Effective date: 01.07.2026 · Last updated: 16.07.2026 (this version replaces the version of 14.07.2026).
Eesti keeles: Andmetöötlusleping (Estonian original). This document is a translation; in case of any conflict, the Estonian version prevails. The English translation may be updated with a delay and may temporarily reflect the earlier (14.07.2026) version. This Data Processing Agreement (hereinafter the DPA) governs the processing of personal data carried out by RATTURI KALA OÜ (Tarje) on the Customer's behalf in the provision of Tarje's web-based point-of-sale and management system. The DPA has been drawn up in accordance with Article 28(3) of the General Data Protection Regulation (GDPR) and forms an integral part of the Terms of Service.
1. Definitions
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meaning given to them in the Terms of Service.
- Tarje or the Processor — RATTURI KALA OÜ (private limited company), registry code 17385866, registered address Ratturi, Reigi küla, Hiiumaa vald, Hiiu maakond 92265, e-mail info@tarje.ee.
- Customer or the Controller — the business using the Service (e.g. a restaurant, café or bar) that has accepted the Terms of Service.
- Service — Tarje's web-based point-of-sale and management system (Tarje POS) at https://pos.tarje.ee together with related features.
- End Customer — a customer of the Customer (e.g. a café visitor or loyalty customer) whose personal data are processed in the Service on the Customer's behalf.
- Terms of Service — the terms governing the use of the Tarje Service, available at terms-en.html.
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
- Sub-processor — a third party engaged by Tarje to process personal data on the Customer's behalf (GDPR Article 28(2) and (4)).
- Personal data, processing, data subject and personal data breach — as defined in Article 4 of the GDPR.
2. Parties, roles and scope
2.1. The Parties' roles in the processing of personal data are as follows:
| Party | Role (GDPR) |
|---|---|
| Customer (the café/restaurant/business using the Service) | Controller |
| RATTURI KALA OÜ (registry code 17385866), hereinafter Tarje | Processor |
2.2. The DPA forms an integral part of the Terms of Service and becomes binding between the Parties automatically when the Customer accepts the Terms of Service and processes the personal data of End Customers (e.g. café visitors) in the Service. Separate signing is not required, but the Customer may request a signed copy at info@tarje.ee.
2.3. The DPA governs only data that Tarje processes on the Customer's behalf and on the Customer's instructions (e.g. End Customer, order and loyalty data). With respect to the Customer's own account and billing data, Tarje acts as an independent controller in accordance with the Privacy Policy, and this DPA does not apply to such data.
2.4. In the event of a conflict between the DPA and the Terms of Service, this DPA prevails with respect to the processing of personal data.
3. Subject matter, duration, nature and purpose of processing
3.1. The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the types of personal data are described in Annex A.
3.2. Tarje processes personal data only to the extent necessary to provide the Service to the Customer, including sales and order management, the loyalty programme, gift card management, delivery of e-receipts and invoices, reporting and related features.
3.3. The Service also operates during a temporary internet outage: in such a case, data are temporarily stored on a device under the Customer's control and synchronised to the Service once the connection is restored. The Customer is responsible for the physical and access security of the Customer's devices. Tarje's backups do not include unsynchronised data held on the Customer's devices.
4. Processing on documented instructions
4.1. Tarje processes personal data only on the Customer's documented instructions, including with regard to transfers of data to third countries or international organisations (GDPR Article 28(3)(a)). This DPA, the Terms of Service and the Customer's ordinary use of the Service's features constitute the Customer's documented instructions. Additional instructions shall be given by the Customer in a form enabling written reproduction (e.g. by e-mail to info@tarje.ee). The Customer's documented instructions are also deemed to include, among other things, integrations activated by the Customer in the Service and the transmission of data via API or webhook to a destination designated by the Customer; the Customer is responsible for the selection of such recipients, the access granted to them and their further processing of the data, and such recipients are not Tarje's sub-processors.
