Data Processing Agreement
How Menu.ceo processes personal data on behalf of restaurant customers.
1. Key Terms
This Data Processing Agreement ("DPA") is between Menu.ceo and the restaurant, company, or other legal entity using the Service ("Customer"). It forms part of the Terms of Service and applies when Menu.ceo processes personal data on Customer's behalf.
- Controller or business: Customer, because Customer decides why and how hosted-menu visitor data is collected.
- Processor or service provider: Menu.ceo, because we process Customer Personal Data to provide the Service under Customer's instructions.
- Subprocessor: a provider Menu.ceo uses to process Customer Personal Data while delivering the Service.
- Customer Personal Data: personal data Menu.ceo processes on Customer's behalf through hosted menus, analytics, or related support.
Terms such as personal data, process, controller, processor, business, and service provider have the meanings given by the applicable data-protection law. If this DPA conflicts with the Terms about processing Customer Personal Data, this DPA controls.
2. Scope of Processing
Menu.ceo processes Customer Personal Data to host and secure Customer's menu, measure menu visits, attribute visits to shared links and campaigns, provide reports, troubleshoot the Service, and perform related support requested by Customer.
People whose data may be processed
- Visitors to Customer's hosted menu
- Customer's account users and team members
- People whose information Customer includes in submitted restaurant or menu content
Categories of data
- IP address, browser, device type, operating system, user agent, approximate region, and related identifiers
- Referrer, campaign parameters, short-link source, page activity, supported interactions, and timestamps
- Account contact details, team access information, support content, and restaurant information
- Menu text, images, logos, restaurant photos, and other content submitted by Customer
The Service is not designed for special-category or sensitive personal data. Customer will not intentionally submit or use the Service to collect that data unless the parties agree in writing and applicable law permits the processing.
Customer's documented instructions consist of this DPA, the Terms, Customer's Service configuration, and lawful instructions submitted through support. Processing continues for the subscription term and any limited retention period in Section 3.
3. Data Retention
- Hosted-menu analytics history is retained for up to 3 years on Starter and up to 5 years on Growth while needed to provide historical reports.
- Account, menu, uploaded, and support data is retained while needed to provide the Service and for a limited period after account closure for recovery, security, dispute, or legal needs.
- Customer may request deletion of Customer Personal Data at any time, subject to applicable law and technical backup cycles.
At the end of the Service, Menu.ceo will delete or return Customer Personal Data on request unless applicable law requires retention. Data retained by law remains protected by this DPA and will not be processed for another purpose.
4. Subprocessors
Customer gives Menu.ceo general authorization to use subprocessors needed to provide the Service. Depending on the features Customer uses, subprocessors may include:
- Cloudflare: infrastructure, content delivery, and security
- Anthropic and Google: AI-assisted processing of Customer-submitted menu content
- Resend: requested support and service-message delivery
Menu.ceo requires subprocessors to protect personal data under terms that are materially consistent with this DPA. Menu.ceo remains responsible for each subprocessor's performance of its data-protection obligations to the extent required by applicable law.
We may add or replace subprocessors as the Service changes. We will update this page and provide additional notice when required by law. Customer may raise a reasonable data-protection objection by contacting us promptly after receiving notice.
5. International Data Transfers
Menu.ceo operates from the United States, and subprocessors may process data in the United States or other countries. This may involve transferring personal data outside the country where it was collected.
Where applicable law requires a transfer mechanism, the parties will rely on an approved mechanism, such as an adequacy decision or applicable Standard Contractual Clauses, together with supplementary safeguards where required.
6. Security Measures
Menu.ceo maintains reasonable technical and organizational safeguards appropriate to the nature of the Service and the risks of processing, including:
- Encryption in transit through HTTPS/TLS
- Authentication and role-based account access controls
- Access restrictions for authorized personnel
- Rate limiting and abuse-prevention controls
- Infrastructure and security services from trusted vendors
- Procedures for investigating security incidents
Personnel authorized to process Customer Personal Data are subject to confidentiality obligations. Menu.ceo will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data, as required by law, and will provide reasonably available information needed for Customer's response.
7. Roles and Responsibilities
Customer responsibilities
- Provide lawful, fair, and documented processing instructions
- Establish a lawful basis and obtain consent where required
- Give menu visitors clear privacy and cookie notices
- Configure the Service and Customer's content in compliance with applicable law
- Receive and respond to privacy-rights requests from menu visitors
Menu.ceo responsibilities
- Process Customer Personal Data only on documented instructions unless law requires otherwise
- Keep Customer Personal Data secure and confidential
- Assist Customer reasonably with data-subject requests, security obligations, impact assessments, and regulator inquiries
- Provide information reasonably necessary to demonstrate compliance with this DPA
- Allow a reasonable compliance review or audit when required by applicable law, subject to confidentiality, security, and reasonable scope and timing restrictions
8. Data Access and Deletion
Customer can access available account, menu, and analytics data through the Service. Available exports reflect the data processed and stored by the selected plan and current product functionality; Menu.ceo does not promise a consolidated raw event-log or archive export unless expressly offered.
Customer may request access assistance, correction, export, restriction, return, or deletion by emailing privacy@menu.ceo. Menu.ceo may verify the request and may charge reasonable costs for unusually burdensome assistance where applicable law permits.
9. Governing Law
This DPA is governed by the laws of the State of California, United States, without regard to conflict-of-law rules. Any dispute relating to this DPA will be resolved as stated in the Terms of Service unless applicable data-protection law requires otherwise.
This DPA becomes effective when Customer accepts the Terms or first uses a Service feature that involves Menu.ceo processing Customer Personal Data on Customer's behalf, whichever is later.