Pursuant to Art. 28 GDPR · Version: 2026-09-14.2
This agreement applies between the customer (controller within the meaning of Art. 4 No. 7 GDPR) and Tippale.com, Inh. Michael Lev-Ari, Auf dem Neuen Feld 8, 63303 Dreieich, Deutschland (processor). Its subject is the processing of personal data in connection with the use of the Tippale platform for tip distribution, shift scheduling, time tracking and payroll.
The controller remains responsible for the lawfulness of the processing and for the rights of the data subjects.
Processing includes collection, storage, organisation, calculation, retrieval, disclosure on instruction, return and deletion for the contracted modules: tips, scheduling, time tracking, payroll, absences, purchasing, accounting, inventory, document intake and extraction, team communication, reports and AI assistance. Data subjects also include suppliers, their contacts and other persons named in customer documents. Health, disability and religious-affiliation data can be special categories under Art. 9 GDPR and may be processed only on lawful instructions with restricted access.
The processor processes data solely on the documented instructions of the controller and not for its own purposes. If it considers an instruction unlawful, it informs the controller without delay.
The controller grants general authorisation for the service categories listed below. The applicable provider documentation determines the legal entity, location and any further sub-processors. A customer-connected provider is a sub-processor only insofar as it processes data on Tippale’s behalf; independent controllers and customer-appointed providers are not automatically sub-processors. Tippale’s own subscription billing via Base44 Payments is addressed in the Privacy Policy:
The controller is informed in advance of intended changes and may object on important data-protection grounds. The processor binds every sub-processor by a written agreement imposing substantially the same data-protection obligations and remains responsible for its performance.
Where data is processed outside the EEA, this is based on an adequacy decision or the EU Standard Contractual Clauses including supplementary safeguards.
The processor assists the controller with data-subject requests (access, rectification, erasure, portability), data-protection impact assessments and notification duties under Art. 33, 34 GDPR. Data breaches are reported without undue delay after becoming known.
After termination of the contract, data is returned or deleted at the controller's choice, unless statutory retention obligations (in particular tax and social-security periods) prevent this.
The processor demonstrates compliance with this agreement on request and permits audits to a reasonable extent, provided operations are not disproportionately affected.
This agreement takes effect when it is accepted electronically by an authorised representative during business onboarding and applies for the duration of the Service. Electronic acceptance is recorded with the document version, business, user, language and timestamp. The controller may issue documented instructions and remains responsible for their lawfulness.
Data protection enquiries: privacy@tippale.com. Further details can be found in the Imprint and the Privacy Policy.