4.2. If the processing of personal data is required by European Union or Member State law applicable to Tarje, Tarje may process the data without the Customer's instructions; in such a case, Tarje shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4.3. Tarje shall immediately inform the Customer if, in Tarje's opinion, an instruction infringes the GDPR or other European Union or Member State data protection provisions. Tarje is entitled to suspend the implementation of such an instruction until clarification is received.
5. Confidentiality
5.1. Tarje ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR Article 28(3)(b)).
5.2. Access to personal data is granted only to persons who need it for the performance of their duties, and only to the extent necessary. The confidentiality obligation continues to apply after the end of the employment or contractual relationship.
6. Security measures (GDPR Article 32)
6.1. Tarje implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons (GDPR Article 28(3)(c) and Article 32). The measures are described in Annex B.
6.2. Tarje reviews the security measures regularly and improves them in line with technological developments and risks. Tarje may update the measures provided that the overall level of security is not reduced.
7. Sub-processors
7.1. The Customer grants Tarje a general written authorisation to engage sub-processors (GDPR Article 28(2)). The list of approved sub-processors is set out in Annex C.
7.2. Tarje enters into a contract with each sub-processor that imposes on the sub-processor substantially the same data protection obligations as this DPA (GDPR Article 28(4)). Tarje remains fully liable to the Customer for the performance of the sub-processor's obligations.
7.3. Tarje shall inform the Customer in advance of intended changes concerning sub-processors (addition or replacement), giving the Customer a reasonable period to raise reasoned objections. If the Parties do not reach a resolution of the objection within a reasonable time, the Customer is entitled to terminate the use of the Service in accordance with the procedure set out in the Terms of Service.
7.4. The up-to-date list of sub-processors is available from Tarje at info@tarje.ee.
8. International transfers
8.1. Personal data are, as a rule, processed in the European Union or the European Economic Area (EU/EEA).
8.2. If a sub-processor processes data outside the EU/EEA, Tarje ensures appropriate safeguards, such as the Standard Contractual Clauses (SCCs) approved by the European Commission, a European Commission adequacy decision or other appropriate safeguards in accordance with Chapter V of the GDPR.
8.3. Transfers to third countries take place only on the Customer's documented instructions in accordance with clause 4.1, or where required by law applicable to Tarje in accordance with clause 4.2.
9. Assistance with data subjects' rights
9.1. Tarje assists the Customer, taking into account the nature of the processing and insofar as possible by appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to data subjects' requests (GDPR Articles 12–23 and Article 28(3)(e)), including requests for access, rectification, erasure, restriction, objection and data portability.
9.2. The Service includes tools for this purpose: the Customer can at any time view, rectify and export End Customer data (in a machine-readable format, including CSV/Excel) and delete individual End Customer records.
9.3. If a data subject submits a request directly to Tarje, Tarje shall forward it to the Customer without undue delay and shall not respond to the request on the merits without the Customer's instructions, unless legislation requires otherwise.
10. Personal data breach and assistance (Articles 32–36)
10.1. Upon becoming aware of a personal data breach, Tarje shall notify the Customer without undue delay (GDPR Article 33(2)).
10.2. The notification shall include the information reasonably available to Tarje that enables the Customer to fulfil its obligations, including, where possible: a description of the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of personal data records concerned, the likely consequences of the breach, and the mitigation and remedial measures taken or proposed. Where it is not possible to provide all the information at the same time, Tarje shall provide it in phases without undue delay.
10.3. For the avoidance of doubt: notifying the supervisory authority (the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), https://www.aki.ee) within 72 hours of becoming aware of the breach (GDPR Article 33(1)) and, where necessary, notifying the data subjects (Article 34) are obligations of the Customer as controller. Tarje does not notify the supervisory authority or the data subjects on the Customer's behalf, except by separate agreement between the Parties or where required by legislation.
