Last Updated: August 01, 2026
This Data Processing Agreement (“DPA“) forms part of the Terms and Conditions or other agreement (“Agreement“) between JAVISTAB, trading as JavisTab (“JavisTab“, “Processor“, “Service Provider“, or “Data Intermediary“);
and the customer identified in the applicable Agreement (“Customer“, “Controller“, or “Business“).
This DPA governs the processing of Personal Data by JavisTab on behalf of Customer in connection with the Services.
1. SCOPE
This DPA applies where JavisTab processes Personal Data on behalf of Customer in connection with:
- JavisTab WordPress plugins;
- reservation systems;
- booking systems;
- SaaS services;
- APIs;
- integrations;
- hosting;
- support; and
- related Services.
This DPA applies to the extent that applicable Data Protection Laws require a data processing agreement.
2. DEFINITIONS
“Personal Data”
Means information relating to an identified or identifiable natural person, including “personal data”, “personal information”, or equivalent terms under applicable Data Protection Laws.
“Controller”
Means the party determining the purposes and means of processing Personal Data.
“Processor”
Means the party processing Personal Data on behalf of the Controller.
“Data Protection Laws”
Means applicable data protection and privacy laws governing the processing, including where applicable:
- EU GDPR;
- UK GDPR;
- Data Protection Act 2018;
- CCPA/CPRA;
- Singapore PDPA;
- and other applicable privacy legislation.
“Sub-processor”
Means a third party appointed by JavisTab to process Personal Data on behalf of Customer.
3. ROLE OF THE PARTIES
For Customer Data processed through JavisTab’s reservation and booking functionality:
Customer acts as Controller / Business.
JavisTab acts as Processor / Service Provider / Data Intermediary, as applicable.
Customer determines:
- purposes of processing;
- categories of Personal Data;
- categories of data subjects;
- lawful basis;
- retention periods;
- booking purposes;
- customer communications; and
- other business purposes.
JavisTab processes Personal Data only to provide the Services and in accordance with Customer’s documented instructions, except where applicable law requires otherwise.
This allocation follows the principle that controllers determine the purposes and means while processors act on the controller’s instructions.
4. PROCESSING INSTRUCTIONS
JavisTab shall process Personal Data only:
- to provide the Services;
- to maintain and secure the Services;
- to provide technical support;
- to prevent fraud and abuse;
- to troubleshoot problems;
- to comply with Customer’s documented instructions; and
- as otherwise permitted by this DPA or applicable law.
JavisTab shall not:
- sell Customer Data;
- use Customer Data for unrelated advertising;
- use Customer Data to establish independent customer profiles;
- disclose Customer Data except as authorized by Customer or required by law; or
- use Customer Data for JavisTab’s own unrelated commercial purposes.
5. DETAILS OF PROCESSING
Subject Matter
Provision of restaurant reservation, booking, table management, notification, integration, analytics, support, and related software services.
Duration
Processing will continue for the duration of Customer’s use of the applicable Services, followed by deletion or return in accordance with this DPA and applicable law.
Nature of Processing
Processing may include:
- collection;
- recording;
- organization;
- storage;
- retrieval;
- consultation;
- transmission;
- modification;
- deletion; and
- other processing necessary to provide the Services.
Purposes
Processing may be performed to:
- create reservations;
- manage bookings;
- manage restaurant tables;
- send reservation notifications;
- provide integrations;
- maintain Accounts;
- provide support;
- maintain security;
- prevent fraud;
- troubleshoot technical issues; and
- provide other functionality requested by Customer.
6. CATEGORIES OF DATA SUBJECTS
Customer may submit Personal Data relating to:
- restaurant guests;
- customers;
- reservation holders;
- employees;
- staff;
- administrators;
- website visitors;
- business contacts; and
- other individuals whose data Customer lawfully submits.
7. CATEGORIES OF PERSONAL DATA
Depending on Customer configuration, Personal Data may include:
- name;
- email address;
- telephone number;
- reservation date and time;
- number of guests;
- table information;
- booking history;
- cancellation information;
- customer notes;
- special requests;
- IP address;
- device information;
- browser information;
- location information where enabled;
- payment status;
- communication preferences; and
- other information entered into the Services.
Customer should not submit special-category or highly sensitive Personal Data unless legally permitted and reasonably necessary.
8. CUSTOMER RESPONSIBILITIES
Customer shall:
- comply with applicable Data Protection Laws;
- establish an appropriate legal basis for processing;
- provide appropriate privacy notices;
- obtain required consents;
- ensure Personal Data is accurate;
- configure the Services appropriately;
- maintain appropriate retention periods;
- respond to data-subject requests;
- maintain appropriate security;
- provide lawful processing instructions; and
- ensure that instructions provided to JavisTab are lawful.
Under GDPR/UK GDPR, the controller retains responsibility for its processing even when a processor is used.
9. JAVISTAB OBLIGATIONS
JavisTab shall:
- process Personal Data only according to documented instructions;
- maintain appropriate confidentiality obligations;
- implement appropriate security measures;
- assist Customer with applicable data-subject requests;
- assist Customer with security and breach obligations;
- maintain appropriate records where required;
- cooperate with applicable supervisory authorities where legally required;
- notify Customer of applicable Personal Data Breaches; and
- delete or return Personal Data following termination, subject to legal retention requirements.
10. CONFIDENTIALITY
JavisTab shall ensure that persons authorized to process Personal Data:
- are subject to confidentiality obligations; and
- access Personal Data only as necessary to perform their duties.
11. SECURITY MEASURES
JavisTab shall implement reasonable technical and organizational measures appropriate to the risk.
These measures may include:
Access Control
- role-based access;
- authentication;
- least-privilege access;
- administrative access controls.
