Taberna

Data processing terms

The building instructs, Taberna processes.

These terms are part of the terms of service for every building and are written to meet GDPR Article 28, the CCPA/CPRA service-provider contract requirements, and the processor terms in the Minnesota, Colorado, Virginia, Connecticut and similar state privacy laws. A signed copy on your letterhead is available on request. Last updated 2026-09-05.

1. Roles and scope

For personal data in the building's records (tenants and their people, applicants, guests, contacts, signers), the building is the controller (or "business") and Taberna (Jeromy Darling, sole proprietor) ("Taberna") is the processor (or "service provider"). Subject matter: running the building through the Taberna service. Duration: while the building uses Taberna, plus the deletion period. Nature and purpose: storage, display to authorized people, messaging the building asks for, payments through the building's Stripe account, optional screening and e-signature, and the public site. Data subjects and categories are listed in the privacy policy.

2. Instructions

Taberna processes personal data only on the building's documented instructions: these terms, the settings the building chooses in the console, and the actions its authorized people take. Taberna will not sell it, share it for advertising, combine it with data from other buildings, or use it for any purpose other than providing the service, and will tell the building if an instruction appears to break the law. Taberna will not process it outside the direct business relationship with the building.

3. Confidentiality

Every person Taberna allows to access building data (today, one) is bound to confidentiality. Access is limited to what running and supporting the service needs and is logged.

4. Security

Taberna keeps technical and organizational measures appropriate to the risk: TLS everywhere; passwords hashed with PBKDF2 and per-user salts; single-use, expiring, hashed tokens for invites, links, and resets; role-based access; an activity log of every change; card data never touching Taberna; rate limits; daily retention enforcement; hosting on Cloudflare's SOC 2 and ISO 27001 audited infrastructure. Details are in the privacy policy.

5. Subprocessors

The building authorizes the subprocessors listed here and in the privacy policy. Taberna flows down data-protection obligations no less protective than these terms to each, and remains responsible for them.

Taberna gives at least 30 days' notice by email before adding a subprocessor that will see building records. The building may object on reasonable data-protection grounds; if the objection can't be resolved, the building may end the service and export its data, with a pro-rated refund of any prepaid fees.

6. Helping the building with rights requests and assessments

Taberna provides the tools for access, correction, deletion, portability, and opt-out in the product, and forwards any request it receives about a building's records to the building within 5 business days. Taberna gives reasonable help with data-protection impact assessments and consultations with authorities, at no charge beyond what is unreasonable.

7. Personal data breach

Taberna notifies the building without undue delay and within 72 hours of confirming a personal data breach affecting the building's data, by email to the owner's address, with what is known: nature, categories and approximate numbers, likely consequences, measures taken, and a contact. Updates follow as facts arrive. Taberna does not notify the building's data subjects or authorities on its behalf unless asked or required.

8. Return and deletion

The building can export all its data at any time (Setup → Export, JSON and CSV). When the building deletes itself or the agreement ends, Taberna deletes the building's personal data, including uploaded files, within 30 days, except what the law requires Taberna to keep (payment records), which is kept only for that purpose and then deleted. Written confirmation of deletion is available on request.

9. Audit

Taberna makes available the information needed to show compliance with these terms: this document, the privacy policy, the subprocessor list, and Cloudflare's and Stripe's audit reports. Once a year, or after a breach, the building may ask reasonable written questions and, at its own cost and on 30 days' notice, have an independent auditor bound by confidentiality review Taberna's compliance; Taberna cooperates and may charge only reasonable costs of the time.

10. Where data lives

Data is stored in the United States on Cloudflare and served through its global network. For a building whose data subjects are in the European Economic Area, the United Kingdom, or Switzerland, the parties adopt the EU Standard Contractual Clauses (module two, controller to processor) and the UK Addendum by reference, with the building as exporter and Taberna as importer; ask and we will countersign.

11. Liability and precedence

Liability under these terms is governed by section 10 of the terms of service, except that the cap does not apply to Taberna's breach of section 2 (instructions) or section 5 (subprocessors) of this document. Where these terms conflict with the terms of service on data protection, these terms win.

Effective 2026-09-05. Contact: hello@taberna.pro.