DATA PROCESSING AGREEMENT (DPA)

Last updated: 2026.07.12.

This is a courtesy translation provided for information purposes only. In the event of any discrepancy or dispute, the Hungarian-language version of this document shall prevail and is the sole legally binding version.

1. INTRODUCTORY PROVISIONS

1.1. Subject matter of the Agreement


This Data Processing Agreement (hereinafter: the "DPA") is entered into between Nagy György egyéni vállalkozó (Nagy György, sole proprietor; hereinafter: "Bukio" or the "Processor") and the Restaurant using the Bukio Platform as a subscriber (hereinafter: the "Restaurant" or the "Controller"), with respect to the processing of the personal data of Guests in connection with the Restaurant's reservation system.

1.2. Legal background


This DPA has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), in particular Article 28 thereof, as well as the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).

1.3. Relationship with the Terms of Service


This DPA sets out the detailed rules of Section 10 of the Terms of Service (ToS) and the relevant chapters of the Privacy Policy. In the event of any conflict – specifically within the subject matter of the processor relationship – the provisions of this DPA shall prevail.

1.4. Annexes


The following form an integral part of the DPA:
  • Annex 1 – Description of the scope of data processed (Section 16)
  • Annex 2 – List of authorised sub-processors (Section 17)
  • Annex 3 – Technical and organisational measures (TOM) (Section 18)

1.5. Limits of the scope of the DPA


This DPA applies exclusively to the processing by Bukio of Guest data relating to the Restaurant's reservation system. It does not extend to processing carried out by Bukio in its capacity as an independent controller (e.g. restaurant account and billing data, platform-level security, authentication and abuse-prevention data); such processing is governed by Bukio's Privacy Policy.

2. THE PARTIES

2.1. Processor (Bukio)


Business name: Nagy György egyéni vállalkozó

Registered office: 6726 Szeged, Középkikötő Sor 14/b

Tax number: 59721639-1-26

Data protection contact: privacy@bukio.hu

General contact: hello@bukio.hu

2.2. Controller (Restaurant)


The Restaurant's details are provided by the Restaurant's representative during registration on the Platform and are stored by Bukio in the Restaurant's account. The Restaurant is responsible for keeping these details up to date.

2.3. Electronic conclusion of the agreement


The parties acknowledge that this DPA is concluded electronically, by the Restaurant's declaration of acceptance made at registration (or upon acceptance of a subsequent amendment of the ToS/DPA), which is recorded with a timestamp and IP address.

3. DEFINITIONS

3.1. Definitions


Unless otherwise provided, the terms used in this DPA have the meaning defined in Article 4 of the GDPR. In particular:
  • Controller: the Restaurant, which determines the purposes and means of the processing of Guest data.
  • Processor: Bukio, which processes Guest data on behalf of and in accordance with the instructions of the Restaurant.
  • Sub-processor: any further processor engaged by Bukio for the performance of the Engagement.
  • Guest: the natural person who initiates a table reservation through the Restaurant's reservation form and whose data are the subject of this DPA.
  • Engagement: the data processing engagement given by the Restaurant to Bukio in connection with the operation of the reservation system.
  • Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

4. SUBJECT MATTER, PURPOSE AND DURATION OF THE ENGAGEMENT

4.1. Subject matter of the Engagement


The Restaurant engages Bukio to process, on behalf of and in accordance with the instructions of the Restaurant, the personal data detailed in Annex 1 as part of the technical operation of the Restaurant's reservation system.

4.2. Purpose of the Engagement


The purpose of the Engagement is:
  • the technical operation of the reservation system;
  • the administrative servicing of the reservation relationship between the Guest and the Restaurant;
  • technical support of the Restaurant's duties as controller;
  • ensuring backups and business continuity.

4.3. Duration of the Engagement


The Engagement lasts for the duration of the Restaurant's subscription (or account) under the ToS and terminates automatically upon its termination. The Restaurant is entitled to terminate the Engagement by deleting its account through the self-service function; in such case, the provisions of Section 15 apply.

5. NATURE AND CHARACTERISTICS OF THE PROCESSING

5.1. Characteristics of the processing (Article 28(3) GDPR)

  • Subject matter: the processing of personal data relating to Guests' reservations.
  • Duration: the entire duration of the Engagement, as well as the deletion/return period under Section 15.
  • Nature and purpose: see Sections 4.1–4.2.
  • Type of personal data: see Annex 1 (Section 16).
  • Categories of data subjects: Guests using the Restaurant's reservation system.

