Data Processing Agreement (DPA)
Standard contractual clauses governing the processing of personal data pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).
Effective: January 1, 2026 • Version: 2026-09-v1
The natural or legal person operating short-term accommodation who registers for taakflow and determines the purposes of guest bookings.
taakflow, operated by its natural-person developer (Operator: Nikos, located in Greece), providing specialized software services for TAAK resilience fee tracking.
Art.11. Subject Matter, Purpose & Legal Basis
This Data Processing Agreement ("DPA") supplements the taakflow Terms of Service and applies to all processing of personal data carried out by taakflow on behalf of the Host (the "Controller") in connection with the Greek Climate Crisis Resilience Fee (TAKK) under Law 4389/2016 (Art. 53), Law 5162/2024, and AADE Decision A.1217/2023.
taakflow acts strictly as a Data Processor pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR). The Host acts as the Data Controller.
Art.22. Scope of Processing & Categories of Personal Data
taakflow processes guest personal data solely to calculate, track, facilitate advance collection, and record the statutory Climate Crisis Resilience Fee:
- Categories of Data Subjects: Guests staying at accommodation properties registered by the Controller.
- Processed Data Categories: Guest full name, dates of arrival and departure, total nights of stay, calculated fee amount, payment status, and payment transaction reference.
- CURRENT CHECKOUT EXCLUSION: taakflow guest checkout does not request passport or national-ID numbers. A legacy compatibility field may exist on imported historical records; operators can permanently clear it with the legacy-data cleanup tool.
Art.33. Duration & Data Retention
This DPA remains in effect for the duration of the Host’s active account on taakflow.
Pursuant to Greek tax law (Law 4174/2013 on tax audit limitation periods), transaction and statutory fee records are retained for five (5) years following the fiscal year of issuance, after which they are permanently expunged or anonymized.
Art.44. Obligations of the Processor (GDPR Article 28(3))
taakflow expressly covenants and warrants to adhere to the following statutory obligations:
- Documented Instructions (Art. 28(3)(a)): Process personal data solely on documented instructions from the Controller, including with regard to transfers of personal data to a third country.
- Confidentiality (Art. 28(3)(b)): Ensure that all persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security of Processing (Art. 28(3)(c) & Art. 32): Implement robust technical and organizational measures (TOMs), including TLS 1.3 in transit, AES-256-GCM encryption at rest for sensitive credentials, salted cryptographic hashing, and automated rate limiting.
- Subprocessors (Art. 28(3)(d)): Not engage another processor without prior specific or general written authorization. The current subprocessor register is maintained at /subprocessors.
- Assistance with Data Subject Requests (Art. 28(3)(e)): Assist the Controller by appropriate technical and organizational measures in fulfilling the obligation to respond to requests exercising data subject rights under Chapter III GDPR.
- Breach Notification & Compliance Assistance (Art. 28(3)(f)): Notify the Controller without undue delay, and at the latest within 48 hours, upon confirming a personal data breach affecting Controller data, and assist with DPIAs.
- Deletion or Return (Art. 28(3)(g)): At the choice of the Controller, delete or return all personal data upon termination of services, subject to statutory tax retention periods.
- Audits & Demonstrating Compliance (Art. 28(3)(h)): Make available to the Controller all information necessary to demonstrate compliance with Article 28 obligations.
Art.55. Authorized Subprocessors
The Controller grants general written authorization for taakflow to engage the infrastructure subprocessors listed in our public Subprocessor Register at /subprocessors (including Stripe Payments Europe Ltd and only those infrastructure or transactional-email providers actually selected, enabled, and disclosed in that register).
taakflow shall give the Controller at least thirty (30) calendar days prior written notice of any intended changes concerning the addition or replacement of subprocessors. The Controller has fourteen (14) calendar days to object on reasonable data protection grounds.
Art.66. International Data Transfers
All primary database and compute instances are hosted within the European Union (Frankfurt, Germany and Finland). Any transfer of personal data outside the EEA is conducted strictly under European Commission Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46.
Art.77. Governing Law & Jurisdiction
This DPA and any contractual or non-contractual disputes arising out of it shall be governed by and construed in accordance with the laws of the Hellenic Republic.
The parties submit to the jurisdiction of the competent courts of Athens, Greece, and recognize the regulatory authority of the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ).
Public Subprocessor Register
Review our complete list of infrastructure and hosting vendors.
DPA & Privacy Contact
For subprocessor inquiries, DPA counter-signing, or data protection matters:
taakflow DPA Desk
privacy@taakflow.gr