Skip to content
FeaturesGetting startedPricingManufacturers
  • Español
  • English
Sign in Request a demo
FeaturesGetting startedPricingManufacturers
Sign in Request a demo

Data protection

Data processing agreement

Last updated: 9 September 2026 (version 1)

This agreement governs the processing of personal data that Dazeris Software, S.L.U. carries out on behalf of each store that subscribes to RestQ. It forms part of the Terms of service, is deemed accepted upon subscription and, in data protection matters, prevails over them. It is drawn up in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

Note: This is a courtesy English translation. In the event of any discrepancy, the Spanish version prevails.

1. Parties

Data controller
The store, company or professional that subscribes to RestQ (“the Customer”), identified in the accepted proposal or order.
Data processor
Dazeris Software, S.L.U. (“Dazeris”)
Tax ID
B93844595
Registered office
Calle Panaderos, 8, 4.º Pta. D · 02400 Hellín (Albacete)
Data protection contact
privacidad@dazeris.com

2. Subject matter

Dazeris will process on the Customer’s behalf the personal data needed to provide RestQ: the Android, iPhone and web application with which the Customer’s employees consult the catalogue, calculate prices and prepare quotes in store, and the panel with which Dazeris administers the service. The processing is described in Annex I.

Dazeris processes Customer Data solely to provide the service and in accordance with this agreement. The Customer retains ownership of its data, under section 14 of the Terms of service. The store’s audit log — the sensitive actions performed on its data, with date, item affected and internal identifiers — forms part of Customer Data.

3. Duration

This agreement applies from the first access of a Customer user to RestQ, including trial periods, and for as long as the Customer subscribes to the service. When the service ends, or a trial expires without subscription, section 9 applies, and this agreement continues to govern the data retained under that section until its deletion. The confidentiality obligations and the obligation to keep the record under Article 30(2) of the GDPR survive thereafter.

4. Obligations of Dazeris as processor

Dazeris undertakes to:

  1. Process the data only on the Customer’s documented instructions, which are the Terms of service and this agreement, the service configuration decided by the Customer (store, shops, users, roles and permissions) and the written instructions it sends to the contact address. If Dazeris considers that an instruction infringes the GDPR or other applicable law, it will inform the Customer before carrying it out.
  2. Not use the data for its own purposes nor disclose it to third parties, except to the sub-processors in Annex III and except where required by Union or Member State law applicable to Dazeris; in that case it will inform the Customer before the disclosure, unless that law prohibits it on important grounds of public interest. Dazeris will not comply with requests from third-country authorities that are not enforceable under Article 48 of the GDPR without first informing the Customer.
  3. Ensure that the persons authorised to process the data have committed themselves in writing to confidentiality and to the duty of secrecy (Article 5 of the Spanish Data Protection Act, LOPDGDD), an obligation that survives the end of their relationship with Dazeris. Administrative access to Customer Data is limited to the Dazeris staff who need it to provide the service, who sign in with a Google account through federated authentication and, for operations affecting a store or its users, must have interactively confirmed their session within the previous fifteen minutes.
  4. Apply the security measures in Annex II, review their effectiveness at least once a year and after every security incident, and keep them up to date with the evolution of the service and of the risks.
  5. Engage sub-processors only under the conditions of section 6.
  6. Assist the Customer in handling data subjects’ rights, under section 7.
  7. Assist the Customer in complying with its obligations regarding security, notification of personal data breaches, impact assessments and prior consultation of the supervisory authority, under section 8, taking into account the nature of the processing and the information available to it.
  8. Return or delete the data when the service ends, under section 9.
  9. Make available to the Customer the information necessary to demonstrate compliance with these obligations and allow the audits in section 10.
  10. Maintain the record of categories of processing activities carried out on behalf of the Customer, with the content of Article 30(2) of the GDPR.
  11. Process the data within the European Union. The only transfers to third countries authorised by the Customer are those in Annex III, covered by an adequacy decision of the European Commission (Article 45 of the GDPR) or, failing that, by the standard contractual clauses incorporated into Google’s Cloud Data Processing Addendum (Article 46). Dazeris will not make any other international transfer without the Customer’s prior instruction or authorisation, handled under the procedure in section 6, unless required by Union or Member State law; in that case it will inform the Customer before the transfer, unless that law prohibits it on important grounds of public interest.