6. RIGHTS AND OBLIGATIONS OF THE CONTROLLER (RESTAURANT)

6.1. Legal basis and purpose


It is the sole responsibility of the Restaurant to ensure that the legal basis, purpose and duration of the processing of Guest data comply with the GDPR and Hungarian data protection rules.

6.2. Instructions


The Restaurant shall give its instructions to Bukio in writing or by using the appropriate function of the Platform. Use of the Platform in accordance with its intended purpose constitutes a written instruction given to Bukio.

6.3. Obligations of the Restaurant


The Restaurant shall:
  • make its own Privacy Policy available to Guests and record its acceptance in a documented manner;
  • register on the Platform only with accurate and complete company details;
  • act as controller in responding to Guests exercising their rights under the GDPR;
  • follow Bukio's security notices and notifications of changes to sub-processors.

6.4. Attention – responsibility for the content of the Privacy Policy


The validity, lawfulness and adequacy of the content of the Restaurant's Privacy Policy is, under the GDPR, the sole responsibility of the Restaurant as controller. If the Restaurant uses the template privacy policy generated by the Platform, it expressly warrants that it has had it reviewed by a lawyer in advance, and by using it declares that it is legally adequate for the Restaurant's own circumstances. The Restaurant alone is liable for any consequences arising from any error in the generated policy – in particular fines imposed by the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) and damages. Bukio provides only a technical framework and does not warrant lawfulness.

6.5. Warranties of the Restaurant


The Restaurant warrants that it has a legal basis for the processing of Guest data, that processing for marketing purposes takes place only on an appropriate legal basis, and that it shall be fully answerable to the Guest in all matters falling outside Bukio's role as processor.

7. OBLIGATIONS OF THE PROCESSOR (BUKIO) (Article 28(3) GDPR)

7.1. Undertakings of Bukio


Bukio expressly undertakes to:
  • process Guest data only on the written instructions of the Restaurant, unless required to do so by Union or Member State law; if, in its opinion, an instruction infringes data protection rules, it shall immediately inform the Restaurant;
  • ensure that its employees and contributors who have access to Guest data are bound by an obligation of confidentiality;
  • implement technical and organisational measures in accordance with Article 32 of the GDPR and Annex 3;
  • engage sub-processors only in accordance with Section 9 and Annex 2;
  • assist the Restaurant in fulfilling the rights of data subjects (Guests) (Section 10);
  • assist the Restaurant in fulfilling its obligations regarding data security, breach notification, DPIA and prior consultation;
  • upon termination of the Engagement, delete or return Guest data in accordance with Section 15;
  • make available the information necessary for audits in accordance with Section 13.

8. CONFIDENTIALITY

8.1. Obligation of confidentiality


Bukio treats Guest data as confidential; they may be disclosed to third parties only with the written consent of the Restaurant or to the extent necessary to comply with a legal obligation. Employees and contributors who have access to Guest data remain bound by confidentiality even after the end of their relationship with Bukio.

Bukio is entitled to anonymise and aggregate data relating to the operation of the Platform in such a way that no natural person or specific Restaurant can be identified from them; the resulting anonymous statistical data do not constitute personal data.

9. SUB-PROCESSORS

9.1. General authorisation


By accepting this DPA, the Restaurant grants Bukio a general, prior authorisation to engage sub-processors for the performance of the Engagement. The current list of authorised sub-processors is set out in Annex 2 (Section 17).

9.2. Engaging a new sub-processor


Bukio shall notify the Restaurant of the engagement of a new sub-processor at least 30 days before such engagement. The Restaurant may object on justified data protection grounds. If the objection cannot be remedied, the Restaurant is entitled to terminate the Engagement with effect from the start date of the new sub-processor's engagement.

9.3. Liability for sub-processors


Bukio is liable for the activities of the sub-processors it engages as if it had performed them itself – subject to the limitations of liability permitted by law. Data processing agreements in accordance with Article 28 of the GDPR are in place with the sub-processors.

10. ASSISTANCE IN FULFILLING THE RIGHTS OF DATA SUBJECTS

10.1. Assistance


Bukio – upon the Restaurant's instruction – assists the Restaurant in fulfilling Guests' rights under the GDPR (information, access, rectification, erasure, restriction, data portability, objection). The Platform may also provide self-service functions for the exercise of certain data subject rights (e.g. cancellation/deletion on the Reservations page).

10.2. Direct requests from Guests


If a Guest contacts Bukio directly to exercise a data subject right, Bukio – where the request falls within the Restaurant's scope as controller – forwards the request to the competent Restaurant and cooperates in its fulfilment as processor. Bukio undertakes a technical deadline of no more than 30 days for supporting the request, except for immediate self-service functions.

