Data Processing Agreement (DPA) – Annex 1 to the momoscreen Terms
Last updated: 28.09.2026
pursuant to Art. 28 GDPR between the Customer who uses momoscreen under the Terms (“Customer”, controller) and JetCoders GmbH, Kirchengasse 7, 1070 Wien, Austria, FN 619970 x, info@momoscreen.com (“momoscreen”, processor).
1. Conclusion, term, order of precedence
1.1 This DPA forms part of the Terms and is concluded electronically upon their acceptance (Art. 28(9) GDPR), including upon acceptance of a new version in the app.
1.2 It applies for as long as the contract under the Terms exists and beyond that until the Customer Data has been deleted or returned (clause 11).
1.3 In the event of conflicts, this DPA takes precedence over the Terms in data protection matters. Expressions used have the meaning given in Art. 4 GDPR.
2. Subject matter, nature and purpose
2.1 Subject matter: provision of momoscreen under the Terms. In doing so, momoscreen processes personal data on behalf of the Customer (“Customer Data”).
2.2 Nature and purpose: collecting, storing, displaying, transmitting (e.g. sending emails), translating, anonymising and deleting Customer Data in order to provide the functions used by the Customer, in particular reservations and emails to guests, statistics for the Customer (e.g. the source of reservations), guests' consents to the Customer's marketing, the publication of the Customer's content, the handling of data subject requests (clause 8), data backup and support.
2.3 Not covered is data that momoscreen processes as a controller in its own right, e.g. the Customer's account and contract data, support requests and technical access data for the operation and security of the platform (e.g. server logs, IP addresses). The momoscreen privacy policy applies to such data.
3. Data subjects and data
| Data subjects | Data categories |
|---|---|
| The Customer's guests | Contact details (e.g. name, email address, phone number), reservation data (e.g. date, time, number of people, note, status), communication with the guest, marketing consents and their withdrawal |
| Persons whom the Customer names or shows in content (e.g. employees) | e.g. name, role, photos, other information entered by the Customer |
The note may contain voluntary health information from guests (e.g. allergies, intolerances). momoscreen does not ask for such information; on behalf of the Customer, it points out in the form that such information is voluntary and that by entering it the guest consents to its use by the Customer. The Customer is responsible for lawfulness.
4. Instructions
4.1 momoscreen processes Customer Data only on documented instructions from the Customer, including with regard to transfers to third countries, unless momoscreen is required to do so by Union law or Austrian law; in that case, momoscreen informs the Customer of that legal requirement beforehand, unless that law prohibits this.
4.2 The Terms, this DPA and the Customer's settings and actions in the app constitute the Customer's complete instructions. momoscreen implements additional instructions sent by email only insofar as this is technically and organisationally possible and reasonable; momoscreen may charge for the effort involved.
4.3 If momoscreen considers an instruction to be unlawful, it informs the Customer without undue delay and may suspend its execution until the Customer confirms or changes it.
5. Obligations of the Customer
The Customer is responsible for the lawfulness of the processing, in particular for the legal basis and for informing guests. For this purpose, momoscreen provides a privacy notice for guests that contains the name, full address and phone number of the business from its profile; the Customer must keep this information accurate. The Customer does not enter any guest data in the support chat and reports errors in the processing without undue delay.
6. Confidentiality and security
6.1 Persons with access to Customer Data have committed themselves to confidentiality or are under a statutory obligation of confidentiality (§ 6 DSG). They are only given access insofar as they need it for their tasks.
6.2 momoscreen implements the technical and organisational measures pursuant to Art. 32 GDPR (Annex A) and may change them as long as the level of protection is not reduced.
7. Sub-processors and third countries
7.1 The Customer grants momoscreen general authorisation to engage sub-processors. Those listed in Annex B are deemed authorised.
7.2 momoscreen announces intended additions or replacements at least 14 days in advance by email or in the app; if a change is urgent (e.g. outage or security problem), momoscreen informs the Customer without undue delay afterwards. The Customer may object by email on data protection grounds until the announced date, or in the case of urgent changes within 14 days of being informed; in that case, either party may terminate the contract without notice.
7.3 momoscreen contractually obliges sub-processors to comply with data protection obligations that correspond to those of this DPA (Art. 28(4) GDPR); the providers' standard contracts are sufficient if they contain these obligations.
7.4 Some sub-processors are based in the USA or may access data from there (Annex B). The Customer instructs momoscreen to transfer Customer Data to third countries to this extent. This only takes place in accordance with Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision (including the EU-US Data Privacy Framework) or standard contractual clauses of the EU Commission.
