Data Processing Addendum

1.Introduction

This Addendum details the conditions for processing personal data within the BikesBay.Cloud system, clarifying the provisions set out in the Privacy Policy and Terms of Service. The primary goal is to ensure compliance with the General Data Protection Regulation (GDPR).

2. Data Processing Principles

Data processing within the System is based on legality, fairness, transparency, integrity, and confidentiality.

3. Roles and Responsibilities

  • The System Owner acts as a data processor.
  • Hetzner, providing server infrastructure, also acts as a data processor, ensuring compliance with GDPR.
  • System Users act as data controllers, determining the purposes and means of processing their clients' personal data.

4. Data Processing and Usage Objectives

Data processed in the System includes personal information of clients such as names, addresses, contact details, and payment data. These data are used for managing bookings, serving customers, and for analytical purposes to enhance the functionality of the System.

5. Data Transfer

Personal data may only be transferred to third parties in strict compliance with legal requirements and with necessary confidentiality guarantees. Data transfers can only occur in cases prescribed by law and with the consent of the data subjects.

6. Security Measures

  • Encryption: All data are encrypted during storage and transmission.
  • Access Audit: Strict accounting and control of data access are maintained.
  • Backup: Regular data backups are performed to prevent data loss.
  • Access Control: Data access is restricted and only available to authorized individuals.
  • Security Assessment: Regular security assessments are conducted to identify and mitigate potential vulnerabilities.

7. Data Subject Rights

Data subjects have the right to access information about whether their data are being processed and to which categories of data they have access. Full access to data is not provided due to technical limitations of the system. Data subjects also have the right to rectification, deletion of their data, and restriction of processing, as well as the right to object to processing. Details of these rights, including request and verification procedures, are described in detail in the Privacy Policy.

8. Amendments to the Addendum

Any changes to this document will be published on the website with prior notification to users 30 days in advance.

9. Contact Information

For inquiries related to data processing, please contact via email at: [email protected]