11. HANDLING OF PERSONAL DATA BREACHES (Articles 33–34 GDPR)

11.1. Notification


Bukio shall notify the Restaurant without undue delay, and no later than 48 hours after becoming aware of it, of any personal data breach affecting the Restaurant's Guest data falling within the scope of this DPA.

11.2. Content of the notification


The notification shall – to the extent of the information available – describe the nature of the breach, the approximate number and categories of data and data subjects concerned, the contact person, the likely consequences, and the measures taken or proposed.

11.3. Notification to the NAIH and to Guests


With respect to the Guest data that are the subject of this DPA, notification to the NAIH and communication to Guests is primarily the obligation of the Restaurant as controller. In the event of a breach affecting data processed by Bukio in its capacity as an independent controller, Bukio shall separately fulfil its own statutory obligations.

12. DATA PROTECTION IMPACT ASSESSMENT (DPIA) AND PRIOR CONSULTATION

12.1. Assistance


If the Restaurant is required to carry out a DPIA or to initiate a prior consultation, Bukio shall, upon the Restaurant's written request, provide the reasonably necessary information regarding the operation of the Platform. The assistance does not extend to preparing the DPIA document or conducting the consultation with the supervisory authority.

13. RIGHT OF AUDIT

13.1. Exercise of the audit right


The Restaurant is entitled to verify Bukio's compliance with the obligations set out in this DPA. The audit may be exercised no more than once a year, with at least 30 days' prior notice, during business hours, subject to confidentiality, at the Restaurant's expense, and may not affect Bukio's data relating to other Restaurants, its business secrets or its source code.

Bukio primarily satisfies the exercise of the audit right by providing up-to-date security summaries, sub-processor documentation and written statements of compliance. A more in-depth technical audit may be requested if these are insufficient for the examination of a specific, concrete data protection risk.

14. TRANSFERS TO THIRD COUNTRIES

14.1. Transfers outside the EEA and safeguards


The Restaurant acknowledges and authorises that Bukio – due to the registered office or global infrastructure of certain sub-processors listed in Annex 2 – may also transfer Guest data outside the European Economic Area, in particular to the United States. Bukio's primary application, database and cache infrastructure operates in the EU, in the Frankfurt region; backups are stored in the EU (Germany).

Bukio guarantees that any such transfer takes place subject to appropriate safeguards, in particular the EU–US Data Privacy Framework (DPF), Standard Contractual Clauses (SCC), and, where necessary, supplementary measures. The Restaurant may request a copy of the safeguards applied at privacy@bukio.hu.

15. FATE OF THE DATA UPON TERMINATION OF THE ENGAGEMENT

15.1. Deletion or return


Upon termination of the Engagement, Bukio shall – at the Restaurant's choice – with respect to the Guest data concerned:
  • delete them within 30 days of termination, or
  • return them within 30 days of termination to the Restaurant (e.g. by way of an export).

    In the absence of a choice, Bukio shall carry out deletion. Self-service account deletion by the Restaurant constitutes a choice of deletion.

15.2. Mandatory retention and backups


Deletion does not affect data which Bukio is required to retain under Union or Hungarian law; Bukio retains such data separately and solely for the purpose of retention. Deleted data contained in backups are permanently removed or overwritten in accordance with the backup rotation cycle, within 30 days at the latest, and are not restored in normal operation, except for business continuity or incident response purposes.

15.3. Liability and indemnification


The parties acknowledge that the Restaurant is primarily liable with respect to its own processing activities, while Bukio is liable where it has specifically breached its obligations under the GDPR applicable to processors or has disregarded a lawful instruction of the Restaurant. Bukio's liability for damages exists within the limits set out in Section 8 of the ToS; the limitation does not apply to the mandatory liability rules under Article 82 of the GDPR. The Restaurant shall indemnify Bukio against all claims and fines arising from the Restaurant's breach of its obligations as controller.

16. ANNEX 1 – SCOPE OF DATA PROCESSED

16.1. Categories of data subjects


Guests using the Restaurant's reservation system – natural persons.

16.2. Categories of personal data

  • name of the person making the reservation – identification of the Guest, contact
  • e-mail address – contact, notifications, sending of the reservation identifier
  • telephone number – contact
  • date/time and number of persons of the reservation – fulfilment of the reservation
  • reservation status (new/confirmed/cancelled/deleted) – record keeping
  • optional "special request" free text – fulfilment of the reservation
  • reservation identifier – viewing on the Reservations page
  • security log data (IP address, browser/device data) – abuse prevention
  • guest block (blocklist) entries: e-mail address, IP address, browser/connection fingerprint – enforcement of blocks ordered by the Restaurant, abuse prevention; the block remains in place until revoked by the Restaurant, and at most until the account is terminated

16.3. Processing operations and special categories of data


Operations: collection, recording, storage, alteration, retrieval, display, export, backup, restoration, deletion, transfer to sub-processors.



