Data Processing Agreement (DPA)

Pursuant to Art. 28 GDPR · Version: 2026-09-14.2

v2026-09-14.2

1. Parties and Subject Matter

This agreement applies between the customer (controller within the meaning of Art. 4 No. 7 GDPR) and Tippale.com, Inh. Michael Lev-Ari, Auf dem Neuen Feld 8, 63303 Dreieich, Deutschland (processor). Its subject is the processing of personal data in connection with the use of the Tippale platform for tip distribution, shift scheduling, time tracking and payroll.

The controller remains responsible for the lawfulness of the processing and for the rights of the data subjects.

2. Nature, Scope and Purpose of Processing

Processing includes collection, storage, organisation, calculation, retrieval, disclosure on instruction, return and deletion for the contracted modules: tips, scheduling, time tracking, payroll, absences, purchasing, accounting, inventory, document intake and extraction, team communication, reports and AI assistance. Data subjects also include suppliers, their contacts and other persons named in customer documents. Health, disability and religious-affiliation data can be special categories under Art. 9 GDPR and may be processed only on lawful instructions with restricted access.

3. Categories of Data Subjects and Data

  • Data subjects: employees, managers and owners of the customer.
  • Data categories: master data (name, contact details, date of birth, address, nationality), working-time, clock-in/out and shift data incl. GPS check results, remuneration and tip data, social-security and tax data, bank/payout data, garnishments, absences (vacation, sickness) and related documents, contracts and signed onboarding forms, in-app messages, as well as business documents (invoices, POS reports, cash book) that may contain personal data of third parties.

4. Processing on Instructions

The processor processes data solely on the documented instructions of the controller and not for its own purposes. If it considers an instruction unlawful, it informs the controller without delay.

5. Technical and Organisational Measures (Art. 32 GDPR)

  • Encrypted transmission (TLS) and encrypted storage of sensitive data.
  • Role- and tenant-based access control (row-level security per business).
  • Authentication via the platform's identity provider, access logging.
  • Appropriate backup, recovery and effectiveness-review measures under Art. 32 GDPR, with provider-managed controls assessed against the applicable provider documentation.
  • Confidentiality obligations for all persons involved in processing.

6. Sub-processors

The controller grants general authorisation for the service categories listed below. The applicable provider documentation determines the legal entity, location and any further sub-processors. A customer-connected provider is a sub-processor only insofar as it processes data on Tippale’s behalf; independent controllers and customer-appointed providers are not automatically sub-processors. Tippale’s own subscription billing via Base44 Payments is addressed in the Privacy Policy:

  • Base44 - hosting, database, authentication, file storage, e-mail dispatch and AI integrations
  • AI model providers engaged via Base44 (e.g. OpenAI, Google, Anthropic) - schedule generation, insights, assistants, document extraction; subject to contractual data-use restrictions
  • Apple Push Notification service / Google Firebase Cloud Messaging - push delivery to mobile devices
  • POS, Wix and delivery-platform providers - only where connected by the controller

The controller is informed in advance of intended changes and may object on important data-protection grounds. The processor binds every sub-processor by a written agreement imposing substantially the same data-protection obligations and remains responsible for its performance.

7. Third-country Transfers

Where data is processed outside the EEA, this is based on an adequacy decision or the EU Standard Contractual Clauses including supplementary safeguards.

8. Duties of Assistance

The processor assists the controller with data-subject requests (access, rectification, erasure, portability), data-protection impact assessments and notification duties under Art. 33, 34 GDPR. Data breaches are reported without undue delay after becoming known.

9. Deletion and Return

After termination of the contract, data is returned or deleted at the controller's choice, unless statutory retention obligations (in particular tax and social-security periods) prevent this.

10. Evidence and Audit Rights

The processor demonstrates compliance with this agreement on request and permits audits to a reasonable extent, provided operations are not disproportionately affected.

11. Duration and Contractual Effect

This agreement takes effect when it is accepted electronically by an authorised representative during business onboarding and applies for the duration of the Service. Electronic acceptance is recorded with the document version, business, user, language and timestamp. The controller may issue documented instructions and remains responsible for their lawfulness.

12. Contact

Data protection enquiries: privacy@tippale.com. Further details can be found in the Imprint and the Privacy Policy.