Data Processing Agreement
This DPA is entered into between the Customer (the Controller) and [company legal name] (the Processor) and applies to personal data within Customer Data processed by the Processor on the Controller's behalf in providing the MiseOS service. Terms defined in the Terms of Service and in UK GDPR have the same meaning here.
1. Roles and scope
The Controller determines the purposes and means of processing personal data entered into its Venues; the Processor processes it only to provide, support and secure the Service. Details of the processing are set out in Annex A.
2. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions (which include the Terms of Service, this DPA, and the Controller's use of the Service's features), unless required otherwise by law, in which case the Processor will inform the Controller unless prohibited;
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Annex B;
- assist the Controller, taking into account the nature of processing, in responding to data subject rights requests; the Controller manages its own staff's requests using the Service's tools where possible, with Processor assistance where needed;
- assist the Controller with obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs) taking into account the information available to the Processor;
- notify the Controller without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting the Controller's personal data, providing information reasonably required for the Controller's own notifications;
- at the end of provision of the Service, make Customer Data exportable for 30 days and then delete personal data from live systems, with backup copies overwritten in the normal backup cycle (not exceeding [35] days), unless retention is required by law;
- make available information reasonably necessary to demonstrate compliance with this DPA and, no more than once in any 12-month period and on at least 30 days' notice, allow an audit limited in scope to the Processor's compliance with this DPA, at the Controller's cost and without access to other customers' data.
3. Subprocessors
- The Controller gives general authorisation to the subprocessors listed in Annex C (also published at /subprocessors).
- The Processor will give at least 14 days' notice of intended additions or replacements via that page [and email to account holders]; the Controller may object on reasonable data-protection grounds, in which case the parties will discuss in good faith and the Controller may cancel affected Venues if the objection cannot be resolved.
- The Processor imposes data-protection obligations on subprocessors materially equivalent to this DPA and remains responsible for their performance.
4. International transfers
Where processing involves transfer of personal data outside the UK, the Processor ensures a valid transfer mechanism: UK adequacy regulations (including the UK–US Data Bridge where the recipient is certified) or the UK International Data Transfer Addendum to the EU SCCs.
5. Controller obligations
The Controller warrants it has a lawful basis for the personal data it records; will inform its staff about the processing (the Processor's privacy policy §1 supports this); will not record special-category data (for example health details in time-off notes) — free-text fields are not intended for such data and the Service does not solicit it; and will manage Team Member access and removal.
6. Liability
Liability under this DPA is subject to the exclusions and cap in the Terms of Service, to the extent permitted by data protection law.
Annex A — Details of processing
- Subject matter & nature: hosting, storage, synchronisation, backup, display, export, and — on the Controller's instruction through use of the features — AI-assisted processing (transcription of invoice images to structured prices, recipe/dish import, Sous responses, voice synthesis) of data within the Controller's Venues.
- Duration: the term of the Controller's use of the Service plus the export/deletion period in §2.7.
- Purpose: provision of kitchen-operations software to the Controller.
- Categories of data subjects: the Controller's staff and workers (who may include 16–17-year-old employees); supplier contact persons; the Controller's own users.
- Categories of personal data: names; contact details; role/title; employment terms relevant to rota costing (pay rates, contracted hours, holiday); shift and attendance records; time-off records; sign-offs and attributions on food-safety and operational records; invitation email addresses; supplier contact details.
- Special categories: none intended or solicited (see §5).
Annex B — Technical and organisational measures
- Encryption in transit (TLS) for all client–server and server–provider traffic.
- Venue-level isolation enforced by row-level security in the database; authenticated access via the identity provider; role-based permissions within Venues controlled by the Controller.
- Provider-managed encryption at rest.
- Server-side secret management: AI provider keys held as environment variables and never exposed to clients; all AI calls proxied and authenticated.
- Daily backups with [point-in-time recovery]; backup retention within the cycle in §2.7.
- Guards against bulk destructive operations propagating through sync; deploy history enabling rollback.
- Least-data metering: AI usage metered as counts and token totals, not content.
- Offline-first design limiting data loss during connectivity failure.
Annex C — Authorised subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, storage, sync | EU (Frankfurt) |
| Netlify | Application hosting and serverless functions | US/global |
| Stripe | Payment processing | US/EU |
| Anthropic | AI text processing on instruction | US |
| Google (Gemini API) | Voice synthesis on instruction | US |
| [email provider] | Transactional email (invites, notices) | [region] |
