GDPR · Article 28
GDPR · Član 28
Data Processing Agreement
Restaurant Partners
Ugovor o obradi podataka
Partneri restorani
Version 1.0 · Effective 26 June 2026 · Aligned with GDPR Article 28
Verzija 1.0 · Na snazi od 26. juna 2026. · Usklađeno s GDPR-om, Član 28
Parties to this Agreement
Stranke ovog Ugovora
Data Controller ("Restaurant")
Voditelj obrade ("Restoran")
The restaurant business that has registered on the QRForge platform and accepted these terms. The Controller is responsible for the lawful processing of customer personal data for their business purposes.
Restoranski poslovni subjekt koji se registrovao na platformi QRForge i prihvatio ove uvjete. Voditelj obrade odgovoran je za zakonitu obradu ličnih podataka kupaca u poslovne svrhe.
Data Processor ("QRForge")
Obrađivač podataka ("QRForge")
OD DataPoint, vl Hodzic Nermin, Bosnia and Herzegovina — operating the QRForge platform. Contact: admin@qrforge.link
OD DataPoint, vl Hodzic Nermin, Bosna i Hercegovina — operater platforme QRForge. Kontakt: admin@qrforge.link
1. Subject Matter & Duration
1. Predmet i trajanje
QRForge processes personal data on behalf of the Restaurant solely to provide the ordering and delivery management platform services described in the QRForge Terms of Service. This DPA is incorporated by reference into the Terms of Service and takes effect upon the Restaurant's registration on the platform.
QRForge obrađuje lične podatke u ime Restorana isključivo radi pružanja usluga platforme za naručivanje i upravljanje dostavom opisanih u Uvjetima korištenja QRForgea. Ovaj UOP ugrađen je referencom u Uvjete korištenja i stupa na snagu registracijom Restorana na platformi.
This DPA remains in force for the duration of the Restaurant's use of the platform and expires upon account deletion or termination of the service relationship.
Ovaj UOP ostaje na snazi za period korištenja platforme od strane Restorana i ističe brisanjem računa ili prestankom poslovnog odnosa.
2. Personal Data Processed
2. Obrađeni lični podaci
| Category | Data Elements | Purpose |
Kategorija | Elementi podataka | Svrha |
| Customer identity | Name, email address | Order identification & communication |
Identitet kupca | Ime, e-mail adresa | Identifikacija narudžbe i komunikacija |
| Contact data | Phone number (optional) | Order issue resolution |
Kontakt podaci | Broj telefona (opcionalno) | Rješavanje problema s narudžbom |
| Order data | Items, quantities, total amount, timestamps | Order fulfilment & billing |
Podaci o narudžbi | Artikli, količine, ukupni iznos, vremenske oznake | Ispunjenje narudžbe i naplata |
| Delivery address | Street, city, notes | Courier dispatch |
Adresa dostave | Ulica, grad, napomene | Upućivanje dostavljača |
Special categories of personal data (as defined by GDPR Article 9) will not be processed under this Agreement.
Posebne kategorije ličnih podataka (kako su definirane GDPR-om, Član 9) neće biti obrađivane u okviru ovog Ugovora.
3. QRForge's Obligations as Processor
3. Obaveze QRForgea kao obrađivača
QRForge shall:
QRForge će:
- Process personal data only on documented instructions from the Restaurant (as expressed through use of the platform features).
- Ensure all personnel with access to the data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures (see Section 5).
- Not engage sub-processors without informing the Restaurant (see Section 6).
- Assist the Restaurant in responding to data subject rights requests within the legally required timeframe.
- Delete or return all personal data upon termination of the service, at the Restaurant's choice, unless retention is required by law.
- Provide all information necessary to demonstrate compliance with GDPR Article 28 obligations upon written request.
- Obrađivati lične podatke samo prema dokumentovanim uputstvima Restorana (izraženim kroz korištenje funkcija platforme).
- Osigurati da su svi zaposlenici s pristupom podacima vezani obavezama povjerljivosti.