Encryption
- encryption in transit;
- secure communication protocols;
- encryption or equivalent protections where appropriate.
Availability
- backup procedures;
- monitoring;
- recovery procedures;
- redundancy where commercially appropriate.
Security Management
- security updates;
- vulnerability management;
- logging;
- incident response;
- access reviews.
GDPR Article 32 expressly requires security measures appropriate to risk, including confidentiality, integrity, availability, resilience, restoration capability and regular testing.
12. SUB-PROCESSORS
Customer provides general authorization for JavisTab to engage Sub-processors where necessary to provide the Services.
JavisTab may use providers for:
- hosting;
- cloud infrastructure;
- databases;
- email delivery;
- SMS;
- payments;
- monitoring;
- analytics;
- customer support;
- security;
- backups;
- authentication; and
- other infrastructure.
JavisTab will require Sub-processors to provide appropriate data protection obligations consistent with the nature of the processing.
Where required by applicable law, JavisTab will notify Customer of material changes to Sub-processors and provide an opportunity to object.
13. DATA SUBJECT REQUESTS
Where Customer receives a request from a data subject relating to Personal Data processed by JavisTab, Customer remains responsible for responding.
Where reasonably necessary, JavisTab will assist Customer with:
- access requests;
- correction;
- deletion;
- restriction;
- portability;
- objection; and
- other applicable rights.
JavisTab will not generally respond directly to data subjects unless:
- Customer instructs JavisTab to do so; or
- applicable law requires JavisTab to respond directly.
14. PERSONAL DATA BREACH
JavisTab shall notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Data.
The notice may include, to the extent reasonably available:
- nature of the breach;
- categories of affected data;
- affected data subjects;
- likely consequences;
- mitigation measures;
- containment measures; and
- available incident information.
JavisTab will reasonably cooperate with Customer’s investigation and legally required notification obligations.
Customer remains responsible for determining whether notification to a regulator or affected individuals is legally required, except where applicable law places that obligation directly on JavisTab.
15. GOVERNMENT REQUESTS
If JavisTab receives a legally binding request from a governmental authority for Customer Data, JavisTab will, where legally permitted:
- notify Customer;
- provide relevant details;
- reasonably challenge an unlawful request where appropriate; and
- disclose only the information legally required.
Nothing in this DPA requires JavisTab to violate applicable law.
16. INTERNATIONAL TRANSFERS
Customer acknowledges that JavisTab may use Sub-processors located outside the country where Customer is established.
For EU/EEA transfers, JavisTab will rely on an applicable lawful transfer mechanism, which may include:
- adequacy decisions;
- EU Standard Contractual Clauses;
- another legally recognized safeguard.
For UK transfers, JavisTab may rely on:
- UK adequacy regulations;
- UK International Data Transfer Agreement;
- UK Addendum to EU SCCs; or
- another legally recognized mechanism.
International transfers under GDPR and UK GDPR require applicable safeguards where the relevant transfer rules apply.
For Singapore transfers, JavisTab will implement appropriate contractual or other safeguards required to provide a level of protection comparable to the PDPA where applicable.
17. CALIFORNIA DATA
To the extent JavisTab processes Personal Information governed by CCPA/CPRA as a Service Provider or Contractor:
JavisTab shall:
- process Personal Information only for permitted business purposes;
- not sell Personal Information;
- not share Personal Information for cross-context behavioral advertising;
- not retain, use, or disclose Personal Information outside permitted purposes;
- provide reasonable assistance with applicable consumer rights;
- implement appropriate security measures; and
- notify Customer of circumstances requiring Customer’s attention.
Customer remains responsible for providing legally required notices and responding to consumer requests.
18. SINGAPORE DATA
Where JavisTab acts as a Data Intermediary under Singapore PDPA, JavisTab shall implement reasonable security arrangements and appropriate retention practices and notify Customer of relevant data breaches without undue delay.
The PDPC recognizes that data intermediaries have specific obligations concerning protection, retention and breach notification when processing data for another organization.
19. AUDIT AND COMPLIANCE INFORMATION
Upon reasonable written request, JavisTab may provide Customer with information reasonably necessary to demonstrate compliance with this DPA.
Where required by applicable law, JavisTab may permit audits subject to:
- reasonable notice;
- reasonable frequency;
- confidentiality;
- security requirements;
- business continuity requirements; and
- reimbursement of reasonable audit costs where permitted.
Customer may not conduct audits that unreasonably disrupt JavisTab’s operations or compromise the security of other customers.
Where available, JavisTab may satisfy audit requirements through:
- security documentation;
- certifications;
- independent audit reports;
- questionnaires; or
- other reasonable compliance evidence.
20. DELETION AND RETURN OF DATA
Upon termination of the Services, JavisTab will, at Customer’s choice where technically feasible:
- return Customer Data; or
- delete Customer Data.
JavisTab may retain information where required by:
- applicable law;
- legal claims;
- fraud prevention;
- security requirements;
- accounting requirements; or
- legitimate legal retention obligations.
Data retained under such circumstances will remain subject to applicable confidentiality and security obligations.
21. CONFLICT
If this DPA conflicts with the general Terms concerning the processing of Personal Data, this DPA shall prevail solely with respect to data-processing obligations.
The remaining provisions of the Terms remain in effect.
22. TERM
This DPA remains effective for as long as JavisTab processes Customer Personal Data.
Sections concerning:
- confidentiality;
- security;
- data deletion;
- liability;
- dispute resolution; and
- other provisions intended by their nature to survive
shall survive termination as applicable.
23. CONTACT
Data protection inquiries:
JAVISTAB
Trading as JavisTab
Privacy Email: service@javistab.com
DPO: service@javistab.com
Address: Hanoi, VietNam
Last Updated: August 31, 2026



