Joint Controllership Agreement
Version: October 2026
Agreement pursuant to Art. 26 GDPR between the Partner (business using VidiReserve under the Terms for Restaurants and Event Providers) and VidiScope GmbH (referred to as "VidiReserve" in the Terms), Römerstr. 27, 89250 Senden, Germany ("VidiScope"), together "the parties".
§ 1 Subject matter
(1) This agreement is Annex 1 to the Terms for Restaurants and, under their § 6 (2), forms part of the user agreement. It applies for the term of that agreement.
(2) It governs joint controllership for the booking process: guests can reserve a table, book an event, buy a voucher, send a group request or join a waiting list via VidiReserve, whether on vidireserve.com, on the Partner's page on VidiReserve or via a widget that the Partner embeds on its own website. The booking process ends when the booking is transmitted to the Partner. The booking has been transmitted to the Partner as soon as it is stored in VidiReserve and can be accessed by the Partner in the back office. The automatic acknowledgement of receipt to the guest is still part of the booking process; notifications to the Partner (e-mail, push), later confirmations, changes and reminders are part of the processing after transmission.
(3) The Partner determines its offer, availability and conditions as well as any additional information requested. VidiScope determines the technical design, the process and security. The parties thus jointly determine the purposes and means of this processing.
(4) This agreement does not cover processing by the Partner after transmission, for which the Partner is responsible itself (§ 6 (1) of the Terms; where VidiScope acts on its behalf, the data processing agreement, Annex 2, applies), nor processing for VidiScope's own purposes, such as guest accounts on the platform or reviews. VidiScope may also use the data collected in the booking process as a controller in its own right where the guest books with a guest account (display in the guest account), and to invite guests to submit reviews and to check those reviews.
§ 2 Data subjects, data, purposes, recipients and legal bases
- Data subjects: guests and customers of the Partner who use the booking process, and persons whose data guests provide in the process (e.g. voucher recipients, members of a group).
- Data: contact details, booking data (date, time, party size, requests, allergies and dietary preferences where applicable), payment status, technical data (IP address, browser identifier, signals for bot protection) and a log of booking attempts for protection against abuse.
- Purposes: presenting the offer, receiving and acknowledging receipt of the booking, protection against abuse and transmission to the Partner.
- Recipients: the Partner; for online payments, the payment service provider connected by the Partner.
- Legal bases: Art. 6(1)(b) GDPR; for information on allergies and dietary preferences Art. 9(2)(a) GDPR (explicit consent in the booking form); for third-party data and protection against abuse Art. 6(1)(f) GDPR; for a newsletter subscription in the booking process Art. 6(1)(a) GDPR.
§ 3 Responsibilities of VidiScope
(1) VidiScope is responsible for the operation, availability and security of the platform and the widgets (Art. 25 and 32 GDPR).
(2) VidiScope informs guests about the booking process in accordance with Art. 13 and 14 GDPR in the VidiReserve privacy policy and makes the essence of this agreement available there (Art. 26(2), second sentence, GDPR). In the widget, VidiReserve links to the privacy policy with the information on joint controllership.
(3) VidiScope is the central point of contact for data subjects: datenschutz@vidireserve.com.
(4) VidiScope selects the service providers used for the booking process and concludes the necessary contracts with them (hosting, e-mail delivery, bot protection by Cloudflare Turnstile).
(5) VidiScope notifies personal data breaches affecting the booking process to the supervisory authority and, where required, communicates them to the data subjects (Art. 33 and 34 GDPR); VidiScope informs the Partner without undue delay. For breaches affecting data after transmission, Clause 9 of the data processing agreement applies.
§ 4 Responsibilities of the Partner
(1) The Partner is responsible for the accuracy and lawfulness of its information, in particular its offer, conditions and additional questions. It only requests information that is necessary for the booking.
(2) If the Partner embeds a widget on its own website, it refers to it in its privacy policy and obtains consent where required for its website. It embeds widgets only on domains it has approved for this purpose.
(3) For processing after transmission, the Partner fulfils its obligations as controller itself, including its information obligations.
(4) The Partner informs VidiScope without undue delay of any personal data breaches in its area that affect the booking process.
§ 5 Rights of data subjects
(1) Data subjects may exercise their rights in respect of and against each of the parties (Art. 26(3) GDPR).
(2) VidiScope answers requests concerning the booking process. If such requests reach the Partner, it forwards them without undue delay to datenschutz@vidireserve.com. VidiScope forwards requests concerning data after transmission to the Partner without undue delay.
(3) The parties support each other and provide each other with the information required for this.
§ 6 Liability
Towards data subjects, the parties are liable in accordance with Art. 82(4) GDPR. Between the parties, each party bears the damage resulting from an infringement within its area of responsibility under this agreement (Art. 82(5) GDPR).
§ 7 Final provisions
With regard to joint controllership, this agreement takes precedence over the Terms. Amendments are governed by § 12 of the Terms.