Data Processing Agreement (DPA)
Effective from 1 January 2026 · Last updated 7 October 2026
This Data Processing Agreement (“DPA”) supplements the Terms of Service and applies where the operator of Smart Menu (“Smart Menu”, the “Processor”) processes personal data on behalf of the restaurant Customer (the “Controller”) in the course of providing the Service, pursuant to Article 28 GDPR. In case of conflict between this DPA and the Terms, this DPA prevails with respect to the processing of personal data.
1. Subject matter, nature and purpose of processing
The Processor processes personal data solely to provide the Service (digital menu, automatic translation, virtual assistant for diners, shared tables for diners, menu import, AI menu analysis, management through the Telegram assistant, team access, multiple menus, usage statistics and related features), in accordance with the Controller’s documented instructions, for the duration of the contract.
2. Categories of data subjects and data
- Data subjects: restaurant team members authorised by the Controller; diners who view the menu, use the virtual assistant or join a shared table.
- Team members: contact and account data (email, name, role) and, for those who connect the Telegram assistant, their Telegram identifier and the messages and photos they send to it.
- Diners: the content of messages sent to the assistant (processed to reply, not stored); for shared tables, the name or nickname typed and the dishes chosen; essential technical data. Usage statistics are anonymous and contain no personal data.
- Any additional personal data the Controller enters into the menu content is under its sole responsibility.
The Service is not designed to process special categories of data (Article 9 GDPR); the Controller undertakes not to enter any.
3. Processor obligations
The Processor undertakes to:
- process data only on the Controller’s documented instructions, unless required by law;
- ensure that persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (Article 32 GDPR), described in Annex A;
- assist the Controller, taking into account the nature of processing, in responding to data subject rights requests;
- assist the Controller in ensuring compliance with obligations regarding security, breach notification and impact assessments;
- notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of any personal data breach affecting data processed on its behalf;
- make available to the Controller the information needed to demonstrate compliance and allow for audits, as set out in section 7.
4. Controller obligations
The Controller warrants that it has a valid legal basis for the data it uploads or has processed through the Service, that it provides data subjects with the required notices, and that its instructions comply with the law. The Controller is responsible for the accuracy of the data it enters and for managing its team’s accounts.
5. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed below. The Processor imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains responsible for their performance.
| Sub-processor | Activity | Location | Safeguards |
|---|---|---|---|
| Supabase, Inc. | Database hosting, account authentication, file storage (logos, backgrounds, dish photos, menu-import uploads) and live sync of shared tables on the digital menu | European Union / United States | EU Commission Standard Contractual Clauses (SCC) |
| Stripe Payments Europe, Ltd. | Payment processing and subscription management | Ireland / United States | Standard Contractual Clauses (SCC) |
| Google Ireland Ltd. (Gemini API) | Automatic menu translation, the virtual assistant for diners, dish suggestions (upselling), AI menu analysis, reading menus from uploaded photos/PDFs (menu import) and understanding messages sent to the Telegram assistant. Submitted content is not used to train the models. | Ireland / United States | Standard Contractual Clauses (SCC) |
| Google Ireland Ltd. (Sign in with Google) | Optional account sign-in and registration. When chosen, we receive the name, email address and profile picture from the Google account. | Ireland / United States | Standard Contractual Clauses (SCC) |
| Telegram FZ-LLC | Menu-management assistant via the Telegram bot, including photos sent to it (only for accounts that connect it) | United Arab Emirates / European Union | Standard Contractual Clauses (SCC) |
| WhatsApp Ireland Limited (Meta) | Priority support chat for the Standard plan (opened directly from the user’s own device; message content is not processed by us) | Ireland / United States | Standard Contractual Clauses (SCC) |
| Vercel Inc. | Web application hosting and content delivery (CDN) | European Union / United States | Standard Contractual Clauses (SCC) |
The Processor will give reasonable prior notice of changes to the list of sub-processors; the Controller may object on legitimate data protection grounds and, failing a solution, terminate the affected part of the Service.
6. Transfers outside the EU
Any transfers to third countries take place on the basis of an adequacy decision or the EU Commission Standard Contractual Clauses, with supplementary measures where needed.
7. Audit
On written request and with reasonable notice, no more than once a year (unless requested by an authority or following a breach), the Processor will provide the Controller with the information and documentation needed to verify compliance, including through certifications or independent third-party reports where available.
8. Return and deletion
During the contract, data is kept only as long as needed: shared tables are deleted 24 hours after creation, the log of incoming Telegram messages after 30 days, and menu-import files as soon as the menu has been extracted (see the Privacy Policy). On termination of the contract, at the Controller’s choice, the Processor returns or deletes the personal data processed on its behalf, subject to any statutory retention obligation. Residual data in backups is deleted in line with the ordinary rotation cycles.
9. Liability
Liability of the parties in relation to this DPA is subject to the limitations and exclusions set out in the Terms of Service.
Annex A - Technical and organisational measures
- encryption of data in transit (TLS/HTTPS);
- password hashing using dedicated functions;
- role-based access control (owner, manager, staff) and least-privilege principle;
- per-customer data isolation enforced at database level (row-level security) as well as in the application, and environment segregation;
- verification of incoming webhooks (payments, Telegram) with signatures or secret tokens;
- automatic deletion of data at the end of its retention period;
- regular backups and recovery procedures;
- event logging for security purposes;
- infrastructure providers with recognised certifications (e.g. ISO 27001, SOC 2);
- internal procedures for incident and data breach management.
Contact
Smart Menu - Tirana, Albania
Contact: WhatsApp