10.4. Tarje shall cooperate with the Customer and take reasonable measures to mitigate the effects of the breach and to prevent its recurrence, and shall document the circumstances relating to the breach.
10.5. Tarje assists the Customer, taking into account the nature of the processing and the information available to Tarje, in fulfilling the obligations set out in GDPR Articles 32–36: security of processing (Article 32), breach notification (Articles 33–34), data protection impact assessment (Article 35) and prior consultation of the supervisory authority (Article 36) (GDPR Article 28(3)(f)).
11. Obligations of the Controller (the Customer)
11.1. The Customer confirms and warrants that: (a) it has a valid legal basis for the personal data processed in the Service (e.g. consent, contract or legitimate interest); (b) it has duly informed the data subjects (including End Customers and its employees) in accordance with GDPR Articles 13–14; (c) its instructions to Tarje comply with applicable law; (d) the data it enters are accurate and lawfully collected.
11.2. The Customer shall not enter special categories of personal data (GDPR Article 9) or data relating to criminal convictions and offences (Article 10) into the Service. The Service is not intended for the processing of such data.
11.3. The Customer is responsible for the proper management of its user accounts, passwords and employee PIN codes and for the security of its devices to the extent within its control, including the timely revocation of access rights when an employee leaves.
12. Return and deletion of data upon termination of the contract
12.1. The Customer can at any time export its data via the Service in a machine-readable format (including CSV/Excel) and delete individual End Customer records.
12.2. Upon the end of the provision of the processing services, Tarje shall, at the Customer's choice, delete or return all personal data processed on the Customer's behalf (GDPR Article 28(3)(g)). Return takes place via the Service's export function (CSV/Excel).
12.3. Upon termination of the contract, Tarje retains the data for a reasonable period (as a rule, up to 30 days) so that the Customer can download them, after which the data are deleted or anonymised, except for data whose retention is required by European Union or Member State law — in such a case, the data are retained only to the extent and for the period required and are not processed for any other purpose.
12.4. Data may persist in backups until the end of the automatic backup rotation (up to 60 days); backups are used solely for restoration purposes and are not processed for any other purpose.
12.5. At the Customer's written request, Tarje shall confirm the deletion of the data in a form enabling written reproduction.
13. Information and audits
13.1. Tarje makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer (GDPR Article 28(3)(h)).
13.2. Tarje fulfils its information obligation primarily by providing documentation, written responses and existing third-party assessments (e.g. sub-processors' certificates and audit reports). An on-site or remote audit shall take place with reasonable advance notice, during normal business hours and in a manner that does not jeopardise the security of the Service or the data of other customers; the persons participating in the audit shall assume a confidentiality obligation.
13.3. Each Party bears its own costs relating to an audit. If an audit identifies a material breach of this DPA by Tarje, Tarje shall bear the reasonable and documented costs of the audit.
13.4. An auditor mandated by the Customer may not be a competitor of Tarje.
14. Liability and compensation
14.1. The Parties' liability towards data subjects is determined under Article 82 of the GDPR. Tarje, as processor, is liable for damage caused by processing only where it has not complied with the obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the Customer's lawful instructions.
14.2. Where one Party has paid compensation to a data subject for damage for which the other Party is wholly or partly liable, the paying Party is entitled to claim back from the other Party that part of the compensation corresponding to the other Party's part of responsibility for the damage (GDPR Article 82(5)).
14.3. In other respects, the limitations of liability set out in the Terms of Service apply to the liability between the Parties to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects or the Parties' liability towards the supervisory authority.
15. Term, amendment and applicable law
15.1. This DPA entered into force on 01.07.2026 (last updated: 16.07.2026; previous version: 14.07.2026) and remains in force for as long as Tarje processes personal data on the Customer's behalf, including during the post-termination period set out in clause 12.
15.2. Tarje may amend the DPA in the same manner as the Terms of Service; the Customer shall be notified of amendments in advance in the manner set out in the Terms of Service. Amendments may not reduce the level of data protection set out in this DPA without the Customer's consent.
