concluded under Article 28 of Regulation (EU) 2016/679 (GDPR)
This translation is for information only. The binding version is the Slovak wording available at callania.eu/spracovatelska-zmluva. In case of any discrepancy, the Slovak text prevails.
Parties
Controller: the client — a business using the Callania Booking service, identified by the details given in its account.
Processor: - Company: MACET, s.r.o. · Registered office: Nitrianska 32/189, 949 11 Nitra · Company ID (IČO): 35 953 781 - Contact: booking@callania.eu
This agreement forms an integral part of the General Terms of Service and is entered into the moment a business is created in the service.
1. Subject matter and duration
The processor processes personal data on behalf of the controller solely for the purpose of running the reservation system — receiving and managing bookings, notifying customers, keeping customer records, and related features the controller switches on in the service.
The agreement lasts for the duration of the main contract and ends together with it.
2. Nature of processing and categories of data
| Data subjects | the controller’s customers who book an appointment or a stay; people on the waiting list; the controller’s staff with access to the system |
| Categories of data | first and last name, email, phone number, language, booking note, booking history and statuses, no-show flag, source of the visit, and for accommodation the number of guests and the dates of stay |
| Operations | collection, storage, access, modification, transmission of notifications, erasure |
| Special categories | the service is not intended for processing health data or other special categories. If the controller enters them anyway (for example in a note), it does so on its own responsibility and must have a legal basis for it. |
3. Obligations of the processor
The processor:
1. processes the data only on documented instructions from the controller; using the features and settings of the service counts as an instruction 2. ensures that persons with access to the data are bound by confidentiality 3. implements the technical and organisational measures under Article 32 GDPR set out in Annex B 4. does not disclose the data to third parties other than the sub-processors under article 4 and cases required by law 5. assists the controller in handling data subject requests — by providing an export of the data, or by rectifying or erasing it on the controller’s instruction 6. assists in meeting the obligations under Articles 32 to 36 GDPR to the extent appropriate to the nature of the processing and the information available to it 7. reports a personal data breach without undue delay, within 48 hours of becoming aware of it, together with what happened, who is affected and what steps are being taken 8. makes available, upon request, the information needed to demonstrate compliance with these obligations 9. informs the controller if, in its opinion, an instruction infringes the law
4. Sub-processors
The controller gives the processor general authorisation to engage the further processors listed in Annex A.
When the list changes — an addition or a replacement — the processor informs the controller at least 30 days in advance by email. The controller may object within that period; if the objection cannot be accommodated, it may terminate the main contract as of the effective date of the change without penalty.
The processor imposes the same obligations on sub-processors and remains responsible for their performance.
5. Transfers outside the EU
No transfer of data outside the European Economic Area takes place. Should one become necessary, the processor will inform the controller in advance and put appropriate safeguards under Chapter V GDPR in place.
6. Erasure and return of data
After the agreement ends, the processor will, at the controller’s choice, erase or return the data. An export is available directly in the service.
If the controller does not request an export, the data is erased within 30 days of the end of the agreement. Backups are purged as part of the regular cycle, within 6 months at the latest; until then they are encrypted and not accessible to normal operation.
The processor may retain data whose retention is required by law.
7. Audits
The controller has the right to verify compliance with this agreement. On written request, the processor will provide the necessary information and records. An on-site audit is possible by arrangement, at most once a year and with at least 14 days’ notice, so as not to disrupt operations; the controller bears the cost of its own audit.
8. Liability
The liability of the parties is governed by Article 82 GDPR and by the limitation of liability in the main contract, where the law permits it.
Annex A — Sub-processors
| Sub-processor | What it does | Location |
|---|---|---|
| Hetzner Online GmbH | server hosting, storage, backups | Germany |
| Webglobe, a.s. (company ID 52486567) | sending email notifications | Slovakia |
| BulkGate s. r. o. | sending SMS notifications (only if the controller enables the add-on) | Czechia |
Booking portals (Booking.com, Airbnb) are not our sub-processors — the controller has its own relationship with them and we merely exchange availability data on its instruction.
Annex B — Technical and organisational measures
Access and network. Server sign-in by key only, no passwords, no root login. Only the web and management ports are reachable from outside. The database is not reachable from the internet.
Encryption. All traffic over HTTPS. Passwords stored with argon2id. Backups encrypted.
Separation of data. Each business’s data is separated and the separation is verified by automated tests on every change.
Resilience. Daily backups, retention of 14 daily and 8 weekly copies, and a monthly automated check that a backup can be restored.
Logging. Access and changes are written to the audit. Tokens and phone numbers are masked in operational logs.
Monitoring. System integrity checks, antivirus scanning, automatic detection of unusual changes, and a daily status report.
Minimisation. Only the data needed for the purpose reaches notifications and exports. Booking feeds for portals contain no personal data of guests, only the booking code.