Skip to content
Ovyrena
Features Industries Pricing Contact
Log in Start free trial

Legal

Data Processing Agreement

Last updated: 6 October 2026

Contents

  1. Scope and parties
  2. Roles
  3. Details of the processing
  4. Your instructions
  5. Confidentiality
  6. Security
  7. Sub-processors
  8. International transfers
  9. Government access requests
  10. Data subject requests
  11. Personal data breaches
  12. Assistance
  13. Return and deletion
  14. Audits and information
  15. Liability and term
  16. Contact
  17. Annex 1
  18. Annex 2
  19. Annex 3

This agreement explains how Ovyrena handles the personal data you enter about your Customers and your team, and what we promise to do to protect it.

1. Scope and parties

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the business that uses Ovyrena (“you”, the controller) and NIKOLA MILENKOVIĆ PR AGENCIJA ZA RAČUNARSKO PROGRAMIRANJE KRAGUJEVAC, Janka Katića 3A, 34000 Kragujevac, Republic of Serbia, registration number 64662198, tax ID 110116517 (“Ovyrena”, “we”, the processor).

It applies whenever we process personal data on your behalf while providing the Service, and it is designed to meet Article 28 of the EU General Data Protection Regulation (GDPR) and Article 45 of the Serbian Law on Personal Data Protection. It takes effect when you accept the Terms and needs no separate signature. If it conflicts with the Terms on data protection, this DPA prevails.

2. Roles

You decide why and how personal data about your Customers and Employees is processed in Ovyrena, so you are the controller and we are your processor.

For the data we need to run our own business, such as your account, subscription and billing details, we act as an independent controller as described in our Privacy Policy. This DPA does not cover that data.

3. Details of the processing

The subject matter, nature, purpose, types of data and categories of data subjects are listed in Annex 1. We process the data for as long as you use the Service and until it is deleted under section 13.

4. Your instructions

We process personal data only on your documented instructions. The Terms, this DPA and the way you configure and use the Service are your complete instructions. We tell you promptly if we believe an instruction breaks data protection law.

We never sell your data, use it for advertising, or use it for our own purposes. We may process it without your instruction only where the law requires it, and we will tell you first unless the law forbids that.

5. Confidentiality

Everyone at Ovyrena who can access your personal data is bound by confidentiality and may access it only as needed to provide, support or secure the Service.

6. Security

We apply the technical and organisational measures described in Annex 2 and keep them appropriate to the risk. We may improve them over time, but we will not reduce the overall level of protection.

7. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 3. We will tell Owners by email at least 30 days before we add or replace a sub-processor. If you have a reasonable data protection objection, tell us within that period; if we cannot resolve it, you may cancel the affected subscription and we will refund any prepaid fees for the remaining period.

Each sub-processor is bound by a written contract with data protection obligations at least as protective as this DPA, and we remain responsible to you for its work.

8. International transfers

We store the Service’s data on servers in the European Union. Ovyrena itself is established in the Republic of Serbia, and some sub-processors are in the United States.

Where a transfer to us or to a sub-processor is a restricted transfer under the GDPR, it is covered by an adequacy decision, such as the EU–US Data Privacy Framework, or by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), which are incorporated into this DPA by reference: Module Two between you and us, and Module Three between us and our sub-processors.

9. Government access requests

We disclose your data to a public authority only when we are legally compelled by a binding order, never on an informal request. We review the legality of every request, challenge requests we consider unlawful or disproportionate, and disclose only the minimum that is required.

We notify you before any disclosure unless the law forbids it; if it does, we try to have that prohibition lifted and inform you as soon as we are allowed. We do not build back doors or give any authority direct access to our systems, and we keep a record of the requests we receive. Our assessment of the transfer to Serbia is available on request.

10. Data subject requests

The Service lets you view and correct the data of your Customers and Employees. Where you cannot handle a request yourself, we help you respond to requests from data subjects to exercise their rights. If a data subject contacts us directly about your data, we forward the request to you and do not answer it ourselves unless you ask us to.

11. Personal data breaches

We notify you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach that affects your data. The notice describes what happened, the data and people affected, the likely consequences and what we are doing about it, and we update it as we learn more. This gives you time to meet your own 72-hour duty to notify the supervisory authority.

12. Assistance

Taking into account the nature of the processing and the information available to us, we help you with data protection impact assessments, prior consultations with supervisory authorities and your other obligations under Articles 32 to 36 GDPR.

