Data Processing Agreement
A formal agreement governing how Vendo processes personal data on behalf of restaurant operators. Incorporated by reference into the Terms of Service and intended for use by Subscribers (and their lawyers) who need a DPA on file.
Parties
- Data Controller: the Subscriber (restaurant operator) that has accepted Vendo's Terms of Service.
- Data Processor: MoonFactory LLC, doing business as Vendo, registered in the State of Georgia, United States.
1. Definitions
The following terms have the meanings given in the EU General Data Protection Regulation (GDPR), or the analogous concept under other applicable law:
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data.
- Data subject — the natural person to whom personal data relates.
- Supervisory authority — the data protection regulator with jurisdiction over the Controller.
- Subprocessor — a third party engaged by the Processor to process personal data on the Controller's behalf.
2. Scope and purpose
Vendo processes personal data solely to provide the platform services described in the Terms of Service. Specifically:
- Categories of data subjects: the Subscriber's staff and the Subscriber's customers (diners).
- Types of personal data: names, contact information (phone, email), delivery addresses, order history, payment tokens (not card numbers), staff roles, and authentication credentials.
- Duration: the term of the Subscriber's subscription agreement, plus the deletion timelines stated in the Terms of Service.
3. Processor obligations
Vendo will:
- process personal data only on the Controller's documented instructions (the Terms of Service and the Subscriber's configuration of the platform constitute those instructions);
- ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations;
- implement the technical and organizational security measures described in Section 4;
- not engage a new subprocessor without giving the Controller prior notice as described in Section 5;
- assist the Controller in responding to data subject rights requests (access, deletion, portability, correction);
- assist the Controller with data protection impact assessments where required by law;
- delete or return all personal data on termination as described in Section 9 of the Terms of Service (30-day export window, deletion within 90 days);
- make available to the Controller information necessary to demonstrate compliance with this DPA.
4. Security measures
The specific technical and organizational measures Vendo applies today:
- Transport encryption: TLS 1.2 or newer on every connection, enforced at the Cloudflare edge.
- Infrastructure: dedicated server hosted by Hetzner in Germany, not shared cloud instances.
- Access control: role-based access at the application layer; individual staff accounts; no shared logins.
- Audit logging: append-only logging of every data-modifying administrative operation.
- Backups: automated backups on a regular schedule.
- Incident response: a documented internal process for identifying, containing, and reporting security incidents.
- Personnel: access to production data limited to authorized MoonFactory personnel under confidentiality obligations.
5. Subprocessors
- The current list of subprocessors is published at /legal/subprocessors.
- Vendo will provide at least 30 days' written notice before engaging a new subprocessor.
- The Controller may object within that 30-day window. If the objection cannot be resolved, the Controller may terminate the subscription without penalty.
- Vendo binds every subprocessor to data-protection obligations no less protective than this DPA.
6. Data breach notification
If Vendo becomes aware of a personal data breach affecting the Controller's data, Vendo will notify the Controller without undue delay, and in any event within 72 hours of becoming aware. The notice will include, to the extent then known: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to mitigate.
7. Audit rights
- The Controller may audit Vendo's compliance with this DPA.
- Audits require 30 days' written notice, take place during normal business hours, and may occur no more than once per 12-month period.
- The Controller bears the cost of the audit.
- Vendo may satisfy audit requests by providing relevant certifications, third-party audit reports, or written documentation in lieu of an on-site audit, where the requested information is available in that form.
8. International transfers
- Primary storage of platform data is in Germany, on Hetzner infrastructure, within the EU.
- U.S.-based subprocessors (Stripe, Cloudflare) receive limited data necessary for their function. Transfers to the United States are covered by appropriate safeguards including the EU Standard Contractual Clauses where applicable.
- Vendo will not transfer personal data to a jurisdiction without adequate protection unless an appropriate transfer mechanism is in place.
9. Term and termination
- This DPA is effective for the duration of the Subscriber's subscription.
- Obligations regarding data deletion and confidentiality survive termination.
10. Liability
Liability under this DPA is subject to, and combined with (not in addition to), the limitation of liability in the Terms of Service.
11. Order of precedence
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of personal data, this DPA controls. For all other matters, the Terms of Service control.
12. Contact
Data protection contact: legal@vendo.pizza.
