Terms
Data Processing Agreement (DPA)
Effective from: 1 June 2026
This data processing agreement (the “DPA”) governs the rights and obligations between the Provider (as the Processor) and the User (as the Controller) in the processing of End Customers’ personal data in connection with the use of the Eazo Service.
1. Parties
The Processor is the operator of the Service:
- Radek Hřebeček
- Registered office: Jirečkova 1017/18, Praha 7 - Holešovice, 170 00, Česká republika
- Company ID (IČO): 04557824, VAT ID (DIČ): CZ9106050756
- E-mail: [email protected]
- Data box (datová schránka): iyxbwt7
The Controller is the User of the Service as defined in the Terms and Conditions.
2. Introductory provisions
- This DPA forms an integral part of the Eazo Terms and Conditions.
- Processing takes place in accordance with Regulation (EU) 2016/679 (GDPR).
- By registering an Account in the Service, the Controller expressly agrees to this DPA and considers it concluded.
3. Subject, purpose and duration of processing
- Subject and purpose: The Processor will process personal data for the Controller in order to ensure the technical operation of the Eazo Service, in particular to record, manage and send confirmations of bookings made by the Controller’s End Customers.
- Duration of processing: Processing will take place for the duration of the contractual relationship established by registering the Account, or until the Controller deletes its data from the Service.
4. Categories of data subjects and types of data
- Data subjects: The Controller’s End Customers (persons who make a booking through the Widget).
- Types of data: First name, surname, e-mail address, phone number, and any text notes or booking details entered by the End Customer or the Controller.
5. Obligations of the Processor
The Processor undertakes to:
- process personal data only on documented instructions from the Controller (including instructions given through the administration of the Service) and these terms,
- ensure that persons authorised to process personal data (e.g. technical support) have committed themselves to confidentiality,
- take all appropriate technical and organisational measures to ensure a level of security appropriate to the risk (encryption, backups, access control),
- taking into account the nature of the processing, assist the Controller in responding to requests to exercise the rights of data subjects (End Customers),
- assist the Controller in fulfilling its obligations under Articles 32 to 36 of the GDPR (security, incident notification),
- at the choice of the Controller, delete or return all personal data after the end of the provision of services, and delete existing copies unless the law requires their storage.
6. Other processors (sub-processors)
- The Controller grants the Processor a general authorisation to engage other processors (e.g. hosting or transactional e-mail providers).
- The Processor will inform the Controller of any intended addition or replacement of other processors (e.g. by updating the Privacy Policy). The Controller has the right to object to such changes.
- Where the Processor engages another processor, it will contractually impose on it the same data protection obligations as set out in this DPA.
7. Final provisions
- This DPA is concluded electronically at the moment the User completes registration in the Eazo Service.
- Matters not expressly governed by this agreement are governed by the Terms and Conditions and the laws of the Czech Republic (the GDPR and the Civil Code).
- This DPA is drawn up in Czech and English. In the event of any discrepancy, the Czech version prevails.