Data Processing Agreement (DPA)

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller solely to provide the restaurant operations management SaaS during the subscription and the agreed post-termination deletion window.

2. Nature and purpose

Processing includes collection, recording, organisation, storage, retrieval, transmission, backup, restriction, anonymisation and deletion. Purposes include account administration, staff scheduling, hygiene submissions, supplier invoices, inventory, procurement, business analytics, security auditing and support.

3. Data subjects and data categories

Data subjects may include restaurant staff, authorised users and supplier contacts. Data may include identity and contact details, role and schedule, labour cost, hygiene records and photographs, contact or payment information visible on invoices, and login and activity logs. POS synchronisation does not store guest names, phone numbers, email addresses or delivery addresses by default.

4. Documented instructions and lawfulness

The Processor acts only on documented instructions expressed through the agreement, settings, support requests and platform actions, unless required otherwise by law. The Controller is responsible for purposes, legal bases, staff notices, permissions, accuracy and the lawfulness of uploaded content.

5. Confidentiality and security

Authorised personnel are bound by confidentiality. Measures include a separate database and file directory per tenant, least privilege, password hashing, AES-GCM encryption of secrets, HTTPS, session protection, login throttling, protected files, audit logs, backups, restore testing, security updates and incident response.

6. Sub-processors

The Controller grants general written authorisation for the public list of sub-processors. The Processor will publish intended additions or replacements and provide the contractual objection period, impose equivalent data protection obligations, and remain responsible for their performance.

7. Assistance with data-subject rights

Using export, rectification, restriction, anonymisation, deletion and request-tracking tools, the Processor reasonably assists the Controller with access, rectification, erasure, restriction, portability, objection and other applicable requests.

8. Personal data breaches

After confirming a breach affecting Controller data, the Processor will notify the Controller without undue delay and provide available information about the nature, affected data and persons, likely consequences, measures taken or proposed, and a contact point.

9. DPIA, supervisory authority and audits

Taking account of the nature of processing and available information, the Processor reasonably assists with security, impact assessments, prior consultation and evidence of compliance. Audits require reasonable notice, confidentiality and minimal disruption.

10. Return and deletion

After termination, the Controller may export data during the agreed window. The Processor then returns or deletes production data unless EU or Member State law requires retention, and removes backup copies through the backup rotation cycle. Registering a request alone does not automatically erase data; final erasure follows the verified termination procedure.

11. International transfers

Where personal data is processed outside the EEA, the Processor relies on an applicable adequacy decision, Standard Contractual Clauses or another valid safeguard, with location and safeguard information stated in the sub-processor list.

12. Agreement hierarchy

This DPA forms part of the SaaS agreement. For conflicts concerning personal-data processing, this DPA prevails unless mandatory law requires otherwise.

Annex A: default retention periods

AI raw extraction 30 days; invoice images 365 days; hygiene photographs 365 days; security and audit logs 365 days; successful-login history 90 days; revoked/expired session records 30 days; temporary uploads 24 hours; production-data deletion window after termination 30 days; backup purge target 90 days. Periods are purpose-based and may be adjusted by the Controller within system and contract limits.

Annex B: processing description

Processing is generally continuous until subscription termination and completion of deletion. Data is processed in hosted databases, protected file storage, backups, support tools and the configured AI interface.

Standard-text hash:0dd694da158d30a0626cdd696d64bfd59859dd7e3086613bc44046f2269b9739