Retention enforcement — automated daily routines archive and delete data according to the retention rules described in the Privacy Policy and delete venues scheduled for removal;
  • Breach handling — a documented process for detecting, assessing, and notifying personal data breaches (Section 9);
  • Infrastructure controls — network security, physical security, and backups are inherited from our hosting providers (Supabase and Vercel) under their own security programmes; their certifications are available on their websites.

Annex III — Sub-Processors

Sub-processor Service Location / region Transfer mechanism
Supabase Hosting, database, authentication, storage, real-time sync Primary region: Switzerland European Commission adequacy decision (Switzerland)
Vercel Application hosting, CDN, analytics, performance monitoring EU / US Standard Contractual Clauses for transfers outside the EEA
Stripe Payment processing EU / US Standard Contractual Clauses for transfers outside the EEA
Resend Transactional email EU / US Standard Contractual Clauses for transfers outside the EEA
Cloudflare Turnstile bot protection Global Standard Contractual Clauses for transfers outside the EEA
Browser / OS push services (Apple, Google, Mozilla) Delivery of kiosk order alert notifications Determined by the device vendor Vendor's own transfer safeguards; only a push token and alert trigger are processed

The current list is also published at /subprocessors, where changes are reflected. Changes are announced as described in Section 7.