5. Obligations of the Customer as controller

The Customer undertakes to:

  1. Have a legal basis for processing the data of its employees and of any other person whose data it enters into RestQ, and inform them in accordance with Articles 13 and 14 of the GDPR, referring them to the RestQ privacy policy for what it describes.
  2. Give Dazeris lawful instructions and, when requesting user additions, removals or changes, do so through an authorised person of the Customer.
  3. Not enter into RestQ special categories of data (Article 9 of the GDPR) or children’s data, and not use the free-text field of quotes to collect data about its end customers: the application labels it as a reference and it is not designed for that purpose. If it nevertheless does so, the Customer will be responsible for that data, must inform the persons concerned in accordance with Articles 13 and 14 of the GDPR and may order its rectification or erasure through the mechanisms in section 7. Dazeris does not review the content of that field.
  4. Safeguard its users’ credentials, notify Dazeris without delay when an employee leaves so that their access is deactivated, and periodically review the roles and permissions assigned.
  5. Assess, before subscribing and during the service, whether the measures in Annex II are appropriate to the risk of the processing it carries out.

6. Sub-processors

The Customer gives Dazeris general authorisation to engage the sub-processors listed in Annex III and their own sub-processors listed in Google Cloud’s public list of sub-processors. Dazeris ensures, by contract with each sub-processor (in the case of Google, the Cloud Data Processing Addendum), data protection obligations equivalent to those in this agreement, and remains fully liable to the Customer for its sub-processors’ compliance.

Dazeris will inform the Customer of any addition or replacement of a sub-processor — including those that Google notifies to it regarding its own sub-processors — at least 30 days in advance, by updating Annex III on this page and notifying the Customer’s contact address. The Customer may object on reasonable grounds within that period; if the objection cannot be resolved, it may terminate the service before the change takes effect, with a refund of the proportional part of any fees paid in advance for the unused period.

7. Rights of data subjects

Where a data subject exercises a right vis-à-vis Dazeris concerning data for which the Customer is the controller, Dazeris will forward the request to the Customer without undue delay, keeping the date of receipt, and will not respond on its own initiative unless instructed by the Customer.

So that the Customer can handle those rights, Dazeris carries out at its request, free of charge and within ten working days, the following operations on the data:

  • Access and portability: a copy of a user’s profile, store membership and sign-in account data; or a complete export of the store’s data in a structured, commonly used format (readable JSON, with dates in ISO format).
  • Rectification: correction of a user’s display name or email address, which Dazeris applies to the sign-in account, the profile and the store membership. The email address is also the sign-in identifier, so the user will have to sign in again.
  • Erasure: removal of a user — which Dazeris carries out in two steps, deactivation and deletion — and which deletes their sign-in account, profile and store membership; or removal of the whole store, under section 9. The internal identifiers the user left as author on quotes, prices and the audit log become pseudonymised: once the account is deleted, they no longer resolve to any person.
  • Restriction and objection: deactivation of a user, reversible, which immediately prevents signing in or renewing a session and any write, and leaves their data stored without any other processing; an already open session loses its remaining access when its credential expires, in under an hour.
  • Correction of the audit log: removal of a personal data item archived in error in an entry, noted on the entry itself.

The steps and time limits, from the data subject’s point of view, are on the Data deletion page.

8. Personal data breaches and other obligations

Dazeris will notify the Customer of any personal data breach affecting its data without undue delay and in any event within 48 hours of becoming aware of it, including where a sub-processor reports it, at the Customer’s contact address, with the information under Article 33(3) of the GDPR available to it: the nature of the breach, the categories and approximate number of data subjects and records concerned, a point of contact at Dazeris, the likely consequences and the measures taken or proposed. Where it is not possible to provide all the information at once, it will be provided in phases. Dazeris will cooperate with the Customer in investigating, containing and documenting the breach (Article 33(5)) and will not report it to the supervisory authority or to third parties without the Customer’s instruction, except where legally obliged in its own right. It is for the Customer, as controller, to decide on notification to the supervisory authority and communication to data subjects; Dazeris will assist with both.

Dazeris will also assist the Customer, insofar as it depends on the service, in carrying out data protection impact assessments and prior consultations of the supervisory authority where required.

9. End of the service: return and deletion

When the service ends, the Customer will choose, before the end date or within the following 30 days, between:

  • return of the Customer Data by means of a complete export (shops, quotes, users, pricing configuration and audit log) in readable JSON format, delivered through a secure channel, followed by deletion; or
  • direct deletion.

