This document applies automatically to every Menivo customer and forms an integral part of our Terms and Conditions. It does not need to be signed separately — accepting the Terms also means accepting this agreement. If you need a signed copy for your GDPR records, write to office@menivo.io.
1. Parties and subject matter
This Data Processing Agreement ("DPA") is concluded, pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"), between:
- The Controller — the Menivo customer, that is the restaurant, bar, café or other entity holding an account on the Platform and determining the purposes and means of processing its own customers' data; and
- The Processor — WEB DESIGN BY PC MAINTENANCE S.R.L., J08/804/2018, tax ID 39172796, which processes that data solely on behalf of and on the instructions of the Controller.
The subject matter of this DPA is the processing of personal data of the Controller's end consumers — the restaurant's own customers — carried out through the Menivo Platform.
What this DPA does not cover: your account data, your representatives' data and billing data. For those, Menivo acts as a controller in its own right, and the applicable rules are set out in our Privacy Policy.
2. Details of the processing
| Element | Description |
|---|---|
| Subject matter | Provision of the digital menu, reservations, online ordering, POS and reviews platform |
| Duration | For the term of the subscription agreement, plus the deletion periods in section 10 |
| Nature of processing | Collection, storage, structuring, consultation, transmission to the Controller, erasure |
| Purpose | Solely to provide the Platform's functionality to the Controller |
| Categories of data subjects | The Controller's customers and prospective customers who book, order or leave reviews |
| Categories of data | Name, phone number, email address, delivery address, party size, reservation date and time, notes, order contents, review rating and text, IP address and user agent (for reviews, as an anti-fraud measure) |
| Special categories | Not intentionally processed. Free-text notes may contain dietary preferences which, in some contexts, could reveal sensitive data — the Controller is responsible for not soliciting such information |
3. Menivo's obligations as processor
We undertake:
- to process the data only on documented instructions from the Controller — use of the Platform's features constituting such instructions — unless EU or Romanian law requires otherwise, in which case we will inform you beforehand unless the law prohibits it;
- not to use end-consumer data for our own purposes, not to sell it, and not to use it for our own marketing;
- to ensure that persons authorised to process the data have committed to confidentiality;
- to implement the technical and organisational measures set out in section 6;
- to assist you in meeting your obligations regarding security, breach notification, impact assessments and prior consultation with the authority;
- to make available the information necessary to demonstrate compliance with Article 28 GDPR.
If we consider that an instruction received from you infringes the GDPR or Romanian law, we will inform you without delay.
4. Your obligations as controller
As the controller, you are responsible for:
- having a valid legal basis for every processing operation you initiate through the Platform;
- informing end consumers through your own privacy policy, which should mention that you use Menivo as a technology provider;
- configuring the Platform so that you collect only necessary data — for example, not requesting unnecessary fields in the reservation form;
- responding to data subject requests addressed to you;
- not entering special categories of data (health, religious beliefs, biometric data) into the Platform and not soliciting such information from consumers;
- ensuring that your staff's access to account data is limited to what each role requires.
5. Sub-processors
You give us general authorisation to engage sub-processors in providing the service. The current list is as follows:
| Sub-processor | Service | Processing location |
|---|---|---|
| ROMARG S.R.L. | Web hosting, database and file storage | Romania (EU) |
| Sendinblue SAS (Brevo) | Sending confirmation emails to consumers | France (EU) |
| Meta Platforms Ireland Ltd. | WhatsApp Business Cloud API for notifications and support | Ireland (EU) / United States |
| Anthropic PBC | AI features: allergens, nutritional values, translations, support assistant | United States |
| OpenAI, L.L.C. | Image generation for editorial content | United States |
We impose on each sub-processor, by contract, data protection obligations at least equivalent to those in this DPA, and we remain fully liable to you for their performance.
We will inform you at least 30 days before adding or replacing a sub-processor. If you object on reasonable grounds, you may terminate the subscription without penalty, with a pro-rata refund of the unused period.
6. Security measures
In accordance with Article 32 GDPR, we apply the following technical and organisational measures:
- encryption of traffic via HTTPS/TLS on all connections;
- storage of passwords only as hashes, using modern algorithms;
- irreversible hashing of IP addresses in consent logs;
- role-based access control, separating administration and staff permissions;
- logical isolation of data between different customers' accounts;
- cryptographic signature verification of requests received through external webhooks;
- login attempt throttling and protection against automated attacks;
- regular backups with restore capability;
- regular security updates of the platform and its dependencies;
- logging of significant administrative operations.
7. Security breach notification
We will notify you without undue delay and within 48 hours at the latest of becoming aware of a security breach affecting data processed on your behalf.
The notification will describe the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. We will give you the support you need to notify the supervisory authority within the 72-hour period that applies to you as controller.
8. Assistance with data subject requests
If an end consumer contacts us directly to exercise their rights, we will not respond on the merits; we will tell them that you are the controller and forward the request to you without delay.
Through the Platform interface we provide you with the means to access, correct, export and delete your consumers' data. Where a request cannot be resolved through the interface, we will provide reasonable technical assistance at no additional cost.
9. International transfers
Primary processing takes place on servers located in Romania. Transfers to sub-processors in the United States (Anthropic, OpenAI and, in certain circumstances, Meta) are carried out on the basis of the Standard Contractual Clauses adopted by the European Commission and/or the EU-US Data Privacy Framework, supplemented by additional technical measures such as encryption in transit and minimisation of the data transmitted.
10. Deletion and return of data
On termination of the agreement, at your choice:
- we will make available to you, on request, an export of the data processed on your behalf, within 30 days; and
- we will delete the data from active systems within 30 days of termination, and from backups within a maximum of 90 days, as those backups rotate.
Deletion does not apply to data we are legally required to retain — in particular accounting documents, which are archived for 10 years under Romanian Law no. 82/1991.
11. Audit
On written request, we will make available the information necessary to demonstrate compliance with this DPA. You have the right to carry out an audit, or to mandate an independent auditor bound by confidentiality, no more than once per calendar year, on reasonable notice of at least 30 days, during normal business hours and without disrupting operations.
Additional audits requested beyond that limit may be carried out at your expense, except where the audit follows a confirmed security breach.
12. Term and termination
This DPA takes effect upon acceptance of the Terms and Conditions and remains in force for as long as we process personal data on your behalf. The provisions on confidentiality, deletion and liability survive termination.
In the event of a conflict between this DPA and the Terms and Conditions, this DPA prevails in respect of the processing of personal data.
WEB DESIGN BY PC MAINTENANCE S.R.L.
Trade Register: J08/804/2018 · CIF: 39172796 (not registered for VAT)
Registered office: Str. Viitorului, Săcele, jud. Brașov, România
Email: office@menivo.io · Phone / WhatsApp: +40 770 322 147
Web: menivo.io