← Back to Foodamigos

Foodamigos Data Processing Agreement (DPA)

White-Label Partners. Annex 1 to the Foodamigos Partner Agreement (Order Form), between Foodamigos GmbH, Am Hauptbahnhof 6, 53111 Bonn, Germany (the "Processor" or "Foodamigos") and the partner identified in the Order Form (the "Controller" or "Partner").

This Annex forms an integral part of the partner agreement concluded between the parties (Order Form) together with the Foodamigos Partner Platform Terms (together the "Main Agreement"). It is agreed upon conclusion of the Order Form; no separate signature is required.

Preamble

The Partner participates in the Foodamigos Partner Program as a white-label partner. The Partner operates its business in its own name and under its own brand; the business and customer relationship with the Partner's restaurant customers rests exclusively with the Partner. Foodamigos, as a pure technology provider, provides the platform (including the online ordering webshop, mobile apps, AI Website Builder, admin portal and APIs) and, in this context, processes personal data exclusively on behalf of and on the instructions of the Partner.

Where the Partner itself acts as a processor within the meaning of Art. 28 GDPR in relation to personal data of its restaurant customers (in particular end-customer data), Foodamigos acts as a further processor (sub-processor) within the meaning of Art. 28(2) and (4) GDPR. In that case these Clauses apply accordingly; the Partner warrants that the agreements it has concluded with its restaurant customers permit the engagement of Foodamigos and cover the required instructions.

Clause 1: Purpose and scope

The purpose of these standard contractual clauses (the "Clauses") is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 (General Data Protection Regulation). The Controller and the Processor have agreed to these Clauses in order to ensure such compliance. These Clauses apply to the processing of personal data as specified in Annex I. Annexes I to III form an integral part of the Clauses. These Clauses are without prejudice to the obligations to which the Controller is subject under Regulation (EU) 2016/679.

Clause 2: Interpretation

Where these Clauses use terms defined in Regulation (EU) 2016/679, those terms have the same meaning as in that Regulation. These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679, and shall not be interpreted in a way that runs counter to the rights and obligations provided for in that Regulation or that prejudices the fundamental rights or freedoms of data subjects.

Clause 3: Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the parties existing at the time when these Clauses are agreed or entered into thereafter, these Clauses prevail.

Clause 4: Description of processing

The details of the processing operations, in particular the categories of personal data and the purposes for which the personal data is processed on behalf of the Controller, are specified in Annex I.

Clause 5: Obligations of the parties

5.1 Instructions. The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which it is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Controller may issue further instructions throughout the duration of the processing; such instructions shall always be documented. Use of the configuration, administration and export functions provided by Foodamigos in the Partner Account is deemed a documented instruction. The Processor immediately informs the Controller if, in its opinion, instructions infringe Regulation (EU) 2016/679 or applicable Union or Member State data protection provisions. Instructions that change the subject matter of the engagement are to be agreed between the parties.

5.2 Purpose limitation. The Processor processes the personal data only for the specific purpose(s) set out in Annex I, unless it receives further instructions from the Controller. The Processor does not process the data for its own purposes; Clause 9.4 (anonymised and aggregated data) remains unaffected.

5.3 Duration. The data is processed by the Processor only for the duration specified in Annex I.

5.4 Security of processing. The Processor implements the technical and organisational measures specified in Annex II to ensure the security of the personal data, including protection against a breach of security leading, whether accidentally or unlawfully, to destruction, loss, alteration, unauthorised disclosure of or access to the data (a "personal data breach"). In assessing the appropriate level of security, the parties take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for data subjects. The Processor grants its personnel access to the personal data only to the extent strictly necessary for the performance, management and monitoring of the contract, and ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.5 Sensitive data. If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data for the purpose of uniquely identifying a natural person, data concerning health, sex life or sexual orientation, or data relating to criminal convictions and offences ("sensitive data"), the Processor applies specific restrictions and/or additional safeguards at the request of and in coordination with the Controller.

5.6 Documentation and compliance. The parties must be able to demonstrate compliance with these Clauses. The Processor deals promptly and adequately with enquiries from the Controller about the processing of data under these Clauses. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in these Clauses and stemming directly from Regulation (EU) 2016/679. At the Controller's request, the Processor also permits and contributes to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance; the Controller may take relevant certifications held by the Processor into account. The Controller may conduct the audit itself or mandate an independent auditor; audits may include inspections at the premises or physical facilities of the Processor and shall, where appropriate, be carried out with reasonable notice. The parties make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request.