15.3. This DPA is governed by the law of the Republic of Estonia. Disputes are resolved in accordance with the procedure set out in the Terms of Service.
15.4. If any provision of the DPA proves to be invalid, the remaining provisions remain in force; the invalid provision shall be replaced by a valid provision that comes as close as possible to the purpose of the invalid provision.
ANNEX A — Description of processing
| Nature and purpose of processing | Collection, recording, storage, display, alteration, erasure and transmission of personal data to the extent necessary to provide the Service (point-of-sale and management system) to the Customer: sales and order management, loyalty programme, gift card management, delivery of e-receipts and invoices, reporting and related features; on the Customer's instructions, transmission of data to recipients designated by the Customer (e.g. integrations, API, webhooks). During a temporary internet outage, data may be temporarily stored on the Customer's device and synchronised once the connection is restored. |
|---|---|
| Subject matter of processing | Personal data that the Customer and its users enter into the Service or that arise in the course of using the Service on the Customer's behalf. |
| Duration of processing | For the term of the contract (use of the Service) and during the post-termination period set out in clause 12. |
| Categories of data subjects | The Customer's end customers (e.g. café visitors, loyalty customers); the Customer's employees and users (e.g. service staff). |
| Types of personal data | Name; contact details (e.g. telephone, e-mail) to the extent entered by the Customer; loyalty programme data (e.g. points, visit and purchase history); order data; the End Customer's e-mail address entered for sending an e-receipt or invoice; gift card data (code, balance, optional holder name); employee name and role and authentication data (the PIN is stored hashed, not in plain text). |
| Special categories of data | The Service is not intended for the processing of special categories of personal data (GDPR Article 9). The Customer undertakes not to enter such data into the Service. |
| Location of processing | As a rule, the EU/EEA; exceptions in accordance with clause 8 and Annex C. |
ANNEX B — Technical and organisational security measures (Article 32)
- Database-level access restriction — row-level security (RLS) ensures that each Customer can access only its own data; the data of different cafés are strictly segregated from one another.
- Encryption in transit — all data traffic takes place over an encrypted connection (TLS/HTTPS).
- Protection of authentication data — employee PIN codes are stored only in hashed form (bcrypt), not in plain text.
- Access rights management — role-based access; sensitive operations and data are restricted server-side.
- Application secrets — service keys are kept server-side and are not transmitted to devices.
- Backups — regular automatic database backups (made at least once every 24 hours), retained for up to 60 days. Backups do not include unsynchronised data held on the Customer's devices.
- Two-factor authentication (2FA) — TOTP-based two-factor authentication is available for Customer accounts.
- Password policy — a password must be at least 12 characters long and contain letters and numbers; passwords are checked against a database of known leaked passwords.
- Overwrite protection and change history — database-level safeguards against the mass emptying of collections, and a version history of settings changes.
- Logging and monitoring — security and error monitoring enabling incidents to be detected and handled.
- Data minimisation and retention periods — data are processed only to the extent necessary and retained only for as long as necessary.
- Confidentiality obligations — persons with access to personal data are under a confidentiality obligation (clause 5).
Tarje reviews the security measures regularly and improves them in line with technological developments and risks.
ANNEX C — Approved sub-processors
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Supabase | Database and cloud hosting | EU (Frankfurt, AWS eu-central-1) |
| Stripe | Payment processing (card data are processed directly by Stripe; Tarje does not store them) | Covered by SCCs |
| Resend | Sending technical and service-related e-mails (including, on the Customer's instructions, e-receipts and invoices to End Customers) | Covered by SCCs |
| veebimajutus.ee (Elkdata OÜ) | Domain, DNS and e-mail infrastructure | Estonia (EU) |
The up-to-date list of sub-processors is available from Tarje at info@tarje.ee. Notification of changes and the right to object are set out in clause 7.