- Implementirati i održavati odgovarajuće tehničke i organizacijske sigurnosne mjere (vidi Odjeljak 5).
- Ne angažirati pod-obrađivače bez informiranja Restorana (vidi Odjeljak 6).
- Pomoći Restoranu u odgovaranju na zahtjeve prava ispitanika u zakonski propisanom roku.
- Brisati ili vraćati sve lične podatke po prestanku usluge, po izboru Restorana, osim ako zakon ne zahtijeva čuvanje.
- Pružiti sve informacije potrebne za dokazivanje usklađenosti s obavezama GDPR-a, Član 28, na pisani zahtjev.
4. Restaurant's Obligations as Controller
4. Obaveze Restorana kao voditelja obrade
The Restaurant shall:
Restoran će:
- Ensure it has a valid legal basis for collecting and processing customer personal data via the QRForge platform.
- Provide customers with a clear privacy notice explaining the use of QRForge for order processing.
- Not instruct QRForge to process personal data in violation of applicable law.
- Promptly notify QRForge if it receives a data subject rights request that requires QRForge's involvement.
- Osigurati da ima valjani pravni osnov za prikupljanje i obradu ličnih podataka kupaca putem platforme QRForge.
- Pružiti kupcima jasnu obavijest o privatnosti koja objašnjava korištenje QRForgea za obradu narudžbi.
- Ne uputiti QRForge da obrađuje lične podatke kršeći primjenjivi zakon.
- Odmah obavijestiti QRForge ako primi zahtjev za prava ispitanika koji zahtijeva uključivanje QRForgea.
5. Technical & Organisational Measures
5. Tehničke i organizacijske mjere
QRForge implements the following security measures appropriate to the risk:
QRForge implementira sljedeće sigurnosne mjere primjerene riziku:
- Encryption at rest and in transit — all data stored in Google Cloud Firestore (AES-256 encryption); all communications over TLS 1.2+.
- Access control — role-based access; least-privilege principle; admin access protected by multi-factor authentication and custom claims.
- Audit logging — all privileged admin actions are logged with timestamp, actor identity, and IP address.
- Session management — tokens expire after 1 hour; refresh tokens revoked immediately upon account suspension.
- Infrastructure — hosted on Google Cloud (europe-west1); ISO 27001, SOC 2 Type II certified infrastructure.
- Incident response — breaches affecting personal data will be reported to affected Controllers within 72 hours of discovery.
- Enkripcija u mirovanju i prijenosu — svi podaci pohranjeni u Google Cloud Firestore (AES-256 enkripcija); sva komunikacija putem TLS 1.2+.
- Kontrola pristupa — pristup zasnovan na ulogama; princip najmanje privilegija; admin pristup zaštićen višefaktorskom autentifikacijom i prilagođenim tvrdnjama.
- Revizijsko logiranje — sve privilegovane admin radnje bilježe se s vremenskom oznakom, identitetom aktera i IP adresom.
- Upravljanje sesijama — tokeni istječu nakon 1 sata; refresh tokeni opozivaju se odmah po suspenziji računa.
- Infrastruktura — hostovano na Google Cloudu (europe-west1); ISO 27001, SOC 2 Type II certificirana infrastruktura.
- Odgovor na incidente — povrede koje utječu na lične podatke bit će prijavljene pogođenim voditeljima obrade u roku od 72 sata od otkrivanja.
6. Sub-processors
6. Pod-obrađivači
QRForge currently uses the following sub-processors:
QRForge trenutno koristi sljedeće pod-obrađivače:
| Sub-processor | Location | Purpose |
Pod-obrađivač | Lokacija | Svrha |
| Google Firebase / Cloud | EU (europe-west1) | Database, auth, hosting, storage |
EU (europe-west1) | Baza podataka, autentifikacija, hosting, pohrana |
| Sentry (self-hosted bundle) | EU | Error monitoring |
EU | Praćenje grešaka |
QRForge will notify the Restaurant of any intended changes to sub-processors at least 14 days in advance, allowing the Restaurant to object. All sub-processors are bound by data processing agreements providing equivalent protections.