If the Customer does not communicate its choice, Dazeris will make the export, keep it blocked and available to the Customer for 30 days and then delete the data. Dazeris will carry out the deletion in the production systems, including the sign-in accounts of the Customer’s users, within 30 days of termination or of delivery of the export, whichever is later, and will confirm it in writing at the Customer’s request. Data already deleted may persist in the sub-processors’ backups and logs for the periods they establish (Firebase Authentication: up to 180 days); those copies are not used to restore deleted Customer Data. Dazeris will keep blocked only the data that a legal obligation requires it to retain, for the period that obligation establishes.

Audit log. On the Customer’s instruction set out in this agreement, the entries of the store’s audit log are not deleted with the rest of the Customer Data: Dazeris keeps them blocked and pseudonymised — they contain no user’s name or email address, and their internal identifiers no longer resolve to anyone once the accounts are deleted — as a security and traceability record and for the defence of claims, without using them for any other purpose, until each entry reaches 24 months from its date, at which point it is deleted automatically. During that time they remain subject to this agreement. The Customer receives a copy of them in the export.

10. Information and audits

Dazeris will make available to the Customer the information necessary to demonstrate compliance with this agreement, including the description of the security measures and, to the extent that Google makes them available to its customers, the reports and certifications of its sub-processors (for the Google Cloud services used: ISO 27001, ISO 27017, ISO 27018, SOC 1 and SOC 2, within the scope Google publishes).

The Customer, itself or through an independent auditor who is not a competitor of Dazeris and is bound by confidentiality, may carry out an audit once a year, with 30 days’ notice, during business hours and at its own cost. In addition, without that limit and with such notice as the circumstances allow, it may audit where a personal data breach affecting its data has occurred, where there are reasonable indications of non-compliance with this agreement or where a supervisory authority so requires. Audits will not give access to other customers’ data nor compromise the security of the service; their results will be communicated to Dazeris, which will remedy proven deficiencies without undue delay. As regards sub-processors, the audit is satisfied by the reports and certifications in the previous paragraph. Dazeris will also respond to any inspection by the supervisory authority.

11. Liability

Vis-à-vis data subjects, each party is liable under Article 82 of the GDPR, and neither this agreement nor the Terms of service limit that liability. As between the parties: Dazeris is liable for the damage, administrative fines and third-party compensation arising from failing to comply with the obligations that the GDPR specifically imposes on processors or from acting outside the Customer’s lawful instructions; the Customer is liable for those arising from its obligations as controller, including the lawfulness of the data and of the instructions it gives; and where both parties have contributed to the damage, each is liable in proportion to its fault, with the right of recourse under Article 82(5) of the GDPR. The limitation of liability in section 17 of the Terms of service applies between the parties in matters not provided for here, and does not extend to damage caused by wilful misconduct or gross negligence.

12. Form, versions and amendments

The accepted proposal or order identifies by its date the version of this agreement governing the relationship. The Customer may at any time request a PDF copy signed by Dazeris, and Dazeris keeps previous versions and provides them on request.

Dazeris will notify amendments to this agreement to the Customer’s contact address at least 30 days in advance. Amendments that reduce the guarantees of the Customer or of data subjects will require its express acceptance or will allow it to terminate the service before they take effect, with a refund of the proportional part of any fees paid in advance. In the event of a conflict between this agreement and the Terms of service in data protection matters, this agreement prevails.

13. Contact

Communications relating to this agreement are sent to privacidad@dazeris.com. Dazeris will contact the Customer at the contact address stated in the accepted proposal or order.

Annex I. Description of the processing

Nature and purpose Provision of RestQ: authentication of the Customer’s users and control of their access; application of roles, permissions and isolation between stores and shops; consultation of the catalogue, price calculation and preparation, saving and retrieval of quotes; retention of quote authorship; logging of sensitive actions; technical support and administration of the service.
Operations Collection, recording, structuring, storage, consultation, alteration, disclosure by transmission to the sub-processors in Annex III, restriction, export and erasure.
Categories of data subjects Employees and contractors of the Customer who use RestQ (administrators, shop managers and salespeople), and the Customer itself where it is a natural person and uses the application. If the Customer enters third-party data in the free-text field of quotes, despite the instruction not to do so, also its end customers.
Categories of data Identification and contact (display name, email address); credentials managed by Firebase Authentication (password, stored only as a cryptographic hash; account status; IP address and user agent of sign-ins); organisational data (store and shop the user belongs to, role, permission keys); internal authorship identifiers on quotes, prices and the audit log; the Customer’s business data linked to persons only through that authorship (quotes, pricing configuration). No special categories of data are processed.
Duration For as long as the Customer subscribes to the service, and afterwards for the periods in section 9 (30 days for return and deletion; 24 months from each entry for the audit log).
Location European Union (database in the eur3 European multi-region; functions and storage in europe-west1, Belgium), with the exceptions in Annex III.

