Data processing agreement
This agreement is part of the terms of use between the restaurant holding a Couvella account (the “controller”, “you”) and Edenroche Sàrl (the “processor”, “we”). Where South Africa’s Protection of Personal Information Act (POPIA) applies, the controller is the “responsible party”, the processor is the “operator”, and this agreement is the written contract between them that POPIA requires. It covers the personal data about your guests that we process for you. Effective 17 September 2026.
1. Scope and roles
You decide why and how guest data is collected: through your booking page, the widget, imports and your team’s entries. We process it on your behalf to provide the application. Where the GDPR applies, you are the controller and we are the processor under Article 28; under the Swiss Federal Act on Data Protection, the same roles apply under Article 9; under POPIA, you are the responsible party and we are the operator under sections 20 and 21. Nothing here makes us a controller of guest data.
2. The processing
Subject matter: running the reservations of your restaurant. Duration: for as long as you hold an account, and the deletion period in section 9 after that. Nature and purpose: storing bookings and guest records, showing them to your team, sending guests the messages a booking calls for (confirmation, reminder, reconfirmation request, change, cancellation, review request), holding cards and taking charges under your card policy through your Stripe account (in South Africa, through Paystack, with your restaurant as a subaccount), producing statistics, answering your team’s questions through Ask, and keeping backups. Data subjects: your guests, and people who join your waiting list or leave a review. Categories of data: name, email address, telephone number, language, booking details (date, time, party size, area, table, status, history), special requests and notes your team writes, ratings and comments, newsletter consent and its time, whether messages were delivered, and, for a card guarantee, a token and the last four digits held by Stripe or Paystack. We never see full card numbers. No special categories of data are asked for; if a guest volunteers one in a request (an allergy, say), it is stored as text with the booking.
3. Your instructions
We process guest data only on your documented instructions. The settings you choose in the application, the actions your team takes in it, and these terms are those instructions. We will not process guest data for any other purpose, and in particular not for our own marketing or to build profiles across restaurants. If we believe an instruction breaks data protection law we tell you at once and may hold off carrying it out until it is clarified. If the law we are subject to requires us to process guest data otherwise, we tell you beforehand unless that law forbids it. Where POPIA applies, this means we process guest data only with your knowledge or authorisation, as section 20 requires.
4. Confidentiality
Only people who need access to guest data to run or support the application have it, and each of them is bound to confidentiality by contract. Access by our staff is limited to what a support request or an operational task needs. We treat guest data as confidential and do not disclose it unless the law requires us to, or in the course of our proper duties, as section 20 of POPIA requires.
5. Security
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR, Article 8 of the Swiss act and, where POPIA applies, the safeguards of section 19, which section 21(1) requires of us as operator: encryption in transit everywhere and at rest in the database and backups; access to the application by short-lived signed links and sessions, with roles and an optional screen lock; separation of every restaurant’s data by identifier in every query; a content security policy and rate limits on public routes; logging of changes to bookings and settings with who made them; backups every six hours to a separate store, verified after each run; and error monitoring that alerts us. We review these measures as the application changes.
6. Sub-processors
You authorise us to use the sub-processors on the list of sub-processors, each bound by a contract that imposes data protection obligations no weaker than these. We remain responsible to you for their work. We tell you by email at least 30 days before a new sub-processor begins processing guest data, or as soon as practicable where a replacement is needed urgently to keep the application running. You may object on reasonable grounds; if we cannot resolve the objection, you may end the terms without penalty and section 9 applies.
7. Transfers
Guest data is stored in the European Union and Switzerland. Where a sub-processor processes data outside the EU, the EEA, the United Kingdom or Switzerland, it does so under the European Commission’s standard contractual clauses or another safeguard recognised by the relevant law, with the Swiss additions where Swiss law applies. Where POPIA applies, guest data is transferred out of South Africa to these countries, whose laws give it adequate protection, and every sub-processor is bound by an agreement to protect it, as section 72 of POPIA allows.
8. Assistance
The application lets you answer most guest requests yourself: a guest’s record can be viewed, corrected, exported and erased from the Guests screen, and their newsletter consent withdrawn. Where you need more, we help you within a reasonable time to respond to a guest exercising their rights, to meet your duties on security, breach notification, impact assessments and consultation with an authority, taking into account what we know and the nature of the processing.
If we become aware of a personal data breach affecting guest data, we tell you without undue delay and in any case within 48 hours of becoming aware, with what we know about its nature, the data and guests concerned, the likely consequences and the measures taken, and we add to that as we learn more. Where POPIA applies, we tell you immediately where there are reasonable grounds to believe that guest data has been accessed or acquired by an unauthorised person, as section 21(2) requires, so that you can notify the Information Regulator and the guests concerned under section 22.
9. Deletion and return
While the account is open, guest details are erased automatically after the retention period you set, and at once when your team erases a guest. When the terms end, you can export bookings and consenting guests as CSV beforehand and for 30 days afterwards on request. After that we delete guest data, except what we must keep under the law that applies to us, and except copies in backups, which are removed in the ordinary course after one month and are not restored other than to recover the application.
10. Showing compliance
We give you the information you reasonably need to show that this agreement is kept: this document, the list of sub-processors, a description of the security measures, and answers to reasonable written questions. Where that is not enough for an obligation you are under, we allow an audit by you or an independent auditor you appoint, once a year unless a breach or an authority requires more, on 30 days’ notice, during working hours, without disturbing other restaurants’ data, and at your cost.
11. Liability and law
The liability provisions and the governing law and jurisdiction of the terms of use apply to this agreement. Where this agreement and the terms differ on the processing of guest data, this agreement prevails.
12. Contact
For anything under this agreement: Edenroche Sàrl, Avenue Centrale 85, 1884 Villars-sur-Ollon, Switzerland, hello@couvella.com. If you need this agreement as a separately signed document, write to us and we send one.
