QRMenu legal

Data processing addendum

Version 1.0 · Effective

This Data Processing Addendum (“DPA”) forms part of the service agreement between the customer as controller (“Controller”) and Digital Menu as processor (“Processor”). Contact: support@digitalmenu.faridfajrak.com.

1. Processing details

Subject matter and duration: hosting, publication, support and optional AI processing for the agreement term plus the documented deletion period. Nature and purpose: collection, storage, organization, retrieval, transmission to authorized subprocessors, publication at Controller instruction, and deletion. Data subjects: Controller personnel and people represented in Controller-supplied menu material; diners are represented only by country-level aggregate scan facts. Data types: account/contact data, venue/menu text and images, publication settings, authentication/security events, billing references and country-level scan facts. Special-category data is not intended; Controller must not submit it without a separate written instruction and lawful basis.

2. Instructions and confidentiality

Processor acts only on documented Controller instructions in the agreement, product controls and support requests, unless Union or Member State law requires otherwise. Processor will notify Controller if an instruction appears unlawful where legally permitted. Personnel with access are authorized, trained and bound by confidentiality.

3. Security

Processor maintains proportionate technical and organizational measures including access control, isolated credentials, encryption in transit, least-privilege production access, audit records for privileged actions, tested backup/restore procedures, vulnerability and secret scanning, incident runbooks, bounded retention, and resumable account erasure. Controller remains responsible for its users, source data and publication choices.

4. Subprocessors and transfers

Controller gives general authorization for the suppliers in the versioned subprocessor register. Processor remains responsible for equivalent data-protection obligations, gives reasonable notice of a material addition, and accepts a reasoned objection based on data-protection grounds. International transfers use an applicable adequacy decision or contractual safeguards.

5. Assistance

Taking account of the processing and information available, Processor assists with data-subject requests, security obligations, breach assessment, data-protection impact assessments and regulator consultation. Processor will notify Controller without undue delay after confirming a personal-data breach and provide available facts without delaying the first notice.

6. Return and deletion

At Controller request or termination, Processor deletes or returns personal data unless law requires retention. Public access and live credentials are disabled first; active storage is erased through the documented workflow and isolated backups expire within 35 days with erasure tombstones replayed on restoration. Lawfully retained financial/security facts are minimized.

7. Information and audit

Processor provides information reasonably necessary to demonstrate compliance. Audits are coordinated to protect other customers, security and confidentiality, normally beginning with current documentation and independent evidence; on-site access requires reasonable notice unless a regulator or confirmed incident requires urgency.

8. Priority and execution

This DPA prevails over conflicting agreement terms for personal-data processing. The agreement’s liability and governing-law terms otherwise apply. This public template is not an executed agreement; request an execution-ready copy from support@digitalmenu.faridfajrak.com and record the applicable customer, agreement and signatures.