Data Processing Agreement
1. About this Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement governing a business Customer’s use of rest easy where rest easy processes Customer Personal Data on the Customer’s behalf. rest easy is operated under the registered business name RestEasy, registration no. 782525, Athlone, Co. Westmeath, Ireland. General, legal and privacy contact is talk@resteasy.ie; technical support contact is tech@resteasy.ie.
2. Definitions
“Applicable Data Protection Law” means applicable data-protection and privacy law, including the GDPR where applicable. “GDPR” means Regulation (EU) 2016/679. “Controller”, “Processor”, “Data Subject”, “Personal Data” and “Processing” have the meanings given in Applicable Data Protection Law. “Customer” means the business or organisation using rest easy. “Customer Personal Data” means Personal Data processed by rest easy on behalf of the Customer under the agreement. “Subprocessor” means a Processor engaged by rest easy to process Customer Personal Data.
3. Roles and scope
For Customer Personal Data covered by this DPA, the Customer is Controller and rest easy is Processor. rest easy may separately act as Controller for processing undertaken for its own purposes, as described in the Privacy Policy. This DPA takes effect when the Customer relationship requires Processor activity and continues while that activity continues.
4. Processing instructions
rest easy will process Customer Personal Data only on documented Customer instructions, as necessary to provide the contracted service, or as required by Applicable Data Protection Law. This DPA, the agreement, Customer configuration and legitimate use of the platform constitute documented instructions. If law requires processing contrary to an instruction, rest easy will inform the Customer unless prohibited by law. rest easy may inform the Customer and suspend affected Processing if it reasonably believes an instruction infringes Applicable Data Protection Law.
5. Customer responsibilities
The Customer is responsible for the lawful basis, transparency, accuracy and lawfulness of Customer Personal Data and instructions; appropriate user access; responding to Data Subject matters for which it is responsible; and providing any workplace or privacy information required by law. The Customer should not submit unnecessary special-category data through free-text fields, including health, biometric, racial or ethnic, religious, political, trade-union, sexual-life or orientation information, unless expressly supported and a lawful basis exists.
6. Confidentiality and security
rest easy will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations. It will implement appropriate technical and organisational measures, taking account of the state of the art, implementation costs, and the nature, scope, context, purposes and risks of Processing. The current measures are described in Schedule 2.
7. Assistance and Personal Data Breaches
Taking account of the nature of Processing, rest easy will provide reasonable assistance with Data Subject requests, Data Protection Impact Assessments and prior consultation with supervisory authorities where required and relevant. If rest easy receives a request directly relating to Customer-controlled data, it will ordinarily refer the requester to the Customer unless legally required otherwise. rest easy will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, where required, and provide available information reasonably necessary to assist the Customer.
8. Subprocessors and international transfers
The Customer gives general authorisation for rest easy to engage appropriate Subprocessors necessary to provide the service. rest easy will impose appropriate data-protection obligations on Subprocessors and remains responsible for their relevant Processing. rest easy will notify the Customer of material new Subprocessors by updating Schedule 3 or another reasonable electronic notice mechanism, allowing the Customer to raise a reasonable data-protection objection. Where Customer Personal Data is transferred outside the EEA, rest easy will use an appropriate Chapter V mechanism, such as an adequacy decision, Standard Contractual Clauses or another legally recognised safeguard.
9. Return and deletion
Following the end of Processing, rest easy will, at the Customer’s choice where applicable, delete or return Customer Personal Data, subject to the agreement, Applicable Data Protection Law, legitimate retention requirements and technical limitations. Customer Personal Data may remain temporarily in protected backups until normal backup rotation expires. The planned 90-day account lifecycle is not currently automated and is not a current commitment under this DPA.
10. Information and audits
rest easy will make available information reasonably necessary to demonstrate compliance with its Article 28 obligations. Where legally required, it will permit reasonable audits or inspections on reasonable prior notice, during normal business hours where practicable, subject to confidentiality, avoidance of disruption and protection of other Customers’ information. Existing security documentation should be used where sufficient. The Customer bears its own audit costs unless law requires otherwise or material non-compliance is identified.
11. Liability, precedence and governing law
Liability under this DPA is subject to the applicable liability provisions of the Terms of Service, except where Applicable Data Protection Law requires otherwise. This DPA prevails over general Terms only to the extent of a conflict concerning Customer Personal Data. A specific properly executed written agreement prevails where it expressly says so. This DPA is governed by the laws of Ireland.
Schedule 1 — Details of Processing
Subject matter, duration and purpose
Provision of the rest easy operational-management service for the duration that rest easy processes Customer Personal Data under the Customer relationship, subject to applicable retention and deletion requirements. Processing supports Customer accounts, authorised-user access, operational check recording, Critical Control Point (CCP) management, NFC-supported check recording, issue management, dashboards, reporting, notifications, support, security and related service functionality. A CCP is a configurable operational or checkable point and is not limited to a restroom.
Nature of Processing
Processing may include collection, recording, organisation, storage, retrieval, consultation, display, transmission, reporting, analysis required for service functionality, restriction, deletion or anonymisation where applicable, and backup and recovery.
Data Subjects and Customer Personal Data
Data Subjects may include Customer employees, workers, contractors, cleaners, managers, authorised Customer users and other individuals whose information the Customer lawfully enters. Customer Personal Data may include names, business email addresses, optional phone numbers, platform roles, business or unit associations, account identifiers, operational check activity, timestamps, CCP associations, NFC-use indicators, Customer-entered notes, issue acknowledgement or resolution activity, and reporting or audit information. Passwords are not included; authentication uses protected credentials and password hashes. Anonymous public feedback is not automatically treated as Customer Personal Data; related privacy processing is described in the Privacy Policy.
Schedule 2 — Technical and Organisational Measures
- HTTPS/TLS for browser communications.
- Password hashing, authentication, role-based access control and business-scoped access restrictions.
- Secure PHP sessions using Secure, HttpOnly and SameSite=Lax settings, with trusted-device controls where enabled.
- Prepared database statements and appropriate database access controls.
- Controlled administrative and support access, logging and security monitoring appropriate to the service.
- Backups and recovery measures where applicable; backup retention is not represented as a fixed period.
- Cloudflare Turnstile for selected public-form abuse prevention.
- Security maintenance, patching and incident-handling processes appropriate to the service.
Schedule 3 — Subprocessors
HostGator / Newfold
Provides website, database and hosted-email infrastructure in the United States. Appropriate international-transfer safeguards are used where required, including Standard Contractual Clauses where applicable.
Cloudflare
Provides Turnstile security and abuse-prevention services for selected public forms where used.
Google Analytics is consent-based Controller-side analytics and is not listed as a Subprocessor for Customer Personal Data. No live payment provider is listed. Browser push delivery may involve browser-selected push services; no separate provider is identified in this schedule because the provider depends on the recipient browser.
Related documents
See the Terms of Service, Privacy Policy and Cookie Policy. Cookie preferences can be changed through Cookie settings.
