العودة إلى الصفحة الرئيسية
تتوفر هذه الوثيقة حاليًا باللغة الإنجليزية فقط.

Data Processing Agreement

Servinka

Last updated: 2026-06-26 · Effective date: [Effective date]

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms & Conditions between Solvinka AB, organisation number 5595946707 ("Servinka", "Processor"), and the Provider that uses the Platform ("Provider", "Controller"). It governs Servinka's processing of personal data on the Provider's behalf and reflects Article 28 GDPR. Where it conflicts with the Terms on data-protection matters, this DPA prevails.

It applies only where Servinka acts as processor — i.e. to personal data about the Provider's Customers that the Provider collects and manages through the Platform. Servinka's processing of Provider-account and billing data as a controller is governed by the Privacy Policy, not this DPA.

1. Definitions

"GDPR", "personal data", "processing", "controller", "processor", "data subject", "sub-processor", and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data Servinka processes on the Provider's behalf through the Platform.

2. Roles

The Provider is the controller and Servinka is the processor of Customer Personal Data. The Provider is responsible for the lawfulness of its collection and use of that data, including having a valid legal basis and providing data subjects with the required information.

3. Scope and instructions

Servinka processes Customer Personal Data only on the Provider's documented instructions, including those given through the Platform's configuration and ordinary use, and as set out in this DPA, the Terms, and the Privacy Policy — except where required by EU or Member-State law, in which case Servinka will inform the Provider unless that law prohibits it. Servinka will inform the Provider if, in its opinion, an instruction infringes the GDPR. Servinka will not process Customer Personal Data for its own purposes or sell it.

4. Subject matter, duration, nature, purpose (Annex)

ItemDetail
Subject matterProvision of the Servinka Platform (storefront, bookings, payments, customer management, notifications)
DurationFor the term of the Terms, until deletion/return under Section 11
Nature & purposeHosting, storage, retrieval, transmission, display, and processing of Customer Personal Data to operate the Platform on the Provider's behalf
Categories of data subjectsThe Provider's Customers (and, where entered, their representatives)
Categories of personal dataIdentification and contact data (name, phone, email), language, booking/purchase records, addresses, free-text notes, and company/tax details (company name, organisation number, VAT number, billing address)
Special categoriesNot intended; the Provider must not enter Article 9 data unless strictly necessary and lawful

5. Confidentiality

Servinka ensures that persons authorised to process Customer Personal Data are bound by confidentiality and process it only on instructions.

6. Security (Art. 32)

Servinka implements appropriate technical and organisational measures, including: encryption in transit (TLS) and at rest; row-level security and tenant isolation; least-privilege access controls and authentication; secrets management; security headers and a Content-Security-Policy; rate-limiting on public endpoints; logging and continuous monitoring; and regular review of these measures. Measures may be updated provided the level of security is not reduced.

7. Sub-processors

The Provider gives general authorisation for Servinka to engage sub-processors. Current sub-processors are listed in the Privacy Policy (Supabase, Vercel, Stripe, Resend, Upstash, PostHog, Sentry). Servinka imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance. Servinka will give the Provider prior notice of any intended addition or replacement of a sub-processor, and the Provider may object on reasonable data-protection grounds; if the objection cannot be resolved, the Provider may terminate the affected service.

8. Assistance to the Controller

Taking into account the nature of the processing, Servinka assists the Provider by appropriate technical and organisational measures, insofar as possible, to: respond to data-subject requests (access, rectification, erasure, restriction, portability, objection) — primarily through Platform functionality; and meet the Provider's obligations under Articles 32–36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the information available to Servinka.

9. Personal data breach

Servinka notifies the Provider without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to assist the Provider's own notification obligations under Articles 33–34. Servinka does not assess on the Provider's behalf whether the breach is notifiable to a supervisory authority or data subjects.

10. International transfers

Servinka (and its sub-processors) may transfer Customer Personal Data outside the EU/EEA only with appropriate safeguards under Chapter V GDPR — primarily the European Commission's Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework — as described in the Privacy Policy. The Provider authorises these transfers.

11. Return and deletion

On termination of the Platform services, and at the Provider's choice, Servinka deletes or returns Customer Personal Data and deletes existing copies, unless EU or Member-State law requires storage (e.g. statutory accounting retention). The Provider may export its data through the Platform for a reasonable period before deletion.

12. Audits

Servinka makes available to the Provider information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Provider or an auditor it mandates — subject to reasonable confidentiality, scheduling, scope, and security conditions, and to Servinka being able to satisfy reasonable requests primarily by providing relevant documentation and sub-processor reports.

13. Liability and miscellaneous

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA is governed by the law of Sweden. If any provision is invalid, the rest remains in effect.

14. Contact

Data-protection matters under this DPA: Solvinka AB, privacy@servinka.com, Södra Storgatan 69, 267 40 Bjuv.