EN ES
← Back to Start Page

Data Processing Agreement (DPA)

Last updated: August 07 2026

This Data Processing Agreement ("DPA") specifies the data protection obligations of the parties under Article 28 of the General Data Protection Regulation (GDPR) and forms an integral part of the Terms of Use between Booklogica (operated by Drazen Miletic, Austria; "Processor") and the business entity utilizing the service ("Controller").

1. Scope and Subject Matter

The Processor provides technical calendar synchronization services (Booklogica Calendar Sync). In providing these services, the Processor processes personal data (such as reservation metadata, client names, email addresses, phone numbers, and timestamps) strictly on behalf of and according to the instructions of the Controller. The duration of the processing corresponds to the duration of the underlying Terms of Use agreement.

2. Obligations of the Controller

The Controller is solely responsible for assessing the lawfulness of the data processing and for safeguarding the rights of data subjects. The Controller guarantees that it has obtained all necessary consents or has a valid legal basis to collect and process the personal data of its end-clients via the Booklogica platform.

3. Technical and Organizational Measures

The Processor implements appropriate technical and organizational security measures under Article 32 GDPR to protect the data against unauthorized access, alteration, disclosure, or loss. Data is hosted utilizing secure EU-based Google Cloud infrastructure and protected via Cloudflare network shields. The Processor ensures that all personnel authorized to process the personal data have committed themselves to strict confidentiality.

4. Sub-processors

The Controller hereby grants a general written authorization for the Processor to engage sub-processors for hosting, infrastructure, and security optimization. Current authorized sub-processors are Google Cloud Services and Cloudflare. The Processor ensures that all sub-processors are contractually bound to data protection standards equivalent to those in this DPA. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, allowing the Controller to object.

5. Data Subject Rights & Obligations

The Processor will assist the Controller, as far as reasonably possible, in fulfilling its statutory obligations under the GDPR, including responding to end-user requests regarding data access, rectification, restriction, or deletion. Data deletion requests sent by the Controller to [email protected] will be processed permanently without undue delay.

6. Term, Termination, and Deletion

This DPA remains active as long as the Controller maintains an active account with Booklogica. Upon termination of the service or account deletion, all active synchronization metadata and associated logs will be permanently deleted from the Processor's live servers within a reasonable timeframe, unless applicable Union or Member State law requires storage of the personal data.

7. Limitation of Liability

Any liability arising under or in connection with this DPA shall be governed by, and subject to, the limitations and exclusions of liability set forth in the primary Booklogica Terms of Use.