Skip to content
Back to GDPR rights

Data Processing Agreement

Our standard GDPR Article 28 DPA. Request a counter-signed copy and we'll return it within 3 business days.

What's in the DPA

Roles

OpenALaCarte acts as a Processor; you (the operator) act as Controller of your diners' personal data. Our current sub-processors are listed below, and we give 30 days' notice before adding one.

Security

Encryption in transit (TLS 1.2+). AES-256-GCM at rest for sensitive credential fields (POS tokens, SSO secrets, sensor secrets); volume- and backup-level encryption follows the hosting and object-store configuration. Production access is role-segregated and audit-logged. No third-party penetration test has been carried out yet — the scope is defined and the engagement is planned. We run a public vulnerability-disclosure programme with safe harbour.

Sub-processors

Stripe (payments and Connect payouts), OVH (hosting — application, database and job worker), IONOS (transactional email), and the OpenStreetMap Foundation (Nominatim), which your visitors' browsers contact directly for location search. Enabled only if you configure them: Twilio (SMS/WhatsApp) and Anthropic (AI features). Analytics is self-hosted, so no third party receives it. 30-day notice on additions; objection rights in Clause 7.

Data residency

Your data is hosted on infrastructure dedicated to OpenALaCarte and shared across our customers, with tenant separation enforced in the application layer. We do not publish a processing region until the datacentre is confirmed from the hosting account. Per-region data residency is not guaranteed by default and is not yet self-serve; it is contractual, available on Enterprise agreements or by request.

Breach notification

We notify you without undue delay, and within 72 hours, of confirmed personal-data breaches affecting your tenancy, with impact assessment + remediation plan.

Audit rights

SOC 2 Type II and ISO 27001 are planned — neither is held today, nor yet under way. We will publish a report when one exists. Customer-initiated audits available on Enterprise contracts with 30-day notice.

Enterprise / custom terms

Custom MSAs, custom indemnification, NET-60 payment terms, and per-region data-residency riders are available on Enterprise contracts. Talk to legal →

Last updated September 2026. Version 1.0.