Data Processing Agreement pursuant to Art. 28 GDPR
As of: August 2026
Preamble
This data processing agreement (hereinafter "DPA") specifies the data protection obligations of the parties in the context of using the MenuMonkeys Service. It forms part of the General Terms and Conditions and becomes binding upon conclusion of the contract between the using business and the Provider.
Controller (hereinafter "Client") is the business using the Service (hospitality/hotel business).
Processor (hereinafter "Contractor") is AzApp.one GmbH, Mitländerstrasse 20, 71642 Ludwigsburg, Germany.
1. Subject matter, nature and purpose of the processing
The Contractor processes personal data on behalf of and according to the instructions of the Client, insofar as this is necessary to provide the Service (digital QR ordering and guest communication system). The subject matter is in particular the receipt, storage, display and transmission of order, reservation and – where activated – guest contact data as well as the associated notification of the business.
2. Duration
The processing takes place for the term of the underlying main contract. The DPA ends with its termination; the obligations to delete or return (Section 10) continue to apply.
3. Nature of the data and categories of data subjects
The categories of data processed and of data subjects result from Annex 1.
4. Client's right to issue instructions
The Contractor processes the data exclusively within the scope of the agreements made and according to the documented instructions of the Client. Use of the Service and its configuration are deemed to be an instruction. If the Contractor considers an instruction to be unlawful, it informs the Client; it is entitled to suspend implementation until confirmation.
5. Obligations of the Contractor
The Contractor
- processes the data only according to instructions and not for its own purposes;
- obliges the persons authorised to process the data to maintain confidentiality;
- takes the technical and organisational measures pursuant to Art. 32 GDPR in accordance with Annex 2;
- supports the Client, as far as possible, in fulfilling data subjects' rights (Art. 12–23) and obligations under Art. 32–36 GDPR;
- reports personal data breaches without undue delay after becoming aware of them (Section 9);
- provides the Client with the information necessary for verification and enables audits (Section 8).
6. Technical and organisational measures
The Contractor maintains the technical and organisational measures described in Annex 2 and adapts them in line with the state of the art. Any change must not fall below the agreed level of protection.
7. Sub-processors
The Client grants general authorisation for engaging the sub-processors named in Annex 3. The Contractor ensures that corresponding data protection obligations (Art. 28(4) GDPR) are met by these. The Contractor will notify intended changes (addition/replacement) in good time; the Client may object for good, data-protection-related cause.
8. Audit rights
Upon request, the Contractor demonstrates compliance with its obligations – primarily by means of suitable evidence, reports or certificates. Insofar as necessary, it enables inspections by the Client or an auditor commissioned by the Client after reasonable prior notice and without disrupting operations.
9. Notification of data breaches
The Contractor informs the Client without undue delay of any breaches of protection of the data processed on its behalf and supports the Client in fulfilling its notification and communication obligations under Art. 33 and 34 GDPR with the available information.
10. Deletion and return
After completion of the processing, the Contractor deletes the data processed on behalf or returns it at the Client's choice, unless there is a statutory retention obligation. During the term of the contract, the Client can export or delete its data itself via the export and deletion functions provided.
11. Liability and final provisions
The statutory provisions and the rules of the main contract apply to liability. In the event of contradictions between the DPA and the main contract, the provisions of this DPA take precedence with regard to data protection. German law applies.
Annex 1 – Types of data and categories of data subjects
Categories of data subjects: guests and end customers of the business, hotel guests, employees of the business (users of the application).
Types of data:
- order data: order items, notes, table/room number, time, amount
- optional guest contact data (only when activated): name, email, phone
- reservation data: name, email, phone, party size, time, shortened IP hash, proof of consent
- push registrations (endpoint and key of the device)
- user/master data of business employees: name, email, role, access data (as a hash)
Annex 2 – Technical and organisational measures (Art. 32 GDPR)
- Confidentiality: role-based access control (RBAC), tenant-separated data storage, passwords as bcrypt hash, encrypted storage of sensitive keys/secrets (AES-256-GCM), pseudonymisation (e.g. shortened IP hash instead of plaintext IP).
- Integrity: encrypted transmission (TLS/HTTPS), access and change logging (audit logs), input validation, rate limiting of security-critical endpoints.
- Availability and resilience: hosting in an EU data centre (Hetzner, Germany), daily encrypted backups with limited retention, access protection of the database (no public reachability).
- Procedures for regular review: security reviews, logging of security-relevant events, separation of permissions (principle of least privilege).
Annex 3 – Approved sub-processors
- Hetzner Online GmbH (Germany) – server hosting and backup storage
- Cloudflare, Inc. (EU/USA, SCC) – TLS termination, security, delivery
- Resend, Inc. (EU/USA, SCC) – transactional email
- Google Ireland Ltd. / Google LLC (USA, SCC/DPF) – AI menu import and translation
- OpenAI and Groq, Inc. (USA, SCC) – AI fallback
- Stripe Payments Europe Ltd. / Stripe, Inc. (EU/USA, SCC/DPF) – payment processing of the plan subscription
- Telegram (only when the notification function is activated by the business) – transmission of order notifications to the operator chat
Note: If the business uses optional own connections (e.g. its own point-of-sale, payment or printer system), their data protection arrangement lies within the business's area of responsibility.