Annex II. Security measures

Technical

  • Server-side access control: database and storage security rules that isolate each store, require store membership on every read and apply each user’s roles and permission keys on every write and on reads of restricted data (user directory, cost data). One store cannot access another store’s data. The rules have an automated test suite that runs before every deployment, and a control periodically compares the rules in force with the versioned ones.
  • Sensitive operations on the server: adding and removing users and changing their permissions, managing shops and administering the service run in server functions that verify the caller’s authorisation.
  • Authentication: individual accounts managed by Firebase Authentication, with passwords of at least eight characters including upper-case and lower-case letters and digits, throttling of failed sign-in attempts and protection against email enumeration. Dazeris administration accounts sign in with Google federated authentication and recent session confirmation for operations on stores and users. Deactivating a user immediately prevents signing in or renewing a session and any write; an already open session expires in under an hour.
  • Application integrity: RestQ incorporates Firebase App Check (Play Integrity on Android, DeviceCheck on iPhone and reCAPTCHA Enterprise on the web). Server-side enforcement of the attestation has been in force since 7 September 2026 on the database, on storage and on the server functions: a request without a valid attestation is rejected, so a copy of the application that cannot attest itself may open and sign in, but reads and writes no data.
  • Audit log: sensitive actions are recorded in a log that no user can modify or delete, with internal identifiers and without names or email addresses, and with the identifier of whoever performs them from the panel; those Dazeris performs with an administration tool are attributed to whoever runs it. The creation of stores and users, password reset links, catalogue and manufacturer access, product deletion and changes to store status and to permissions also raise an alert to Dazeris staff.
  • Encryption in transit (TLS) and at rest, provided by the Google platform.
  • Availability: the database is replicated across the eur3 European multi-region managed by Google, and Customer Data can be exported in full at any time (section 7).
  • Data on the device: the local working copy is cleared on the next launch after signing out; on Android, automatic backup and device-to-device transfer are disabled.
  • Minimisation: the audit log and technical logs contain no names or email addresses; application diagnostics are voluntary and are not linked to the account.
  • Separate environments for development and production, with demonstration data in the former.

Organisational

  • Administrative access limited to the staff who need it, under the principle of least privilege, and revocable immediately.
  • Documented incident response procedure, including rotation of credentials, cutting off accounts, review of the audit log and the notification to the Customer under section 8.
  • Defined retention periods, applied automatically for the audit log, and a documented procedure for return and deletion when the service ends.
  • Internal record of processing activities, locations and sub-processors, kept up to date with changes to the service.
  • Review of the effectiveness of the measures and of the risk analysis at least once a year and after every security incident.

Annex III. Sub-processors

Sub-processor Service and purpose Location Safeguards
Google Cloud EMEA Limited Cloud Firestore (database), Cloud Functions (server-side operations), Cloud Storage (catalogue images; no personal data) European Union: eur3 (European multi-region) and europe-west1 (Belgium) Cloud Data Processing Addendum, accepted on 25 August 2026
Google Cloud EMEA Limited Firebase Authentication (user authentication) United States Cloud Data Processing Addendum; transfer covered by an adequacy decision of the European Commission and, failing that, by standard contractual clauses
Google Cloud EMEA Limited Firebase App Check (application integrity; processes device attestation material, not Customer Data) and Cloud Logging (technical logs with internal identifiers, without names or email addresses) Global service Cloud Data Processing Addendum

The application’s voluntary diagnostics (Firebase Crashlytics) are not part of this agreement: Dazeris processes them as controller, with each user’s consent and without linking them to the account, as described in the privacy policy. On iPhone, the integrity attestation is issued by Apple (DeviceCheck) from a device identifier, without access to Customer Data.

The sales platform for mattress and bedding stores and retailers with a dedicated sleep section.

A product by Dazeris

Product

  • Features
  • Getting started
  • Pricing
  • Manufacturers
  • FAQ
  • Request a demo
  • Support

Legal

  • Legal notice
  • Privacy policy
  • Cookie policy
  • Terms of service
  • Data processing agreement
  • Data deletion

© 2026 Dazeris Software, S.L.U. · All rights reserved.

We use analytics cookies to understand how the site is used and improve it. You can accept or reject them; more information in the cookie policy.