Special categories of data: within the Engagement, Bukio does not request special categories of data under Article 9 of the GDPR. The Guest may voluntarily provide such data in the "special request" field (e.g. allergies); the Restaurant (controller) processes such data only to the extent necessary for the fulfilment of the reservation.

17. ANNEX 2 – AUTHORISED SUB-PROCESSORS

17.1. Current list


Before updating this Annex, Bukio fulfils its prior notification obligation under Section 9.2.
  • Vercel Inc. (USA; execution region: Frankfurt, EU) – web hosting, application hosting, infrastructure. Safeguards: DPF / SCC.
  • MongoDB, Inc. (Atlas) (USA; region: Frankfurt, EU) – database and data storage. Safeguards: DPF / SCC.
  • Upstash Inc. (USA; region: Frankfurt, EU) – Redis cache, temporary storage of OTPs, rate limiting. Safeguards: DPF / SCC.
  • Twilio SendGrid Inc. (USA; global involvement possible) – delivery of transactional e-mails. Safeguards: DPF / SCC.
  • Hetzner Online GmbH (Germany; region: EU) – storage of encrypted backups of the database on a server separated from the production system. Safeguards: processing within the EU (without transfer to third countries).
  • OneSignal, Inc. (USA) – delivery of browser (web push) notifications to restaurant users in the admin interface; the notification may contain the basic details of the reservation (e.g. date/time, number of persons, name of the person making the reservation). Not used on the guest-facing reservation form or in the mobile application. Safeguards: DPF / SCC.

    Note: card payments are provided by Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.), which relates to Bukio's own billing-related processing carried out in its capacity as controller (payment data of Restaurant Users). Stripe has no access to the Guest data that are the subject of this DPA and is therefore not a sub-processor under this DPA; details are set out in Bukio's Privacy Policy.

18. ANNEX 3 – TECHNICAL AND ORGANISATIONAL MEASURES (TOM)

18.1. Confidentiality

  • Encrypted communication: HTTPS (TLS 1.2+) for all data traffic.
  • E-mail-based OTP authentication (with short validity), limitation of login attempts (rate limiting).
  • Database encryption at rest (provider-level encryption at rest).
  • Role-based access control, principle of least privilege.
  • httpOnly + Secure cookie attributes on authentication cookies.
  • The mobile application's session token is kept in secure storage on the device (Android Keystore / iOS Keychain); the app does not persistently store reservation data.
  • Confidentiality obligation of employees/contributors.

18.2. Integrity and availability

  • Audit log of operations affecting reservations.
  • Input validation in the APIs (schema-based).
  • Regular, encrypted backups in a separate environment (EU, Germany).
  • Primary infrastructure in the Frankfurt (EU) region; use of the providers' native high-availability capabilities.
  • Backup rotation: deleted data are permanently removed from backups within 30 days at the latest.

18.3. Abuse prevention and review

  • Redis-based rate limiting and brute-force protection.
  • Structured security logging; where technically justified, e-mail identifiers in pseudonymised (salted/hashed) form.
  • TTL-based automatic deletion of temporary data (e.g. OTPs).
  • Monitoring of dependency updates; risk-proportionate security testing.
  • The above measures may be updated provided the same or a higher level of protection is maintained.

19. FINAL PROVISIONS

19.1. Entry into force and amendment


This DPA enters into force automatically upon the Restaurant's registration declaration under the ToS. An amendment that reduces the level of protection of Guest data enters into force only with the express acceptance of the Restaurant; otherwise, Section 15 of the ToS applies.

19.2. Miscellaneous provisions


The invalidity of any provision of the DPA does not affect the validity of the remaining provisions. The DPA is governed by Hungarian law and the GDPR; disputes are subject to the jurisdiction clause of the Terms of Service (ToS). The language of the DPA is Hungarian. The DPA – together with the ToS and the Privacy Policy – constitutes the entire agreement between the parties regarding the processing of Guest data. Sections 8, 15 and 19 remain in force after the termination of the DPA.
This Data Processing Agreement is effective as of 2026.07.12.
Prepared with regard to Article 28 of the GDPR (Regulation (EU) 2016/679) and the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).