Data Processing Agreement (DPA)
Level Ledger by Bar_Melis · GDPR Article 28
Version 1.0 — 8 July 2026
This Agreement is entered into between:
- The Venue — [venue legal name, address] — the Controller; and
- Andrea Melis, operating as Bar_Melis, Italy — the Processor.
It governs the Processor's processing of personal data on the Controller's behalf when providing the Level Ledger service, and forms part of the Terms of Service. Where they conflict on data protection, this DPA prevails.
1. Roles & subject matter
The Controller determines the purposes and means of processing its venue data. The Processor processes personal data only to provide and support Level Ledger, strictly on the Controller's documented instructions (these terms and its use of the Service being such instructions).
2. Duration, nature & purpose
Duration: for the term of the Service. Nature & purpose: hosting, storing, and processing the Controller's operational records so the venue can run its bar operations.
3. Data subjects & categories of personal data
| Data subjects | Personal data |
|---|---|
| The venue's staff | Name, role, hashed access PIN, activity/authorship stamps |
| Supplier contacts | Contact name, email, phone (as entered by the venue) |
No special-category data is required by the Service. The Controller must not enter special-category or irrelevant personal data.
4. Processor obligations (Art. 28(3))
- Instructions only — process personal data only on the Controller's documented instructions, including on international transfers, unless required by law (in which case it informs the Controller unless the law forbids).
- Confidentiality — ensure persons authorised to process are bound by confidentiality.
- Security (Art. 32) — implement appropriate technical and organisational measures (see §5).
- Sub-processors — engage sub-processors only under §6; impose equivalent data-protection obligations; remain fully liable for them.
- Assistance with data-subject rights — assist the Controller, by appropriate measures, to respond to requests to exercise data-subject rights (access, rectification, erasure, portability, restriction, objection).
- Assistance with compliance — assist with security, breach notification, data-protection impact assessments, and prior consultation, taking account of the nature of processing and information available.
- Breach notification — notify the Controller without undue delay after becoming aware of a personal-data breach, with the information the Controller needs to meet its obligations.
- Return or deletion — at the Controller's choice, delete or return all personal data at the end of the Service and delete existing copies, unless retention is required by law.
- Audit — make available information necessary to demonstrate compliance and allow and contribute to reasonable audits by the Controller or its mandated auditor.
5. Security measures (Art. 32)
- Each venue runs on a dedicated, isolated instance (data is not co-mingled between venues).
- Encryption at rest — the database volume is encrypted.
- Encryption in transit — all access over HTTPS/TLS.
- Credentials — access PINs are stored hashed with a salt, never in clear.
- Access control — role-based authorisation (default-deny); server-verified sessions with expiry.
- Backups — periodic backups; volume snapshots enabled.
6. Sub-processors
The Controller authorises the following sub-processor:
| Sub-processor | Purpose | Location |
|---|---|---|
| Fly.io (hosting) | Hosts the venue's Level Ledger instance and encrypted storage | EU — Frankfurt (fra) |
The Processor will give the Controller reasonable prior notice of any intended change of sub-processor, allowing the Controller to object.
7. International transfers
Personal data is hosted in the EU (Frankfurt). The Processor will not transfer personal data outside the EEA without an appropriate transfer mechanism (e.g. Standard Contractual Clauses) and prior notice.
8. Liability & governing law
Liability under this DPA is subject to the limitations in the Terms of Service, save for liability that cannot be limited under the GDPR. This DPA is governed by the laws of Italy.
9. Signatures
Name: ________________
Title: ________________
Date: ____________
Signature: ________________
Name: Andrea Melis
Title: Founder
Date: ____________
Signature: ________________
Contact
Data matters: hello@levelledger.bar
← levelledger.bar