Data Processing Agreement
Our standard GDPR Article 28 DPA. Request a counter-signed copy and we'll return it within 3 business days.
Download DPA (PDF)
Sent by email while the download is being finalised
Request counter-signed copy
Reply within 3 business days
What's in the DPA
Roles
OpenALaCarte acts as a Processor; you (the operator) act as Controller of your diners' personal data. Our current sub-processors are listed below, and we give 30 days' notice before adding one.
Security
Encryption in transit (TLS 1.2+). AES-256-GCM at rest for sensitive credential fields (POS tokens, SSO secrets, sensor secrets); volume- and backup-level encryption follows the hosting and object-store configuration. Production access is role-segregated and audit-logged. No third-party penetration test has been carried out yet — the scope is defined and the engagement is planned. We run a public vulnerability-disclosure programme with safe harbour.
Sub-processors
Stripe (payments and Connect payouts), OVH (hosting — application, database and job worker), IONOS (transactional email), and the OpenStreetMap Foundation (Nominatim), which your visitors' browsers contact directly for location search. Enabled only if you configure them: Twilio (SMS/WhatsApp) and Anthropic (AI features). Analytics is self-hosted, so no third party receives it. 30-day notice on additions; objection rights in Clause 7.
Data residency
Your data is hosted on infrastructure dedicated to OpenALaCarte and shared across our customers, with tenant separation enforced in the application layer. We do not publish a processing region until the datacentre is confirmed from the hosting account. Per-region data residency is not guaranteed by default and is not yet self-serve; it is contractual, available on Enterprise agreements or by request.
Breach notification
We notify you without undue delay, and within 72 hours, of confirmed personal-data breaches affecting your tenancy, with impact assessment + remediation plan.
Audit rights
SOC 2 Type II and ISO 27001 are planned — neither is held today, nor yet under way. We will publish a report when one exists. Customer-initiated audits available on Enterprise contracts with 30-day notice.
Enterprise / custom terms
Custom MSAs, custom indemnification, NET-60 payment terms, and per-region data-residency riders are available on Enterprise contracts. Talk to legal →