Data Processing Agreement (DPA)

Level Ledger by Bar_Melis · GDPR Article 28

Version 1.0 — 8 July 2026

Template — not legal advice. A starting point for an early-access pilot in the EU. Have it reviewed by a qualified data-protection lawyer before signing.

This Agreement is entered into between:

It governs the Processor's processing of personal data on the Controller's behalf when providing the Level Ledger service, and forms part of the Terms of Service. Where they conflict on data protection, this DPA prevails.

1. Roles & subject matter

The Controller determines the purposes and means of processing its venue data. The Processor processes personal data only to provide and support Level Ledger, strictly on the Controller's documented instructions (these terms and its use of the Service being such instructions).

2. Duration, nature & purpose

Duration: for the term of the Service. Nature & purpose: hosting, storing, and processing the Controller's operational records so the venue can run its bar operations.

3. Data subjects & categories of personal data

Data subjectsPersonal data
The venue's staffName, role, hashed access PIN, activity/authorship stamps
Supplier contactsContact name, email, phone (as entered by the venue)

No special-category data is required by the Service. The Controller must not enter special-category or irrelevant personal data.

4. Processor obligations (Art. 28(3))

  1. Instructions only — process personal data only on the Controller's documented instructions, including on international transfers, unless required by law (in which case it informs the Controller unless the law forbids).
  2. Confidentiality — ensure persons authorised to process are bound by confidentiality.
  3. Security (Art. 32) — implement appropriate technical and organisational measures (see §5).
  4. Sub-processors — engage sub-processors only under §6; impose equivalent data-protection obligations; remain fully liable for them.
  5. Assistance with data-subject rights — assist the Controller, by appropriate measures, to respond to requests to exercise data-subject rights (access, rectification, erasure, portability, restriction, objection).
  6. Assistance with compliance — assist with security, breach notification, data-protection impact assessments, and prior consultation, taking account of the nature of processing and information available.
  7. Breach notification — notify the Controller without undue delay after becoming aware of a personal-data breach, with the information the Controller needs to meet its obligations.
  8. Return or deletion — at the Controller's choice, delete or return all personal data at the end of the Service and delete existing copies, unless retention is required by law.
  9. Audit — make available information necessary to demonstrate compliance and allow and contribute to reasonable audits by the Controller or its mandated auditor.

5. Security measures (Art. 32)

6. Sub-processors

The Controller authorises the following sub-processor:

Sub-processorPurposeLocation
Fly.io (hosting)Hosts the venue's Level Ledger instance and encrypted storageEU — Frankfurt (fra)

The Processor will give the Controller reasonable prior notice of any intended change of sub-processor, allowing the Controller to object.

7. International transfers

Personal data is hosted in the EU (Frankfurt). The Processor will not transfer personal data outside the EEA without an appropriate transfer mechanism (e.g. Standard Contractual Clauses) and prior notice.

8. Liability & governing law

Liability under this DPA is subject to the limitations in the Terms of Service, save for liability that cannot be limited under the GDPR. This DPA is governed by the laws of Italy.

9. Signatures

Controller (the Venue)

Name: ________________
Title: ________________
Date: ____________
Signature: ________________
Processor (Bar_Melis)

Name: Andrea Melis
Title: Founder
Date: ____________
Signature: ________________

Contact

Data matters: hello@levelledger.bar

← levelledger.bar