QRForge će obavijestiti Restoran o svim planiranim promjenama pod-obrađivača najmanje 14 dana unaprijed, omogućavajući Restoranu da se usprotivi. Svi pod-obrađivači vezani su ugovorima o obradi podataka koji pružaju jednakovrijednu zaštitu.
7. International Transfers
7. Međunarodni prijenosi
Personal data is processed primarily within the EU (Google Cloud europe-west1 region). Where transfers outside the EU/EEA occur (e.g. Google support operations), they are governed by Google's Standard Contractual Clauses (SCCs) and GDPR-compliant Data Processing Addendum.
Lični podaci obrađuju se primarno unutar EU-a (Google Cloud region europe-west1). Gdje dolazi do prijenosa izvan EU/EEP-a (npr. Google podrška), regulirani su Googleovim Standardnim ugovornim klauzulama (SCC) i GDPR-usklađenim Dodatkom za obradu podataka.
8. Data Breach Notification
8. Obavještavanje o povredi podataka
In the event of a personal data breach, QRForge will notify the Restaurant without undue delay and, where feasible, within 72 hours of becoming aware, providing: a description of the nature of the breach; categories and approximate number of data subjects affected; likely consequences; and measures taken or proposed.
U slučaju povrede ličnih podataka, QRForge će obavijestiti Restoran bez nepotrebnog odgađanja i, gdje je izvedivo, u roku od 72 sata od saznanja, navodeći: opis prirode povrede; kategorije i aproksimativni broj pogođenih ispitanika; vjerovatne posljedice; i poduzete ili predložene mjere.
9. Data Subject Rights Assistance
9. Pomoć u ostvarivanju prava ispitanika
QRForge will assist the Restaurant in fulfilling requests from customers exercising their GDPR rights (access, rectification, erasure, portability, restriction, objection). Requests must be submitted to admin@qrforge.link and will be processed within 30 days.
QRForge će pomoći Restoranu u ispunjenju zahtjeva kupaca koji ostvaruju GDPR prava (pristup, ispravak, brisanje, prenosivost, ograničenje, prigovor). Zahtjevi se podnose na admin@qrforge.link i obradit će se u roku od 30 dana.
10. Governing Law
10. Mjerodavno pravo
This DPA is governed by the laws of Bosnia and Herzegovina. The parties voluntarily align with GDPR as the applicable standard. Any disputes shall be resolved before the competent courts of Bosnia and Herzegovina.
Ovaj UOP reguliran je zakonima Bosne i Hercegovine. Stranke se dobrovoljno usklađuju s GDPR-om kao primjenjivim standardom. Sporovi se rješavaju pred nadležnim sudovima Bosne i Hercegovine.
Execution. By accepting QRForge's Terms of Service, the Restaurant acknowledges and agrees to this Data Processing Agreement. For a signed PDF copy, email admin@qrforge.link.
Potpisivanje. Prihvatanjem Uvjeta korištenja QRForgea, Restoran potvrđuje i pristaje na ovaj Ugovor o obradi podataka. Za potpisanu PDF kopiju, pišite na admin@qrforge.link.
Data Processor
OD DataPoint, vl Hodzic Nermin
QRForge Platform
Bosnia and Herzegovina
admin@qrforge.link
Signature: ___________________
Date: _______________________
Obrađivač podataka
OD DataPoint, vl Hodzic Nermin
Platforma QRForge
Bosna i Hercegovina
admin@qrforge.link
Potpis: _____________________
Datum: _____________________
Data Controller (Restaurant)
Business name: _______________
Authorised signatory: _________
Title: _______________________
Address: ____________________
Signature: ___________________
Date: _______________________
Voditelj obrade (Restoran)
Naziv poslovnog subjekta: _____
Ovlašteni potpisnik: __________
Funkcija: ___________________
Adresa: _____________________
Potpis: _____________________
Datum: _____________________