Bokko
Back to home

Legal Document

Data Processing Agreement (DPA)

This document records the terms of the GDPR Article 28 Data Processing Agreement between Bokko (processor) and the service provider (controller) subscribing to the platform. Effective as of: July 11, 2026 (Open Beta — v1-open-beta-r3-en).

Governing Language. This English translation is provided for convenience only. In the event of any discrepancy or dispute, the Hungarian version of this DPA shall be the sole authoritative text.
Summary of Roles: Regarding data of guests using the booking page, the controller is the subscriber (the provider), and the processor is Bokko. Bokko's independent privacy policy applies only to platform business users.

Contents

1. Parties & Definitions 2. Subject & Duration 3. Nature & Purpose 4. Categories & Subjects 5. Right to Instruct 6. Confidentiality 7. Security Measures (Art. 32) 8. Sub-processors 9. International Transfers 10. Supporting Subject Rights 11. Data Breaches 12. Impact Assessments (DPIA) 13. Audit & Compliance 14. Deletion & Return 15. Liability & Indemnity 16. Governing Law 17. Versioning

1. Parties and Definitions

Data Controller: The business subscriber (the "Subscriber") processing guest data.

Data Processor: Bokko, the platform operator, processing data on behalf of the Subscriber.

Definitions for Personal Data, Processing, and Data Subject are as per Article 4 of the GDPR.

2. Subject and Duration

This DPA governs the processing of guest booking data performed by Bokko on behalf of the Subscriber. It remains in force for the duration of the contractual relationship.

3. Nature and Purpose of Processing

Bokko performs the following operations on behalf of the Subscriber:

  • receiving and managing booking requests;
  • sending transactional notifications (emails/SMS);
  • storing guest profiles and booking history;
  • technical service for payments and invoicing integrations.

4. Data Categories and Data Subjects

Data Subjects: Guests (customers of the Subscriber).

Categories: Name, phone number, email, service details, booking status history, payment/billing metadata, and consent logs.

Prohibited Data: The Subscriber is strictly prohibited from recording special categories of data (GDPR Art. 9) on the platform.

5. Right to Instruct

The Subscriber is the controller and has the sole right to instruct. Bokko processes data only based on documented instructions, including platform configuration settings.

5a. Advance documented general instruction — guest data-management portal

Bokko provides a central, cross-provider, magic-link-authenticated self-service guest data-management portal ("My Data"), through which a guest (data subject) may request the withdrawal of marketing consent and the anonymisation of their erasable personal data. By accepting this agreement, the Subscriber (controller) instructs Bokko in advance, on a general basis, to execute such data-subject requests automatically — without individual controller discretion — according to the following objective, pre-defined conditions (guards):

  • Bokko anonymises only operational personal data not subject to statutory retention (in particular record retention under the Hungarian Accounting Act and VAT Act); records that must be retained by law remain, segregated;
  • in the case of an open financial or legal matter (a payment, refund, final invoice, or legal dispute in progress), the affected data is retained until the matter is closed, after which the system automatically re-evaluates erasability;
  • execution is two-stage: immediate access restriction, followed by final erasure after a short, encrypted, isolated recovery window;
  • Bokko logs the execution of every data-subject request and attributes the legal basis to the controlling Subscriber (Bokko executes the controller's instruction).

The Subscriber may at any time limit or suspend this general instruction (e.g. by taking a specific request for manual review, or by applying a legal hold) through the relevant dashboard surface; a decision given this way likewise qualifies as a documented instruction. If, in Bokko's assessment, the automatic execution of a given request would breach the law, Bokko suspends execution and forwards the request to the controlling Subscriber for decision.

6. Confidentiality

Bokko ensures that persons authorized to process data have committed themselves to confidentiality and access data only on a need-to-know basis.

7. Technical and Organizational Measures (Art. 32)

Bokko implements appropriate technical and organizational measures (TOMs), including encryption at rest and in transit, role-based access control, and tokenized guest response flows.

8. Sub-processors

Bokko has general authorization to engage sub-processors. The current list is available at getbokko.com/legal/sub-processors. Subscribers will be notified of changes 14 days in advance and have the right to object.

9. International Transfers

Transfers outside the EEA are based on Standard Contractual Clauses (SCC) or the EU–US Data Privacy Framework (DPF).

10. Supporting Data Subject Rights

Bokko assists the Subscriber in fulfilling requests from data subjects to exercise their rights under GDPR Chapter III.

Through the central guest data-management portal ("My Data", see Section 5a), the data subject may also exercise their right to erasure and to withdraw marketing consent in a self-service manner. Bokko processes requests received through the portal on the basis of the Subscriber's advance documented general instruction under Section 5a; requests requiring manual review or subject to a legal hold are decided by the controlling Subscriber in the dashboard.

11. Data Breaches

Bokko notifies the Subscriber of personal data breaches without undue delay after becoming aware of them.

14. Deletion and Return

Upon termination, Bokko provides a 30-day window for the Subscriber to export data via the self-service export function. After this window expires, Bokko deletes or anonymizes the data, except where law requires retention (e.g., accounting obligations applicable to Bokko as invoice issuer).

Scope note — Bokko's own logs: Security, access, and audit logs necessary for the operation of the system (access log, rate limiting, security telemetry, fraud prevention) may be retained by Bokko as an independent controller — based on its own legal obligations and legitimate interests in legal defence. The deletion obligation under this DPA does not extend to such logs; the applicable retention periods are set out in the Retention Policy.

Backups: With regard to the Firestore database, Bokko operates several complementary backup mechanisms exclusively for disaster recovery and continuity purposes:

  • Point-in-Time Recovery (PITR): the database can be restored to any point within the last 7 days — 1-minute granularity for the last 1 hour, 1-hour buckets for 7 days.
  • Daily automatic backup: 14-day retention on the entire Firestore database.
  • Weekly automatic backup: every Monday, 84-day (12-week) retention on the entire Firestore database.

Backup mechanisms serve only system-level disaster recovery; restoration of individual guest records is generally not performed — unless required to fulfil a legal obligation or for official proceedings. Backups are stored encrypted at rest (encryption-at-rest) on the Google Cloud platform, protected by the same access-control mechanisms as the live database.

At the Subscriber's request, Bokko issues written confirmation of the deletion.

Temporary retention suspension (legal hold): Upon the Subscriber's documented instruction, Bokko may temporarily suspend the execution of deletion with respect to specific records if continued retention is necessary for the fulfilment of a legal obligation, for official proceedings, or for the establishment, exercise, or defence of legal claims. Such retention is purpose-bound, time-limited and documented; upon termination of the suspension, Bokko processes the affected records according to the general deletion rules. The suspension request and its justification must be sent in writing by the Subscriber (support@bokko.app).

15. Liability

Liability for data protection-related damages is governed by Article 82 of the GDPR. General liability limits in the Service Agreement do not apply to GDPR Art. 82 claims.

16. Governing Law

Hungarian law and the GDPR apply. Supervisory authority: NAIH (Hungary).

Product

Features Sign up Log in Status Help

Legal

All legal documents Privacy Policy Terms of Service Service Agreement Imprint & Contact

Compliance

Sub-processors Retention policy Cookie policy Security & privacy

© 2026 Bokko