5.7 Use of sub-processors. The Processor has the Controller's general authorisation for the engagement of the sub-processors listed in Annex III. The Processor specifically informs the Controller in text form at least four (4) weeks in advance of any intended changes to that list through the addition or replacement of sub-processors, thereby giving the Controller sufficient time to object before the engagement; the Processor provides the information necessary to enable the Controller to exercise its right to object. Where the Processor engages a sub-processor to carry out specific processing activities (on behalf of the Controller), it does so by way of a contract imposing on the sub-processor, in substance, the same data protection obligations as those applying to the Processor under these Clauses. The Processor ensures the sub-processor complies with the obligations to which the Processor is subject pursuant to these Clauses and Regulation (EU) 2016/679. At the Controller's request, the Processor provides a copy of such sub-processor agreement and any subsequent amendments; to the extent necessary to protect business secrets or other confidential information, including personal data, the Processor may redact the text before sharing a copy. The Processor remains fully responsible to the Controller for the performance of the sub-processor's obligations under its contract with the Processor and notifies the Controller of any failure by the sub-processor to fulfil its contractual obligations.

5.8 International transfers. Any transfer of data by the Processor to a third country or an international organisation takes place only on the basis of documented instructions from the Controller or in order to fulfil a specific requirement under Union or Member State law to which the Processor is subject, and must comply with Chapter V of Regulation (EU) 2016/679. The Controller agrees that, where the Processor engages a sub-processor in accordance with Clause 5.7 for carrying out specific processing activities (on behalf of the Controller) and those activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the Processor and the sub-processor may ensure compliance with Chapter V by using standard contractual clauses adopted by the Commission pursuant to Article 46(2) of Regulation (EU) 2016/679, provided the conditions for their use are met.

Clause 6: Assistance to the Controller

The Processor promptly notifies the Controller of any request it receives from a data subject and does not respond to the request itself, unless authorised to do so by the Controller. Data subject requests relating to the Partner's restaurant customers or their end customers are forwarded by the Processor to the Partner, and data subjects are referred to the Partner or the respective restaurant customer.

Taking into account the nature of the processing, the Processor assists the Controller in fulfilling its obligation to respond to data subjects' requests to exercise their rights, in particular through appropriate export, access, rectification and deletion functions in the Partner Account, following the Controller's instructions.

In addition to the Processor's obligation to assist the Controller pursuant to Clause 7, the Processor, taking into account the nature of the processing and the information available to it, also assists the Controller in ensuring compliance with: (a) the obligation to carry out a data protection impact assessment where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons; (b) the obligation to consult the competent supervisory authority/ies prior to processing where a data protection impact assessment indicates a high risk absent mitigating measures; (c) the obligation to ensure that personal data is accurate and up to date, by informing the Controller without delay if it becomes aware that data it processes is inaccurate or outdated; and (d) the obligations under Article 32 of Regulation (EU) 2016/679.

The parties set out in Annex II the appropriate technical and organisational measures by which the Processor supports the Controller in the application of this Clause, as well as the scope and extent of the assistance required. Disproportionate costs incurred by the Processor for assistance within the scope described in this Clause 6 may be charged on to the Controller; the standard export functions governed by Clause 9 always remain free of charge.

Clause 7: Notification of personal data breaches

In the event of a personal data breach, the Processor cooperates with and assists the Controller so that the Controller can comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679, taking into account the nature of the processing and the information available to the Processor.

7.1 Breach concerning data processed by the Controller. The Processor assists the Controller: (a) in notifying the personal data breach to the competent supervisory authority/ies without undue delay after the Controller has become aware of it, where relevant (unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons); (b) in obtaining the information to be stated in the Controller's notification pursuant to Article 33(3), including at least: the nature of the personal data, where possible the categories and approximate number of data subjects and records concerned; the likely consequences of the breach; and the measures taken or proposed to address it and, where appropriate, to mitigate its possible adverse effects, where and insofar as not all information can be provided at the same time, the initial notification contains the information then available and further information is provided subsequently without undue delay; and (c) in complying with the obligation under Article 34 to communicate the breach to the data subject without undue delay where it is likely to result in a high risk to the rights and freedoms of natural persons.

