AGREEMENT FOR CAMPSITES
Data Processing Agreement
concluded pursuant to Article 28 of Regulation (EU) 2016/679
to the PitchPace Console Services Agreement
This is the agreement in the wording a campsite signs. To receive it for signature, write to [email protected]; it is signed electronically.
Parties: the Park identified in the Order Form ("Controller") and Webinson s. r. o., Alžbetina 16, 040 01 Košice, Slovak Republic, IČO 50 399 411, DIČ 2120324261, VAT ID SK2120324261, Commercial Register of the City Court Košice, section Sro, file 39598/V, trading as PitchPace ("Processor"). This DPA is executed together with, and forms part of, the Console Services Agreement (the "Services Agreement").
1. Subject matter, nature and duration of processing
1.1 Processor operates the PitchPace console for Controller: a web application in which Controller's staff enter and manage bookings, availability, prices, units and calendar connections. Processor processes the personal data that Controller enters or imports into it on Controller's documented instructions (Art. 28 GDPR), for the duration of the Services Agreement. Processing consists of storage, retrieval, display to Controller's own users, calculation of availability and prices, import and publication of calendars, export, and deletion. There is no automated decision-making concerning data subjects and no profiling.
1.2 What the console does not do, by design. It takes no payments and holds no card data; it sends no messages to guests; it has no guest accounts and no public booking pages; it issues no invoices; it does not register guests with any authority. Guests do not use the console.
1.3 Data minimisation and tenant separation by design. For a booking the console keeps only: the dates, the unit, the numbers of adults, children and infants, the status, the amounts and how they were worked out, a free-text note, the guest's name, e-mail address and telephone number, and a history of what was done to the booking (what, when, and the name or e-mail address of the console user who did it). Every record is kept under Controller's property, and every read and write is checked against the property of the signed-in person before it happens: a person signed in to one property cannot read another's. Passwords are stored only as Argon2id hashes; session and setup tokens only as hashes; the addresses of booking-site calendars are kept as secrets and shown only in masked form.
2. Categories of data and data subjects
| Category | Data | Data subjects |
|---|---|---|
| Reservation | arrival and departure dates, unit, numbers of adults, children and infants, status, total and deposit amounts, how the price was worked out, the history of what was done to the booking (what, when and by which console user) | Park guests; the Park's staff named in the history |
| Guest contact | name, e-mail address, telephone number | Park guests and bookers |
| Notes | free text that Controller's staff write on a booking | whoever the note is about |
| Booking-site calendars | the address of each connected calendar (a secret) and the stays it publishes: dates and the label the site gives them (usually "Reserved"), normally without any guest data | normally none; a guest, if a site puts a name in a label |
2.2 The accounts of the people who sign in to the console (name, e-mail address, role, language, password hash, sign-in times, device labels) are not processed under this DPA: Processor is an independent controller of them, for providing the service, for its security and for its own legal duties, as its privacy notice (https://pitchpace.app/privacy) says.
3. Incidental personal data and data not to be entered
3.1 Controller shall not enter into the console special categories of personal data (Art. 9 GDPR), data on criminal convictions, or identity-document data; the console is not built to protect them as such. Controller is responsible for what its staff write in free-text notes.
3.2 If a note or an imported calendar label is found to contain personal data beyond the categories in clause 2, Processor does not use it for any purpose and, at Controller's request, deletes it without undue delay.
4. Instructions, confidentiality, security
4.1 Processor processes personal data only on documented instructions of Controller; the Services Agreement, the Order Form and Controller's use of the console constitute such instructions. If Processor considers that an instruction infringes data-protection law, it informs Controller.
4.2 Persons authorised to process are bound by confidentiality.
4.3 The technical and organisational measures are set out in Annex A.
5. Sub-processors
5.1 General authorisation with notice: Processor may engage the sub-processors listed in Annex B and will give 14 days' notice of changes, during which Controller may object on reasonable grounds. The current list is also published in the privacy notice at https://pitchpace.app/privacy.
Annex B (current):
| Sub-processor | Role | Location / transfer mechanism |
|---|---|---|
| Hetzner Online GmbH | hosting: the server, the database and the backups | Germany (Nuremberg); no transfer outside the EEA |
| Cloudflare, Inc. | network delivery (CDN and tunnel), DNS and e-mail routing for the domain; sees the traffic to and from the console | global network; transfers rely on the EU–US Data Privacy Framework or EU Standard Contractual Clauses |
No other sub-processor receives Controller's data: the console sends no e-mail through a third party, takes no payments and uses no analytics or advertising service.