13. Return and deletion

When the Service ends, the Owner may ask us to return a copy of the data in a common machine-readable format, such as CSV, or to delete it. We delete it within 30 days of the request, including from sub-processors, unless the law requires us to keep it.

Until such a request, the data of a cancelled or archived Company is kept so that you can reactivate it, as described in the Terms. Deleted data may remain in backups until they are overwritten, which happens within 30 days, and is not restored or used in that time.

14. Audits and information

We make available the information you reasonably need to show that we meet this DPA, and answer your written questions about our security. If that is not enough, you may audit our compliance once a year, or after a breach, with at least 30 days’ notice, during business hours, at your own cost, by yourself or by an independent auditor bound by confidentiality. Audits must not give access to other customers’ data.

15. Liability and term

Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow them to be limited. This DPA lasts as long as we process personal data on your behalf.

16. Contact

Questions about this DPA or about how we process your data: hello@ovyrena.com.

Annex 1: Details of the processing

Details
Subject matterProviding the Ovyrena service: managing Bookings, Resources, orders, payments, staff and analytics for your business.
Nature of processingHosting, storage, organisation, retrieval, display, calculation, transmission (email and push notifications), export and deletion.
PurposeOnly to provide, support and secure the Service for you, as described in the Terms.
Data subjectsYour Customers (people and contact persons of organisations); your Owners and Employees, including people you invite.
Customer dataName, email address, phone number, notes you write, Bookings (Resource, dates, times, people, status, cancellation reason), orders and charges, payments (amount, method, time, cash register receipt number). Requests Customers send you themselves: online booking requests (name, email address, phone number, their note, the time they agreed to the processing and a pseudonymised IP address), and calls for staff, bill requests and orders sent from a Resource QR code.
Employee dataName, nickname, email address, phone number, Job Title and Role, Location access, shifts and schedule, assigned Bookings, activity in the Service, and on mobile devices a push notification token.
Technical dataIP address, browser and device information, sign-in and security records.
Special categoriesNone are required. Do not enter health or other special category data in free-text fields such as notes.
DurationFor the term of the Service, then until deletion under section 13.

Annex 2: Security measures

  • Encryption in transit: all traffic uses HTTPS. The servers accept web traffic only through Cloudflare and are protected by a firewall.
  • Access to the Service: passwords are stored only as secure hashes; sign-in, password reset and public booking forms are protected by rate limiting and bot protection; sessions use HttpOnly, Secure cookies, end after 30 minutes of inactivity and at most 3 hours, and can be revoked on the server.
  • Separation and authorisation: every request is checked on the server against the user’s Company and Role, so one business can never see another’s data, and each Employee sees only what their Role allows.
  • Application security: protection against cross-site request forgery and cross-site scripting on every form and page.
  • Server access: administration only by named staff over SSH with keys; password and root logins are disabled.
  • Non-production safety: test environments never send email to real recipients.
  • Logs: server and security logs are kept for up to 90 days; expired session records are deleted after 7 days.
  • Backups and recovery: backups are kept with our hosting provider in the European Union, only our administrator can access them, and they are overwritten on a rolling basis within 30 days.
  • Incident response: breaches are assessed and reported to you as described in section 11.

Annex 3: Sub-processors

Sub-processorPurposeLocation
Hetzner Online GmbHHosting of the application and databaseGermany (EU)
Twilio Inc. (SendGrid)Sending service emails to Owners and Employees, such as invitations and password resets, and to your Customers about their online booking requests and BookingsUnited States
Cloudflare, Inc.Network protection, traffic delivery and bot protection on sign-up, sign-in, password reset and public booking formsUnited States, global network
Google LLC (Firebase Cloud Messaging)Push notifications to Employees’ Android devices (mobile app)United States
Apple Inc. (Apple Push Notification service)Push notifications to Employees’ iOS devices (mobile app)United States
Ovyrena

Bookings, layouts, orders and teams in one live view.

Ovyrena is software for businesses, sold as a subscription. It records the payments your Customers make to you, but never processes them.

App StoreComing soon Google PlayComing soon

Product

Features Industries Pricing Analytics

Company

Contact Help center Log in Start free trial

Legal

Terms of Service Privacy Policy Refund Policy Cookie Policy Data Processing Agreement
© 2026 Ovyrena. All rights reserved.