7.2 Breach concerning data processed by the Processor. In the event of a personal data breach concerning data processed by the Processor, the Processor notifies the Controller without undue delay after becoming aware of it. The notification contains at least: (a) a description of the nature of the breach (where possible, the categories and approximate number of data subjects and records concerned); (b) contact details of a contact point where further information can be obtained; and (c) the likely consequences and the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects. Where and insofar as not all information can be provided at the same time, the initial notification contains the information then available and further information is provided subsequently without undue delay. The parties set out in Annex II any further information the Processor is to provide to assist the Controller in complying with Articles 33 and 34.

Clause 8: Non-compliance with the Clauses and termination

Without prejudice to Regulation (EU) 2016/679, if the Processor is in breach of its obligations under these Clauses, the Controller may instruct the Processor to suspend the processing of personal data until the Processor complies with these Clauses or the contract is terminated. The Processor promptly informs the Controller if it is unable to comply with these Clauses, for whatever reason.

The Controller is entitled to terminate the contract insofar as it concerns the processing of personal data under these Clauses if: (a) the processing has been suspended pursuant to the preceding paragraph and compliance is not restored within a reasonable time, and in any event within one month following suspension; (b) the Processor is in substantial or persistent breach of these Clauses or its obligations under Regulation (EU) 2016/679; or (c) the Processor fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations under these Clauses and Regulation (EU) 2016/679.

The Processor is entitled to terminate the contract insofar as it concerns the processing of personal data under these Clauses where, after having informed the Controller that its instructions infringe applicable legal requirements pursuant to Clause 5.1, the Controller insists on compliance with those instructions.

Following termination of the contract, the Processor, at the choice of the Controller, deletes all personal data processed on behalf of the Controller and certifies to the Controller that it has done so, or returns all personal data to the Controller (Clause 9.3) and deletes existing copies, unless Union or Member State law requires storage of the personal data. Until the data is deleted or returned, the Processor continues to ensure compliance with these Clauses.

The Processor's liability for breaches of its obligations under this agreement and other infringements of data protection requirements is governed by the provisions of the Main Agreement.

Clause 9: Partner's data sovereignty; data export; customer relationship

9.1 Data sovereignty. All personal data processed under this agreement on behalf of the Partner, in particular data of the Partner's restaurant customers, their end customers, and order, transaction, loyalty and marketing data under the Partner Account (together the "Partner Data"), is under the exclusive data sovereignty of the Partner or its restaurant customers. Foodamigos claims no rights of its own in the Partner Data beyond the processing necessary to provide the services under the Main Agreement.

9.2 Partner's customer relationship. The business and customer relationship with the Partner's restaurant customers rests exclusively with the Partner. Foodamigos will not use Partner Data to actively approach or solicit the Partner's restaurant customers or their end customers, or to advertise its own products or services to them. Contact by Foodamigos is permitted only to the extent (a) required to fulfil legal obligations, (b) required to avert security risks or ensure platform operation, or (c) made on the instruction or with the prior consent of the Partner in text form.

9.3 Data export. During the term of the Main Agreement, the Partner may at any time export the Partner Data via the export functions of the Partner Account in a commonly used, structured and machine-readable format (e.g. CSV or JSON); this includes in particular customer, end-customer, order and revenue data. Upon the Partner's request, Foodamigos additionally provides, within thirty (30) days after termination of the Main Agreement, a complete export of the Partner Data in such a format free of charge. Deletion pursuant to Clause 8 takes place only after the export has been made or the relevant period has expired.

9.4 Anonymised and aggregated data. Foodamigos may use anonymised or aggregated data that does not permit identification of the Partner, its restaurant customers or data subjects for the operation, security, quality assurance and further development of the platform.

Annex I: Description of the processing

A. Subject matter and duration. Provision of the Foodamigos platform and related services under the Main Agreement. The processing lasts for the term of the Main Agreement; return and deletion after its end are governed by Clause 8 and Clause 9.3.

B. Nature and purpose of the processing. Hosting, storage and provision of the Partner Data on the platform; receipt, processing and forwarding of end-customer orders to the Partner's restaurant customers; operation of websites, webshops and mobile apps under the brand of the Partner or its restaurant customers; provision of loyalty, CRM and marketing functions for use by the Partner and its restaurant customers; provision of reporting, export and administration functions in the Partner Account; technical support, error analysis, maintenance and ensuring platform operation.

C. Categories of data subjects. End customers of the Partner's restaurant customers (orderers, app and website users, loyalty participants); owners, employees and contact persons of the Partner's restaurant customers; users of the Partner Account (employees and agents of the Partner).

