Data Processing Agreement

This Data Processing Agreement ("DPA") governs how dojofood, Inc. ("dojofood", "we") processes personal data on behalf of the business that uses the Service ("you", "Customer"). It forms part of our Terms of Service and applies automatically from the moment you start using the Service. No signature is required for it to apply. If your own compliance process needs a countersigned copy, write to [email protected] and we will send one.

This DPA is written to meet Article 28 of the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), which applies wherever you serve people in the European Economic Area, and the equivalent processor obligations under the UK GDPR and, in Türkiye, Law No. 6698 on the Protection of Personal Data.

1. Who is responsible for what

There are two different sets of personal data in play, and they are not governed by the same rules.

The data you put into the platform. Your diners, your account customers and your own staff. You decide what to collect and why. In the language of the GDPR you are the controller and dojofood is the processor. This DPA governs that data.

The data we hold about you as our customer. The people who sign up, the billing contact, the person who filled in a form on our website. There we decide the purposes ourselves, so dojofood is the controller. That data is covered by our Privacy Policy and our Data Processing Notice, not by this DPA.

Getting this split right matters to you: it means we do not acquire rights over your customer relationships, and we cannot use your diners' data for our own purposes.

2. Subject matter, duration, nature and purpose

We process the personal data described in section 3 for one purpose only: to provide the Service to you under the Terms of Service. That means running your catalog and menus, taking and routing orders across your channels, printing and displaying tickets, keeping account balances, producing your reports, and operating the integrations you switch on.

Processing lasts for as long as your account is active, plus the deletion period in section 10.

3. Whose data, and what data

Categories of data subject

  • Your customers: people who order in your restaurant, through your QR menu, or through a delivery channel you have connected
  • Your account customers: people or companies with an open account or running tab with you
  • Your staff: the people you give logins to

Types of personal data

  • Customers: name, phone number, email address where given, delivery address, order and payment history, notes attached to an order or a table, account balances
  • Staff: name, role, login identifier, and the record of actions taken in the system, which exists so that you can see who did what
  • Documents produced by the fiscal and invoicing integrations you enable, which may carry a customer's name, address and tax identifier

Special categories. The Service is not designed to hold special category data under Article 9 GDPR. Do not enter health, religious or similar data into free text fields. A dietary note a diner gives you may in practice reveal such information, so keep those notes to what the order actually requires.

4. What we do not process

We never hold card data. dojofood sends the amount to be collected to your payment terminal and reads back whether it succeeded. Card numbers, expiry dates and security codes never enter the Service. Your card processor holds them under its own contract with you, and that contract is not affected by this DPA.

We do not sell personal data, we do not use your data to train models for other customers, and we do not use it to market to your diners.

5. Our instructions come from you

We process personal data only on your documented instructions. Your use of the Service, the settings you choose and the integrations you switch on are those instructions. Anything else needs a written request from you, unless a law we are subject to requires the processing, in which case we will tell you before we act unless that law forbids it.

If we believe an instruction from you breaches data protection law, we will tell you. We are not obliged to give you legal advice and we will not act as your data protection officer.

6. What you are responsible for

You decide what is collected and you carry the controller's obligations: having a lawful basis, telling your diners what you do with their data, answering their requests, and keeping the data you hold accurate and no larger than you need. Where you rely on consent, you collect it. Do not put personal data into the Service that you have no lawful basis to hold.

7. Confidentiality and security

Everyone at dojofood with access to your data is bound by confidentiality obligations that survive the end of their engagement, and access is limited to the people who need it to run the Service or to support you.

We maintain technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include encryption in transit, encryption of data at rest, access control with per-role permissions and separation between customer accounts, logging of administrative access, regular backups, and a documented process for restoring the Service.

8. Sub-processors

You give us general authorisation to engage sub-processors. We use them in these categories:

  • Cloud hosting and database infrastructure, which stores the Service's data
  • Transactional email delivery, for the messages the Service sends on your behalf
  • Error and performance monitoring
  • The delivery, payment, fiscal and messaging integrations that you switch on yourself

Each is bound by written terms no less protective than this DPA, and we remain responsible to you for what they do.

The current list of sub-processors, with what each one does and where it holds data, is available from [email protected]. We will give you at least 30 days' notice before adding or replacing one. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you on an alternative; if there is none, you may terminate the affected part of the Service without penalty for the unused period.

A delivery marketplace you connect is not our sub-processor. It is a separate company with its own relationship with you and with the diner, and it decides its own purposes. We transmit orders between it and your account on your instruction.

9. Where the data is held, and international transfers

Today the Service's data is hosted in Germany. We may change the hosting region, including to the United States or Türkiye. We will not do so without a valid transfer mechanism in place, and a change of region is a change to our sub-processors, so section 8 applies: you get at least 30 days' notice and the right to object.

Access is a separate question and we would rather be plain about it than let you assume otherwise. dojofood, Inc. is established in the United States and our team works from Türkiye, Europe and the United States. Under the GDPR, reaching the data from outside the EEA is itself a transfer, even when the data stays in Germany. So there are transfers here whatever the hosting region is.

Where a transfer happens we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK Addendum where the UK GDPR applies, and we carry out a transfer impact assessment where one is required. Türkiye is a third country for this purpose: there is no adequacy decision covering it, so access from Türkiye is on the same footing as access from the United States and is covered by the same Clauses. For transfers out of Türkiye we rely on the mechanisms available under Law No. 6698.

The sub-processor list names the region each provider holds data in. Ask us and we will tell you which transfer mechanism applies to any of them.

10. Deletion and return

While your account is active you can export your catalog, orders and reporting at any time.

When your account ends, we delete the personal data we process on your behalf, or return it to you if you ask before the deletion date, within 90 days of the end of your account. Backups are overwritten on their normal cycle, which is no longer than a further 90 days. We keep data beyond this only where a law we are subject to requires it, and only for as long as it requires.

11. Helping you with your obligations

Requests from data subjects. If a diner or a member of your staff contacts us directly to exercise a right, we will not answer for you. We will pass the request to you without undue delay and help you answer it, using the Service's own tools where they cover it.

Breaches. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Notifying your supervisory authority and, where required, the people affected, is your decision and your responsibility as controller.

Assessments. We will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.

12. Audits

On reasonable written notice, no more than once a year unless a supervisory authority or a breach requires otherwise, we will make available the information needed to demonstrate compliance with this DPA and allow an audit conducted by you or an auditor you appoint who is not our competitor. Audits happen during business hours, must not disrupt the Service, and are subject to confidentiality. We may satisfy an audit request with a current third party report or certification where it answers the question.

13. Order of precedence and changes

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins. If it conflicts with the Standard Contractual Clauses, the Clauses win.

We may update this DPA to reflect a change in law, in the Service or in our sub-processors. We will post the updated version here with a new date and, for a material change, tell you before it takes effect.

14. Contact

For anything in this DPA, including a countersigned copy, the sub-processor list, or a data protection question: [email protected], or by post to dojofood, Inc., 1111B South Governors Avenue, Suite 59952, Dover, DE 19904, United States.