7.5 If the Customer is established outside the EEA and outside a country with an adequacy decision of the EU Commission, the standard contractual clauses of the EU Commission (Decision (EU) 2021/914), Module 4, additionally apply, with momoscreen as data exporter and the Customer as data importer; the annexes follow from this DPA, and the place of jurisdiction and the supervisory authority are the Austrian ones. In the event of conflict, the clauses take precedence.
8. Data subject requests
8.1 momoscreen assists the Customer with appropriate technical and organisational measures in responding to requests under Chapter III GDPR, insofar as possible.
8.2 The Customer instructs and authorises momoscreen to respond to and implement, in the Customer's name, requests from guests (e.g. access, rectification, erasure, withdrawal of consent) that reach momoscreen. momoscreen is not obliged to inform the Customer about this. Requests that momoscreen does not handle itself are forwarded to the email address of the Customer account. momoscreen may verify the identity of the requesting person (e.g. by replying to the email address given in the reservation), documents how the request was handled and informs the Customer about this on request.
9. Assistance pursuant to Art. 32 to 36 GDPR
9.1 Taking into account the nature of processing and the information available, momoscreen assists the Customer with security, notifications, communications, data protection impact assessments and prior consultation, insofar as required by law. momoscreen provides assistance beyond this (including under clause 8.1) against reimbursement of the effort involved.
9.2 momoscreen notifies the Customer of any personal data breach affecting Customer Data without undue delay after becoming aware of it, by email to the address of the Customer account, with the information pursuant to Art. 33(3) GDPR insofar as available; momoscreen provides missing information subsequently. The Customer makes notifications to the supervisory authority and communications to data subjects.
10. Evidence and audits
10.1 momoscreen demonstrates compliance with this DPA primarily through this DPA and its annexes, information provided by email, and certificates or audit reports of the sub-processors.
10.2 An on-site audit is permitted if this evidence does not dispel the Customer's justified doubts. It must be announced at least 30 days in advance, takes place during business hours and no more than once per calendar year, and is carried out by the Customer or by an auditor bound to confidentiality who is not a competitor of momoscreen. The Customer bears the costs, including momoscreen's effort. The powers of supervisory authorities remain unaffected.
11. Deletion and return
11.1 During the term, momoscreen automatically anonymises or deletes Customer Data in accordance with the following instructions of the Customer (clause 4.2): reservation requests the guest has not confirmed (confirmation link not clicked) 7 days after receipt (deletion); notes on reservations 30 days after the reservation date (deletion); other reservation data 6 months after the reservation date (anonymisation); marketing consents until withdrawn, proof of consent and withdrawal three years thereafter. The Customer deletes content itself in the app. Changes to these periods are made in accordance with clause 12.2.
11.2 If the Customer requests the return by email no later than 30 days after the end of the contract, momoscreen hands over the Customer Data in a common, machine-readable format. After this period has expired (in the case of a request, after the return), momoscreen deletes the Customer Data within a reasonable period, unless there is an obligation to store it under Union law or Austrian law. Copies in backups are not deleted individually but are overwritten in the regular cycle.
12. Liability, changes, final provisions
12.1 In the relationship between the Customer and momoscreen, the limitations of liability of the Terms (clause 10) apply, insofar as legally permissible. Liability towards data subjects under Art. 82 GDPR remains unaffected.
12.2 Clause 13 of the Terms applies to changes, and clause 7.2 to sub-processors. Otherwise, the final provisions of the Terms apply.
Annex A – Technical and organisational measures
- Data centres: operation with hosting and database providers holding recognised security certifications (e.g. ISO 27001, SOC 2); no own servers.
- Access and access rights: login only with a personal account and password; passwords are only stored in hashed form. Each Customer only sees the data of its own business. Access to administration interfaces and production data only for authorised persons, insofar as necessary for their tasks.
- Encryption: transmission via TLS; database encrypted at rest.
- Integrity and abuse protection: traceability of reservations (origin, status, time); confirmation of guests' email addresses; measures against abusive and automated requests.
- Data minimisation: privacy-friendly default settings (e.g. marketing consent not preselected); automatic anonymisation and deletion (clause 11).
- Availability: scaling cloud infrastructure; automatic database backups.
- Review: regular review and adjustment of these measures.
Annex B – Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc., USA | Hosting and delivery of the application | EU; delivery worldwide, access from the USA |
| Databricks, Inc. (Neon), USA | Database and data backup | EU (Frankfurt) |
| Plus Five Five, Inc. (Resend), USA | Email delivery | USA |
| Microsoft Ireland Operations Ltd. (Microsoft 365), Ireland | Email mailbox (requests from guests) | EU |
| ImageKit Inc., USA | Storage and delivery of images | EU (Frankfurt); logs in the USA |
| OpenAI Ireland Ltd., Ireland | Machine translation | USA |