D. Categories of personal data. Master and contact data (name, address, e-mail address, phone number); order and transaction data (order contents, order history, amounts, timestamps, delivery/pickup addresses); payment-related metadata (payment method, payment status; no full payment card data, such data is processed directly by the payment service providers as independent controllers or under their own terms); loyalty, CRM and marketing data (points balances, vouchers, consent status, campaign data); usage and device data (IP address, log data, device information, app/web usage); communication data (support requests, reviews, feedback). Sensitive data within the meaning of Art. 9 GDPR is not the subject of the agreed processing. Allergen- or diet-related information in orders (e.g. order notes) is processed exclusively to fulfil the respective order.

E. Deletion and retention. Processing takes place for the duration under Section A. After termination of the Main Agreement, return and deletion are governed by Clause 8 and Clause 9.3. Statutory retention obligations remain unaffected.

Annex II: Technical and organisational measures (TOMs)

Foodamigos operates the platform in accordance with the state of the art and implements in particular the following technical and organisational measures within the meaning of Art. 32 GDPR:

1. Confidentiality

Physical access control: data centres of certified hosting providers with physical access controls; no local storage of productive personal data in office premises. System access control: personalised user accounts, strong password policies, two-factor authentication for administrative access, automatic lock-out. Data access control: roles-and-permissions concept on a need-to-know basis, logging of administrative access, regular review of permissions. Separation control: logical tenant separation of data per partner and restaurant customer; separation of production, test and development environments.

2. Integrity

Transfer control: encryption of data transmissions (TLS), encrypted storage (encryption at rest), secured interfaces (API authentication). Input control: logging of security-relevant events and material changes to data and configurations.

3. Availability and resilience

Regular, automated backups with defined recovery processes (backup and recovery); redundant infrastructure, monitoring and alerting, emergency and incident-response processes; vulnerability management, regular security and patch updates.

4. Procedures for regular review

Regular review and evaluation of the effectiveness of the measures; commitment of employees to confidentiality and regular data protection awareness training; selection and monitoring of sub-processors in accordance with Clause 5.7, conclusion of contracts pursuant to Art. 28 GDPR.

5. Assistance measures (re Clauses 6 and 7)

Export, access, rectification and deletion functions in the Partner Account to support data subject rights; notification of the Partner of personal data breaches without undue delay to the contact address stored in the Partner Account; provision of the information required and available for notifications under Arts. 33 and 34 GDPR.

Annex III: List of sub-processors

The Controller has authorised the use of the following sub-processors:

NameAddressContactDescription of the processing
Twilio Ireland Limited or Twilio Germany GmbH Twilio Germany GmbH: Westendstraße 28, 60325 Frankfurt am Main, Germany; or Twilio Ireland Limited: 70 Sir John Rogerson's Quay, Dublin 2, Ireland support@foodamigos.io Communications service provider, in particular the sending and processing of transaction-related messages, e.g. SMS, e-mail, notifications or comparable communications services. Processing of contact and communication data, content data of the respective message, technical metadata and, where applicable, delivery and status information.
Amazon Web Services EMEA SARL 38 Avenue John F. Kennedy, L-1855 Luxembourg support@foodamigos.io Cloud infrastructure and hosting service provider. Processing and storage of platform, user, end-customer, order, log, backup and technical operating data in the context of hosting, databases, storage, network infrastructure, security, monitoring and backup.
Google Cloud EMEA Limited 70 Sir John Rogerson's Quay, Dublin 2, Ireland support@foodamigos.io Cloud infrastructure, hosting, database, analytics, storage, monitoring or other platform services. Processing of platform, user, end-customer, order, log, backup and technical operating data in the context of the Google Cloud services used.

Changes to this list are made in accordance with Clause 5.7 (advance information at least four (4) weeks; Controller's right to object).

Payment service providers (independent controllers, for transparency)

Payment data (including cardholder data) is processed directly by the payment service providers engaged for payment processing. These providers act as independent controllers or under their own terms in connection with payment processing, fraud prevention, settlement, payouts, refunds, chargebacks and KYC/AML obligations, and are therefore not sub-processors within the meaning of these Clauses. For transparency, the payment service providers currently used are:

Payment service providerAddress
Adyen N.V.Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands
Stripe Payments Europe, Limited / Stripe Technology Europe, Limited1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland / 1 Wilton Park, Wilton Place, Grand Canal Street Lower, Dublin 2, D02 FX04, Ireland

Where a payment service provider processes personal data on behalf of Foodamigos in individual cases, Clause 5.7 applies to that processing.