6. Data-subject rights, breach, audits
6.1 Processor assists Controller with requests for access, correction, portability, restriction and erasure. Controller can export its bookings as a CSV file at any time, and edit or cancel them in the console; on Controller's request Processor erases or anonymises the guest data of a booking without undue delay (copies in server backups expire as stated in clause 7.3). Processor records the outcome and provides Controller with the information reasonably needed to answer the request.
6.2 Processor notifies Controller of a personal-data breach without undue delay and within 48 hours of becoming aware of it, with the information required by Art. 33(3) GDPR.
6.3 Controller may audit compliance once per calendar year on 14 days' notice, first in the form of written questions and, where reasonably required to demonstrate compliance, a remote review of the relevant controls. Audits are conducted so as not to disrupt the Service.
7. Retention and deletion
7.1 Controller decides which bookings it keeps. Booking data is kept while the Services Agreement lasts and Controller keeps the property in the console; Controller remains responsible for the periods that apply to its own records (for example accounting and tax records, which the console is not).
7.2 On termination, Processor returns Controller's data at Controller's choice (a CSV export of the bookings and, on request, a structured file with the property's other records: units, prices, settings and calendar connections) and deletes the property, its data and its accounts from the console within 30 days, confirming the deletion in writing on request, except for records that Controller instructs it to preserve under a documented legal duty and data that Webinson lawfully retains as a separate controller (for its own accounting and legal claims). Access and active processing cease immediately.
7.3 Nightly backups of the database stay on the server for 14 nights and are then deleted automatically; deleted data therefore leaves the backups within 14 days. Copies that the operator takes to a workstation for disaster recovery are deleted after 14 days.
8. International transfers
8.1 The console, its database and its backups are in Germany. The network that delivers the console (Cloudflare) is global, so processing under this DPA is not EU-only; the transfers it involves rely on the EU–US Data Privacy Framework or on standard contractual clauses concluded with the provider (Annex B).
9. Liability and precedence
9.1 Liability follows the cap in the Services Agreement. In case of conflict between this DPA and the Services Agreement regarding personal data, this DPA prevails.
10. Written form, governing law and language
10.1 The parties expressly agree that, for the purposes of this DPA, a legal act made by electronic means and signed by a party through the Xodo Sign (eversign) application satisfies the written form, in accordance with Regulation (EU) No 910/2014 (eIDAS).
10.2 This DPA is governed by the law of the Slovak Republic. The English text of this DPA governs; translations into other languages are informational.
Annex A — Technical and organisational measures
- Location and hosting. One server of Hetzner Online GmbH in Nuremberg, Germany, runs the console and its database; nothing else holds Controller's data except the backups of clause 7.3.
- Network. The console listens only on the server's local interface and is published through an encrypted tunnel from Cloudflare; the server's firewall admits only SSH, from the operator's address. Visitors are served over HTTPS with HSTS (one year), and the session cookie is
Secure, so it is never sent over plain HTTP. - Access. Administration is by the operator only, over SSH with keys; there are no shared credentials. The service runs as an unprivileged user in a hardened sandbox (no capabilities, restricted system calls, limited memory).
- Application security. Passwords are stored as Argon2id hashes; the session cookie is HttpOnly, Secure and SameSite, and a session ends after 30 days or 14 days without use; setup and reset links work once and for 7 days; tokens are stored only as hashes; sign-in and setup attempts are rate limited; requests that change data are protected against cross-site forgery; a strict content security policy allows no third-party script; error messages and logs carry no addresses, tokens or guest data.
- Tenant separation. As in clause 1.3; automated tests check that one property never sees another.
- Backups. Every night a copy of the database is written to a directory that only the service account can read, kept for 14 nights and then deleted automatically. A copy that the operator takes to a workstation for disaster recovery is kept in a folder readable only by the operator on a FileVault-encrypted disk and deleted after 14 days.
- End devices. No copies of Controller's data on end-user devices beyond transient processing.
- Deletion. Deletion and anonymisation as in clauses 6.1 and 7; removing a property deletes all of its data in one step.